Frequently Asked Questions
How Pensira scans, why it's offline by design, and how to add it to your account.
What's the difference between a Quick Scan and a Deep Check?
Quick Scan is a fast, in-memory pass you trigger manually — right-click any message → Apps → Quick Scan. It checks URLs against local signature lists for known phishing domains, malware hashes, and flagged content, and runs in milliseconds.
Deep Check is a more thorough pass, also triggered manually from the same right-click menu — it unpacks archives, inspects embedded metadata, runs heuristic and ML-based analysis, and checks for hidden data (steganography) or obfuscated scripts. Neither scan ever runs automatically: Pensira is a User-Installable App with no background/auto-mod access to your messages, so it only ever looks at a message when you explicitly invoke it.
Is Pensira really 100% offline?
Almost entirely, yes. Every scan, signature check, and heuristic runs locally on Pensira's own server through the Pensira Engine — your file, image, and text content is never sent to VirusTotal, OpenAI, Google, or any third-party API.
The one exception: Deep Check additionally sends the bare domain name (never the full URL, message content, or any file) of links you scan to two free reputation services — Cloudflare's malware-blocking DNS and SinkingYachts — to check if a domain is already known-malicious. The Engine's blocklists themselves are also built from several free public threat-intelligence sources, refreshed on a schedule rather than queried live — see the Privacy Policy for the full detail and required attributions.
Can scan results include false positives?
Yes. Like any automated scanner, Pensira occasionally flags content that turns out to be harmless — especially with heuristic-based Deep Checks. We recommend a human review any flagged content before taking permanent action.
If you spot a false positive (or a miss), please let us know through the feedback form — reports directly shape future signature and heuristic updates.
How do I add Pensira?
Pensira installs to your Discord account, not to a specific server — there's no server picker or permission grant involved. Add Pensira to your account, and it's immediately available from the right-click Apps menu on any message, in any server or DM you're in.
How do I see my own stats?
Click "Login with Discord" in the nav. We request your Discord username, avatar, and email address (the "identify" and "email" scopes) — never your servers or messages; see the Privacy Policy for exactly how email is used. You'll see your Cyber XP, scan counts, and badges, exactly like the /profile command in Discord.
Can I log out / is my session remembered?
Yes — click your avatar in the nav and choose "Log out" any time. Your session is stored in a signed browser cookie and is remembered for about a week, or until you log out, whichever comes first.
Are there any rules for using the feedback form?
Submitting feedback requires being logged in with Discord, passes an invisible bot-check (Cloudflare Turnstile), and has a short cooldown between submissions — all to keep the form from being spammed.
Keep it civil: no swearing, harassment, or abusive content. Feedback is linked to your account (see the Privacy Policy), and abusing the form can get your account blocked from dashboard login — see the Terms of Service for the full policy.