Acceptable Use Policy
Last updated
Scanning tools are only legitimate when pointed at things you are allowed to scan. This policy sets that boundary.
Written against the code, not from a template. Every behaviour described here is implemented in this application, and the limitations are listed as plainly as the capabilities. If you find a statement on this page that the software does not match, that is a bug — please tell us.
Permitted use
Use of this application's scanning features is limited to:
- Websites and domains you own, operate, or are otherwise explicitly authorized to test.
- Source repositories you own or have explicit permission to scan.
Prohibited use
- Using this tool against third-party systems without authorization.
- Any attempt to use the scanning or webhook functionality for denial-of-service, mass or indiscriminate scanning, or as a proxy to reach other systems.
- Submitting webhook URLs intended to probe or attack internal network endpoints — see the SSRF limitation noted in the Security Policy.
- Pointing the repository scanner at filesystem paths you are not authorized to read.
- Supplying credentials to the differential-access probe for an account or target you do not control.
Passive is not the same as authorized
This tool performs only passive checks against websites — standard HTTP, TLS, and DNS requests equivalent to a normal browser visit. It does not perform active exploitation, and checks that go beyond a browser visit stay locked until domain ownership is proven.
None of that makes scanning a system you don't control authorized. “Passive-only” is a technical description of the scan's behavior, not a legal permission.