Privacy

This service is built to collect as little data as technically possible. No accounts, no third-party analytics or trackers of any kind, and no cookies at all unless you verify domain ownership (see below).

What we process, and why

We never store the raw output of the underlying scanning tools (testssl.sh, ssh-audit, nmap, …), only the processed findings/grades that are actually shown to you.

Email delivery test (/mailtest)

The mail delivery test works differently from the domain scan: instead of a target you type in, we generate a random, single-use email address and wait for you to send a real message to it from the mailbox you want to test.

Like the domain scan, requests to generate a test address are rate-limited per IP address (see above). We don't keep a separate 30-day abuse log for this feature, since a test address never targets third-party infrastructure, only the mailbox you choose to send from.

Legal basis

Processing is based on legitimate interest (Art. 6(1)(f) GDPR) in operating the service securely, preventing abuse of the scanning infrastructure, and, for the cache and public leaderboard described above, in avoiding unnecessary repeated scans against third-party infrastructure and in providing a public overview of scan results in the spirit of transparency (opt-out available at any time).

Persistent storage & deletion

Unlike an earlier version of this service, scan results and domain verification status are now kept in a database rather than only in a short-lived Redis cache (see above for what exactly is stored and for how long). Want a specific result deleted, or have questions about what's stored for a given target? Contact us via the imprint or theabuse contact and we'll remove it.

Server logs

The underlying web server / reverse proxy may keep standard technical access logs (IP, request, timestamp, user agent) for operational and security purposes for a limited time, like any web server.

Questions about this policy? See the imprint for contact details.