Scan Scope
This scope describes the public, limited profile for an expressly requested external review. The analysis engine only works against the named host and publicly reachable resources. It is not a licence for arbitrary testing and is not legal advice.
Possible in the public profile
- HTTP/HTTPS availability of the named host
- Publicly visible response headers, including security headers
- The host TLS certificate (issuer, validity, SAN)
- DNS and mail records for the domain (MX, SPF, DMARC)
- robots.txt and sitemap.xml
- Common public paths (health, docs, admin entry, config-shaped files) if they answer without a login
- Publicly shipped JavaScript bundles and source maps, if present
- Secret-shaped strings such as API keys in that public code. Redacted in findings where possible
- Public API documentation (OpenAPI/Swagger), if reachable
- Certificate Transparency names for the named domain
- Framework and stack signals from public HTML and headers
- CORS policy, as far as the origin advertises it
- Non-destructive technical reconnaissance within the agreed frame
Explicitly excluded
- Denial of service
- Intentional service disruption
- Destructive modification or deletion
- Credential stuffing and brute force
- Creating test accounts or logging into customer systems
- Authenticated authorization checks between user accounts
- Exploitation of vulnerabilities
- Persistence or malware
- Social engineering
- Unauthorized lateral movement
- Bulk extraction of exposed personal data
- Access to unrelated third-party systems outside the named target
The final wording should be reviewed by qualified German legal counsel before production launch.
This text is a development draft and must be reviewed by qualified German legal counsel before production use. It is not legal advice.