Type any domain you own. We'll check TLS, security headers, DNS, tech stack, and WAF in about 10 seconds — no signup. Email-gated full report adds subdomain takeover, port scan, and pentest probes.
Only scan domains you own or are authorized to test. See AUP.
Drop your email and we'll run the full Black Otter pentest against your domain and email you the report within 24 hours. Includes:
This scan is a one-time snapshot. Romp re-runs it across your whole stack every night — TLS expiry, header drift, new open ports, fresh vuln matches — and alerts you the moment something changes. It runs on hardware you own, and you get every line of source. No subscription required.