Traffic transparency
Asset Intelligence traffic
Kantoku helps organizations observe internet-facing assets they own, control, or are authorized to monitor. This page explains why you may see Kantoku traffic and how to report activity that appears unexpected.
Why you may see this traffic
A Kantoku customer may have configured your domain, IP address, or a related web surface as part of its authorized Asset Intelligence scope.
Traffic can include requests to public pages and common metadata files, rendered browser visits, and targeted checks of internet-facing services selected by the customer. Collection scope and cadence depend on the customer's configuration.
Authorization is required
Kantoku customers must own, control, or have authorization to monitor the assets they configure. The service is not intended for scanning unrelated internet assets or for unauthorized security testing.
Website and network operators remain free to block or rate-limit requests using their normal access controls. If you believe the traffic is outside an authorized scope, please report it so we can investigate.
How requests are identified
Collector-owned HTTP requests use the following user agent. Browser-based collection keeps the standard Chromium identity and adds the Kantoku Asset Intelligence identifier shown below.
KantokuAssetIntelligence/1.0 (+https://kantoku.io/abuse)Kantoku publishes the source IP addresses currently used by Asset Intelligence at api.kantoku.io/v1/source-ips. The list can change over time, so use that endpoint as the source of truth when identifying, allowlisting, or filtering collection traffic.
Report unexpected traffic
Email abuse@kantoku.io and include the source IP address, UTC timestamp, destination hostname or IP address, requested path or port, and the complete user agent or a relevant log excerpt. Please do not include credentials or other secrets.