Promptwatch Logo

Sansec Security Monitor

Sansec Security Monitor is a web crawler that monitors online stores for malicious code, data breaches, and digital skimming attacks.
Monitoring

What is Sansec Security Monitor?

A visit from Sansec Security Monitor is an outside security check of a public online store. Sansec says the crawler has checked stores daily since 2015, looking for malicious code associated with data theft and digital skimming.

The full user agent is Mozilla/5.0 (compatible; Sansec SecurityMonitor/1.0; +https://sansec.io/monitor). Sansec also publishes sansec.io as the reverse DNS suffix for the crawler. The operator explicitly documents support for robots.txt and for crawl delays of up to 30 seconds.

If a scan finds malicious or highly suspicious code, Sansec sends an alert to the contact in /.well-known/security.txt. When that file has no contact, Sansec may try a known address for the domain. The remote crawler cannot inspect PHP, Node.js, or other code that runs only on the server, so it is not a substitute for server-side monitoring.

Sansec Security Monitor has no documented connection to AI search or model training. Its practical effect is limited to the security scan and any warning sent to the merchant. Allowing it does not improve a store's visibility in AI answers.

Not relevant for AI search

Is Sansec Security Monitor relevant for AI search?

No. Sansec Security Monitor is not part of AI search or training, so allowing or blocking it does not change your AI visibility.

Sansec Security Monitor runs synthetic monitoring or uptime checks on a schedule. It is not collecting content for any index or model, so it has no bearing on search rankings or AI answers. You usually see it because your own team or a service you use set up a check.

How to handle Sansec Security Monitor

Keep the crawler allowed if the store owner wants Sansec's external check, and publish a current contact in /.well-known/security.txt so an alert has a clear destination.

Sansec provides this rule for opting out:

User-agent: Sansec Security Monitor
Disallow: /

For a scan that is useful but too frequent, use Crawl-delay with the same token. Sansec documents a maximum delay of 30 seconds. A complete block ends this outside check and its warnings; it does not remove malware or inspect the server-side code that the crawler cannot reach.

Examples

  • A merchant sees `Sansec SecurityMonitor/1.0` on storefront requests, confirms the `sansec.io` reverse DNS suffix, and checks that `/.well-known/security.txt` lists the right address.
  • A store wants the daily outside scan but needs more space between requests, so it sets a five-second crawl delay for `Sansec Security Monitor`.

Frequently asked questions about Sansec Security Monitor

Learn about AI visibility monitoring and how Promptwatch helps your brand succeed in AI search.

Sansec operates and documents the monitor. Its documentation includes the user agent, reverse DNS suffix, robots rules, and alert process.

Be the brand AI recommends

Monitor your brand's visibility across ChatGPT, Claude, Perplexity, and Gemini. Get actionable insights and create content that gets cited by AI search engines.

Promptwatch Dashboard