LEGAL

SCAN POLICY

Last updated July 25, 2026. What we check, what we never do, and how to keep your site out of our scans.

What a free scan runs

HTTP security headers and TLS/certificate metadata, DNS/robots/ sitemap metadata, public JavaScript and asset inspection, safe HEAD/GET requests against obvious public files, and technology fingerprinting. All of it is passive and uses only what a normal visitor's browser would already see.

What we never do

No exploit attempts or destructive tests, no form fuzzing or credential testing, no authenticated or internal scans without your explicit consent, no high-volume crawling, and nothing designed to degrade a site's availability.

Deeper, verified checks

Checks that go beyond public data (like repository or database configuration review) only run after you verify you own the target and grant explicit access. We never scan authenticated areas of a site without that verification.

Rate limits and load

Our scanner is rate-limited and designed to be indistinguishable from a single ordinary visitor's traffic. If a site owner ever believes our scan caused a problem, contact us immediately at [email protected] and we'll investigate.

Opting your site out

If you don't want your site scanned, even if someone else submits your URL, email [email protected] from an address associated with the domain and we'll add it to our exclusion list.

See also our Responsible Disclosure policy for reporting a vulnerability in our own platform.