Promptwatch Logo

Detectify

Detectify is a web security scanner that performs automated security tests on web applications and attack surface monitoring.
Detectify
MonitoringUser Initiated

What is Detectify?

Detectify sends this traffic while assessing a web application for security weaknesses. The customer creates a Scan Profile for an asset and controls the scope of the assessment. This is an authorized test of that application, not an attempt to build a general web index.

Application Scanning begins at the root and can try likely application paths before following discovered pages. The scanner exercises forms and buttons as part of its testing, so careless scope can send messages or change application state. Included paths add starting points; avoided paths keep the scanner away from sensitive or costly sections. The profile can also limit requests per second and exclude subdomains.

The normal Application Scanning header starts with Mozilla/5.0 (compatible; Detectify) and includes a Detectify link with a scan token. That link provides details about who started the scan and when. API scans add their own marker, and customers can select another device header or supply a custom value. Detectify therefore recommends checking its current source addresses before trusting a request.

No part of the supplied record or operator documentation assigns this scanner an AI search or model-training role. It discovers pages only as needed for the customer's security assessment. A block can prevent findings from reaching that customer, but it does not opt the content out of AI use.

Not relevant for AI search

Is Detectify relevant for AI search?

No. Detectify is not part of AI search or training, so allowing or blocking it does not change your AI visibility.

Detectify runs synthetic monitoring or uptime checks on a schedule. It is not collecting content for any index or model, so it has no bearing on search rankings or AI answers. You usually see it because your own team or a service you use set up a check.

How to handle Detectify

Prepare an authorized scan in its Detectify profile. Put email-generating forms, deletion routes, and expensive listings in avoided paths where appropriate, then set a request limit if the application is sensitive to load. Allow Detectify's current published addresses when a WAF would otherwise stop the assessment.

The default identity can be addressed this way:

User-agent: Detectify
Disallow: /

This is not a reliable scan control. Detectify documents profile-level scope settings and customizable user agents, not robots.txt compliance, while the supplied Cloudflare record says it does not follow robots.txt. If the scan is unauthorized, verify the source and token link, then enforce the decision at the WAF or application.

Examples

  • A company scans its customer portal but adds `/close-account` and `/support/new` to avoided paths before the first run. It keeps the rest of the authenticated workflow in scope.
  • Unusual payloads arrive with a Detectify header. The responder follows the scan-specific link and checks the source against Detectify's current address list before allowing further requests.

Frequently asked questions about Detectify

Learn about AI visibility monitoring and how Promptwatch helps your brand succeed in AI search.

Application Scanning uses the root and other potential starting points, then evaluates discovered paths for security tests. A customer can add or avoid paths in the Scan Profile.

Be the brand AI recommends

Monitor your brand's visibility across ChatGPT, Claude, Perplexity, and Gemini. Get actionable insights and create content that gets cited by AI search engines.

Promptwatch Dashboard