Scanning
About ComplianceLayer scanning
Last updated: August 6, 2026
If you found this page from a User-Agent string in your server logs, this is the right place. It explains what ComplianceLayer is, what our scanners do, where the traffic comes from, and how to ask us to stop.
1. What ComplianceLayer is
ComplianceLayer is an external security scanning service. Customers — typically managed service providers and compliance teams — submit a domain and receive a graded report describing that domain's externally observable security configuration. Reports are used as evidence for cyber insurance renewals and compliance audits.
Our customers are required to scan only domains they own or are authorized to assess. That obligation is set out in our Acceptable Use Policy, and we act on reports of unauthorized scanning.
2. What our scanners do
ComplianceLayer performs external, non-exploitative assessment of publicly reachable services. Most checks read information your infrastructure already publishes — DNS records, TLS certificates, HTTP response headers. On authenticated paid scans we also make TCP connection attempts to a fixed list of 17 well-known service ports to determine whether they accept connections.
Specifically, a scan may:
- Resolve DNS records for the domain (A, MX, NS, TXT, SPF, DMARC, DKIM, DNSSEC, CAA)
- Complete a TLS handshake to read the certificate chain and negotiated protocol
- Issue standard HTTP requests to the site root to read response headers and cookie attributes
- Attempt a TCP connection to each of 17 well-known service ports to record whether the port accepts connections
- Query third-party public data sources — Certificate Transparency logs, public blocklists, breach directories — which involves no traffic to your infrastructure at all
3. What our scanners never do
- We do not attempt to exploit any vulnerability
- We do not attempt to authenticate to, guess credentials for, or bypass authentication on any service
- We do not extract, read, or store data from any service beyond the responses described above
- We do not crawl or test paths beyond the site root
- We do not run denial-of-service, fuzzing, brute-force, or load testing of any kind
- We do not install agents or require credentials — there is nothing to deploy on your side
A scan is designed to look, in volume and in kind, like a small number of ordinary requests from an ordinary client.
4. How to recognize our traffic
Our scanners identify themselves in the User-Agent string of every HTTP request they make, and that string links back to this page:
ComplianceLayer-Scanner/1.0 (+https://compliancelayer.net/scanning)
We do not publish a list of scanner addresses. If you see traffic claiming to be ComplianceLayer and want to confirm it actually came from us, email abuse@compliancelayer.net with the source address and an approximate timestamp from your logs, and we will confirm or deny it. A request that carries our User-Agent but that we cannot confirm is someone impersonating us — please report it.
5. Requesting a rescan or disputing a finding
If a report about your organization looks wrong — a finding you believe is inaccurate, or a configuration you have since fixed — you can ask us to re-scan or to review the finding. See Rescans and disputes for how to do that.
6. Requesting exclusion from scanning
If you own a domain and do not want it scanned through ComplianceLayer, you can ask us to block it. We maintain a list of domains that our platform refuses to scan, and a blocked domain cannot be scanned by any customer, on any plan, going forward.
To request exclusion, email abuse@compliancelayer.net from an address at the domain in question, or from an address we can otherwise tie to the domain's registrant, and include:
- The domain or domains you want blocked
- Evidence that you are authorized to make the request for that domain — a reply from the WHOIS or registrar contact, or a DNS TXT record we can verify
We ask for verification only to stop one party from blocking another party's domain. Blocking is free and does not require an account.
Note that exclusion applies to scans run through ComplianceLayer. It does not affect any other scanning service, and it does not remove information that your infrastructure publishes publicly.
7. Reporting abuse
If you believe your infrastructure is being scanned through ComplianceLayer without authorization, email abuse@compliancelayer.net with the domain, the approximate time, and any log excerpts you can share. We investigate every report and will suspend accounts that scan without authorization.
To report a security vulnerability in ComplianceLayer itself, see our vulnerability disclosure policy.
8. Contact
Scanning, abuse and exclusion requests: abuse@compliancelayer.net
Rescans and disputed findings: support@compliancelayer.net
Security vulnerabilities: security@compliancelayer.net
Legal: legal@compliancelayer.net