Transparent security scanning, with strict traffic boundaries.
This page is the identity URL published in LaunchLock scanner requests. LaunchLock does not hide what it is, and active testing is reserved for verified, explicitly authorized targets.
HTTP identity: Mozilla/5.0 (compatible; LaunchLockScanner/1.0; +https://www.launchlock.dev/scanner), with X-LaunchLock-Scanner: 1 on normal scanner requests.
Public Quick scans use bounded GET, HEAD, and careful OPTIONS requests against public content. They do not log in, submit forms, mutate data, brute-force credentials, or run intrusive payloads.
Anonymous Quick content expansion reads robots.txt, honors matching allow and disallow rules, and does not shorten a crawl delay that exceeds its bounded scan window.
Standard and Deep scans require an authenticated owner scope, exact target verification, and explicit consent before active or authenticated checks can run.
LaunchLock applies per-scan time, page, response-size, redirect, and queue limits. Private, loopback, metadata, special-use, and restricted shared-provider targets are blocked.
If a site returns a WAF or browser challenge, LaunchLock may retry the submitted page through a bounded managed-browser path; if access is still denied, the report states the exact coverage limit. Project owners can also authorize a narrowly scoped host rule or deployment-protection token when their provider supports one.
To report unwanted traffic or a suspected abuse case, email support@launchlock.dev with the target hostname, UTC timestamp, and any request or edge trace identifier.