We scan websites for a living. That means our customers have every right to ask hard questions about how we handle what we find. This page answers them plainly — no legal jargon, no buried disclaimers.
ScanTitan scans the external-facing assets you specify. Here is exactly what that means in practice.
ScanTitan scans only the external URLs, domains, and subdomains you explicitly add to your account. We probe them from the outside — the same perspective an attacker would have.
We do not scan internal infrastructure, employee devices, internal networks, or any asset outside the scope you define. Our scanner sends HTTP requests and analyzes responses — it does not require installation on your server or access to your source code.
Scan findings (detected vulnerabilities, malware signatures, exposed assets) are stored in your account so you can track remediation progress over time. This data is stored on servers within the EU.
We do not sell, share, or publish your scan findings. We do not use your findings data to train models or enrich third-party threat databases.
If you provide login credentials for authenticated scanning (available on paid plans), those credentials are encrypted in transit using TLS 1.2 or higher. They are used only during the active scan session and are not stored beyond it.
Scan findings are retained for the duration of your active plan. When you cancel, your data is retained for 30 days to allow export, then deleted.
Under GDPR Article 17 (right to erasure), you can request immediate deletion of your account data at any time by emailing [email protected]. We action deletion requests within 72 hours.
All communication between your browser and ScanTitan is encrypted using TLS 1.2+. Data at rest is encrypted using AES-256. Our portal is served over HTTPS with HSTS enforced.
ScanTitan uses a limited number of third-party sub-processors (cloud infrastructure, payment processing, email). A full list of sub-processors is available in our Data Processing Agreement.
We never sell personal data or scan findings to advertisers, data brokers, or analytics companies.
ScanTitan is registered in the Netherlands. GDPR compliance is not optional for us — it's the legal baseline we operate under by default.
A DPA is available for all business customers. It covers ScanTitan's role as a data processor, your rights as the data controller, sub-processor obligations, and breach notification procedures under GDPR Article 33.
Email [email protected] with "DPA Request" in the subject. We'll send it within one business day.
If you've found a security vulnerability in ScanTitan's platform, we want to hear about it. Security researchers who report issues in good faith are not at legal risk from us — ever.
Send your report to [email protected]. Include: the affected URL or component, steps to reproduce, your assessment of impact, and any proof-of-concept (screenshots, request/response pairs).
You'll receive a confirmation with a tracking reference. A member of our security team will review and respond with our initial assessment.
We aim to remediate confirmed vulnerabilities within 30 days. We'll notify you when the fix is deployed and, with your permission, credit you in our changelog.
Our team responds within one business day. No bots, no ticket queues — a real answer from a real person.