As of: September 2026
We follow a list of companies that are growing fast. From time to time we will offer one of them a free security check of its public website, and this page is the exact terms of that offer: what we touch on your domain, when, what we keep, and how you say no.
Everything starts with a reply from you. A domain is only scanned after someone in your company has answered our offer with "run it", or after you have asked for the check yourself. A full pentest is a separate, later conversation, and it happens under a signed written scope or not at all. Until then nothing goes deeper than the check itself.
· at most ~300 web page requests to your domain (~200 per host), ~1 per second, in one ~10–20 minute window
· one US residential IP address. If that line drops, the check is re-run once, not more.
· plain web requests throughout: no logins, no payloads, no port scan, nothing sent to your systems, robots.txt respected
· subdomains are looked up in certificate logs and DNS records, never brute-forced
One run per signal. A second run happens when you reply or when something new shows up, and you hear about it before it goes. Beyond that we don't touch your domain.
Your domain goes on a permanent list. No more scans, no more emails, no expiry and no need to ask again. It takes effect within minutes.
Keep the written report, share it, ignore it; whether a collaboration follows or not changes nothing on our side. Nobody else sees our findings. The data sits on EU servers (Google Cloud, EU region); an email to sales@rheono.com and we delete the report and the raw logs.
sales@rheono.com. The imprint is linked at the bottom.