FAQ
Frequently asked questions about Barrion.
Is scanning safe for production sites?
Yes. Barrion uses passive scanning, which means it only reads publicly available information from your site -- HTTP responses, headers, TLS certificates, and page content. It never submits forms, sends exploit payloads, or modifies data. You can scan production sites during peak traffic with minimal load on the site.
How often should I scan?
It depends on how frequently your application changes. As a general guideline:
- Active development: Scan after each deployment, or set up daily monitoring on the Business plan.
- Stable applications: Weekly monitoring (available on Essential) catches regressions and new vulnerabilities from dependency updates or configuration changes.
- Compliance requirements: Many frameworks expect at least monthly vulnerability assessments. Set up a monitoring schedule that matches your compliance cadence.
What does passive scanning mean?
Passive scanning analyzes the observable behavior and configuration of a web application without interacting with it in ways that could cause side effects. Barrion inspects HTTP headers, TLS configuration, content security policies, cookie attributes, DNS records, and other publicly visible properties. It does not attempt to exploit vulnerabilities, inject payloads, or authenticate against your application.
Can I scan internal or private sites?
No. Barrion scans public-facing URLs only. The scan engine runs in the cloud and must be able to reach your site over the public internet. Internal applications behind a firewall, VPN, or private network are not accessible to the scanner.
What is the difference between passive scanning and an AI pentest?
Passive scanning evaluates your deployed web application from the outside, reading HTTP responses, headers, TLS, cookies and other observable properties. It never logs in and never sends payloads, so it is safe to run continuously against production.
An AI pentest actively tests the application: it chains requests, tests behind the login with credentials you provide, and drops findings that don't reproduce against the live app before reporting. It is paid in credits before the run starts. See AI Pentesting.
Passive scanning catches configuration and drift; the pentest proves what is exploitable.
How is the security score calculated?
Barrion assigns a score from 0 to 100 based on the results of all security checks run during a scan. Each check is weighted by severity (critical, high, medium, low, informational). Passing a high-severity check contributes more to the score than passing a low-severity one. Similarly, failing a critical check reduces the score more than failing an informational one.
The score maps to a letter grade:
| Score Range | Grade |
|---|---|
| 90--100 | A |
| 80--89 | B |
| 70--79 | C |
| 50--69 | D |
| 0--49 | F |
Can I export reports?
Yes. Every plan can export a passive scan report as PDF, a formatted report suitable for sharing with stakeholders or attaching to compliance documentation. CSV export of the raw findings, for spreadsheets, SIEM tools or custom dashboards, is available on Business. Pentest reports come as PDF, XLSX and JSON on every plan.
Export options are available from the scan results page.
What notification channels are supported?
Barrion supports three notification channels:
| Channel | Essential | Business |
|---|---|---|
| Yes | Yes | |
| Slack | -- | Yes |
| Microsoft Teams | -- | Yes |
Notifications are sent when scheduled scans complete, when your security score changes, and when new vulnerabilities are detected.
How do AI fix recommendations work?
When Barrion identifies a vulnerability, it can generate a tailored fix recommendation that explains what the issue is, why it matters, and exactly how to resolve it -- including code snippets specific to your technology stack.
What compliance frameworks does Barrion support?
Barrion helps you monitor and document security posture relevant to several major compliance frameworks:
- SOC 2 -- Continuous monitoring evidence for the Security trust service criterion
- ISO 27001 -- Technical control assessment for Annex A controls
- PCI DSS -- Web application security scanning that supports your PCI DSS evidence (it is not an ASV scan or an 11.4 penetration test)
- HIPAA -- Technical safeguard verification for web-facing health applications
- GDPR -- Security assessment supporting Article 32 requirements
- FedRAMP -- Continuous monitoring alignment for federal cloud services
Barrion provides scan results and trend data that support your compliance documentation. It does not perform full compliance audits.
How many domains can I scan?
There is no limit on the number of distinct domains you can scan on any plan. The limit is on the number of scans per day (5 for Free, 50 for Essential, 500 for Business). You can distribute your daily scans across as many domains as you need.
Does Barrion store my scan results?
Yes. All scan results are stored and accessible from your dashboard. You can view historical scans, compare scores over time, and track remediation progress. Scan history is retained regardless of your plan tier, including if you downgrade to Free.
Can I use Barrion without creating an account?
Yes. Barrion offers a guest scan feature on the landing page that lets you run a single scan without logging in. Guest scans use Free plan limits (3-page crawl, 18 checks) and results are not saved to an account. For persistent results, monitoring, and advanced features, create a free account.