Allowlist these so your WAF does not hide problems from your own scan. Every scan also reports its egress address on the finding.
Active testing requires proof of control
A DNS TXT record, a file at a known path, a meta tag, or an authenticated provider connection — a checkbox is never sufficient on its own.
Authorization expires
Proof is rechecked on a schedule. Scheduled scans pause rather than continue against a target we can no longer verify.
Sensitive targets get manual review
Government, healthcare, financial infrastructure and known shared-hosting ranges are reviewed by a person before any active test.
What we never do
No denial of service, no destructive payloads, no credential stuffing, no testing of credentials found in code, and no scanning of third-party hosts.
Allowlist these so your WAF does not hide problems from your own scan.
Every scan reports its egress address on the finding, so you can tie traffic in your logs to a specific run.
Scan queue
Normal · 40s median wait
UI runners
Normal
AI triage
Normal · 6s median
API
Normal