๐Ÿš€ OrcaScope private beta โ€” first 10 design partners get 3 months free Join now!
OrcaScope
Inside the platform

Client portal

Hand a client one read-only link. No account for them, no monthly screenshotting for you.

Does the client sign up?

No โ€” one link is all

Access

Read-only, scoped to that one brand

Revocable?

Yes, instantly

Indexed?

No โ€” explicitly noindex

The shape of it

This diagrams the concept, not the UI โ€” screenshots go stale on every redesign; structure doesn't.

One read-only link: verified server-side, returns a scoped viewYour clientno accountServer verifiessecret stays on the serveronly 4 read pathsRead-only viewthis one brand onlyRevoking takes effect instantly.Invalid and revoked look identical โ€” no existence signal.

What it does

A link is the whole handoff

Works for agencies, and for the exec inside your company who won't create an account.

Shows only what it should

Visibility overview, action-plan progress, before/after re-checks and the white-hat pledge โ€” none of your other brands, no account data.

Revoke whenever

End the engagement, revoke the link, done โ€” no password changes, no awkward notice.

How to get going

  1. 1

    Generate a link for one brand

    One link, one brand. Two clients on two brands means two links.

  2. 2

    Send it to the client

    They open it and it works โ€” no account, no password, nothing to install.

  3. 3

    Revoke it when you're done

    Once revoked the link stops working immediately, and your other links are untouched.

How it actually works

These live behind a login, so you can't verify them on the spot. That's exactly why the mechanics are spelled out here; each line maps to a specific implementation.

The link is the key โ€” and the key never leaves the server

The server recomputes the link's signature with a secret that is never sent to the browser. So a link can't be guessed and can't be forged.

The portal can only call four dedicated read paths

It has no general query capability โ€” only four fixed functions that return whitelisted fields. Even if the portal layer were compromised, what's reachable is capped by design.

Invalid and revoked look identical

A wrong link, a revoked link and a never-existed link all return the same page. Distinguishing them would tell a prober "this one was real".

What it can't do

This section matters as much as the ones above. Leaving it out would decide "this fits me" on your behalf.

  • Clients can look; they can't change anything.
  • One link covers one brand โ€” there's no all-brands link.
  • Anyone holding the link can view it โ€” it's a capability link, so forward it like a password.

Other capabilities

Want real numbers before signing up?

The free checkup needs no account and shows you in 30 seconds how AI answers your category today.

Run a free checkup
Client portal ยท OrcaScope