Best Practices for Using Your Rescan Quota

Last updated: July 9, 2026

Introduction

Your Pentest plan includes a limited number of Manual Rescans that allow Astra's security engineers to verify whether the vulnerabilities identified during your assessment have been successfully remediated.

To help you make the most of your available rescans, Astra also offers unlimited Automated Rescans for eligible vulnerabilities. Using Automated Rescans to validate your fixes before requesting a Manual Rescan helps preserve your manual rescan quota while giving you immediate feedback on your remediation efforts.

This guide explains your rescan quota, validity period, rescan rules, and the recommended workflow for efficiently verifying your fixes.

Manual Rescan Quota

The number of Manual Rescans included depends on your Pentest plan.

Pentest Plan

Manual Rescans Included

Pentest (Hybrid)

2 Manual Rescans

Pentest Auto

1 Manual Rescan

Express VAPT

1 Manual Rescan

Note: Need additional Manual Rescans? You can purchase extra Manual Rescans as an add-on to your existing Pentest plan. To explore available options or request additional rescans, please reach out to your dedicated Customer Success Manager (CSM).

Rescan Validity Period

Manual Rescan requests must be submitted within the applicable rescan window for your engagement.

Pentest Plan

Manual Rescan Window

Pentest (Hybrid)

30 days from the date the vulnerabilities were reported

Pentest Auto

60 days from the date the vulnerabilities were reported

Express VAPT

60 days from the date the vulnerabilities were reported

Note: If you're unable to complete your remediation within the applicable rescan window, please contact your dedicated Customer Success Manager (CSM). Extensions to the rescan validity period may be granted on a case-by-case basis.

Understanding Rescan Rules

Choosing the appropriate rescan type ensures your vulnerabilities are verified efficiently.

Manual Rescan

A Manual Rescan can be used to verify vulnerabilities reported by:

  • Astra Security engineers

  • Autonomous Pentester

  • Bug Bounty Hunters

  • AstraBot (Scanner)

Manual rescans are reviewed by Astra's security engineers and count toward your plan's Manual Rescan quota.

Automated Rescan

An Automated Rescan can only be used to verify vulnerabilities reported by AstraBot (Scanner).

Automated rescans:

  • Start immediately after they're requested.

  • Can be performed an unlimited number of times.

  • Do not consume your Manual Rescan quota.

Recommended Workflow

Step 1: Fix the reported vulnerabilities

Implement the necessary code or configuration changes to remediate the identified vulnerabilities.

Step 2: Run an Automated Rescan first (when eligible)

If the vulnerability was reported by AstraBot (Scanner), initiate an Automated Rescan to validate your fix.

Since Automated Rescans are unlimited, they're an excellent way to confirm whether your remediation is successful before using a Manual Rescan.

Step 3: Make additional fixes if required

If the Automated Rescan still reports the vulnerability, continue refining your fix and run another Automated Rescan.

You can repeat this process as many times as needed without affecting your Manual Rescan quota.

Step 4: Request a Manual Rescan

Once you're confident your fixes are complete, request a Manual Rescan for the remaining Pentest findings that require verification by Astra's security engineers.

Using Manual Rescans only after validating your fixes helps you make the best use of your available quota.

Best Practices

  • Use Automated Rescans whenever they're available before requesting a Manual Rescan.

  • Save your Manual Rescans for vulnerabilities that require verification by Astra's security engineers.

  • Group multiple fixes together before requesting a Manual Rescan instead of requesting one after every individual fix.

  • Ensure you've remediated at least 50% of the Critical and High severity vulnerabilities before requesting a Manual Rescan.

  • Submit your Manual Rescan request within your plan's rescan validity period.

  • If you anticipate needing more time, contact your Customer Success Manager before your rescan window expires.

Frequently Asked Questions

Does an Automated Rescan consume my Manual Rescan quota?

No. Automated Rescans are unlimited and do not affect your Manual Rescan allowance.

How many Manual Rescans are included with my plan?

Plan

Manual Rescans

Pentest (Hybrid)

2

Pentest Auto

1

Express VAPT

1

How long do I have to request a Manual Rescan?

Plan

Manual Rescan Validity

Pentest (Hybrid)

30 days

Pentest Auto

60 days

Express VAPT

60 days

Which vulnerabilities can be verified using an Automated Rescan?

Only vulnerabilities reported by AstraBot (Scanner) are eligible for Automated Rescans.

Vulnerabilities reported by Astra Security engineers, the Autonomous Pentester, or Bug Bounty Hunters require a Manual Rescan.

Can I run multiple Automated Rescans?

Yes. Automated Rescans are unlimited for eligible vulnerabilities, so you can use them as many times as needed before requesting a Manual Rescan.

Can my Manual Rescan validity period be extended?

Yes. If you're unable to remediate your vulnerabilities within the standard rescan validity period, please contact your dedicated Customer Success Manager (CSM). Extensions can be provided on a case-by-case basis.

What if I need more Manual Rescans?

Additional Manual Rescans can be purchased as an add-on to your existing Pentest plan. Please contact your dedicated Customer Success Manager (CSM) to discuss the available options.

Summary

For the most efficient remediation workflow:

  • Use Automated Rescans to repeatedly validate fixes for vulnerabilities reported by AstraBot (Scanner).

  • Reserve Manual Rescans for final verification by Astra's security engineers and for vulnerabilities reported through Pentest engagements.

  • Monitor your rescan validity period to ensure requests are submitted on time.

  • Contact your CSM if you need additional Manual Rescans or require an extension to your rescan window.

Following these best practices helps you maximize your Manual Rescan quota while ensuring vulnerabilities are verified as efficiently as possible.