How PenScan Protects Your Data

Every component of PenScan is designed with security-first principles. Here's exactly how we protect your data and your customers.

Your data is private, isolated, and encrypted.

We hold our own platform to the same standards we help you achieve for yours.

You can only scan what you own
PenScan never scans a target until DNS ownership is cryptographically verified. No third-party domain can be tested without demonstrable control — by design, not policy.
Your data is invisible to other tenants
Multi-tenant architecture ensures complete data isolation. Each organisation's targets, scans, and reports are inaccessible to every other account on the platform.
Role-based access control
Granular RBAC with Owner, Analyst, and Viewer roles. Team members can only access the functionality their role requires — nothing more.
Immutable audit logs
Every scan, target verification, and configuration change is logged with full attribution. Audit logs support compliance requirements and give auditors the evidence trail they ask for.
Encrypted in transit & at rest
All data is encrypted in transit via TLS 1.3 and at rest. Scan results, credentials, and API tokens are never stored in plaintext.
Legally compliant by design
Users acknowledge a legal disclaimer before initiating any scan. PenScan's Terms of Service prohibit unauthorized testing, enforced by the ownership verification requirement — not just stated in a checkbox.

You can only scan what you own

PenScan's Target Guard is an enforcement layer that prevents scanning of any domain without proven ownership. There are no exceptions — not even for administrators.

DNS TXT record verification
PenScan generates a unique cryptographic token per target. You add it as a DNS TXT record on your domain. We verify it before any scan can begin.
Per-target unique tokens
Each target receives its own unique verification token. A token for one domain cannot be reused to verify another — ever.
Legal acknowledgement required
Before any scan, users must explicitly acknowledge the legal disclaimer confirming authorization to test the target. This is enforced in the UI, not just the Terms of Service.
Verification flow
1
Add your target domain
PenScan generates a unique TXT record token immediately.
2
Add the TXT record in your DNS
Takes 1–5 minutes with most DNS providers.
3
PenScan verifies ownership
DNS lookup confirms the token matches your domain.
Scanning unlocked
Full scan capabilities available. Asset discovery already complete.

Show your customers you're secure

After scanning, generate a verifiable security certificate and an embeddable widget to display on your website. Build customer confidence visibly.

Verifiable certificates

Each certificate is cryptographically tied to a completed scan. Anyone can verify it's genuine by checking the certificate ID.

Embeddable widgets

Add a security badge to your website with a single line of HTML. The widget always reflects your most recent scan status.

Customer-facing proof

Win enterprise deals by showing prospects a current, verifiable security posture — not a year-old PDF from an external auditor.

Stop hoping you're secure.
Know that you are.

Add your domain, verify ownership with a DNS record, and run your first full security assessment. No consultants, no contracts, no infrastructure to manage.

2 free credits included  ·  No credit card required  ·  Credits valid for 1 year