← All articles

Getting started

How Cyber Report works, from sign-up to PDF.

Cyber Report is an external security scanner for websites you own. You point it at a domain, prove you control that domain, and we run a battery of non-intrusive checks against it — then hand you a prioritised report you can act on or share with a developer.

The flow, end to end

  1. Create an account and confirm your email address.
  2. Submit a domain from the “New scan” screen.
  3. Verify ownership — a one-time step that proves the domain is yours. See Verifying domain ownership.
  4. We fingerprint the site — detect the stack, TLS setup, headers and DNS posture — and decide which checks apply.
  5. We run the applicable scanners, each in an isolated, ephemeral container, rate-limited so we never overload your site.
  6. You get a report: a risk score, findings grouped by severity, a compliance posture overlay, and a downloadable PDF.

What makes a scan safe

  • We only run active checks after you’ve proven ownership. Passive lookups (DNS, certificate transparency, WHOIS) may run before that, but nothing that sends traffic to your site does.
  • Outbound requests are rate-limited per target, so a small site won’t be knocked over.
  • Every scanner runs in a throwaway container with no standing access to your infrastructure.

Re-scanning

Security posture drifts. You can re-scan a domain any time, or put it on a schedule (a paid-plan feature) so we re-check automatically and show you a diff of what changed since last time. See Understanding your report.