Online
Free
- The full scanner — all 9 Otter modules
- Runs in any modern browser
- Unlimited scans
- No signup, no card, no catch
We make software to protect you and yours. Type a domain — watch Romp work.
Non-invasive scans — DNS, TLS, security headers. Sign up for full vulnerability assessment.
strict-transport-security, x-content-type-options, x-frame-options, content-security-policy, referrer-policyexample.comCLOUDFLARE, INC.Jul 1 21:24:46 2026 GMTFree
$99 one-time
Romp is built for prosumers and small security teams — not enterprises. We're free to use online (vs Burp Pro's $475/yr), simpler (no proxy setup, no DAST configuration), and run in a browser. Burp is the right tool for in-depth manual pentest workflows. Romp is the right tool for fast recon + automated checks on dozens of targets.
Romp itself is legal everywhere it ships. Using Romp against systems you don't own or have permission to test is a crime — see our Acceptable Use Policy for the specific statutes (US 18 U.S.C. § 1030, UK Computer Misuse Act 1990, EU 2013/40/EU). Scan only what you own or have written authorization for.
Currently supported: Linux (Debian, Ubuntu, Fedora, RHEL, Arch, Alpine), macOS (Intel + Apple Silicon), and Windows via WSL2. Native Windows (no WSL) is on the roadmap. The Romp PWA runs in any modern browser including Windows Chrome / Edge / Firefox.
Document it, then report it responsibly to the system owner — not on social media, not in a public Discord. Romp gives you the tools; responsible disclosure is on you. If the affected system is ours, email privacy@domainless.fun and we'll respond within 48 hours.
Sign in → Account → Manage Billing → "Cancel subscription" in the Stripe-hosted portal. Your access continues through the end of the paid period. No phone calls, no retention scripts.
Yes. Download purchases are refundable within 14 days if the software does not work as described. After 14 days, all sales are final.
Yes — every scanner is reachable at /v1/scan/:otter/:method with a JWT cookie (Sub tier) or ed25519 license token header (Download tier). The signed public key for offline JWT verification is at /v1/auth/public-key.pem.
The minimum to run Romp: email, password (scrypt-hashed), tier, payment record, and scan-target hostname + your IP at scan time (rate limiting + abuse prevention). We don't sell data, run trackers, or share with marketers. Full details in our Privacy Policy.