Browser plans
Your browser plan stays in memory while the planner is open. It is saved to this browser only when you choose “Save locally”, and you can delete it from the planner. Export files are created on your device.
You can separately choose to remember the latest support result so the site can compare it after its bundled browser data changes. This is opt-in browser storage, is not synchronised, and can be cleared with “Delete saved plan”. Imported .browserslistrc,package.json, policy, and result files are read locally and are not uploaded. Imported policy values, decision-record fingerprints, and optional two-part decision packets are also created only on the visitor's device. A packet repeats the selected browser-policy result and supplied reduced evidence, so it should be reviewed before sharing. Command-line Markdown and JUnit reports can repeat bounded names, opaque identifiers, exceptions, and findings; review the visibility and retention of any CI artifact or workflow summary that receives them.
Your browser is not detected
ControlCurrent does not detect your installed browser or its capabilities, and it does not fingerprint visitors. You choose the browser versions to check.
Evidence you paste or load
Pasted response headers stay in page memory. The site does not visit a URL, save your input, or include complete header values, cookie names, or cookie values in the result. Login credentials are refused. Remove secrets before pasting and use “Clear” when finished.
Advanced evidence files may contain a page list, HTML, local resource bytes, selected request headers, reduced passkey settings, and expected evidence for each page. Markup is read without being run and resources are not loaded. Files chosen or dropped into the website are held in page memory only. Exported reports omit the original page list, excluded page reasons, HTML, resource locations and bytes, inline content, CSP nonces and hashes, request targets, credentials, cookies, passkey challenges, and user or credential IDs.
Exports still contain the non-identifying labels you provide, application and environment IDs, revision and build IDs, producer ID, capture times, page requirements, reduced counts, and fingerprints. Use neutral identifiers rather than names, URLs, or other sensitive details. A fingerprint can reveal later changes but does not prove who produced the original evidence.
The optional command-line signature check keeps only its result and the approved signer identity. It does not retain the full signature bundle, certificate, or transparency-log record.
Network connections
Browser compatibility data is included with the static site. The planner and evidence tools make no background request. External documentation links do not receive the page you came from. Optional signature verification is available only in the command-line tool.
A separate command-line collector can gather evidence from a website you are authorised to assess. It requires explicit confirmation, visits only the exact approved origin, follows only redirects on that origin, and sends no cookies or login credentials. Raw collections can still contain sensitive locations or page information, so they must remain private. The collector cannot be started from this website.
ControlCurrent refuses interactive use when it detects an embedded frame. On a shared hosting origin, enter only deliberately redacted examples; use a dedicated reviewed origin before handling organisation-specific evidence.
Deletion
Use “Delete saved plan” in the planner to remove the saved plan and remembered result, or clear site storage in your browser. There is no server copy to request or delete.