If you saw BeaconBot/1.0 in your logs, this page explains what it is and how to make it stop.
BeaconBot is operated by Ascendant Finance. It notices newly launched or relaunched websites through public signals (Certificate Transparency logs, newly registered domain lists, and public DNS) and records what is publicly observable about them.
For a domain it has not been invited to watch, BeaconBot makes at most one visit every seven days. That visit consists of:
/robots.txt, fetched first and honoured/.well-known/security.txtGET / over HTTP (to check for an HTTPS redirect, which is not followed) and one over HTTPSIt never crawls other paths, submits forms, tries logins, scans ports, or pretends to be a browser. It connects only on ports 80 and 443 and backs off on 429 and 503, honouring Retry-After.
Any one of these stops all BeaconBot activity for your domain, including passive lookups, permanently:
User-agent: BeaconBot Disallow: /
/.well-known/security.txt:
Beacon-Opt-Out: true
Email beacon@koryo.app.