Frequently asked questions
Short answers to the questions we hear most.
Is scanning safe for my production site?
Yes. Checks are external and non-destructive, outbound requests are rate-limited per target, and each scanner runs in an isolated, throwaway container. We won’t exploit findings or alter your data.
Do I have to verify ownership every time?
No — once per domain. Re-scans and scheduled scans reuse the proof. See Verifying domain ownership.
Can I scan a domain I don’t own?
No. Ownership verification is required before any active scan, by design. Scanning infrastructure you don’t control without permission isn’t something we support.
Why is my scan missing results or looking incomplete?
Usually a firewall or WAF blocked our probes. Allow our traffic and re-scan — see Allowlist our scanner.
What does the risk score mean?
A 0–100 measure weighted by severity and real-world exploitability. It’s for tracking one domain over time, not comparing different sites. See Understanding your report.
Does a clean compliance posture mean I’m certified?
No. The compliance overlay is a non-binding view of what our scan observed — not an official certification. It’s a useful signal, not an audit.
How do I get help fixing findings?
Reports with high- or critical-severity findings show a “Get remediation help” option that reaches our team. You can also email [email protected].