LaunchLock
Menu
Scanner coverage

Security checks with the limits shown.

LaunchLock keeps public coverage passive by default, then makes external adapters and active scan gates visible instead of hidden.

Coverage families

Headers

Exposure

Scripts

Readiness

Report signals

PassivePublic scan default
ExternalSkip safely without keys
ActiveVerification required

Passive

Public scan default

External

Skip safely without keys

Active

Verification required

Passive scanner families.

Headers, TLS, cookies, CORS, exposed files, source maps, JS keys, browser storage, auth surface, DNS/email, route discovery, and launch readiness.

External adapters fail closed.

Observatory, SSL Labs, urlscan.io, ZAP baseline, and Nuclei are represented honestly when keys or tools are missing.

Active checks are gated.

Target verification, explicit consent, scope confirmation, rate limits, and audit logs are required before active scans become self-serve.