Pulse review queue, PII, and expected-behavior whitelist
Pulse scans are public, but visitor email, IP hash, and referrer are never exposed. A review queue catches unexpected findings before they show as failures.
Quick answer
Pulse scan scores and issues are public. The visitor's email, IP hash, referrer, and user agent are private — only the scan owner and backend can see them.
What's public vs private
Public: domain, scores, screenshot, list of issues
Private: visitor email, IP hash, user agent, referrer, session metadata
Expected-behavior whitelist
Some findings are noisy on legitimate sites (e.g., missing HSTS on staging)
The Pulse review queue tags these before they surface as failures
Reviewed patterns feed the shared whitelist for future scans
Where to find it in Lemwatch
/pulse — scan URL. Admins see the review queue at /admin/pulse-review.
FAQ
Can I make a Pulse scan private?
No — Pulse is a public tool. For private monitoring, claim the site into your dashboard.
How long are scans kept?
Scored data indefinitely; PII fields auto-purge on a rolling window.