Policy · effective 1 May 2026
How Provantis proves ownership of a website before scanning it — and what each method does and does not prove.
Provantis is a compliance scanning platform. Without a verification gate, anyone could submit a competitor's URL, a regulator's URL, or any other third-party site for an automated audit. That would turn the platform into a competitive-intelligence weapon and would breach the Cybercrimes Act 19 of 2020 (unauthorised access to computer systems and data).
Every domain in your account must therefore be added to your Verified Domain Register. A domain only becomes scannable after we have proof — using one of the methods below — that you own it or are authorised to scan it.
We accept five forms of proof. Customers may pick whichever is easiest. All five are recognised industry standards used by public Certificate Authorities, Google, Microsoft, AWS and Cloudflare.
| Method | What it proves | Equivalent to |
|---|---|---|
| Signup-email match (silent) | The Provantis user's verified signup email shares the same registrable domain (e.g. alice@example.co.za adding example.co.za). |
Confirmed-email signup at any SaaS provider. |
| Email link | Possession of a role mailbox at the domain (admin@, administrator@, webmaster@, hostmaster@, postmaster@, info@). Click a tokenised one-time link. |
Domain-Validated SSL issuance (Let's Encrypt, Sectigo, DigiCert). |
| HTML meta tag | Edit access to the homepage. Paste <meta name="provantis-verify" content="TOKEN"> into the <head>. |
Google Search Console site verification. |
| Verification file | Edit access to the web server. Place a tokenised file at /.well-known/provantis-verify-TOKEN.txt. |
ACME HTTP-01 challenge (Let's Encrypt). |
| DNS TXT record (strongest) | Control of DNS for the domain itself. Publish a TXT record on the apex. | ACME DNS-01 challenge, Microsoft 365 / Google Workspace tenant verification. |
Each successful verification is recorded with:
signup_email, email, meta, file, txt) and, for the email path, the exact mailbox the link was sent to.A separate flag, verification_method='legacy', identifies any domain that was auto-trusted from a customer's primary URL before 1 May 2026, when this verification policy was introduced. Pre-cutoff legacy entries are clearly marked in the audit register; no new legacy entries are created after that date.
Honesty matters here. Domain ownership verification proves technical control of the domain at a point in time. It does not by itself prove:
Provantis users tick an ownership and authority attestation when adding a domain. By doing so they accept legal responsibility under the Provantis Terms of Service for the accuracy of that attestation, and indemnify Provantis (Pty) Ltd against claims by third parties arising from a false attestation.
Customers operating in high-risk environments — for example, large brokerages with rotating IT staff, or underwriting managers handling sensitive insurer book data — may request an "DNS-only" enforcement mode on their tenant. Under this mode the email-link, meta-tag, file and signup-email paths are disabled, and only DNS TXT verification is accepted. Contact support@provantis.co.za to enable it.
Any tenant administrator may remove a verified domain at any time from the Verified Domain Register. Removal is logged. Past scan history for that domain is retained for the audit record, but the domain is immediately removed from any active scan schedule, and no further scans can be initiated against it until it is re-added and re-verified.
This policy is a technical control. It does not constitute legal advice, a regulatory opinion or an audit certification. Customers requiring formal third-party assurance over the verification process should engage a licensed external auditor.
Document owner: Provantis Engineering · Last reviewed: 1 May 2026. Material changes to this policy will be communicated to all active tenants by email at least 14 days before the new policy takes effect.