Security
What we scan, and what we don't
Passive external checks using public data sources. Exact scope, data handling, and disclosure — documented.
EU hosting
Frankfurt · Vercel EU
TLS 1.3
Encrypted · HSTS
Passive only
Read-only · zero writes
Scan scope
Passive & read-only — only what your server already returns to any client.
- DNS — A, MX, NS, TXT, SPF, DMARC, DKIM, CAA, DNSSEC
- TLS/SSL — protocol versions, certificate validity, expiry, chain
- HTTP headers — server strings, security header presence
- Certificate Transparency (crt.sh) — subdomain enumeration
- Shodan passive data — open ports & banners (no active scan)
- Common path validation — low-impact probes, no form submission
- JS bundle analysis — accidental secret exposure patterns
- NVD/EPSS lookup — versions cross-referenced against CVE data
What we never do
- Send authenticated requests or attempt login
- Exploit or trigger any identified vulnerability
- Store data from the scanned domain beyond HTTP responses
- Scan internal networks or non-public endpoints
- Probe admin panels or application logic
- Modify any configuration, files, or state
Scope limitation
External surface only. A clean result does not guarantee your application is free of all vulnerabilities.
Data retention
Data
Retention
Notes
Scan results
12 months
Auto-deleted after expiry.
Domain submitted
12 months
Stored & deleted with results.
Email address
Until deletion
Report delivery only. Never sold.
Server-log IP
30 days
Standard logs, auto-deleted.
Payment data
Not stored
Handled entirely by Stripe.
Site content
Not collected
Headers & metadata only.
False positives
Passive scanning produces false positives. Version banners don't confirm vulnerable software; path probes confirm HTTP responses, not exploitability.
If a finding is inaccurate, send the domain, finding ID, and why. We review within 5 business days.
security@sycrion.comResponsible disclosure
Found a vulnerability in our platform? Report it responsibly. We acknowledge within 48 hours.
security.txt
https://sycrion.ru/.well-known/security.txtInfrastructure
Hosting
Vercel EU · Frankfurt
Database
Neon Postgres · EU · encrypted at rest
Resend · transactional only
Payments
Stripe · PCI DSS L1