Policy · effective 1 May 2026

Domain Verification Policy

How Provantis proves ownership of a website before scanning it — and what each method does and does not prove.


1. Why verification matters

Provantis is a compliance scanning platform. Without a verification gate, anyone could submit a competitor's URL, a regulator's URL, or any other third-party site for an automated audit. That would turn the platform into a competitive-intelligence weapon and would breach the Cybercrimes Act 19 of 2020 (unauthorised access to computer systems and data).

Every domain in your account must therefore be added to your Verified Domain Register. A domain only becomes scannable after we have proof — using one of the methods below — that you own it or are authorised to scan it.

2. Approved verification methods

We accept five forms of proof. Customers may pick whichever is easiest. All five are recognised industry standards used by public Certificate Authorities, Google, Microsoft, AWS and Cloudflare.

Method What it proves Equivalent to
Signup-email match (silent) The Provantis user's verified signup email shares the same registrable domain (e.g. alice@example.co.za adding example.co.za). Confirmed-email signup at any SaaS provider.
Email link Possession of a role mailbox at the domain (admin@, administrator@, webmaster@, hostmaster@, postmaster@, info@). Click a tokenised one-time link. Domain-Validated SSL issuance (Let's Encrypt, Sectigo, DigiCert).
HTML meta tag Edit access to the homepage. Paste <meta name="provantis-verify" content="TOKEN"> into the <head>. Google Search Console site verification.
Verification file Edit access to the web server. Place a tokenised file at /.well-known/provantis-verify-TOKEN.txt. ACME HTTP-01 challenge (Let's Encrypt).
DNS TXT record (strongest) Control of DNS for the domain itself. Publish a TXT record on the apex. ACME DNS-01 challenge, Microsoft 365 / Google Workspace tenant verification.

3. Token lifetimes and reuse

4. Audit trail

Each successful verification is recorded with:

A separate flag, verification_method='legacy', identifies any domain that was auto-trusted from a customer's primary URL before 1 May 2026, when this verification policy was introduced. Pre-cutoff legacy entries are clearly marked in the audit register; no new legacy entries are created after that date.

5. What verification does not prove

Honesty matters here. Domain ownership verification proves technical control of the domain at a point in time. It does not by itself prove:

Provantis users tick an ownership and authority attestation when adding a domain. By doing so they accept legal responsibility under the Provantis Terms of Service for the accuracy of that attestation, and indemnify Provantis (Pty) Ltd against claims by third parties arising from a false attestation.

6. Higher-assurance option

Customers operating in high-risk environments — for example, large brokerages with rotating IT staff, or underwriting managers handling sensitive insurer book data — may request an "DNS-only" enforcement mode on their tenant. Under this mode the email-link, meta-tag, file and signup-email paths are disabled, and only DNS TXT verification is accepted. Contact support@provantis.co.za to enable it.

7. Removing a verified domain

Any tenant administrator may remove a verified domain at any time from the Verified Domain Register. Removal is logged. Past scan history for that domain is retained for the audit record, but the domain is immediately removed from any active scan schedule, and no further scans can be initiated against it until it is re-added and re-verified.

8. Defensive scope

This policy is a technical control. It does not constitute legal advice, a regulatory opinion or an audit certification. Customers requiring formal third-party assurance over the verification process should engage a licensed external auditor.


Document owner: Provantis Engineering · Last reviewed: 1 May 2026. Material changes to this policy will be communicated to all active tenants by email at least 14 days before the new policy takes effect.