Authorising a scan
Why we ask you to prove you own an address before we send it traffic.
Ownership, then authorisation
Before an application target is scanned you prove you control the address — a DNS record, a file at a well-known path, or a meta tag. This stops somebody pointing our scanners at a business they do not own.
Then you authorise the scan itself: what is in scope, what is excluded, what rate we may use, and when we may not run. The authorisation is a record, re-confirmed when it ages, and every scan names the one it ran under.
The free scan is different, and smaller
The public scan at /free-scan requires no authorisation because it does only what a browser does: one page load and public DNS. It requests no other path, sends no input, and attempts no login.
That is also why it finds so little. Everything that needs permission needs permission.