seleth
Sign inSign up

Terms of use

Short version: scan what you own. Everything below follows from that.

What you may scan

Sites and APIs you own, or ones whose owner has authorized you in writing to test. Nothing else. By starting a scan you state that this is true for that target — and you remain responsible for it, whether or not we can verify it.

Two levels, two standards of proof

  • Passive checks load the page the way any visitor does. They need no proof, because they ask the site for nothing a browser would not.
  • Active checks — vulnerability templates, storage probing, and authorization testing — require proof that you control the target: a value we generate, placed where only an owner can put it. We verify it before every active scan, not once.

What we do not allow

  • Scanning someone else's site to find a way in, with or without their knowledge.
  • Using the queue as a load generator — against your own site or anyone else's. Scans run under a request budget and a rate limit, and working around them is not a clever use of the product, it is a misuse of it.
  • Automating sign-ups to get more scans than your account allows.

We act on reports from site owners. A confirmed report ends the account and blocks the domain from being scanned again.

What a report is, and is not

A finding comes with the evidence behind it, so you can check it yourself rather than take our word. But a clean report is not a certificate: it means these checks found nothing, not that nothing is there. Decisions about your production systems stay yours.

Your data

The scan runs in memory; what reaches our database is a summary and masked samples. Details are on the privacy page.

If our traffic reached you by mistake

You are on the wrong page — the one you want explains where our scanner traffic comes from and how to have your domain blocked, no account required.