For the complete documentation index, see llms.txt. This page is also available as Markdown.

Scan Policies

Choose between Light, Standard, and Compliance scan policies to control the depth of scanning on each target.

For each target in your account, we offer three scan policies designed to give you flexibility. You can manage scan policies per target by going to the target settings page, or in bulk on the Targets page.

Scan Policies

  • Light (default) - This non-invasive scan policy includes Firewall Scanning, Technology Scanning, and Website Scanning. It is perfect for third-party managed assets and platform-hosted websites where server vulnerabilities are out of scope.

  • Standard - This scan policy includes all scans in Light, plus server vulnerability scanning to identify common vulnerabilities and exposures (CVEs).

  • Compliance - This scan policy includes all scans in the Standard policy with extra checks for PCI ASV compliance. This scan policy is required for all targets you want to use in generating ASV reports.

Last updated

Was this helpful?