What scanning our own domains taught us
Every case study here is about an asset Infiqon owns — secqon.com and its sibling product docqon.com. We have no customer stories to tell yet, and we will not invent one. What we can show is how the scanner behaves on real sites, with the dates and the numbers, including the times it was wrong.
· secqon.com, docqon.com
SecQon failed its own scan
On 29 August 2026 our own site and API sent none of the five security headers SecQon reports other people for, and our TLS probe could not see that two of our domains still accepted TLS 1.0 and 1.1.
· docqon.com
A deep scan of docqon.com: 4.2 hours, 85,888 requests, nothing exploited
The first complete Deep sweep of docqon.com, an Infiqon product: what it cost in time and requests, what it found, and why "14 confirmed" did not mean 14 exploits.
· secqon.com, www.secqon.com, docqon.com
How we keep findings true: false positives we found on our own domains
Every false positive on this page is one we produced against our own domains. Here is how we caught them, what changed, and what the word "confirmed" is now allowed to mean.
See what a scan finds on your own asset
Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.