We build tools to illuminate attack surface exposure — and we hold our own platform to the highest security and authorization standards.
To prevent misuse, domain scans are locked behind DNS TXT ownership verification. Each account receives a unique cryptographic token that must be published to your DNS record before scanning is enabled.
Before any domain scan is permitted, users must verify ownership by adding a unique TXT record (_theaeye-verify) to their DNS zone. Unverified domains cannot be scanned.
The AEye is exclusively built for defensive perimeter monitoring of authorized domains. We enforce rate limits, authenticated access, and strict ownership controls.
HTTPS is enforced across all endpoints with HSTS and strict CSP. User sessions are signed with 256-bit JWT keys stored exclusively in httpOnly, SameSite cookies.
Account passwords are state-hashed using bcrypt (12 rounds). Secrets are stored in server-only environment variables and never exposed to client-side bundles.
The admin console is isolated on a dedicated subdomain (admin.theaeye.co) with strict role checks, 404 concealment on main hosts, and multi-factor authentication.
If you discover a potential vulnerability in The AEye, we invite responsible report submissions. Email support.theaeye@gmail.com and we will respond promptly.
Have questions about our security practices? Contact our team at support.theaeye@gmail.com or visit our Contact Page.