Security

Built to keep your data under your control.

Ilax handles security-sensitive inputs and results. We make authorization boundaries, account ownership, and data handling explicit — not buried in a policy document.

Verify before you probe

Active external scans start only after domain ownership is verified via DNS TXT or a hosted file. You cannot run reconnaissance on someone else's domain through Ilax.

Strict account isolation

Every scan, domain, finding, and export belongs to a single account. Our queries are always scoped by the signed-in user; there is no shared workspace or cross-account browsing.

Encrypt what matters

External scan secrets and Ilax Internal collected secrets can be encrypted at rest with AES-256-GCM when a deployment encryption key is configured. The key stays in your environment.

You can self-host

Ilax is built to run on your own infrastructure. You control the database, backups, network placement, and key material. We never need access to your deployment to operate.

Product safeguards

  • Domain verification gates every active external scan.
  • Internal scans use explicit target lists and are only available on the Pro plan.
  • All data is scoped to the account that owns the scan.
  • Sensitive scan output can be encrypted at rest with a deployment key.
  • CSV exports are escaped to reduce formula-injection risk.
  • Rate limits and per-plan scan quotas reduce abuse and accidental overload.
  • You can delete domains and scans from the dashboard at any time.

Responsible disclosure

Found a security issue in Ilax? Email us directly. We will respond within 48 hours, keep communication confidential, and work with you to validate and fix the issue before any public disclosure.

security@ilax.agni.sh