Methodology
ScanTrico reports observable link behavior. It does not certify that a site is safe and does not claim to detect every malicious technique.
What V1 observes
For admitted public HTTP/HTTPS targets, ScanTrico validates the destination, follows redirects hop by hop, records the final response, and extracts a bounded set of landing-page signals such as forms, credential inputs and external form relationships.
Evidence classes
- Direct observation: HTTP status, redirect transition, MIME type, form/input relationship.
- Heuristic interpretation: a deterministic rule built from directly observed evidence, such as a credential form posting cross-origin.
- Not observed: behavior outside the V1 observation model. The report's completeness indicator makes this explicit.
Outcome language
Reports use four outcomes: High-risk signals observed, Suspicious signals observed, No material signals observed, and Inconclusive. “No material signals observed” only describes this observation; it is not a safety guarantee.
Network safety
Local, private, reserved and metadata destinations are rejected. DNS failure fails closed. Every redirect destination is revalidated, and the HTTP connection is pinned to an address that passed policy checks.
Portfolio boundary
ScanTrico owns link and landing behavior observations. DNS, registration, breach exposure, availability, certificate history and technology-stack intelligence remain separate products.