Scope authorization

Approve what Loki is allowed to test.

Enter your website, confirm authorization, and adjust subdomains or testing actions only if needed. Loki uses this scope to keep testing bounded and auditable. The submitted target is checked with public discovery, lightweight HTTP probes, and the limits you set here before a paid assessment begins.

If your platform has sensitive areas, production-only workflows, user-account restrictions, payment flows, destructive actions, or customer data that must stay out of bounds, capture those boundaries before checkout. Clear limits help the assessment separate confirmed exposure from paths that are intentionally blocked, untested, or waiting for a safer validation window.

What happens next

After checkout, Loki reviews the authorized scope, access, exclusions, and safety limits before testing starts. The report separates reproduced evidence from blocked, theoretical, and untested paths, then adds business impact, remediation guidance, and agreed retest criteria. This is a one-time checkout; it does not create automatic renewal or continuous testing.

Good scope notes are especially important for applications with login areas, payment flows, admin panels, customer data, or fragile production workflows. Add limits before submitting so Loki can test the public surface aggressively while keeping restricted actions, destructive changes, and sensitive systems outside the approved boundary.

Include temporary test accounts, preferred contact details, and any maintenance windows when they apply. That context helps the assessment move faster and keeps follow-up questions focused on real risk.