3 ms·
Good question! As you already hinted, we will not disclose all our security measures. But our platform is secured on multiple levels. First of all, all commun
by dolfje 11y ago
Good question!
As you already hinted, we will not disclose all our security measures.
But our platform is secured on multiple levels.
First of all, all communication between you and our server is encrypted. No eaves-dropping possible. So only you known your own vurnabilities.
Second because you have to verify your server, a thirdy party can't get secret vurnability data about your system. So they cannot use our system as easy tool to get attack vectors.
Third we separate the scan logic and webserver logic into different servers. And only the scanner has information about passwords and secret information. So while we make our webserver very safe, the scan server is fort knox. One particular nice thing, the scanner server has no open incoming ports. So you cannot access it.
Fourth the PHP dectector file will only react to our server and all data exchange is encrypted with keys only known to the scan server. The commands that have to be executed are also signed with assymetric keys, signed on an offline computer.
Fifth we keep improving our security while monitoring our systems (with our service but also with other tools). Because new attack vectors are released everyday.