Frequently Asked Questions

Detailed answers before your first scan and rollout.

How quickly can we start using Silent Bolt?

There is no agent or code to deploy. Before the first scan a domain has to be verified — a DNS TXT record or an email challenge — and then authorized by an admin; DNS propagation is usually the slowest part. Once a domain is verified and authorized, every later scan starts in seconds.

Will scanning disrupt production systems?

Scanning runs from the outside with rate-limited profiles. If a web application firewall is detected the scan automatically drops to a stealth profile — a fifth of the request rate, half the concurrency and browser-like headers — instead of pushing through it, and every scan is capped at one hour.

What targets can be scanned?

HTTP/HTTPS web applications, APIs, single-page apps, admin panels, and common CMS platforms can be assessed.

How is this different from a single scanner?

Silent Bolt orchestrates multiple tools, correlates findings with AI, prioritizes risk, and produces report-ready output.

Can I use my own AI provider?

Yes. You can connect your own account with OpenAI, Anthropic, Google Gemini, DeepSeek, Kimi or OpenRouter. The key is stored encrypted under your own settings and every call is metered, including which model actually answered.

Are reports client-ready?

Yes. Each completed scan produces a PDF with an executive summary, findings grouped by severity, the raw evidence captured for each finding and remediation guidance — plus a JSON carrying the same records for your own pipelines.

Is multi-tenant isolation supported?

Yes. Workspaces are isolated per customer or department, with role-based access and separated reporting context.

Can findings be routed to collaboration tools?

Yes. Integration workflows can push alerts and issues to external systems such as Teams, Telegram, GitHub, and Jira.

How do you handle data security?

Communication is protected with TLS and workflows are tracked with auditable logs. Access is controlled per workspace.

Can we track progress over time?

Yes. Drift-aware comparisons and risk scoring help teams monitor change between scans and focus on new critical issues.