Draft template - this document must be reviewed and completed by a qualified legal professional before Webforta is offered to customers. Bracketed text marks information that still has to be confirmed.

Security Testing Authorization Terms

What you confirm when you ask Webforta to assess a website.

Your confirmation

By adding a website and starting a scan or monitoring, you confirm that you own the website or hold written authorization from its owner to perform automated, non-intrusive security assessments, and that doing so does not breach any agreement with your hosting provider.

What Webforta does

  • Read-only HTTP and HTTPS GET requests to the verified hostname (and its www/apex variant), plus one OPTIONS request that only reads which methods the server advertises.
  • Requests for a fixed list of commonly exposed files, each matched by content signature, and for a random non-existent path to see how errors are handled.
  • A handful of pages linked from the homepage, and scripts hosted on the verified site, read to identify software versions.
  • One request carrying a made-up Origin header, to check whether the site trusts any origin (CORS).
  • DNS lookups through public resolvers, Certificate Transparency log searches, and lookups in public vulnerability databases. Third-party sites are not scanned.
  • Typical volume: up to about 150 requests per scan, at most 6 in parallel; one request per monitoring check.

What Webforta does not do

  • No exploitation, payload injection, credential guessing or authentication attempts.
  • No port scanning beyond 80 and 443.
  • No crawling beyond the homepage, a handful of pages it links to, and the listed paths.
  • No denial-of-service or load testing.

Identification

Requests identify themselves with the user agent "WebfortaScanner/1.0 (+https://webforta.com/docs/scanner)".


Other policies: Terms of Service · Privacy Policy · Cookie Policy · Acceptable Use Policy · Security Testing Authorization Terms · Data Retention and Deletion Policy · Responsible Disclosure Policy ·