Company · Acceptable useBrowse
CompanyLegalAcceptable use
Acceptable use
The service is free and run by one person, so it depends on people using it the way it’s meant to be used. This page spells out the fair-use part of the terms.
Welcome
- Scanning your own software, or software you’re responsible for.
- Reviewing an SBOM a supplier gave you, if you’re entitled to analyse it.
- Automated scans through the documented CI script and the scan API, within the rate limits.
- Security research against your own account and your own reports, reported privately as described on the security page. Research that follows that disclosure policy is authorised under these terms.
Not allowed
- Uploading inventories you have no right to analyse, such as one obtained without permission.
- Using the results to attack anyone, or to find targets to attack.
- Trying to reach another account’s projects, or guessing report addresses.
- Working around the rate limits, scan limits or project limits, for example by rotating addresses or accounts.
- Uploading files built to exhaust or crash the service. If you find one that does, report it instead.
- Load testing, denial of service, or automated scanning of the site itself.
- Scraping the interface. Use the exports and the API instead.
- Reselling the service, or presenting it as your own.
What happens otherwise
Accounts and clients that break these rules can be limited or suspended, without advance notice where that’s needed. The account holder gets a statement of the reasons, unless the law or the security of the service requires otherwise. Given the size of the operation, that’s likely to come as an email from a person, and a mistake can be talked through.
See also all legal pages and contact.