For the person looking at our traffic
If a request from us reached your server, this page explains who we are, whether the target owner authorized it, and how to stop it.
Sightrove runs website security, code security, and UI quality checks for companies that requested them. Every active request exists because control was proved and a scan was requested.
Reach a human at abuse@sightrove.com. We read that inbox; it is not a form.
A request alone is never enough. No checkbox, plan, or role authorizes a target. Proof is checked again before active work.
The dependable identifier in normal server, WAF, and CDN logs is User-Agent. User-Agent.
User-Agent: Sightrove/1.0 (authorized security scan; +https://sightrove.com/scanning)We identify ourselves instead of pretending to be browser traffic.
A second header carries the exact reference for one request:
X-Sightrove-Scan: prm_01a00445-532d-7000-b063-83e33f470053The value identifies the signed, target-scoped authorization for that scan; it is not an account or workspace identifier.
Automated lookup is not available yet. Send the X-Sightrove-Scan reference to abuse@sightrove.com and we will confirm within one business day.
These are current egress addresses from guarded deployment configuration. Examples are never substituted.
Full detail on the scanner egress page.
Email abuse@sightrove.com with the target host and scan reference. New requests for that target are blocked before they are sent; an in-flight request finishes only within its signed rate and byte budget.
Found a vulnerability in Sightrove itself? Responsible disclosure uses a separate inbox and process.