Skip to main content

Scanning Transparency

Exactly what our scanner observes, how it identifies itself, and the lines it never crosses.

Effective Date: July 5, 2026

1. Passive, Published-Data Observation

Public scans observe only data a domain already publishes to the internet:

  • DNS records, queried through public DNS-over-HTTPS resolvers (Cloudflare, Google, Quad9, NextDNS, Mullvad).
  • TLS certificates and protocol parameters from a standard TLS handshake.
  • HTTP response headers from ordinary GET requests to standard endpoints.
  • Published policy files that exist to be read: robots.txt, security.txt, mta-sts.txt, llms.txt, ai.txt, ai-plugin.json, and similar well-known paths.
  • Certificate Transparency logs and RDAP/WHOIS registration status (with personal contact data redacted by default).

2. What We Never Do

  • No exploitation, no vulnerability payloads, no crafted injection attempts.
  • No authentication bypass attempts and no credential testing of any kind.
  • No port sweeps of arbitrary services; we talk to standard web, DNS, and mail-policy endpoints.
  • No scraping of page content beyond the policy files listed above.
  • AI-surface checks (for example MCP endpoint discovery) are detection-only on public scans: we check whether a published endpoint exists and responds, and never probe past it.

Deeper diagnostics that require authorization are only ever run on domains whose ownership has been verified inside a customer account, under our Terms of Service.

3. How We Identify Ourselves

Our HTTP checks send an identifying User-Agent of the form Vysiro-*Scanner/1.0 (+https://www.vysiro.com), so server operators can attribute and, if they wish, block our traffic. Scans are rate-limited (public scans are limited per IP, and scanner requests use short timeouts and no retries against the target) to keep our footprint negligible.

4. Point-in-Time Results

Every result reflects public data observed at the moment of the scan, evaluated by a versioned, deterministic methodology (published here). Configurations change; re-scan any time for a current result. Scores are opinions based on this observed data, not statements of fact - see our Dispute & Correction Policy.

5. Abuse Contact & Opt-Out

Questions or complaints about scanner behavior: Support@vysiro.com (subject “Scanner”). Domain owners can opt out of public scan pages - the process is described in the Dispute & Correction Policy. We publish our own security.txt and welcome security reports about our platform.