Ownership verification
DNS TXT and HTTP file challenges prove control before any active scanner traffic is allowed.
- Cryptographically random tokens
- Expiring challenges
- Audited verification events
First-party security platform
Waldok verifies ownership, enforces first-party scope, and runs assessments without ever becoming an arbitrary attack tool. Third-party vendors stay out of active scanner traffic.
Verify ownership
DNS TXT or HTTP proof
Enforce scope
Fail closed by design
Assess safely
First-party traffic only
Track findings
Evidence & retests
How it works
Add what you own, prove it, assess within scope, then remediate with evidence. Nothing active runs until ownership is verified.
Hard product rule
DNS, HTTP, TLS, discovery, findings, and reports all operate behind the same ownership and scope engine. There is no override that enables third-party pentesting.
Capabilities
Built for operators who need real coverage without losing control of what can be scanned.
DNS TXT and HTTP file challenges prove control before any active scanner traffic is allowed.
Every active request is revalidated. Redirects, discoveries, and uncertain hosts fail closed.
Projects, targets, and findings stay isolated by organization from day one.
New hosts can be discovered, but they stay unverified until ownership is proven.
Every finding carries context, severity, and proof so remediation is actionable.
PostgreSQL, Redis, Docker, nginx, queue workers, and scheduler — not a prototype stack.
Choose depth and intensity inside policy, without opening the door to arbitrary targets.
Ownership checks, scope denials, and scan starts leave a clear record of what happened and why.
Why it matters
Your own apps, APIs, WordPress sites, and other customer-owned properties can be assessed after verification. Arbitrary third-party websites cannot.
Stripe, Google, OpenAI, Twilio, and similar vendors may appear as integrations. Active scanner traffic never goes to them.
If ownership, classification, or scope is unclear, Waldok does not scan. Decisions are recorded for audit.
Clear records, encrypted secrets, organization isolation, and production infrastructure from the foundation up.
Built for
Governance
Hosts are classified before active testing. Only verified first-party assets can receive scanner traffic.
Mode 1
Inventory and classify hosts. No active scanner traffic until ownership is proven.
Mode 2
DNS or HTTP challenges prove control. Unverified first-party candidates stay blocked.
Mode 3
Active testing runs only on verified, in-scope first-party assets — never on third parties.
FP-V
First-party verified
Ownership proven. Active testing may proceed when in scope.
Example: verified app.example.com
FP-U
First-party unverified
Candidate owned host. Active testing stays blocked.
Example: newly discovered subdomain
3P
Third-party
Known vendor or external dependency. Never actively scanned.
Example: api.stripe.com
BLK
Blocked
Localhost, metadata, or infrastructure that must not be touched.
Example: 169.254.169.254
Put owned applications under continuous command.
Verify what you own, assess within scope, and keep third-party infrastructure out of the blast radius.