Scanning policy
SecretSpan performs external, agentless assessment of internet-facing TLS services. This page states exactly what that involves.
What we do
- Connect to publicly reachable TLS services and complete or abandon a handshake in order to observe the negotiated cryptography.
- Resolve conventional hostnames (www, mail, api, vpn and similar) and scan only those that already exist in public DNS.
- Record the handshake bytes as evidence for the findings we report.
What we never do
- Send application-layer data, credentials, or payloads.
- Attempt exploitation, brute force, or denial of service.
- Attempt to bypass a WAF, rate limiter, or bot protection.
- Enumerate subdomains by brute force. Estate discovery uses certificate-transparency logs and DNS, and requires DNS-TXT proof of domain ownership first.
- Publish reports about any organisation. Customer reports are private.
Authorisation
Estate discovery, continuous monitoring, and the issuing of any attestation all require the customer to prove control of the domain via a DNS-TXT record. A one-time point-in-time assessment does not require that proof: the probes are non-intrusive handshakes against publicly reachable services, and payment identifies the buyer.
We log the relationship between the purchasing account and the requested domain as an abuse signal, and we act on reports.
Rate and volume
Probes for a single host run sequentially with jittered gaps. Concurrency across hosts is rate-limited centrally. A typical host receives roughly 16 short-lived connections per scan.
Contact
To ask about traffic you have seen, or to request that we stop scanning a particular host or network, contact abuse@secretspan.com. We honour removal requests without requiring justification.
Our scanner addresses are published at /scanner-ips.