Acceptable Use Policy
Last updated
Scanning tools are only legitimate when pointed at things you are allowed to scan. This policy sets that boundary.
Draft. Written to accurately describe this application's actual behavior, but not reviewed by qualified legal counsel — treat it as technical documentation rather than a finished legal document.
Permitted use
Use of this application's scanning features is limited to:
- Websites and domains you own, operate, or are otherwise explicitly authorized to test.
- Source repositories you own or have explicit permission to scan.
Prohibited use
- Using this tool against third-party systems without authorization.
- Any attempt to use the scanning or webhook functionality for denial-of-service, mass or indiscriminate scanning, or as a proxy to reach other systems.
- Submitting webhook URLs intended to probe or attack internal network endpoints — see the SSRF limitation noted in the Security Policy.
- Pointing the repository scanner at filesystem paths you are not authorized to read.
- Supplying credentials to the differential-access probe for an account or target you do not control.
Passive is not the same as authorized
This tool performs only passive checks against websites — standard HTTP, TLS, and DNS requests equivalent to a normal browser visit. It does not perform active exploitation, and checks that go beyond a browser visit stay locked until domain ownership is proven.
None of that makes scanning a system you don't control authorized. “Passive-only” is a technical description of the scan's behavior, not a legal permission.