Legal

Scan Consent & Authorisation

Effective 8 July 2026

The Prodable scan is a read-only, non-destructive look at a URL's public surface — the same things any visitor or search engine can already see. Here's exactly what it does, and what you're confirming when you run one.

What the scan is

When you submit a URL, Prodable makes ordinary web requests to it and inspects what comes back — the way a browser or a search engine crawler would. It is read-only and non-destructive. We look at your public surface only; we do not see inside your database, your backend, or anything behind a login.

You must be authorised

Your responsibility
Only submit a URL you own or are authorised to have security-tested. Scanning a site you don't control may be unlawful, and that responsibility is yours, not ours. By running a scan you confirm you have the right to test that target.

What we look at

Across roughly 48 checks in several categories, the scan inspects things like:

What we never do

Targets we may decline

To keep the scanner responsible, we may refuse or block certain targets at our discretion — for example government domains or third-party sign-in pages that aren't yours to test.

What a scan stores

A scan records the target URL, your IP address (for rate-limiting), the findings, and — only if you choose to unlock the full report — your email address. Full detail is in our Privacy Policy. To keep the service fair, scans are rate-limited per IP.

A clean scan is not a guarantee

A good score means we didn't find the issues we check for from the outside — not that your app is free of all vulnerabilities. Security is ongoing, and a deeper look (the Fix, with your access) covers what an external scan can't reach. See our Terms of Service for the full picture.