Scanning policy

What we did, and how to make us stop

If we contacted you about your website's configuration, you did not ask us to look, and it is reasonable to want to know exactly what we did. This page is the full answer. It is also the page to use if you want a finding corrected or your domain left alone — no account, no form, one email.

The short version

We loaded your home page once, the way a browser would, and read public DNS and public certificate records. We did not log in, guess at hidden paths, scan ports, or send anything crafted. We never publish an individual company's result. Email paul@mysecscan.com and we will correct a wrong finding or stop scanning your domain entirely.

Exactly what we requested

What we deliberately did not do

We never publish your result

Our published research reports aggregate percentages across hundreds of companies, with sample sizes. No individual company is named, and no per-company finding is published, ever. A list of individually weak sites would be a target list, not research. If we wrote to you about a specific finding, that finding went to you and to nobody else.

Why we think this is proportionate

Everything above is information your systems publish to anyone who asks: the response your web server gives every visitor, DNS records the email system depends on being readable, and a transparency log certificate authorities are obliged to write to. We do not go behind any access control, and we do not test whether one could be bypassed.

Where a person's data is involved — a name or address in a public business contact record — we process it on the basis of legitimate interests under Article 6(1)(f) GDPR, for the purpose of telling an organisation about a security weakness in its own infrastructure and offering to help fix it. We hold the minimum needed for that, we do not enrich it, we do not sell or share it, and the objection right below overrides the interest on request, with no reason required.

This is a description of what we do and why, not legal advice, and it is not a claim that any particular assessment is lawful in your jurisdiction. If you believe it is not, tell us and we will stop.

Corrections, objections and exclusion

One email to paul@mysecscan.com with your domain. You do not need an account, and you do not have to explain why.

We answer within five business days. If something is urgent — a finding you believe is live and exploitable — say so in the subject line and we will treat it as such.

The technical detail of how each check works is in how we scan; how we handle data generally is in the privacy policy.