Security
Defensive by design, from the ground up
GhostScanAI is built to defend, never to attack. Here's exactly how.
Ownership verification required
Active scanning is impossible until an asset completes DNS TXT, HTML file, meta tag, or approved-domain email verification and you accept a scan-authorisation declaration.
Non-destructive checks only
TLS configuration, security headers, DNS/email authentication, cookie flags and public service exposure — safe configuration analysis, never exploitation or credential attacks.
Tenant isolation, enforced in code
Every query is scoped by an organization ID derived from your authenticated session — never from client input. Cross-tenant access is tested automatically, not just assumed.
Detection and AI, structurally separate
A separate Detection Engine determines evidence. The AI layer only explains and summarises verified findings — it cannot invent a vulnerability.
SSRF-safe scanning
Every scan target is resolved and checked against private/internal IP ranges before any request is made.
Full audit trail
Logins, asset verification, scan authorisation, finding changes, risk acceptances and evidence uploads are all recorded in an append-only audit log.
Responsible disclosure
Found a security issue in GhostScanAI itself? Email security@ghostscanai.com. We ask that you avoid destructive testing, data exfiltration, or accessing other customers' data, and give us reasonable time to respond before public disclosure.