Common questions
Is this safe to run against my production site?
Yes. The free scan uses unauthenticated, non-intrusive probes only — no DOS, no brute force, no exploit payloads that change state. It looks the same to your WAF as a normal vulnerability scanner. Rate-limited to 40 requests/second.
Why do you need my email?
Two reasons: (1) it's how we send you the report — the scan takes a couple minutes and we don't want to make you wait on the page; (2) it lets us rate-limit per address. We don't add you to any marketing list unless you opt in.
My site is behind auth. Will it find anything?
The free scan only tests the public surface. If most of your application is behind login, you'll see mostly header / TLS / public-asset findings here. For a real assessment of the authenticated surface you need our Pen Test ($4,999) where we test from inside the auth boundary with a test account.
Can I scan a competitor's site?
Please don't. Our terms say you must own or have written permission to scan the domain. Unauthorized scanning may violate the CFAA (US) and similar laws elsewhere. We rate-limit per domain partly to deter this.
What if the scan finds nothing?
Good news, but not the whole story. The free scan covers ~7% of the templates our paid tier runs. "Nothing in the free preview" ≠ "nothing real." The paid Automated assessment goes much deeper, and a human Pen Test goes deeper still.