Observe
Collect only public facts available within the announced scope and keep their date, provenance, and limitations.
APPROCHE / Our approach
The method deliberately separates four things: what was observed, the evidence supporting it, the context that helps read it, and the questions that remain open. This prevents a technical signal from becoming a business, legal, or security conclusion too quickly.
This chain is the product’s common thread. It organizes collection, qualification, relationships, and explanation without creating artificial certainty.
Collect only public facts available within the announced scope and keep their date, provenance, and limitations.
Distinguish observed, corroborated, probable, to confirm, unknown, contradictory, and untested states.
Relate facts about the same domain, dependency, change, or context without confusing a visible relationship with contractual responsibility.
Show what these elements support, why they matter, and how far the conclusion can reasonably go.
The engine retrieves the public page, its redirect chain, and the resources planned by the method, then queries the DNS records needed for the reading. It does not execute remote JavaScript, bypass protections, or perform intrusion testing.
Each normalized fact keeps its provenance, date, and evidence limited to what is useful for understanding the observation. A missing detection remains a missing observation and does not prove the component does not exist elsewhere or at another time.
Scanapse separates degrees of knowledge instead of blending them. Information can be observed, corroborated, probable, to confirm, unknown, contradictory, or untested. Unknown is neither favorable nor unfavorable, and an assumption does not become a fact because it sounds plausible.
A CDN, mail relay, DNS provider, or visible technology can explain part of a domain’s public operation. On their own, they do not prove the origin host, contract, actual data location, or exact role of every provider.
A snapshot shows one state at one moment. Repeated readings help distinguish what appears, disappears, changes, or remains stable. This temporal depth adds meaning, but it does not certify operational resilience.
Scanapse does not look for SQL injection, application vulnerabilities, internal permissions, non-public secrets, code vulnerabilities, or components behind authentication. A rich or favorable record is not a security audit.
Some observations may be related to RFCs, standards, or regulatory texts when the context reasonably supports it. This helps readers ask better questions. It is not legal advice, certification, or an automatic compliance conclusion.
Private and reserved addresses are blocked, allowed ports are limited, redirects are revalidated, and response volumes are capped. The service favors reproducibility and caution over exhaustive probing. Internal errors and secrets are not exposed publicly.
The method serves the reading. When information cannot be established with enough material, Scanapse prefers to say so rather than fill the gap with an attractive but fragile conclusion.