Security

External security checks

As of: September 2026

We follow a list of companies that are growing fast. From time to time we will offer one of them a free security check of its public website, and this page is the exact terms of that offer: what we touch on your domain, when, what we keep, and how you say no.

1. What we do

Everything starts with your request, and with a human on our side. A domain is only scanned after a researcher has confirmed your free-check request (your email address is part of that check). If we approached your company first, a domain is only scanned after someone in your company has answered our offer with "run it". A full pentest is a separate, later conversation, and it happens under a signed written scope or not at all. Until then nothing goes deeper than the check itself.

2. What actually happens

  • at most ~300 web page requests to your domain (~200 per host), ~1 per second, in one ~10-20 minute window
  • one US residential IP address. If that line drops, the check is re-run once, not more.
  • plain web requests throughout: no logins, no payloads, no port scan, nothing sent to your systems, robots.txt respected
  • subdomains are looked up in certificate logs and DNS records, never brute-forced

3. How often

One run per signal. A second run happens when you reply or when something new shows up, and you hear about it before it goes. Beyond that we don't touch your domain.

4. Say no, once, forever

Enter your domain and work email below. If your email matches the domain, your entry becomes final the moment you click the confirmation link. Otherwise our team reviews it within a day. While your domain is listed, it is not scanned and not emailed.

We store your name, email and area only to verify this request. EU servers. Details: Privacy.

5. The report is yours

Keep the written report, share it, ignore it; whether a collaboration follows or not changes nothing on our side. Nobody else sees our findings. The data sits on EU servers (Google Cloud, EU region); an email to sales@rheono.dev and we delete the report and the raw logs.

6. Contact

sales@rheono.dev. The imprint is linked at the bottom.