Security at DevScan AI
A testing tool must never become a risk to the sites it tests or the people who use it. These are the controls built into DevScan.
Scanner network isolation
Every outbound request from our scanners, browsers and load workers passes through an egress guard that resolves DNS itself, refuses private, internal, link-local and cloud-metadata addresses, and connects only to the address it validated. The scanner cannot be used to reach internal networks.
Non-destructive testing
Scans are passive: we crawl, render and observe. We never submit forms, buy things, send messages, exploit vulnerabilities, brute-force passwords or scan ports. Security checks look at configuration only.
Load testing only with proof of ownership
Load tests require verified domain ownership (DNS, file or meta tag), an explicit authorization statement, fixed presets, automatic abort when a site becomes unstable, and an emergency stop.
Account security
Passwords are hashed with Argon2id. Sessions use HttpOnly, Secure, SameSite cookies with CSRF protection, can be listed and revoked, and login, signup and password-reset endpoints are rate limited.
Encryption of secrets
GitHub tokens, API-test headers, user-flow credentials and webhook secrets are encrypted at rest with keys stored outside the database. API keys are shown once and stored only as hashes.
Private by default
Reports are private to your workspace. Share links are unguessable, read-only, can expire and can be revoked. Secrets are redacted before any AI analysis and never written to logs.
Found a vulnerability? Please report it responsibly to [email protected].