Methodology

Safety and limitations

The passive-request boundary, public-report visibility, and the questions a light scan cannot answer.
Read as Markdown

Safety boundary

The light scan makes capped, passive requests to public HTTP and HTTPS targets. It does not authenticate, submit forms, invoke API or MCP tools, send messages, create data, guess credentials, scan ports, exploit vulnerabilities, or bypass access controls.

Only public targets are accepted. Every redirect and extracted URL is checked again before it is requested.

Public results

Light-scan reports are public and may appear in the public scan directory. Do not submit private staging domains, internal URLs, or URLs containing sensitive information.

The preview API shares the visible form's safety validation and durable rate limits. It is for low-volume evaluation, not bulk processing.

Not a certification

A light check cannot prove that signup, billing, email, authenticated workflows, JavaScript-rendered controls, search ranking, accessibility compliance, security, privacy, legal compliance, or user demand is correct.

Use a scoped deep scan when explicit owner authorization is available and a review needs source, configuration, dependencies, or selected workflows.