Acceptable Use Policy
Loading version…
1. Purpose
[PLACEHOLDER — REQUIRES LEGAL REVIEW] This policy exists so a passive external security scanner does not itself become a tool for unauthorized reconnaissance. Every scan submission requires you to affirmatively confirm you own the target domain or have authorization to assess it — see the attestation checkbox on the scan form, and the audit trail we keep of that attestation.
2. Prohibited uses
- [PLACEHOLDER — REQUIRES LEGAL REVIEW] Submitting a domain for scanning that you do not own and do not have authorization to assess.
- [PLACEHOLDER — REQUIRES LEGAL REVIEW] Attempting to circumvent a domain's opt-out signal (the
_janus-opt-outDNS TXT record) or rate limits. - [PLACEHOLDER — REQUIRES LEGAL REVIEW] Using scan results to harass, extort, or otherwise cause harm to a domain's owner or operator.
- [PLACEHOLDER — REQUIRES LEGAL REVIEW] Automating submissions in a way designed to circumvent per-IP rate limits or place excessive load on the service.
3. Consequences of violation
[PLACEHOLDER — REQUIRES LEGAL REVIEW] Violating this policy may result in suspension or termination of access, and — depending on severity — a report to relevant authorities. See the Terms of Service's suspension and termination section.
4. Reporting a concern
If you believe this scanner has been used against your domain without authorization, or its behavior toward your domain is otherwise a problem, you can block it immediately via the DNS opt-out record, or tell us directly — see /about-this-scanner for both options.
5. Changes to this policy
[PLACEHOLDER — REQUIRES LEGAL REVIEW] We may update this policy from time to time. Material changes will be reflected in the version and effective date shown at the top of this page.