Our scanning
Who we are, what we scan, and how to reach us.
Outerwall provides continuous threat exposure management to organisations through their managed service providers. If you have seen traffic from our addresses, this page explains why and what to do.
What we read without scanning
Our research is passive. It reads public sources such as certificate transparency logs, DNS, published internet scan data, registers, breach notices, job adverts and vendor case studies. It may visit public web pages as an ordinary visitor would, within a small page budget. It does not scan.
What we scan, and when
- We actively check only internet-facing assets that their owner has approved.
- Before any active check, the owner has proven control of the domain, signed a scope and received our scan addresses 24 hours in advance.
- Checks run inside the agreed testing window, and they are non-destructive.
- We never test an organisation's suppliers without that supplier's own signed consent.
- We never work around a firewall. A blocked check is recorded as blocked.
Our scan addresses
We publish the addresses we scan from here before our first active scan.
If you see traffic from us
Email abuse@outerwall.ai with the source addresses, the times and your time zone. We reply within 24 hours. We check the traffic against the authorisation we hold. If it was not in scope, we stop it and tell you what happened.
Security issues in Outerwall itself
Please report them to security@outerwall.ai. Our security.txt has the details.