Disclaimer
SecScan's free checkers are a diagnostic aid, not a guarantee. Please read the scope and limitations below before relying on a result.
Not a penetration test or certification
The public checkers perform a passive read of externally visible configuration. They are not a penetration test, a security audit, or a certification of any kind. A clean result means nothing obviously wrong was visible from the outside at the time of the scan — it does not mean an application is secure or cannot be compromised. High-stakes systems still warrant a thorough, authorized penetration test by a qualified professional. See how we scan for the methodology.
Point-in-time and may contain errors
Every result reflects only the configuration observed at the moment of the request. Configuration changes, deployments, CDN behaviour, and transient network conditions can all change the outcome. Results may contain false positives and false negatives. Verify any finding against your own systems before acting on it, and treat the absence of a finding as “not observed”, not “confirmed safe”.
Authorized use only
Although reading public configuration is non-intrusive, you should only scan domains that you own or are explicitly authorized to assess. You are responsible for ensuring your use of the tools complies with applicable laws and any agreements that govern the systems you check.
No warranty, no liability
- The tools and their output are provided “as is”, without warranty of any kind.
- SecScan is not liable for any loss or damage arising from use of, or reliance on, the tools or their results.
- Remediation guidance is general in nature. Test any configuration change in a safe environment before applying it to production.