CyberRecona CGregLab Security productReturn to dashboard
Safety policy

Authorized Scanning Policy

How CyberRecon determines which targets may receive passive intelligence, active discovery, and scheduled monitoring.

Last updated 28 August 2026

Your authorization obligation

Before submitting a domain, you must reasonably verify that you own it or have clear permission from the owner to perform the selected checks. Agency users should keep written client authorization that identifies the domains, allowed methods, dates, and responsible contacts.

Verification methods

For recurring monitoring and active discovery, CyberRecon can require control proof through a DNS TXT record or a verification file served from the target domain. Verification confirms technical control at that moment; it does not replace a contract or expand the authorized scope.

Passive and active checks

  • Passive intelligence uses publicly available DNS, registration, certificate, hosting, and webpage indicators.
  • Active service discovery may connect to approved public addresses and ports to identify exposed services.
  • CyberRecon blocks private, loopback, link-local, reserved, and otherwise unsafe network destinations and validates public targets before network operations.
  • A target must remain within its validated public address set during active operations.

Scope changes and revocation

Stop monitoring and remove a domain when authorization ends, ownership changes, or a client asks you to stop. CyberRecon may require reverification or pause a target when control proof expires or material ownership signals change.

Safe reporting

Share reports only with people authorized to receive the underlying security information. Redact unnecessary personal data and sensitive infrastructure details before broader distribution.