01 · Operator
Who operates Cythentic-ExposureScan
- Company
- Cythentic, Inc.
- Type
- Monitoring bot
- Official docs
- cythentic.com
02 · Behavior
What Cythentic-ExposureScan does
Cythentic offers a free external exposure scan on its website. The scan checks 21 risk areas from outside, such as open ports, known vulnerabilities, security headers and SSL issues. Cythentic says it uses publicly available information and does not access internal systems. Results feed a risk scorecard and sales follow-up.
03 · Impact
Why Cythentic-ExposureScan matters for your site
If you allow it
- Scans are passive checks of public signals
- A scan may reveal security gaps worth fixing
If you block it
- Scans can be started by third parties for any domain
- Results serve Cythentic's sales funnel, not your visibility
- No documented robots.txt support
04 · Allow
How to allow Cythentic-ExposureScan
robots.txt
User-agent: Cythentic-ExposureScan
Allow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "Cythentic-ExposureScan")
Action: Skip › All Super Bot Fight Mode rules
# Also check Security › Bots: "Block AI bots" can block it regardless of robots.txt.
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: Cythentic-ExposureScan
Allow: /
nginx
# nginx serves every user agent by default.
# Make sure no rule like this blocks it:
# if ($http_user_agent ~* "Cythentic\-ExposureScan") { return 403; }
Apache
# Apache serves every user agent by default.
# Make sure .htaccess has no rule like this:
# RewriteCond %{HTTP_USER_AGENT} Cythentic\-ExposureScan [NC]
# RewriteRule .* - [F,L]
05 · Block
How to block Cythentic-ExposureScan
Start with robots.txt. If Cythentic-ExposureScan keeps showing up in your logs, block it at your CDN or web server.
robots.txt
User-agent: Cythentic-ExposureScan
Disallow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "Cythentic-ExposureScan")
Action: Block
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: Cythentic-ExposureScan
Disallow: /
nginx
# In your server { } block:
if ($http_user_agent ~* "Cythentic\-ExposureScan") {
return 403;
}
Apache
# .htaccess
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} Cythentic\-ExposureScan [NC]
RewriteRule .* - [F,L]
</IfModule>
06 · User agents
User agents we see for Cythentic-ExposureScan
| User agent | Share | Last seen | Status |
|---|---|---|---|
Cythentic-ExposureScan/1.0 (https://cythentic.com/x/scan) |
100% | Unverified |
07 · Verification
Is it really Cythentic-ExposureScan?
Cythentic-ExposureScan’s operator publishes no IP ranges or hostnames, so requests cannot be verified. Treat the user agent as a claim, and watch your logs for unusual request rates.
FAQ
Questions about Cythentic-ExposureScan
What is Cythentic-ExposureScan?
It is the scanner behind Cythentic's free external exposure scan. It checks a domain for open ports, vulnerabilities, missing security headers and SSL issues.
Does Cythentic-ExposureScan respect robots.txt?
Cythentic does not document robots.txt handling. Blocking the user agent at the server or firewall is the reliable option.
How do I contact Cythentic about the scanner?
The scan page lists corey@cythentic.com as the contact for questions.
Last reviewed Oct 8, 2026