Transparency by design

Security and Safe Scanning

The security boundaries around public website scans.

Public websites only

The scanner restricts schemes and ports, rejects credentials and queries, checks DNS for private and special addresses, and revalidates redirects. Download sizes, parser work and scan duration are bounded.

Bounded workload

An edge IP rate limit, global daily admission ceiling and expiring host lease limit free usage. Requests are sequential within each scan and honor the scanner’s robots policy. Browser execution is disabled.

Private evidence

Fetched markup is data, never executed. Evidence is inserted as text. Targets and page bodies are excluded from application logs and third-party analytics. DNS preflight is not connection pinning; runtime egress and redirects require production security review.


Scoring methodology · Data sources · Free tools