Scanning policy
If you found this page in your logs, this is who we are and how to make us stop. You do not need an account and you do not need to contact anyone first.
- User-Agent
- SentinelSurface/1.0 (+https://localhost/scanning)
- Abuse contact
- abuse@localhost
- Response time
- Within 24 hours
- Scanner ranges
- Not yet published — this deployment does not scan from a dedicated range.
What we send
- A TCP connection to a fixed list of common service ports, and a read of whatever the service announces on connect.
- A TLS handshake on HTTPS ports, to read the certificate and the protocol versions offered.
- One HTTP GET on / and one on /.well-known/security.txt.
What we never send
- Exploit payloads or proof-of-concept code of any kind.
- Login attempts, credential stuffing, password spraying or brute force.
- Directory brute-forcing, fuzzing or parameter tampering.
- Anything that writes or changes state on your systems.
We read what is already publicly visible. We never attempt to log in, never send an exploit, and never change anything on your systems.
Why we scanned you
Someone proved control of a domain — by publishing a DNS record or a file on the webserver — and asked us to monitor its external exposure. If that domain resolves to your infrastructure, that is why you saw us. If you believe the person who asked had no authority to, the opt-out below takes effect immediately and we will escalate the conflict to a human rather than resolving it in our customer's favour.
Opt out
Submit a domain or a CIDR range and we stop immediately. No account, no verification step, no questions.