Public methodology

URL Radar Methodology and Analysis Limits

A transparent account of what URL Radar checks, how evidence is scored, how browser isolation works and what a report cannot prove.

Evidence collection

Radar validates every submitted URL and every redirect against public-network policy before fetching. Requests are bounded by time, bytes, redirect count and concurrency. Static analysis does not execute page scripts.

Analysis layers

Independent checks cover URL and brand context, reputation, domain and hosting context, DNS, TLS, redirects, response content, forms, scripts, clipboard behaviour, documents and file-delivery indicators. Selected risks may also use a separate credential-free browser worker.

Scoring and confidence

Deterministic findings carry severity and points. Correlation rules increase confidence only when independent evidence supports the same interpretation. A brand mismatch on infrastructure registered less than 14 days ago is elevated to at least Suspicious and requires review. Reputation-provider matches remain visibly separate from heuristic scoring. Shared infrastructure can suggest a relationship but never changes a verdict by itself.

Browser-analysis boundary

The isolated worker uses a pinned public-network request broker, blocks private destinations and service workers, limits requests and bytes, and never runs operating-system commands or downloaded files. Eligible brand and new-domain signals receive rendered title and visible-brand comparison. One controlled verification interaction may be used on eligible pages; forms are not submitted.

Privacy and retention

New free scans create public reports retained for 30 days and listed on the dashboard for 24 hours. Public report views reduce HTTP addresses to their website origin so paths, query values, fragments and embedded credentials are withheld. The submitting browser can display its own exact entered address from session-only storage. Reports remain unindexed, exact duplicate matching uses the internally retained normalised address, and expired database records are physically deleted. Legacy reports created under the earlier private policy are not retroactively listed.

Known limitations

Review the engine changelog