Security scan
A real penetration test against a site you have proved you own, run by a model in a loop.
- 01Forms a hypothesis
- 02Tests it
- 03Reads what came back
Goes again
Leaves the loop
A vulnerability is reported only once the model has demonstrated it with a working proof-of-concept. That is why the report is short and everything in it is real.
Proving the domain is yours
This is the gate, and it is deliberately strict.
Security scan › Prove domain ownershipYou are given a token. Publish one of these records, then press Check now.
Either one proves it
TXT
- Name
_zerolog-verify.yourdomain.tld- Value
- the token you were given
CNAME
- Name
_zerolog-verify.yourdomain.tld- Value
<token>.verify.zerolog.ch
Only in addition
A
- Name
- the apex
- Value
- our published ingress IP
Accepted only alongside a TXT or CNAME proof, never on its own.
TXT and CNAME are equally strong. CNAME exists because some DNS panels make it easier. The A record on its own proves too little, because plenty of things can point an A record at us.
Re-checked, not stamped
Verification is re-checked, not stamped once. Remove the record and the domain loses verified status at the next check, and scans against it stop. That is intentional: authorisation is a fact about now, not a box you ticked in March.
Running one
- 01
Add and verify the domain.
- 02
Pay for the scan. It is a service you buy each time, not an unlock you buy once.CHF 20 per scan · card or TWINT
- 03
Start it. It runs as a background job, so you can close the browser.
- 04
Read the findings. Each one carries the proof-of-concept that established it.
Model usage during the scan is billed from your ordinary credit on top of the scan fee, priced per request like everything else.
Scope
The scanner cannot leave the target.
- Shell commandsrun in your own container
- HTTP requestsgo out over a network route that only reaches hosts you have verified
This is enforced by the tools the loop is allowed to call, not by asking the model nicely, so it has no way to route around it.
Scan only what you own. Pointing this at somebody else’s infrastructure is unlawful in most places, and the ownership check exists so that the product cannot be used to do it by accident.