Security and Privacy
Learn how AssetLoom Network Scanner protects your network data, handles scan results locally, and supports secure, privacy-conscious network discovery.
AssetLoom Network Scanner discovers information about devices on your network, so both the networks you scan and the results you generate should be handled carefully.
This guide explains how the scanner handles data, and the recommended practices for keeping your network scans secure.
1. How Scan Data Is Handled
The Network Scanner performs discovery from the computer where you run it. Depending on the available discovery methods, it can collect information such as:
- IP addresses
- MAC addresses
- Hostnames
- Open TCP ports
- Device classification
- Scan timestamps
The scanner saves this information to the CSV or JSON output file you specify. Your scan results remain in the local output file unless you choose to move or share that file yourself.
2. Protect Your Scan Results
Scan results provide information about the devices and services available on your network. For this reason, treat CSV and JSON result files as sensitive network inventory data.
To protect your results:
- Store configuration and output files in directories that only authorized users can access.
- Follow your organization’s security policies when storing, transferring, or sharing scan results.
- Do not email or share complete scan output unless your organization’s policy allows it.
- Remove or redact sensitive information before sharing files for troubleshooting when necessary. If you ran the scanner with administrator access, also make sure the resulting files have appropriate permissions before giving other users access.
3. Recommended Security Practices
Only Scan Authorized Networks
Before scanning a network, make sure you have permission to scan the selected targets.
Use approved_ranges whenever possible to explicitly define which networks the scanner is permitted to scan.
For example: "approved_ranges": ["192.168.1.0/24"]
This helps prevent the scanner from unintentionally scanning networks outside your approved scope. Routed networks and public IP ranges are blocked by default and require explicit approval if needed.
Validate the Scope Before Scanning
Before scanning a new or broad network range, run a dry run:
- macOS/Linux:
sudo ./assetloom-scanner --config ./config.json --dry-run TARGET - Windows:
.\assetloom-scanner.exe --config .\config.json --dry-run TARGET
A dry run does not send discovery packets. It shows which targets will be accepted or rejected, the number of candidate hosts, how the target is classified, and which discovery protocols would be used.
Review this information before starting the actual scan to make sure the scanner will only operate within the network scope you intend to scan.
Sharing Information for Support
If you need help troubleshooting a scan, you may be asked to provide information including
- The scanner version output from
--version - The command used
- Dry-run output
- The scanner capture log
- Configuration file
- A relevant output row.
Before sharing:
- Remove sensitive values from your configuration where necessary.
- Share only the output rows needed to investigate the issue.
- Do not share complete scan results outside your organization unless approved.
What’s Next?
- Operating System Notes: Platform-specific guidance on running the scanner on macOS, Windows, and Linux
- CLI Reference: A complete list of scanner commands and command-line options
- Configuration Reference: Details about
config.jsonsettings, including scan scope, protocols, ports, timeouts, concurrency, and limits - Release Verification: Instructions on checking the scanner version, build information, SHA256 checksum, and SBOM