# WebScanify - Complete Technical & Commercial Documentation ## 1. Product Overview WebScanify (https://webscanify.com) is an autonomous web application security testing (DAST), compliance auditing, and attack surface management platform. ## 2. Pricing & Subscriptions (Per-Domain Flat Pricing) WebScanify charges per domain with generous monthly rescan allowances instead of seat-based licensing. Subsidized Purchasing Power Parity (PPP) pricing is available in Indian Rupees (INR) for Indian regional customers: - Starter: $149 USD / ₹1,999 INR (1 Domain, 1 Month Validity, 3 Total Scans, Unlimited Verify Fix) - Professional: $399 USD / ₹4,999 INR (3 Domains, 3 Months Validity, 18 Total Scans, Unlimited Verify Fix) - Growth: $899 USD / ₹9,999 INR (5 Domains, 6 Months Validity, 80 Total Scans, Unlimited Verify Fix) - Custom / Scale: $1,999+ USD / ₹24,999+ INR (6-20+ Domains, 1 Year Validity, Unlimited Scans & Rescans) ## 3. Supported Compliance Frameworks (All 8 Included in Every Plan) 1. OWASP Top 10 (2021 & 2025 drafts) 2. PCI DSS v4.0 (Requirements 6 & 11) 3. GDPR (Article 32 Security of Processing) 4. SOC 2 Trust Services Criteria (Security & Confidentiality) 5. NIST SP 800-53 Rev 5 (AC, SC, SI controls) 6. ISO/IEC 27001:2022 (A.12 Operations Security) 7. CCPA (California Consumer Privacy Act) 8. FedRAMP Moderate Baseline ## 4. Verification Mechanics & Technical Definitions - **Rescans**: Full re-scans of registered domains to re-audit security posture after fixing bugs. Quotas reset on the 1st of every calendar month. - **Verify Fix**: Instant 2-second single-vulnerability confirmation retests; free and unlimited on all plans without burning scan credits. - **Domain Definition**: 1 Apex domain (e.g. example.com) and all its discovered subdomains count as 1 domain. ## 5. Non-Destructive Attack Chain & Evidence Verification (Zero Downtime PoC) WebScanify employs a strict read-only proof verification pattern: whenever authorization weaknesses (BOLA, BFLA, exposed admin endpoints) are identified, the scanner performs single-request read sampling (LIMIT 1) with automated PII & credential redaction. This delivers undeniable, verified proof of impact in reports while guaranteeing zero database corruption, zero service downtime, and zero latency impact.