Responsible Scanning Policy
1. Our scanning philosophy
Custodis exists to help organizations understand their external attack surface without becoming part of the problem. Every scan we run is designed to be non-intrusive, attributable, and easy to identify. We do not exploit vulnerabilities, we do not attempt to bypass authentication, and we do not perform any action that a benign internet observer could not perform. Our scans are read-only probes built on well-established techniques: certificate transparency monitoring, passive DNS enumeration, TLS handshake inspection, HTTP HEAD and GET requests against advertised endpoints, and banner-grab connections to ports that are already responding to the public internet.
2. What we never do
We never attempt to exploit a vulnerability, even one we have detected. We never submit credentials, bypass login pages, or interact with authenticated areas of any application. We never write to forms, post comments, or modify any state on a target system. We never run brute-force password attempts, credential stuffing, or any other authentication-targeting activity. We never perform denial-of-service tests, traffic floods, or any scan pattern designed to degrade availability. We never download significant payloads — our requests fetch only what is needed to evaluate a header, a banner, or a certificate. If a probe would require us to do any of the above, we do not perform it; we surface the question instead.
3. Asset ownership verification
Active scanning is only enabled on assets you have verified ownership of through one of our supported methods: DNS TXT record, a well-known file served at a specific path, or an HTTP response header containing a unique verification token. Verification is re-checked on a rolling schedule, and if a previously verified asset stops responding to the verification challenge, active scanning is paused until ownership is re-established. Subdomains discovered through certificate transparency are attributed to a parent domain only after that parent has been verified; unverified assets remain in a passive observation state where we only ingest publicly logged metadata.
4. Rate limits and scan intensity
Scans are paced to stay well below thresholds a normal service would treat as abusive. We cap requests per host, per port, and per scan window, and we back off exponentially when we observe rate-limit responses, connection resets, or elevated latency. A full scan of a typical asset completes within minutes and generates traffic equivalent to a handful of casual visitors. Customers on higher tiers can request more frequent scans, but the per-scan intensity does not change — we increase cadence, not pressure. If you need us to scan less frequently or from a narrower window, you can configure that in the console at any time.
5. Identifying our traffic
All Custodis scan traffic originates from a published, stable set of IP addresses and carries a distinctive User-Agent string that identifies the platform and links to this policy. Network defenders can obtain our current source ranges, with reverse DNS and ASN information, by writing to abuse@custodis.app. Every request we make also identifies itself in the User-Agent header, which links back to this page. Network defenders are welcome to allowlist our ranges to reduce noise in their intrusion detection systems, or to block them if they prefer — we will not attempt to evade either choice. Changes to the IP allowlist are announced at least thirty days in advance through the same page and our status feed.
6. Customer responsibilities
You may only enable scanning on assets you own or have explicit written authorization to assess. You must not use Custodis to probe assets belonging to third parties, competitors, prospects, vendors, or any other party that has not granted you permission. You must not attempt to evade our rate limits, spoof verification records, or otherwise misrepresent ownership. You are responsible for ensuring that your use of the service complies with applicable law in your jurisdiction and in the jurisdiction of the target asset. Misuse is grounds for immediate termination under section 7 of our Terms of Service, and we will cooperate with law enforcement where required.
7. Reporting abuse or concerns
If you believe Custodis is scanning an asset it should not be, or if you would like us to stop scanning an asset that has been registered to a customer, write to abuse@custodis.app with the affected hostname, IP address, or domain, and a brief description of the issue. We acknowledge every report within one business day and act on confirmed abuse reports within twenty-four hours, including pausing scans against the disputed asset while we investigate. If you are a security researcher who has identified a vulnerability in Custodis itself, please follow the disclosure process at security@custodis.app — we will not pursue legal action against good-faith research conducted under that process.
8. Changes to this policy
We may update this policy as our scanning techniques evolve or as we add new probe types. Material changes — anything that broadens what we scan, changes our IP allowlist, or alters the asset verification requirements — will be announced in-product and via email at least fourteen days before they take effect. Editorial revisions and clarifications are published immediately and noted in the LAST UPDATED date at the top of this page. The current version is always authoritative.
See something we shouldn't be scanning?
Write to abuse@custodis.app.