Scanning Policy

OpenBash operates passive external observation against publicly reachable hosts. Scope is limited to data already served publicly by the target host.

Identification

Our requests carry a User-Agent prefixed with OpenBash-, followed by a component name, version and a URL pointing to this policy. Identify our traffic by the User-Agent string.

To attribute a specific request, send the source IP, full timestamp (with timezone) and request line to abuse@openbash.com. Reply from access logs within 24h.

Opt out

robots.txt directives apply at the host level — disallow our User-Agent on any hostname you control.

For bulk exclusion across multiple domains, an ASN or an entire organization, email abuse@openbash.com with the scope. Applied across the platform within 24h, permanent.

Contact

abuse@openbash.com — opt-out, abuse, impersonation reports
hello@openbash.com — commercial and general enquiries