- How do I get authorisation to scan a client's domain?
- Each target requires the client to set up verification: DNS TXT, a file on the server, or an HTML meta tag. The client puts the token in place, which is the documented authorisation computer-misuse laws expect, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act. Email us for a template authorisation letter if you want a paper trail in the retainer file before the client configures verification.
- Can I give clients a permanent URL to check posture themselves?
- Each workspace has one public trust page, and it covers every domain in the workspace. For a view of one client's site, send a share link for their latest scan: read-only, watermarked if you like, and valid for up to 90 days. You can see how many times it was opened.
- Do credits roll over between clients?
- Credits belong to the workspace, not to individual targets, so any pattern works: 5 scans of one client this month, 20 of another next month. Credits last 60 days from purchase.
- Can my SOC dashboard pull findings programmatically?
- Yes. Version 1 has
GET /api/v1/targets and GET /api/v1/findings, filterable by severity, category, status and owner, with bearer-token auth on a workspace key. The API-keys settings page shows a two-line curl example. - What about findings on client sites we don't host?
- Vantyris doesn't care where a site is hosted. It scans anything on the public internet and names each fix in terms the host's support team will recognise: the Cloudflare panel path, the Nginx directive, the Apache .htaccess block or the GoDaddy DNS field, whichever the finding needs.
- How do I tell which client sites need attention this morning?
- Open the portfolio dashboard. It sorts worst first by Critical and High count, then by score drop since the last scan. Acknowledged items get their own column, so the 'needs action' count stays honest. The CSV export for the monthly review is one click.