Skip to content

Security at DevScan AI

A testing tool must never become a risk to the sites it tests or the people who use it. These are the controls built into DevScan.

Scanner network isolation

Every outbound request from our scanners, browsers and load workers passes through an egress guard that resolves DNS itself, refuses private, internal, link-local and cloud-metadata addresses, and connects only to the address it validated. The scanner cannot be used to reach internal networks.

Non-destructive testing

Scans are passive: we crawl, render and observe. We never submit forms, buy things, send messages, exploit vulnerabilities, brute-force passwords or scan ports. Security checks look at configuration only.

Load testing only with proof of ownership

Load tests require verified domain ownership (DNS, file or meta tag), an explicit authorization statement, fixed presets, automatic abort when a site becomes unstable, and an emergency stop.

Account security

Passwords are hashed with Argon2id. Sessions use HttpOnly, Secure, SameSite cookies with CSRF protection, can be listed and revoked, and login, signup and password-reset endpoints are rate limited.

Encryption of secrets

GitHub tokens, API-test headers, user-flow credentials and webhook secrets are encrypted at rest with keys stored outside the database. API keys are shown once and stored only as hashes.

Private by default

Reports are private to your workspace. Share links are unguessable, read-only, can expire and can be revoked. Secrets are redacted before any AI analysis and never written to logs.

Found a vulnerability? Please report it responsibly to [email protected].