WEBSCOPEPILOT
Security and scanning approach
Restricted external requests
The scanner accepts HTTP and HTTPS on standard ports. It checks every returned DNS address, connects directly to a validated public address, and validates each redirect again. Private, loopback, link-local, metadata and this service’s own addresses are blocked. There is one scanning worker and bounded request size and duration.
Data protection
Passwords and recovery codes are hashed using Django. TLS protects browser traffic. Reports require the originating session or account. The application runs under a dedicated non-root service account. Production secrets are stored outside the source repository.
Honest limitations
These are basic passive checks, not a security certification. No external scanner can prove that a website is secure. Local backups help recover software or data mistakes but do not protect against loss of this VPS.
Report a concern
Use the in-app support form to describe a suspected issue with minimal reproducible details. Do not include passwords or secrets, access other users’ data, perform denial-of-service tests or exploit unrelated systems. No paid bounty is offered.