Best Practices for Using Your Rescan Quota
Last updated: July 9, 2026
Introduction
Your Pentest plan includes a limited number of Manual Rescans that allow Astra's security engineers to verify whether the vulnerabilities identified during your assessment have been successfully remediated.
To help you make the most of your available rescans, Astra also offers unlimited Automated Rescans for eligible vulnerabilities. Using Automated Rescans to validate your fixes before requesting a Manual Rescan helps preserve your manual rescan quota while giving you immediate feedback on your remediation efforts.
This guide explains your rescan quota, validity period, rescan rules, and the recommended workflow for efficiently verifying your fixes.
Manual Rescan Quota
The number of Manual Rescans included depends on your Pentest plan.
Pentest Plan | Manual Rescans Included |
|---|---|
Pentest (Hybrid) | 2 Manual Rescans |
Pentest Auto | 1 Manual Rescan |
Express VAPT | 1 Manual Rescan |
Note: Need additional Manual Rescans? You can purchase extra Manual Rescans as an add-on to your existing Pentest plan. To explore available options or request additional rescans, please reach out to your dedicated Customer Success Manager (CSM).
Rescan Validity Period
Manual Rescan requests must be submitted within the applicable rescan window for your engagement.
Pentest Plan | Manual Rescan Window |
|---|---|
Pentest (Hybrid) | 30 days from the date the vulnerabilities were reported |
Pentest Auto | 60 days from the date the vulnerabilities were reported |
Express VAPT | 60 days from the date the vulnerabilities were reported |
Note: If you're unable to complete your remediation within the applicable rescan window, please contact your dedicated Customer Success Manager (CSM). Extensions to the rescan validity period may be granted on a case-by-case basis.
Understanding Rescan Rules
Choosing the appropriate rescan type ensures your vulnerabilities are verified efficiently.
Manual Rescan
A Manual Rescan can be used to verify vulnerabilities reported by:
Astra Security engineers
Autonomous Pentester
Bug Bounty Hunters
AstraBot (Scanner)
Manual rescans are reviewed by Astra's security engineers and count toward your plan's Manual Rescan quota.
Automated Rescan
An Automated Rescan can only be used to verify vulnerabilities reported by AstraBot (Scanner).
Automated rescans:
Start immediately after they're requested.
Can be performed an unlimited number of times.
Do not consume your Manual Rescan quota.
Recommended Workflow
Step 1: Fix the reported vulnerabilities
Implement the necessary code or configuration changes to remediate the identified vulnerabilities.
Step 2: Run an Automated Rescan first (when eligible)
If the vulnerability was reported by AstraBot (Scanner), initiate an Automated Rescan to validate your fix.
Since Automated Rescans are unlimited, they're an excellent way to confirm whether your remediation is successful before using a Manual Rescan.
Step 3: Make additional fixes if required
If the Automated Rescan still reports the vulnerability, continue refining your fix and run another Automated Rescan.
You can repeat this process as many times as needed without affecting your Manual Rescan quota.
Step 4: Request a Manual Rescan
Once you're confident your fixes are complete, request a Manual Rescan for the remaining Pentest findings that require verification by Astra's security engineers.
Using Manual Rescans only after validating your fixes helps you make the best use of your available quota.
Best Practices
Use Automated Rescans whenever they're available before requesting a Manual Rescan.
Save your Manual Rescans for vulnerabilities that require verification by Astra's security engineers.
Group multiple fixes together before requesting a Manual Rescan instead of requesting one after every individual fix.
Ensure you've remediated at least 50% of the Critical and High severity vulnerabilities before requesting a Manual Rescan.
Submit your Manual Rescan request within your plan's rescan validity period.
If you anticipate needing more time, contact your Customer Success Manager before your rescan window expires.
Frequently Asked Questions
Does an Automated Rescan consume my Manual Rescan quota?
No. Automated Rescans are unlimited and do not affect your Manual Rescan allowance.
How many Manual Rescans are included with my plan?
Plan | Manual Rescans |
|---|---|
Pentest (Hybrid) | 2 |
Pentest Auto | 1 |
Express VAPT | 1 |
How long do I have to request a Manual Rescan?
Plan | Manual Rescan Validity |
|---|---|
Pentest (Hybrid) | 30 days |
Pentest Auto | 60 days |
Express VAPT | 60 days |
Which vulnerabilities can be verified using an Automated Rescan?
Only vulnerabilities reported by AstraBot (Scanner) are eligible for Automated Rescans.
Vulnerabilities reported by Astra Security engineers, the Autonomous Pentester, or Bug Bounty Hunters require a Manual Rescan.
Can I run multiple Automated Rescans?
Yes. Automated Rescans are unlimited for eligible vulnerabilities, so you can use them as many times as needed before requesting a Manual Rescan.
Can my Manual Rescan validity period be extended?
Yes. If you're unable to remediate your vulnerabilities within the standard rescan validity period, please contact your dedicated Customer Success Manager (CSM). Extensions can be provided on a case-by-case basis.
What if I need more Manual Rescans?
Additional Manual Rescans can be purchased as an add-on to your existing Pentest plan. Please contact your dedicated Customer Success Manager (CSM) to discuss the available options.
Summary
For the most efficient remediation workflow:
Use Automated Rescans to repeatedly validate fixes for vulnerabilities reported by AstraBot (Scanner).
Reserve Manual Rescans for final verification by Astra's security engineers and for vulnerabilities reported through Pentest engagements.
Monitor your rescan validity period to ensure requests are submitted on time.
Contact your CSM if you need additional Manual Rescans or require an extension to your rescan window.
Following these best practices helps you maximize your Manual Rescan quota while ensuring vulnerabilities are verified as efficiently as possible.