Frequently Asked Questions
Everything you need to know about UNPWNED and how it keeps your domains secure.
What does UNPWNED scan?
The public check runs 149 bounded checks for externally observable headers, DNS, certificate-transparency and technology signals. Current ownership verification unlocks the 428-check surface suite. Reaching the 721-check full suite also requires explicit active-testing authorization. You can also connect GitHub repositories for scheduled secret, dependency and configuration scans.
Can I monitor my GitHub repos?
Yes. UNPWNED offers GitHub Repo Monitoring on paid plans. Connect your GitHub account via OAuth, select the repositories you want to monitor, and UNPWNED will run scheduled scans checking for leaked secrets (34+ patterns), vulnerable dependencies, and exposed config files like .env, credentials.json, and SSH keys. When issues are found, you get notified via email and webhooks, and UNPWNED can automatically create GitHub Issues in the affected repository so your team can track and resolve findings directly in your workflow.
Is it safe to scan my domain?
The anonymous public check is bounded to low-impact, externally observable reads. Owner-only path, port, database, API and protocol probes require current ownership verification. The separately labeled active-testing tier also requires explicit authorization. UNPWNED does not modify the target, but these checks can reach application controls and must only run with current authority.
How long does a scan take?
Most standard scans finish in a couple of minutes. Deep scans run many more checks and usually take several minutes. The exact time depends on how many checks apply and how quickly the site and external APIs respond. You'll receive a notification when your report is ready.
Why did my scan return results instantly?
A lookup may return an already published historical result before you request a new check. Public cache reuse for new scans is currently disabled. A newly accepted public check runs fresh but remains bounded and partial; current ownership verification unlocks owner-authorized checks and official-grade eligibility, while active testing requires separate explicit authorization.
What's the difference between Free and the paid plans?
Free shows what the completed checks found: 2 on-demand scans a month, severity breakdown and finding titles, plus one lifetime Deep Scan on a currently verified domain. Anonymous public checks can show a limited assessed score but never an official grade. Paid shows how to fix findings with full details and AI fix prompts, unlimited re-scans and Deep Scans, PDF export, score trends, monitoring, CVE alerts, GitHub integration and badge eligibility. Solo costs $9/month or $90/year for 1 domain, Studio costs $29/month or $290/year for 5 domains, and Scale costs $49/month or $490/year for 15 domains. Studio and Scale add priority support. Cancel anytime.
How does the AI report work?
Anthropic is optional and may draft only the report executive summary. UNPWNED sends it the canonical domain plus normalized finding kind, category, severity and count, and valid CVE or GHSA identifiers where applicable. It does not send response bodies, paths, source code, credentials, cookies, IP addresses, account data or audit data. Findings, scores and remediation guidance remain deterministic, and the model cannot make target requests.
Do you store my scan data?
Yes. Scan results and generated reports are stored so you can access them from your dashboard and are retained under the schedule in our Privacy Policy. We do not sell personal data. We disclose data only to the service providers and other recipients listed in the Privacy Policy, with the stated safeguards. Account deletion removes or de-identifies data on the published schedule, while limited billing, authorization, fraud and legal-defense records may be retained where required.
Can I share my report with my team?
Yes. Every report gets a unique shareable link (token-based URL) that you can send to teammates, clients, or stakeholders. The link provides read-only access to the report without requiring a login.
What if I find a critical vulnerability?
Don't panic. The scanner-based report explains the issue and provides deterministic step-by-step remediation guidance. For critical findings, we recommend obtaining qualified review, addressing them promptly, and running a follow-up scan to confirm the fix. Studio and Scale subscribers also get priority support.
Who built UNPWNED?
UNPWNED is built and maintained by Raz Azulay, an independent developer and founder. It started as a way to catch the security mistakes that slip into fast-moving and AI-assisted builds, and has grown into a full outside-in scanner.
How do I contact support?
Reach us anytime at support@unpwned.io. Studio and Scale subscribers get priority response times. We typically respond within 24 hours.
Still Have Questions?
Reach out to us at support@unpwned.io and we'll get back to you within 24 hours.
Start Scanning Free