01
Authorized targets only
Use the service only for public websites and systems you own, administer, or are authorized to assess. A public URL is not by itself proof of authorization for intrusive activity.
02
Prohibited conduct
- +Scanning private, loopback, link-local, internal, credentialed, or otherwise non-public resources.
- +Attempting exploitation, credential attacks, denial of service, evasion, scraping behind access controls, or interference with another service.
- +Submitting malware, secrets, regulated personal data, payment-card data, or content you lack the right to process.
- +Using results to mislead customers, fabricate endorsements, impersonate another party, or make unsupported ranking or AI-citation claims.
- +Circumventing rate limits, account controls, payment limits, or report-access restrictions.
- +Using the service in violation of sanctions, export controls, privacy, intellectual-property, consumer-protection, or computer-misuse law.
03
Automated and agentic changes
Where automated remediation is enabled, you remain responsible for approving scope, maintaining backups, validating changes, and controlling credentials. We may require scoped access, a staging environment, or human approval before deployment.
04
Enforcement
We may rate-limit, block, suspend, preserve evidence, or terminate activity that presents a security, legal, or operational risk. Report suspected abuse to [email protected] with the URL, time, and relevant evidence.