← sycrion.ru

Security

What we scan, and what we don't

Passive external checks using public data sources. Exact scope, data handling, and disclosure — documented.

EU hosting

Frankfurt · Vercel EU

TLS 1.3

Encrypted · HSTS

Passive only

Read-only · zero writes

Scan scope

Passive & read-only — only what your server already returns to any client.

  • DNS — A, MX, NS, TXT, SPF, DMARC, DKIM, CAA, DNSSEC
  • TLS/SSL — protocol versions, certificate validity, expiry, chain
  • HTTP headers — server strings, security header presence
  • Certificate Transparency (crt.sh) — subdomain enumeration
  • Shodan passive data — open ports & banners (no active scan)
  • Common path validation — low-impact probes, no form submission
  • JS bundle analysis — accidental secret exposure patterns
  • NVD/EPSS lookup — versions cross-referenced against CVE data

What we never do

  • Send authenticated requests or attempt login
  • Exploit or trigger any identified vulnerability
  • Store data from the scanned domain beyond HTTP responses
  • Scan internal networks or non-public endpoints
  • Probe admin panels or application logic
  • Modify any configuration, files, or state

Scope limitation

External surface only. A clean result does not guarantee your application is free of all vulnerabilities.

Data retention

Data

Retention

Notes

Scan results

12 months

Auto-deleted after expiry.

Domain submitted

12 months

Stored & deleted with results.

Email address

Until deletion

Report delivery only. Never sold.

Server-log IP

30 days

Standard logs, auto-deleted.

Payment data

Not stored

Handled entirely by Stripe.

Site content

Not collected

Headers & metadata only.

False positives

Passive scanning produces false positives. Version banners don't confirm vulnerable software; path probes confirm HTTP responses, not exploitability.

If a finding is inaccurate, send the domain, finding ID, and why. We review within 5 business days.

security@sycrion.com

Responsible disclosure

Found a vulnerability in our platform? Report it responsibly. We acknowledge within 48 hours.

security.txt

https://sycrion.ru/.well-known/security.txt
security@sycrion.com

Infrastructure

Hosting

Vercel EU · Frankfurt

Database

Neon Postgres · EU · encrypted at rest

Email

Resend · transactional only

Payments

Stripe · PCI DSS L1

Sycrion · Privacy · Methodology