Scanner policy

What our scanner does, precisely.

If you have found requests from ShipSafe in your logs, this page tells you exactly what they were and why. If you would rather we never touched your site again, the form at the bottom takes effect immediately and needs nothing from you but a domain.

User-Agent
ShipSafe-Scanner/1.0 (+https://shipsafe.world/scanner)

Fixed and never rotated. We do not spoof a browser and we do not use residential proxies. Attackers hide; we announce ourselves.

What we request
  • Your home page, once.
  • The JavaScript files that page links to, same-origin only, up to 12.
  • Any source map those files point at.
  • One HEAD request for response headers.
  • /robots.txt, which we honour.

That is the complete list for an unverified target. It is the same set of files any visitor’s browser downloads when they open your site.

What we never do
  • Log in, submit a form, or send a credential of ours.
  • Write, modify, or delete anything.
  • Enumerate. No ID walking, no directory brute-forcing, no wordlists.
  • Store a response body. Ever — not in a log, not in a cache, not in our database.
  • Attempt to bypass a control, defeat rate limiting, or evade detection.
  • Scan government, military, banking, or major-platform domains. Refused in code.
  • Scan an IP address, a private network address, or a cloud metadata endpoint.
Requests to your backend

6 of our 39 checks send a request to an application’s own backend — for example, asking a database for a row count. Those only ever run against a domain whose owner has proved control of it by placing a token we issued on the site, and every such request is recorded with the proof it relied on.

Where we do check a database, we ask for a count rather than rows, so the response body is empty by construction. We learn whether a table is world-readable without any of its contents reaching us.

Limits
  • 8s per request, 45s per scan
  • at most 24 requests per scan
  • at most 3 redirects, re-checked at every hop
  • 2MB per file, 8MB per scan
  • at most 3 checks against one target per hour, from anyone
  • every scan is tied to a signed-in account that accepted our terms
Records we keep

For every scan we record the time, the exact URLs requested with their methods and status codes, the authorisation it relied on, and the version of our Terms in force. We keep those records for 24 months. If you ask what we did to your site, that is what we will show you.

Contact

scanner@shipsafe.world — a person reads this and replies within 24 hours.

Do not scan my site

No account. No questions. Immediate.

Enter a domain and we will never request anything from it again. This covers subdomains, applies to everyone including our own paying customers, and we do not verify that you own it — the cost of being wrong in your favour is a lost prospect, and that is the cheaper mistake.

Related: Terms · Privacy