Smoke Test
Features Pricing Methodology Log In Sign Up

Testing Methodology and Safe Harbor

Clear scope, explicit authorization, and reproducible evidence are built into every Smoke Test engagement.

Last updated: September 7, 2026

Authorization gate

Before scanning, an account holder confirms authority and verifies control by an email link at the target domain or a DNS TXT record. The service records the authorization time and keeps unverified or unpaid targets disabled.

What we test

  • Public DNS, TLS, HTTP response headers, exposed network services, and discovered web-application routes.
  • Passive and active OWASP ZAP checks, authenticated paths when test credentials are supplied, access-control and business-logic modules when enabled, and known-exploited-vulnerability correlation.
  • Repeat scans that compare findings over time and verify whether previously observed issues remain.

Boundaries

Targets resolving to private, loopback, link-local, or reserved networks are rejected. Scan workers pin the approved hostname to a validated public address at launch. Crawling and active tests remain scoped to the registered target.

Smoke Test does not intentionally perform denial-of-service, destructive exploitation, persistence, phishing, social engineering, or attacks against unrelated third parties.

Evidence and limitations

Reports include affected endpoints, available request or response evidence, severity, standards mappings, remediation guidance, an immutable version, and an integrity-verification record. Automated reports are explicitly identified as not analyst-attested. Human Reviewed subscriptions include review and signed attestation of one selected full assessment per subscription year.

Coverage depends on reachable application states, test-account permissions, defenses, time limits, and the target behavior observed during that scan. Framework crosswalks identify relevant supporting evidence; they do not independently certify compliance.

Safe-harbor commitment

We consider good-faith customer testing performed within an authorized Smoke Test scope to be permitted activity. We will not pursue legal action for accidental, non-destructive effects reported promptly and handled in accordance with these terms. This commitment does not authorize testing of systems outside the registered scope or override the rights of third parties.

Report a concern

To request exclusions, coordinate a maintenance window, report unintended impact, or disclose a vulnerability in Smoke Test itself, contact admin@smoketest.pro.

© 2026 Smoke Test. Continuous security evidence for modern web apps.

Methodology & Safe Harbor Terms Privacy DPA