Complete Guide to SecureScan
Everything you need to scan your infrastructure, understand the results, and prove you have fixed your vulnerabilities.
SecureScan is a Penetration Testing as-a-Service platform that lets you assess the security of your domains and IP addresses with professional scanners β with nothing to install or configure. This guide walks you from sign-up to your first report, explaining clearly how each stage of the process works. You don't need to be a security expert: the key concepts are explained step by step.
1. What is SecureScan
SecureScan is a Penetration Testing as-a-Service (PTaaS) platform: a simple, on-demand way to run professional vulnerability scans against your infrastructure. You sign up, buy the credits you need, point us at the target you want to assess, and receive a detailed report of the vulnerabilities found.
Behind the scenes, SecureScan orchestrates industry-recognized scanners β such as nmap for the network, OpenVAS for vulnerability assessment, nuclei for web vulnerabilities, and testssl for SSL/TLS analysis β and combines their results into a single, readable picture. It is built for SMBs, web agencies, and IT professionals who want a reliable security check without the complexity of running the tools by hand.
2. Getting started
To get started, create an account with your email and confirm your address through the verification link you receive by email. Registration is free and gives you access to the dashboard, where you manage your scans, reports, and credits.
To launch scans you need credits, which you buy through the available packages or subscriptions. Payments are handled securely via Stripe or PayPal, and your credits are added to your account automatically as soon as the payment goes through.
3. The scan packages
SecureScan offers several packages depending on how deep you need the analysis to be. The Basic package runs a network scan with nmap (ports, services, configurations); the Vuln package adds vulnerability assessment with OpenVAS and CVE matching; the Web package focuses on web application vulnerabilities with nuclei; the Full package combines everything into a complete audit.
Beyond the general-purpose packages, there are scans tailored to the most popular CMS platforms β WordPress, Joomla, Magento, PrestaShop, and WooCommerce β as well as targeted analyses such as SSL/TLS, mail servers, SQL injection, and hardening audits for Linux and Windows servers. You can choose the package that best fits your goal right when you launch the scan.
4. Verifying target ownership
For legal and ethical reasons, you can only scan domains and IP addresses you can prove you own or control. So before the first scan on a new target, SecureScan asks you to complete an ownership verification. This protects both you and others from unauthorized scans.
You have two methods to choose from. With the DNS method, you add a TXT record containing a token provided by SecureScan to your domain's zone. With the HTTP method, you upload a small verification file to the /.well-known/ folder of your site. In both cases, SecureScan automatically checks for the token and, once confirmed, enables scanning on that target.
5. Launching a scan and following it in real time
Once the target is verified, you pick the package and start the scan. SecureScan shows you the progress in real time with a progress bar and the current step β for example port scanning, service detection, or vulnerability checks β so you always know where the work stands.
While it runs, you can expand the step details and watch the network bandwidth chart. On the Pro and Business plans, a terminal-style technical log is also available, showing the raw scanner output for those who want to dig into the details. Deeper scans can take time, but you don't have to wait around: you'll get an email notification when they finish.
6. Reading the results: vulnerabilities, severity, and CVEs
When the scan finishes, you get a list of the vulnerabilities found, each classified by severity β critical, high, medium, or low β so you immediately understand what to tackle first. The dashboard sums up the numbers with charts and indicators, while for each vulnerability you'll find a description, the affected target, and any associated CVE.
Each vulnerability also comes with a recommended solution that shows you how to fix it. CVEs (Common Vulnerabilities and Exposures) are standard, internationally recognized identifiers: they let you research the issue further and assess its real impact on your system.
7. Targeted Rescan: verify your fixes without repeating everything
One of SecureScan's standout features is the Targeted Rescan. After fixing a vulnerability, instead of rerunning the entire scan β which can take hours β you can verify that single fix with a targeted rescan that checks only that one vulnerability. It's faster, cheaper, and gives you instant confirmation.
If you've fixed several vulnerabilities, the batch Rescan lets you select multiple ones with checkboxes and verify them all together in a single operation, paying one credit per vulnerability. When it's done, you can see which ones are actually resolved and which are still open.
8. Signed PDF reports and certificates
Every scan produces a detailed PDF report you can download and share. The reports are digitally signed with an RFC 3161 timestamp β an evidentiary-grade guarantee that certifies the document's date and integrity: useful for audits, compliance, and dealings with clients or suppliers.
When you verify the fix of a vulnerability through Targeted Rescan, SecureScan can generate a dedicated fix certificate, and for batch rescans a summary report is available. They're the ideal way to formally demonstrate that you've resolved the security issues identified.
9. Credits, subscriptions, and pricing
SecureScan runs on credits: every scan or rescan consumes a certain number of credits depending on its type. You can buy one-off credit packages or take out a subscription, choosing the option best suited to how often you check your infrastructure.
A single rescan costs one credit, while batch rescans cost one credit for each vulnerability verified. On the plans page you'll always find the up-to-date pricing with costs, included credits, and the details of each option, so you can weigh up the best solution for your needs.
10. Privacy and security
Security is at the heart of SecureScan, including the way it handles your data. Scans are only run against targets you've proven you own, your reports stay accessible to your account alone, and the entire platform takes a privacy-first approach to managing information.
If you have any questions about how a specific analysis works, what gets checked, or the limits of authorized use, you can consult our legal pages or contact our support team. We want you to use SecureScan in an informed, secure, and compliant way.
Ready to secure your infrastructure?
Create a free account, verify ownership of your domain, and launch your first scan in just a few minutes.