Protector Class operates an automated digital-exposure scanner that examines public-facing internet infrastructure for indicators of security risk. This page explains exactly what we do, what we do not do, and how to opt out if you do not want your domain scanned.
For every domain we scan, we perform standard reconnaissance-tier checks against the public-facing surface of the domain. The same surface that any internet user, security researcher, or attacker can already see with no credentials. Specifically:
/.env, /.git/config) to detect whether they are publicly accessibleWe are a detection-only scanner. We do not exploit any vulnerability we discover. Specifically, we never:
All HTTP requests originating from our scanner use a polite User-Agent string identifying us:
Protector Class-Scanner/1.0 (security audit; contact: security@protectorclass.com)
If you do not wish your domain to be scanned by Protector Class, email security@protectorclass.com from any address at the domain in question (or from any address with provable authority over the domain) and request removal. We will:
Occasionally during a customer Domain Audit, Protector Class will discover an exposure that does not belong to the customer. For example, a publicly-exposed credential in a third-party vendor used by the customer, or a misconfiguration on a partner organization's domain. Our handling of these findings:
If you are a third-party organization who believes Protector Class has information about an exposure affecting you, email security@protectorclass.com. We will respond within 72 hours and, where appropriate, share what we can without breaching customer confidentiality.
If you have discovered a security vulnerability in any Protector Class property (protectorclass.com or any subdomain or product surface), please report it to security@protectorclass.com. We commit to:
We do not currently operate a paid bug-bounty program. We deeply appreciate responsibly-disclosed reports.
Our scanning activity is reconnaissance-tier and is conducted in accordance with industry standards established by major commercial vulnerability scanners (Tenable, Qualys, Rapid7, and others). We rely on public, unauthenticated access to infrastructure that is, by definition, publicly served by the target. We do not exceed authorized access as defined under the U.S. Computer Fraud and Abuse Act, Canadian Criminal Code section 342.1, the U.K. Computer Misuse Act 1990, or analogous statutes in other jurisdictions.
If you are a domain owner with concerns about a specific scan, contact us. We can provide scan logs and answer any questions about our methodology.
We thank all security researchers who have responsibly disclosed issues to us. (No public acknowledgments at this time.)
Exposure intelligence for people and businesses that never had access to it.
© 2026 ADMBA ONE INC · 1200 Bay Street, Suite 1201, Toronto, ON M5R 2A5. All rights reserved. Toronto · Read-only by design