Documentation
Limits, and what happens when a store reaches one
Ottom caps how often it visits any one storefront, and the cap belongs to the store being visited rather than to the account asking. This page lists every limit a scan can meet, from the daily ceiling to the free scan and the trial, and says what happens at each one.
Every limit
- Scans any one storefront accepts in a day
12 retrieval checks and 3 full agent journeys. Counted against the storefront being visited, across everyone who asks, rather than per account. Your own scans of your own store share it with anyone else scanning it. The day is the calendar day in UTC, so the count starts again at midnight UTC.
- The same ceiling on a storefront under an enterprise contract
36 retrieval checks and 4 full agent journeys, and up to 72 and 8 on some contracts. Raised only on storefronts the contracting business has verified as its own, and still counted across everyone who asks. It is the highest number any storefront can receive from Ottom in a day.
- Free scans
One free scan per store, per email address, every 30 days. Asking again for the same store inside the 30 days hands back the report already made rather than running a new scan. A scan that failed is not handed back, so asking again after one runs a fresh scan.
- Re-scans included with the $9 report
1 re-scan within 7 days of buying it. Per purchase rather than per day, so waiting until tomorrow does not add another. The daily ceiling above still applies to it.
- Agent journeys during a free trial
3 full agent journeys for the whole trial. Whatever the plan’s own schedule would run. Retrieval checks run on the plan’s schedule throughout, and journeys follow it once the trial ends.
- Re-checks when you publish a Shopify theme
1 retrieval check a day. On Defend and Patrol, through the Shopify app. A merchant iterating on a theme can publish many times in an afternoon, so the first publish of the day is the one that is checked.
- Crawl-delay in your robots.txt
Honoured up to 5 seconds between requests. A longer delay is treated as that many seconds, so a WAF default of several minutes does not turn one scan into hours of traffic.
- Product pages read one at a time
At most 3 per scan. Only when the store publishes no catalogue that can be read in one request, such as a Shopify or WooCommerce product feed. A store read this way is judged on those few products.
- Payment submission
Never, on any plan. The agent stops at the payment step. No order is ever placed.
What happens when a store reaches its daily limit
Nothing waits in a queue for later. What you see depends on what asked for the run.
- A scan you start
Refused, with a message saying the store has reached its daily limit. Nothing is queued: start it again after midnight UTC.
- The agent journey after a scan
The retrieval check still runs and is reported. The report says that checkout was not tested on this scan, and why.
- Your scheduled monitoring
A subscribed store’s own schedule is held ahead of everyone else’s requests for that store, so a stranger running a free scan cannot take the run you pay for. If the store is still at its ceiling, that one run is skipped and the next runs when it is due.
Questions
Why is the limit counted against the store and not against me?
Because it exists to protect the merchant being visited. A limit that reset when you asked from a different account, or that a paying customer could raise on somebody else’s storefront, would not protect anyone.
I hit the limit on my own store. What used it?
Every request for that storefront counts, including anyone else running a free scan on it. Your plan’s scheduled runs are held back for you ahead of those, so it is your own on-demand scans that meet the limit first.
Does a higher plan raise the daily limit?
No. Plans change how often your own schedule runs, not how much traffic a storefront accepts. Only an enterprise contract on the storefront itself raises its ceiling.
When does the count start again?
At midnight UTC. The limit is per calendar day in UTC, not a rolling 24 hours.
How Ottom identifies itself, and how to opt a store out, is on the agent page. What each plan runs is on the plans page.