HigherSelf Systems Engineering
Menu

Scanner / operating policy

Public checks.
Clear boundaries.

This page describes the public-source scanner’s recorded conduct policy. It is not an invitation to probe your private systems or a claim that an automated scan proves a business healthy.

What it checks.

Public pages, links, sitemaps and robots instructions, and public DNS evidence where it is relevant to the question. The user agent is HigherSelfScan/1.0 (+https://higherself.ai/scanner).

Requests use GET or HEAD. The scanner does not submit forms, log in, use credentials, test exploit payloads or change website state. Findings are kept private unless separately authorised for publication.

The recorded limits.

At most one request every two seconds and at most 50 pages in a run. Robots rules are respected. HTTP 429 or 503 responses trigger backoff; two throttles stop the run. Requests, timestamps, byte counts and errors are logged.

These are conduct limits, not a promise that every page or defect is covered. Automated findings need human checking. Earlier manually reviewed false positives included email-authentication interpretation and JavaScript-rendered content.

Block the scanner or opt out.

Add the following to your robots.txt:

User-agent: HigherSelfScan
Disallow: /

Or email your domain to david@higherself.ai and ask for it to be excluded. No reason is required.

For contact records and outreach objections, read the privacy notice. For a business question rather than a scanner enquiry, talk through one workflow.