What we do

VulnScout runs research scans across the public internet using open-source tools, looking for security problems that put organizations at risk. When we check whether a finding is real, we stop at the least intrusive verification possible — we never go further than confirming the problem exists, and we never publish findings about a specific organization. You can read more in our coordinated disclosure policy.

Your right to opt out

You can ask us to exclude your domains and networks at any time. You do not need to give a reason, there are no conditions, and the exclusion stays in place indefinitely.

What to submit

List up to 15 entries for automatic processing, one per line. Larger lists (up to 100 entries) are welcome too — a person will review them, which can take a little longer.

Accepted formats
TypeExample
Domainexample.com — covers example.com and all its subdomains
Wildcard domain*.example.com
Single IPv4 address203.0.113.5
IPv4 network (CIDR)203.0.113.0/24
IPv4 range203.0.113.0-255 or 203.0.113.10-203.0.113.20
IPv4 wildcard203.0.113.*
IPv6 address or network2001:db8::1, 2001:db8::/48
AS numberAS64496

Request an exclusion

We send a confirmation link here. Using an address at one of the domains you list lets us apply the exclusion automatically.

What happens next

We email you a confirmation link. Open it and press the button on that page — that is what tells us the request really came from you. Exclusions are typically applied within 24 hours; in rare cases it can take up to 48. Some submissions are checked by a person first, which is normal and nothing to worry about.

Prefer email?

You can also opt out by writing to security@vulnscout.com, as described in our published policy. This form is just a convenience — it does not replace that channel.

Privacy

We keep the organization name and contact email you enter, the internet address the form was submitted from, and the time of submission. We use them only to verify and honor your exclusion and to contact you about it. Your contact details are never shared with our scanning infrastructure, and the exclusion list is not published.