our scanner

A considerate visitor, not a bot storm

Audera monitors your pharmaceutical sites from the outside, read-only, with nothing installed. This page explains exactly how our scanner behaves, how to recognise it in your access logs, and how to allowlist it if a security layer ever gets in its way.

fig. 01

pacing

One page at a time

A scan visits your pages strictly one page at a time, never concurrently, with a short randomised pause between each request. We never fan out parallel connections, so the load on your origin stays close to a single ordinary reader.

fig. 02

cadence

Daily, off-peak, jittered

Scheduled scans run at most a couple of times a day, in your site's local off-peak hours, with each scan's start time offset by a random amount so many sites never all begin at once.

fig. 03

scope

Read-only, outside-in

We only ever request pages a normal browser would, and we never submit forms, change data, or attempt to authenticate beyond credentials you've explicitly given us for a gated environment.

Identifying us in your logs

Every request Audera makes, from the lightweight status probe to our outbound link checks and the headless browser render, carries the same identification header so you can recognise and allowlist us in one rule:

request header
X-Audera-Monitor: +https://audera.app/scanner

If a WAF, bot-management product, or rate-limiter is blocking automated access, allow requests carrying that header through to your origin. When Audera can't reach a site, we tell you in one clear finding rather than flooding you with per-page errors. The underlying cause is almost always a security layer that hasn't been told we're friendly.

good citizenship

  • We honour redirects and stop at your site's own boundaries
  • We cap how much we download per page and never hammer an endpoint
  • We back off and surface a single finding rather than retrying in a loop

Something still not right? Email [email protected] and a person will help you allowlist us.