Security
This page covers two questions procurement always asks: what happens to our data, and will your scanner break our production environment. Straight answers, including where we are not there yet.
Ironimo is operated by a Netherlands-based company. Scan data — targets, findings, tool output, and reports — is processed and stored on infrastructure in the European Union. Website analytics run on the EU PostHog endpoint, and nothing is captured until a visitor accepts cookies.
We do not sell customer data, and we do not share it with advertisers or data brokers.
If you configure authenticated scanning, the credentials you supply are handled as follows:
Our recommendation is unchanged from what any tester would tell you: create a dedicated, least-privilege account for scanning rather than handing over a real administrator login.
Default scanning is non-destructive. The default chain performs reconnaissance, fingerprinting, enumeration, and passive vulnerability detection. It reads; it does not attempt to modify or destroy data.
Tools capable of aggressive behaviour — sqlmap, hydra, commix — are gated. They run only when you explicitly enable them for a target. Our standing advice is to point those at staging first.
Two practical notes from real scans:
Running these tools against a system you do not own or have written permission to test is illegal in most jurisdictions, including under the Dutch Computer Crime Act and the EU directive it implements. By submitting a target you confirm you are authorised to test it. We log target submissions, and we terminate accounts used to scan third parties without permission.
Scan history is retained for 30 days on Starter, 90 days on Pro, and indefinitely on Enterprise. You can delete a target and its scan history from the application at any time; deletion removes the findings, the stored tool output, and any credentials attached to that target. To delete your entire account and all associated data, email privacy@ironimo.online.
We would rather tell you this than have you find out in a questionnaire:
If any of these are hard requirements for your procurement process, say so at contact@ironimo.online and we will tell you honestly where we are rather than waste your time.
If you find a security issue in Ironimo itself, we want to hear about it. Email security@ironimo.online with enough detail to reproduce it.
Please give us a reasonable window to fix an issue before disclosing it. We do not currently pay bounties.
We use a small number of third parties to run the service. The current list, what they process, and where, is available on request at privacy@ironimo.online. We will sign a data processing agreement.
We answer them. Send yours to contact@ironimo.online. If your change advisory board needs a written description of what a scan does to a production target before approving it, ask and we will write one for your specific configuration.
Last updated 25 August 2026.
Ask directly. We would rather have the awkward conversation before you buy than after.