We run scanners against other people’s infrastructure. That obliges us to state precisely what we do, refuse, and retain.
Active testing requires proof of control
Use DNS TXT, a known-path file, a meta tag, or an authenticated provider connection. A checkbox is insufficient.
Authorization expires
Proof is rechecked. Scheduled scans pause when control can no longer be verified.
Sensitive targets receive human review
Government, healthcare, financial infrastructure, and shared hosting ranges are reviewed before active testing.
What we never do
No denial of service, destructive payloads, credential stuffing, use of secrets found in code, or third-party scanning.
Allowlist only these currently configured addresses when your own WAF would otherwise hide coverage.
Match the address with the signed scan reference in your logs before changing a rule.
Scan queue
Normal · 40s median wait
UI runners
Normal
AI triage
Normal · 6s median
API
Normal