What this FAQ covers
This page answers recurring questions about website security for website owners, agencies, and technical teams. The answers define practical boundaries, identify the evidence that matters, and explain when a question requires account-specific, technical, contractual, or legal review.
- Do I need permission to scan a website?
- Can a website scan prove there are no vulnerabilities?
- What are security headers?
- Should I submit passwords through a public form?
Use the answers responsibly
Apply each answer to the actual website, scope, agreement, and evidence. Avoid overstating a scanner result as a confirmed exploit. When the decision could affect production availability, security, accessibility, billing, privacy, or contractual commitments, document the responsible reviewer and verification plan.
Questions and answers
01Do I need permission to scan a website?
Yes. Assess only sites and systems you own, manage, or have explicit authorization to evaluate.
02Can a website scan prove there are no vulnerabilities?
No. Automated review has scope and visibility limits and cannot prove the absence of exploitable vulnerabilities.
03What are security headers?
HTTP response headers can instruct browsers about transport, framing, content sources, referrer behavior, and other security controls.
04Should I submit passwords through a public form?
No. Establish a secure, scoped access method separately.
05What is responsible remediation?
Use qualified review, approval, testing, backup or rollback, deployment records, and verification for high-impact changes.
06How do I report an Asuruas vulnerability?
Use the responsible disclosure contact, provide reproducible details, minimize data access, and avoid public disclosure before reasonable investigation.
Turn website security into an accountable record.
A clear, supportable answer set for website security linked to the relevant workflow or policy.