Skip to content

How SCARP scans

Know what a run touches before it starts.

The assessment starts with domains you control, observes public exposure, and keeps its evidence in your SCARP tenant. Here is the exact boundary between your team, public sources, and an active run.

01 / First run

What your team provides

You provide domains that your team has verified it owns. You also name the assets that matter most to you. If you do not name them, the run can infer likely relevant assets from public observations; we confirm those assets with you rather than treating an inference as your inventory.

Nothing is installed in your estate. SCARP does not deploy agents or collectors in your environment. Assessments use non-destructive checks and are not designed to change customer systems.

02 / Domain verification

Ownership is checked before active work

Domain verification has two methods. The default is a DNS TXT challenge containing a unique token supplied for that domain.

The alternative is an HTTPS well-known challenge that serves the supplied token as a plain-text response. The check is HTTPS-only and uses the guarded request path.

Domain verification is enabled by default for customer active-scan workflows. A confirmed verification expires after 90 days, so it must be re-established while that tenant policy remains enabled. Exceptional operator workflows are separately governed and audited; this public summary does not treat the default setting as an unconditional gate on every administrative path.

03 / Passive assessment

Public observation, not a change to your estate

A passive assessment consults public sources on your behalf. It looks at certificate and transparency records, internet-exposure and host intelligence, DNS and DNS reputation, routing and ASN data, archived pages, and technology-linked vulnerability intelligence. The keyless sources receive the domain name and/or resolved public IPs relevant to each lookup; routing lookups can also send the customer ASN and prefix, and vulnerability lookups can send technology fingerprints.

The source categories and the boundary for each category are on the Security page. Passive observation does not install anything or write to customer systems.

04 / Active assessment

Explicitly gated requests against verified targets

An active assessment makes requests to the externally reachable surfaces you have authorized so it can check those surfaces directly. Active assessment requires an eligible subscription and an enabled tenant policy. Where that policy requires domain verification or a signed approval workflow, those checks are enforced before launch. Every target is subject to per-target throttling and scan-intensity controls.

Customer-initiated active requests are confined to the authorized target scope. Target validation blocks internal and metadata addresses and pins outbound requests. SCARP uses non-destructive checks and is not designed to modify customer systems; scope and intensity are agreed before the run because customer-controlled endpoints can have their own request side effects.

05 / SOC visibility

Will our SOC see this as an attack?

It may. Active requests exercise the public surface directly, so WAF, bot-detection, and SOC controls may alert on them. Authorization comes from your contract and the agreed scope, together with the verification and approval controls enabled for your workflow.

Traffic currently originates from dynamic cloud egress. A fixed source-IP range and a guaranteed product signature are not available today, so the reliable coordination points are the authorized domains and the scheduled assessment window.

Customers should coordinate the window with their SOC when they want to avoid unnecessary triage. Detection testing without advance SOC notification is available only as a separately documented objective with written approval and an agreed escalation path. The Security page repeats this traffic-identity position alongside the allowlisting answer.

06 / Evidence and storage

What the run leaves behind

The run produces findings, paths, recommended changes, and re-check results; that evidence stays in your SCARP tenant for your team to review. SCARP does not deploy artifacts to the assessed target, although the target may retain its own request logs.

Ready to scope the boundary?

Tell us which domains and assets your team wants to assess.