Scanning is separate
Public assessment uses a dedicated URL Scanner credential. A customer remediation credential is never used for general scanning.
Security model
AgentReadyToday is designed around separation of duties, least privilege, explicit approval, verification, and an audit trail.
Public assessment uses a dedicated URL Scanner credential. A customer remediation credential is never used for general scanning.
Consequential changes require verified domain control through Cloudflare zone access, DNS, or a well-known verification file.
Cloudflare tokens are validated, encrypted with AES-GCM, stored server-side, and never returned through the API.
The approval digest identifies the exact proposed operations. If the plan changes, approval must be given again.
URL inputs are checked against private and reserved networks, DNS is validated, redirects are rechecked, and fetches have byte and time limits.
Site-changing actions include the actor, site, target, result, request identifier, and timestamp in an append-only audit history.