SECURITY BY DESIGN
Scanner security
Public-URL testing is constrained to limit access, preserve evidence integrity and prevent unintended actions.
Destination controls
Only HTTP/HTTPS on standard ports is accepted. The scanner validates DNS answers and connects to a validated public address through an egress proxy, including redirected destinations and subresources. Private, loopback and special-purpose addresses are denied.
Isolated, bounded visits
Browser sessions start clean and close after each test. Page, request, byte and time limits bound the work. Downloads are disabled. The scanner does not purchase, log in, submit complaints or send chatbot messages.
Account and evidence controls
Single-use sign-in tokens and session tokens are stored as hashes. Reports require ownership or explicit sharing. Evidence stays private in storage and is served through the same access checks. Rule edits and account actions are logged.
Production verification
Before public launch, the deployment requires an isolated browser-worker network, secure secrets, HTTPS, restricted database access, tested backups, correct reverse-proxy headers and a security review. Local testing does not establish production isolation.