Security made easy.

We make software to protect you and yours. Type a domain — watch Romp work.

Non-invasive scans — DNS, TLS, security headers. Sign up for full vulnerability assessment.

Or see a sample scan output ↓
Security headers17%
1/6 critical security headers present (11 total seen)
Missing: strict-transport-security, x-content-type-options, x-frame-options, content-security-policy, referrer-policy
DNS5 types
A 104.20.23.154, 172.66.147.243
AAAA 2606:4700:10::6814:179a, 2606:4700:10::ac42:93f3
NS hera.ns.cloudflare.com., elliott.ns.cloudflare.com.
TXT "v=spf1 -all"
TLS / Certificate75d left
Subject: example.com
Issuer: CLOUDFLARE, INC.
Valid until: Jul 1 21:24:46 2026 GMT

Free online, or own the source.

Online

Free

  • The full scanner — all 9 Otter modules
  • Runs in any modern browser
  • Unlimited scans
  • No signup, no card, no catch
Try Romp

Common questions

How is Romp different from Burp / Nessus / OWASP ZAP?

Romp is built for prosumers and small security teams — not enterprises. We're free to use online (vs Burp Pro's $475/yr), simpler (no proxy setup, no DAST configuration), and run in a browser. Burp is the right tool for in-depth manual pentest workflows. Romp is the right tool for fast recon + automated checks on dozens of targets.

Is it legal to use Romp?

Romp itself is legal everywhere it ships. Using Romp against systems you don't own or have permission to test is a crime — see our Acceptable Use Policy for the specific statutes (US 18 U.S.C. § 1030, UK Computer Misuse Act 1990, EU 2013/40/EU). Scan only what you own or have written authorization for.

Can I install the Download tier on Windows?

Currently supported: Linux (Debian, Ubuntu, Fedora, RHEL, Arch, Alpine), macOS (Intel + Apple Silicon), and Windows via WSL2. Native Windows (no WSL) is on the roadmap. The Romp PWA runs in any modern browser including Windows Chrome / Edge / Firefox.

What if my scan finds a real vulnerability?

Document it, then report it responsibly to the system owner — not on social media, not in a public Discord. Romp gives you the tools; responsible disclosure is on you. If the affected system is ours, email privacy@domainless.fun and we'll respond within 48 hours.

How do I cancel?

Sign in → Account → Manage Billing → "Cancel subscription" in the Stripe-hosted portal. Your access continues through the end of the paid period. No phone calls, no retention scripts.

Do you offer refunds?

Yes. Download purchases are refundable within 14 days if the software does not work as described. After 14 days, all sales are final.

Do you have an API?

Yes — every scanner is reachable at /v1/scan/:otter/:method with a JWT cookie (Sub tier) or ed25519 license token header (Download tier). The signed public key for offline JWT verification is at /v1/auth/public-key.pem.

What data do you collect about me?

The minimum to run Romp: email, password (scrypt-hashed), tier, payment record, and scan-target hostname + your IP at scan time (rate limiting + abuse prevention). We don't sell data, run trackers, or share with marketers. Full details in our Privacy Policy.

Built like the security software it claims to be.