Security

Defensive by design, from the ground up

GhostScanAI is built to defend, never to attack. Here's exactly how.

Ownership verification required

Active scanning is impossible until an asset completes DNS TXT, HTML file, meta tag, or approved-domain email verification and you accept a scan-authorisation declaration.

Non-destructive checks only

TLS configuration, security headers, DNS/email authentication, cookie flags and public service exposure — safe configuration analysis, never exploitation or credential attacks.

Tenant isolation, enforced in code

Every query is scoped by an organization ID derived from your authenticated session — never from client input. Cross-tenant access is tested automatically, not just assumed.

Detection and AI, structurally separate

A separate Detection Engine determines evidence. The AI layer only explains and summarises verified findings — it cannot invent a vulnerability.

SSRF-safe scanning

Every scan target is resolved and checked against private/internal IP ranges before any request is made.

Full audit trail

Logins, asset verification, scan authorisation, finding changes, risk acceptances and evidence uploads are all recorded in an append-only audit log.

Responsible disclosure

Found a security issue in GhostScanAI itself? Email security@ghostscanai.com. We ask that you avoid destructive testing, data exfiltration, or accessing other customers' data, and give us reasonable time to respond before public disclosure.