Trust
How Vibe-Check scans, and from where.
We scan security from declared infrastructure, only against targets whose owners have verified control. This page lists the IP addresses our scanner uses and explains the safeguards around active scanning, so you can recognise our traffic and allowlist it.
Where scan traffic comes from
All scan traffic originates from our scanning infrastructure in Sydney, Australia (Fly.io). We don't currently publish a fixed IP allowlist here — if your WAF or Cloudflare setup needs one, contact security@vibe-check-app.com and we'll help you get scans through safely.
Our scanning safeguards
Ownership verification before any scan
Every URL must pass a DNS TXT or file-based ownership check before a single request is sent. Scans against unverified targets are refused at the job level, not just the UI.
Non-destructive, scoped activity
Scans never modify or delete data on your systems. Active probes are scoped and rate-limited — some send crafted requests (e.g. login-endpoint rate-limit tests) but we never write to your database or alter application state. We store likelihood assessments and aggregate counts, never the contents of your data.
Declared infrastructure only
We scan exclusively from our own Sydney, Australia infrastructure — never from a customer’s machine, a third party, or ad-hoc infrastructure. This is our commitment that scan activity is authorised, scoped, and attributable.
You are responsible for authorisation
You confirm you own, or are authorised to test, every target you submit. Scanning systems you do not control may be illegal — see our Terms.
Questions about scan traffic you've seen? See our Terms and Privacy Policy, or contact security@vibe-check-app.com.