FAQ & troubleshooting
A site got the “Needs attention” verdict — what does it mean?
Section titled “A site got the “Needs attention” verdict — what does it mean?”The scanner could not read the site properly. Two typical causes (shown as diagnostic flags in the site list):
- An SPA site — pages are assembled by JavaScript in the browser, and the server HTML contains almost no text. The scanner works with server-rendered HTML, so such a site looks “empty”. Full JS rendering is on the roadmap; for now such sites should be checked manually.
- robots.txt restrictions — the site forbids robot crawling, and the scanner respects that.
The site status “Needs attention” can also be used manually — as a “look into this” mark for colleagues.
Too many false positives — how do I silence them?
Section titled “Too many false positives — how do I silence them?”In order of effectiveness:
- A skip-rule — when the phrase legitimately appears on the site (classics: “whiskey” in a coffee syrup, “cocaine” in the Franck Boclet perfume name). Created in one click from the alert page (“More → Add skip-rule”); by default it applies to this site only.
- The “False positive” status — for one-off cases; false-positive statistics help clean up stop lists.
- Refine the stop list — an overly generic phrase is better replaced with a more specific one.
- “Clear false positives” on the site — bulk-removes already marked false alerts.
On the Premium plan, run “Classify with AI” before manual review — the model proposes a verdict based on context.
I can see a violation on the site but the scanner didn’t find it. Why?
Section titled “I can see a violation on the site but the scanner didn’t find it. Why?”Check in order:
- The phrase is not in the stop lists — the scanner only finds what is listed (exact, morphology-aware matches). Semantic “by meaning” search works on Premium only.
- The page was not crawled — plans have page and depth limits; a very large catalogue
may not be covered fully. Sections listed in
sitemap.xmlare discovered best. - The text is in an image — OCR is out of the system’s scope.
- The content is rendered by JavaScript — see the SPA question above.
- The site may have changed after the last scan — run “Re-scan”.
The “Scanning…” badge has been showing for a long time — is that normal?
Section titled “The “Scanning…” badge has been showing for a long time — is that normal?”Crawling a large site takes time: the scanner pauses between requests to the same domain to avoid loading the merchant’s site. The badge clears automatically when the scan finishes; if it stays longer than ~30 minutes, the crawl probably aborted — run “Re-scan” or contact support.
How often are sites scanned?
Section titled “How often are sites scanned?”Per the frequency in the site form: daily / weekly / monthly, or “Auto” — by the merchant’s risk level (high — daily, medium — weekly, low — monthly). For “Auto” without a computed risk, the organisation’s default frequency applies. An out-of-schedule scan — the “Re-scan” action at any time.
A colleague did not receive the invitation email
Section titled “A colleague did not receive the invitation email”- Check the spam folder and the email address in the user’s card.
- The link is valid for 72 hours — when expired, use “Resend invitation”.
- If email doesn’t reach the employee at all — the “Copy invitation link” action in the user list: hand the link over via any channel.
Violation notifications are not arriving
Section titled “Violation notifications are not arriving”Check the Notification email in “Administration → Settings” — violation emails go to that address (not to individual users). In-app notifications (the bell) reach all officers and administrators of the organisation after every scan with new alerts.
The two-factor authentication code is not arriving
Section titled “The two-factor authentication code is not arriving”The code is sent to the account email and is valid for a few minutes. Check spam; if there is no code, request it again from the sign-in screen. As a last resort the administrator can temporarily disable 2FA in the user’s card.
How do I prove a violation to a card scheme?
Section titled “How do I prove a violation to a card scheme?”Every alert has immutable evidence: a snapshot of the page text (and a screenshot on Premium) tied to the scan moment — later scans never overwrite them. For handover: the “PDF report” on an alert, Excel export from the alert list, the Underwriting case PDF report.
Why can’t I see the “Settings” / “Users” sections?
Section titled “Why can’t I see the “Settings” / “Users” sections?”They are only available to the Administrator role. A compliance officer works on review and cases, an auditor only reads. If you need access — ask your organisation’s administrator (roles in detail).