In this article

We look at why attack surface management and cyber-risk scanning companies, businesses that scan large swaths of the public internet as their core product, run into trouble on hyperscaler infrastructure, what actually needs to be true about a provider’s acceptable use policy and IP allocation to support this workload, and how that differs from running an internal penetration testing lab.


Your product scans the open internet. That’s not a side effect of what you do, it’s the product itself, and it puts you in a strange position with most infrastructure providers: your traffic looks, to an automated abuse system, almost identical to an attacker’s.

That’s a real, structural problem for attack surface management vendors, cyber-risk scoring companies, and vulnerability research platforms, not an edge case. Port scanning, banner grabbing, and service discovery across large IP ranges are exactly the behaviors most hosting providers’ abuse detection exists to catch.

Why This Is a Different Problem Than Penetration Testing

It’s worth being precise about what kind of scanning this is, because it’s a different situation than testing your own environment. We’ve written before about building a contained penetration testing lab on private cloud infrastructure, where the core problem is isolating your own security testing from your own production systems, and from a hyperscaler’s automated defenses that can’t distinguish your authorized test from a real intrusion against your own account.

Attack surface management and internet-scanning companies have a different problem entirely. The scanning isn’t contained to infrastructure you own, it’s aimed outward, at other organizations’ public IP ranges, at real scale, as the actual business. The risk isn’t that your own provider’s monitoring flags your test. It’s that the organizations you scan, who never asked to be scanned, file abuse complaints with your provider, and a provider unprepared for that pattern treats every complaint as a strike against your account regardless of whether the underlying scanning was legitimate, non-intrusive, and industry-standard.

What a Provider’s Acceptable Use Policy Actually Needs to Support

The practical question for this business model isn’t whether scanning is allowed in the abstract. It’s what happens the first time someone reports you.

OpenMetal’s Acceptable Use Policy doesn’t proactively monitor customer traffic or content. Enforcement is complaint-driven: if a report comes in, it’s investigated, and OpenMetal retains discretion over how to respond, rather than an automated system auto-suspending an account the moment a complaint lands. For a scanning company operating at genuine internet scale, that distinction matters enormously. Automated, zero-context suspension on first complaint makes this business model impossible to run at all, since large-scale non-intrusive scanning generates some volume of confused or annoyed recipients almost by definition, regardless of how responsibly it’s done. A complaint-driven process that allows for actual review is the structural difference between a provider you can build this business on and one you can’t.

That said, this isn’t a blank check, and it shouldn’t be treated as one. A legitimate scanning operation should expect to explain itself when asked, and a provider’s discretion cuts both ways: it protects reasonable, well-run scanning operations, and it doesn’t protect operations that are actually abusive or that ignore reasonable requests to stop scanning a specific target on request.

Isolating Reputation with Dedicated IP Space

Internet-wide scanning generates a specific technical need that most workloads don’t: IP reputation isolation. Scanning traffic can end up on abuse blocklists and threat-intelligence feeds maintained by third parties, regardless of intent, simply because the traffic pattern matches what those lists are built to catch. If that traffic shares IP space with unrelated customers, one company’s scanning activity can affect another customer’s mail deliverability, web reputation, or general trust score with third-party security tools, which is a real operational risk for a shared-IP environment.

Dedicated, customer-specific IP allocation avoids that cross-contamination. OpenMetal assigns dedicated public IP space per customer and supports bringing your own IP blocks (/24 or larger) for announcement through its network, which means a scanning company’s IP reputation stays its own problem to manage, not something that leaks onto or from other tenants sharing the same address space. If your scanning volume is large enough that IP allocation is a real planning question, that’s worth a direct conversation about your specific range and routing needs rather than assuming a default allocation covers it.

What Legitimate Scanning Companies Should Have Ready Regardless of Provider

A few practices are close to industry standard for this business model, and having them in place makes any conversation with a provider’s abuse team faster and more productive:

  • A reverse DNS record and a scan-info page explaining who’s scanning, why, and how to opt out, reachable by anyone who looks up the source IP of an unexpected scan
  • A published abuse and opt-out contact that actually gets monitored, so a target organization’s first move is emailing you rather than filing a complaint with your provider
  • Documented rate limiting that keeps individual target networks from being hit hard enough to look like a denial-of-service attempt
  • A clear internal record of scan scope and intent that can be produced quickly if a provider’s abuse team asks for context on a specific complaint

None of this eliminates complaints entirely. Legitimate, well-run scanning still generates some. What it does is make each complaint fast to resolve rather than a prolonged back-and-forth that puts your account at risk while it gets sorted out.

Who This Fits

  • Fits well if your core product involves scanning, fingerprinting, or cataloging systems across large swaths of the public internet that you don’t own or directly manage
  • Fits well if you’ve already been suspended, warned, or had service degraded by a hyperscaler or shared-hosting provider for exactly this kind of traffic pattern
  • Fits well if IP reputation isolation from other tenants is a real operational requirement, not a nice-to-have
  • Doesn’t fit as well if your actual need is testing your own systems or your own clients’ systems under authorization, since that’s a contained penetration-testing scenario with different infrastructure needs, covered in our pentest lab piece

Getting Started

Dedicated bare metal servers and hosted private cloud configurations are on our bare metal pricing page. Full policy details are in our Acceptable Use Policy, and if your scanning volume and IP allocation needs are substantial, that’s worth a direct conversation before you commit to a deployment size.

FAQ

Does OpenMetal allow internet-wide security scanning as a business?

OpenMetal’s Acceptable Use Policy is complaint-driven rather than based on automated, zero-context suspension. Legitimate, non-intrusive scanning for attack surface management or cyber-risk research is a different situation than actual abuse, but any provider retains discretion to act on reports. Review the full Acceptable Use Policy and discuss your specific use case directly before deploying at scale.

Why do hyperscalers suspend legitimate security scanning companies?

Most hyperscaler abuse detection is automated and can’t reliably distinguish authorized, industry-standard scanning from an actual intrusion attempt, especially when third parties who were scanned file complaints. Automated systems often act on complaint volume rather than context, which puts legitimate scanning businesses at risk regardless of how responsibly they operate.

How is this different from a penetration testing lab?

A penetration testing lab is about safely testing systems you own or have explicit authorization to test, contained on infrastructure isolated from your production environment. Internet-wide attack surface scanning targets systems outside your organization at scale as the core product, which raises different questions around IP reputation, third-party abuse complaints, and provider policy, rather than containment from your own systems.

Can I get a dedicated IP block to isolate my scanning traffic’s reputation?

OpenMetal assigns dedicated public IP space per customer and supports bringing your own IP blocks for announcement. For scanning operations at meaningful volume, discussing IP allocation and routing directly, rather than assuming default allocation, is worth doing before deployment.


Chat With Our Team

We’re available to answer questions and provide information.

Reach Out

Schedule a Consultation

Get a deeper assessment and discuss your unique requirements.

Schedule Consultation

Try It Out

Take a peek under the hood of our cloud platform or launch a trial.

Trial Options

 

 

 Read More on the OpenMetal Blog

Infrastructure for Internet-Wide Security Scanning and Attack Surface Management

Aug 17, 2026

We look at why attack surface management and cyber-risk scanning companies, businesses that scan large swaths of the public internet as their core product, run into trouble on hyperscaler infrastructure, what actually needs to be true about a provider’s acceptable use policy and IP allocation to support this workload, and how that differs from running an internal penetration testing lab.

Why the EU Cyber Resilience Act’s Reporting Clock Depends on Your Infrastructure

Aug 07, 2026

We break down what the EU Cyber Resilience Act’s vulnerability reporting obligations actually require starting September 2026, why the tight reporting clock is fundamentally an infrastructure visibility problem, and where dedicated infrastructure and controlled build pipelines make that clock achievable.

Infrastructure for Post-Quantum Cryptography and Crypto-Agility

Aug 05, 2026

We look at why post-quantum cryptography has moved from a research topic to a binding compliance deadline, why “harvest now, decrypt later” makes this an infrastructure problem today rather than a future one, and why crypto-agile key management needs hardware you control directly.

Why MEV Block Building Infrastructure Is Moving to TDX Bare Metal

Jul 09, 2026

The operator trust problem in MEV block building has a hardware solution. This article explains why Intel TDX has become the substrate of choice for confidential block building, and what bare metal adds that cloud TDX doesn’t.

What HIPAA Requires from the Infrastructure Running Your Healthcare AI Workloads

Jul 02, 2026

Healthcare AI workloads carry the same HIPAA obligations as any system touching PHI. This article covers what the 2026 Security Rule update requires from AI infrastructure, why vector embeddings count as PHI, and how dedicated private cloud simplifies the compliance documentation burden.

What DORA’s ICT Concentration Risk Requirements Mean for EU Financial Infrastructure

Jun 17, 2026

DORA has been in force since January 2025, and the third-party ICT risk requirements are where infrastructure decisions land hardest. This article breaks down what Articles 28–30 require, why hyperscaler concentration is now a documented regulatory problem, and how private cloud in the EU changes the risk picture.

Why Immutable Storage Is Now a Cyber Insurance Requirement

Jun 03, 2026

Cyber insurance renewals in 2026 involve technical audits, not questionnaires. This article covers the five controls insurers now require, why standard backup configurations often fail the immutability test, what NIS2 and SEC rules demand, and how dedicated Ceph object storage satisfies the full requirement at predictable cost.

How MSPs Can Win Clients With Compliance and Private Cloud

Apr 30, 2026

Enterprise clients in regulated industries are asking harder infrastructure questions than most MSPs are equipped to answer. This article covers where the Microsoft stack has limits for compliance workloads, what private cloud adds to an MSP’s portfolio, and how to start without overhauling your entire stack.

Hosted Private Cloud for Regulated Industries

Apr 17, 2026

Regulated organizations need more than encryption promises from their cloud provider. This article covers how OpenMetal’s single-tenant hosted private cloud supports HIPAA, PCI DSS, NIST 800-53, and other compliance frameworks across healthcare, finance, government, and beyond.

Adding Confidential Computing to Existing Infrastructure Without Starting Over

Feb 18, 2026

Many companies need confidential computing but can’t rebuild infrastructure from scratch. This guide shows how to add Intel TDX bare metal alongside existing OpenMetal or AWS/Azure/GCP setups. Covers workload prioritization, hybrid architecture patterns, cost analysis, and 2-3 month implementation timeline.