Security
An audit should never put your website at risk
VeriFixScan performs safe, non-destructive checks and is engineered with a security-first architecture from Phase 1.
Non-destructive by design
VeriFixScan only reads. It does not submit forms with real data, delete content, modify records or attempt exploits of any kind. It is an audit tool, not a penetration testing tool.
Respectful crawling
Crawls are rate-limited, identify themselves with a clear user agent and respect robots directives and crawl budgets so your server is never overloaded.
SSRF-hardened scanning
Because the scanner fetches user-provided URLs, the engine resolves and validates every target server-side: private, loopback and link-local ranges are blocked, redirects are limited and re-validated, and requests are timed out.
Secrets stay server-side
API keys for future integrations live in server environment variables only. No secret is bundled into frontend code and no privileged key is ever sent to the browser.
Protected accounts
Authentication is built on a managed provider with hashed credentials, session-based access and row-level authorization so a user can only ever read their own projects and scans.
Minimal data
We store what is required to run and show your audits. Scan targets are your own public URLs; we do not resell or share your data.
Responsible disclosure
Found a security issue in VeriFixScan? Tell us before telling anyone else and we will work with you on a fix.
