Methodology
Every data source, scan type, and documented limitation. We show exactly what we check — and what we can't.
passive — no contact with your servers · active-http — low-impact GET request · active-tls — TLS handshake only
Open ports, CVE tags, version banners from passive scan database.
TLS protocol versions, cipher suites, certificate chain, HSTS, known TLS vulnerabilities.
Subdomain enumeration from public Certificate Transparency logs. No target contact.
Technology fingerprinting, HTTP metadata from historical browser scans.
CVE metadata matched against detected version banners with exploitation probability scores.
Historical URLs for detecting deprecated endpoints and past configuration exposure.
Domain reputation from 90+ security vendor databases.
SPF, DMARC, DKIM, DNSSEC, CAA — direct queries, no target server contact.
Low-impact GET requests to 70 common sensitive paths (.env, admin, config). Status codes only.
Pattern matching against public JavaScript files for 27 categories of exposed secrets.
0–100 indicator of externally observable risk signal density. Not a compliance percentage.
Diminishing returns apply from the 3rd instance of any finding class. “Possible” confidence findings apply at 50% weight. Score clamped to [0, 100].
Separate from severity. A critical finding can have low confidence.
Directly observable. No inference.
Based on observed data with an assumption. Most CVE matches.
Weak signal. Historical or indirect indicator.
External passive scanning has hard limits. These categories require internal access.
Sycrion is not a substitute for penetration testing, DAST, SAST, SCA, cloud configuration review, or internal security audit. It documents external posture as observable from public sources.
Results stored 90 days (free) or 12 months (paid), then deleted.
EU-hosted, Frankfurt region. Processing does not leave the EU.
External queries send the target domain to: Shodan, SSL Labs (US), VirusTotal (US), URLScan.io (EU), crt.sh (EU), NVD (US), FIRST.org (US).
We do not sell scan data or use results for cross-customer benchmarking without explicit opt-in.