Security & trust

ScanTitan Security & Data Handling — What We Scan, Store, and Never Touch

We scan websites for a living. That means our customers have every right to ask hard questions about how we handle what we find. This page answers them plainly — no legal jargon, no buried disclaimers.

Last reviewed: June 2026

What we scan, what we store, what we don't touch

ScanTitan scans the external-facing assets you specify. Here is exactly what that means in practice.

What we scan

ScanTitan scans only the external URLs, domains, and subdomains you explicitly add to your account. We probe them from the outside — the same perspective an attacker would have.

We do not scan internal infrastructure, employee devices, internal networks, or any asset outside the scope you define. Our scanner sends HTTP requests and analyzes responses — it does not require installation on your server or access to your source code.

What we store

Scan findings (detected vulnerabilities, malware signatures, exposed assets) are stored in your account so you can track remediation progress over time. This data is stored on servers within the EU.

We do not sell, share, or publish your scan findings. We do not use your findings data to train models or enrich third-party threat databases.

Authenticated scanning credentials

If you provide login credentials for authenticated scanning (available on paid plans), those credentials are encrypted in transit using TLS 1.2 or higher. They are used only during the active scan session and are not stored beyond it.

How long we keep your data

Scan findings are retained for the duration of your active plan. When you cancel, your data is retained for 30 days to allow export, then deleted.

Under GDPR Article 17 (right to erasure), you can request immediate deletion of your account data at any time by emailing [email protected]. We action deletion requests within 72 hours.

Encryption in transit and at rest

All communication between your browser and ScanTitan is encrypted using TLS 1.2+. Data at rest is encrypted using AES-256. Our portal is served over HTTPS with HSTS enforced.

Third-party data sharing

ScanTitan uses a limited number of third-party sub-processors (cloud infrastructure, payment processing, email). A full list of sub-processors is available in our Data Processing Agreement.

We never sell personal data or scan findings to advertisers, data brokers, or analytics companies.

Compliance status

ScanTitan is registered in the Netherlands. GDPR compliance is not optional for us — it's the legal baseline we operate under by default.

GDPR compliance (EU Regulation 2016/679) Active
Data Processing Agreement (DPA) available Available on request
EU data residency (scan findings stored in EU) Active
TLS 1.2+ encryption in transit Active
AES-256 encryption at rest Active
SOC 2 Type II certification In progress
ISO 27001 certification In progress

Request a Data Processing Agreement

A DPA is available for all business customers. It covers ScanTitan's role as a data processor, your rights as the data controller, sub-processor obligations, and breach notification procedures under GDPR Article 33.

Email [email protected] with "DPA Request" in the subject. We'll send it within one business day.

Responsible disclosure policy

If you've found a security vulnerability in ScanTitan's platform, we want to hear about it. Security researchers who report issues in good faith are not at legal risk from us — ever.

1

Email us with the details

Send your report to [email protected]. Include: the affected URL or component, steps to reproduce, your assessment of impact, and any proof-of-concept (screenshots, request/response pairs).

2

We acknowledge within 2 business days

You'll receive a confirmation with a tracking reference. A member of our security team will review and respond with our initial assessment.

3

We fix, then notify you

We aim to remediate confirmed vulnerabilities within 30 days. We'll notify you when the fix is deployed and, with your permission, credit you in our changelog.

[email protected]

In scope

  • scantitan.com and all subdomains
  • portal.scantitan.com (customer portal)
  • ScanTitan API endpoints
  • Authentication and session handling
  • Data access / privilege escalation

Out of scope

  • Denial of service attacks
  • Social engineering of our staff
  • Physical security
  • Third-party services we use
  • Volumetric testing without prior consent

Security FAQ

Yes — findings are stored in your account so you can track remediation over time. We do not share, sell, or publish your scan findings with any third party. You can request deletion of your data at any time under GDPR Article 17 by emailing [email protected].
No. Credentials provided for authenticated scanning are encrypted in transit using TLS 1.2+ and are used only during the scan session. They are not retained beyond the duration of the scan. We recommend using a dedicated test account with limited permissions for authenticated scans.
Yes — our vulnerability scanner sends real HTTP requests to your site, similar to what an attacker would send. This means Web Application Firewalls (WAFs) and Intrusion Detection Systems (IDS) may flag or block scan traffic. We recommend whitelisting our scanner IP ranges (available in your account settings) before running a full scan, or testing on a staging environment first.
Yes. ScanTitan is registered in the Netherlands and processes data under GDPR. We act as a data processor for your scan data and a data controller for your account data. A Data Processing Agreement (DPA) covering Articles 28 and 32 obligations is available for all business customers — email [email protected] to request it.
Email [email protected] with full details. We acknowledge all reports within 2 business days and commit to not pursuing legal action against researchers acting in good faith. See our responsible disclosure policy above for the full process.

Questions about how we handle your data?

Our team responds within one business day. No bots, no ticket queues — a real answer from a real person.