Passive scanner families.
Headers, TLS, cookies, CORS, exposed files, source maps, JS keys, browser storage, auth surface, DNS/email, route discovery, and launch readiness.
LaunchLock keeps public coverage passive by default, then makes external adapters and active scan gates visible instead of hidden.
Headers
Exposure
Scripts
Readiness
Report signals
Passive
Public scan default
External
Skip safely without keys
Active
Verification required
Headers, TLS, cookies, CORS, exposed files, source maps, JS keys, browser storage, auth surface, DNS/email, route discovery, and launch readiness.
Observatory, SSL Labs, urlscan.io, ZAP baseline, and Nuclei are represented honestly when keys or tools are missing.
Target verification, explicit consent, scope confirmation, rate limits, and audit logs are required before active scans become self-serve.