About the AuditWard scanner
Last updated: June 13, 2026
1. Why You Are Seeing Our Traffic
AuditWard is a security and quality scanning platform. If you found this page from your server logs, an AuditWard customer has requested a scan of a website or application and identified it as one they are authorized to test. Every scan is tied to a customer who has accepted our Terms of Service, which require them to hold all necessary permissions for the systems they scan, and customers verify ownership of their domains via DNS before full scans are permitted.
2. Identifying Our Traffic
Our scanner identifies itself with the following User-Agent string on its HTTP requests:
- AuditWard/1.0 (+https://auditward.com/scanner)
Scan traffic originates from AuditWard infrastructure hosted on Amazon Web Services. The User-Agent string above is the authoritative way to identify our scanner.
3. How Scans Are Authorized
- Scans only run against systems the requesting customer is authorized to test under our Terms of Service.
- Customers verify domain ownership via a DNS TXT record before full scans are permitted. Until a domain is verified, scans are limited to a small set of lightweight, passive checks, and the full active tooling runs only after a domain is verified.
- Every scan session records an authorization audit trail: which domain was verified, who authorized the scan, and when.
- A global scan opt-out registry is checked before any scan starts. Opted-out resources are never scanned, for any customer.
4. How Our Scanner Behaves
- Requests are rate-limited to avoid measurable impact on target systems.
- Paths disallowed by your robots.txt are excluded from crawl-based discovery.
- We never perform denial-of-service or flooding tests.
- Takeover-style weaknesses (for example dangling DNS or storage buckets) are detected and reported only. They are never exploited or claimed.
- Scans against unverified domains are limited to a small set of lightweight, passive checks. The full active tooling, such as port scanning, directory discovery, and vulnerability templates, runs only after domain verification.
5. Opting Out
If you own or operate a system and do not want it scanned by AuditWard under any circumstances, email security@platform.auditward.com with the domain or IP range and evidence that you control it (for example, a DNS TXT record we provide, or a reply from a contact address listed in the domain's WHOIS or security.txt). Once verified, we add the resource to our global opt-out registry. The opt-out is permanent, applies to all customers, and is enforced platform-wide before any scan starts. We confirm the opt-out to you.
6. Reporting Abuse or Problems
If you believe a scan caused a problem, was not authorized, or you have any other concern about our traffic, contact security@platform.auditward.com and include the timestamps, source IPs, and request paths from your logs. We treat these reports with priority and will suspend the offending scan configuration while we investigate. Security vulnerabilities in AuditWard itself are covered by our Responsible Disclosure Policy.