As of: September 2026
We follow a list of companies that are growing fast. From time to time we will offer one of them a free security check of its public website, and this page is the exact terms of that offer: what we touch on your domain, when, what we keep, and how you say no.
Everything starts with your request, and with a human on our side. A domain is only scanned after a researcher has confirmed your free-check request (your email address is part of that check). If we approached your company first, a domain is only scanned after someone in your company has answered our offer with "run it". A full pentest is a separate, later conversation, and it happens under a signed written scope or not at all. Until then nothing goes deeper than the check itself.
One run per signal. A second run happens when you reply or when something new shows up, and you hear about it before it goes. Beyond that we don't touch your domain.
Enter your domain and work email below. If your email matches the domain, your entry becomes final the moment you click the confirmation link. Otherwise our team reviews it within a day. While your domain is listed, it is not scanned and not emailed.
Keep the written report, share it, ignore it; whether a collaboration follows or not changes nothing on our side. Nobody else sees our findings. The data sits on EU servers (Google Cloud, EU region); an email to sales@rheono.dev and we delete the report and the raw logs.
sales@rheono.dev. The imprint is linked at the bottom.