Safety

Is Outerwall safe to run against my clients?

Yes. Until your client approves, Outerwall reads public sources only and sends nothing to your client’s systems. Active checks run only on assets your client has approved, after it proves control of the domain, signs a scope and gets our scan addresses 24 hours in advance. A blocked check is shown as blocked, never worked around.

Before any active check

Five gates, enforced in code.

If a gate isn’t passed, no active check runs, and your client sees only its public footprint and counts of issues by type.

The path to the first active check

  1. Domain addedPublic sources only
  2. Assets confirmedYour client says what is its own
  3. Control provenA DNS record or a file
  4. Scope signedPer asset, inside a testing window
  5. 24 hours’ noticeOur scan addresses, before the first run
  6. Active checksApproved assets only

All five gates passed. Checks run on approved assets only, inside the agreed window, and your client’s contact already has our scan addresses.Stopped at control. The organization sees its public footprint and counts of issues by type. No active check runs, and no exposure detail is shown.

Before approval

What we read without scanning

Public sources only. Research may visit public web pages as an ordinary visitor would, within a small page budget. Nothing is sent to your client’s systems.

  • Infrastructure

    Certificate logs, DNS, internet scan data

  • Records

    Registers, certifications

  • Events

    Breach notices, known-exploited flaws

  • Workforce

    Job ads, staff emails in breaches

  • Vendor references

    Case studies, procurement notices

Our lines

What we never do

  • Test a supplier without its own consent

    Suppliers are observed from public sources. Testing one needs that supplier’s own signed consent.

  • Show exposure detail before control is proven

    Until an organization proves it controls a domain, it sees its footprint and counts of issues by type, never the detail.

  • Use what we find to sell to anyone

    What we learn about an organization is never used to market to it.

  • Keep a leaked password or secret

    Any secret we detect becomes a keyed fingerprint and a count the moment it is collected. The value is never stored.

  • Mix one client’s data with another’s

    Separation is enforced by the database itself, for every partner and every client.

  • Let an AI model decide a finding

    Every decision is tested code, so the same data always gives the same answer.

Data and decisions

How we handle what we find

  • Every finding shows its evidence

    The source, the time and the check that produced it. Anything inferred stays labeled likely until a check confirms it.

  • Where we use AI

    Models pull facts out of public pages and double-check findings. A model can lower a finding’s confidence but never raise it. The decision itself is tested code.

  • Blocked means blocked

    If a firewall blocks a check, we record it as blocked and show it in coverage. We never work around it.

  • Coverage comes first

    What we can’t see is listed before what we found, so a clean result never hides a gap.

Our scanning

Seen traffic from us?

Our scanning page says who we are, what we scan and when, and the addresses we scan from. Email abuse@outerwall.ai with the source addresses and times, and we reply within 24 hours. To report a security issue in Outerwall itself, email security@outerwall.ai.

Is Outerwall scanning your network?

Run it on your own estate first.

Every design partner starts with its own domain, after proving control of it, so you see exactly what your clients would see.