Acceptable Use Policy
Contents
- Who this policy applies to
- Authorization to assess an asset
- What CheckAI verifies, and the limits of that verification
- What CheckAI does and does not do technically
- Prohibited uses
- Fair use and technical limits
- Reporting abuse or a disputed assessment
- Enforcement, suspension and permanent ban
- Changes to this policy
1. Who this policy applies to
This policy applies to every person and organization that uses CheckAI. It applies to account holders, to every member of a customer organization, and to anyone who uses the public scan preview without an account. It forms part of the Terms of Service, and a breach of this policy is a breach of those Terms.
2. Authorization to assess an asset
CheckAI assesses systems. Assessing a system you do not control may be unlawful in your jurisdiction, in the jurisdiction where the system is hosted, or both. Responsibility for having the right to assess a system rests with you, not with CheckAI.
Your representation and warranty
By submitting a domain, hostname, IP address, repository, cloud account, container image or any other asset to CheckAI for assessment, or by connecting a system to CheckAI, you represent and warrant that, for each such asset, you either own it or hold current, documented authorization from its owner sufficient to permit the assessment, and that you have authority to give CheckAI that instruction on behalf of your organization.
This representation is made each time an asset is submitted or a connector is installed, and is treated as repeated for the duration that CheckAI continues to assess that asset. If your authorization for an asset ends, you must remove that asset from CheckAI without undue delay.
Indemnity
You will indemnify CheckAI, and hold it harmless, against any claim, demand, proceeding, loss, liability, damage, cost or expense — including reasonable legal fees — arising from or in connection with an assessment carried out on your instruction where you did not hold the authorization described above. This survives termination of your account.
3. What CheckAI verifies, and the limits of that verification
CheckAI applies controls appropriate to what each part of the product actually does. We describe them here precisely, including where they stop, rather than claiming a level of assurance we do not provide.
| Activity | What CheckAI requires | What that does and does not establish |
|---|---|---|
| Public scan preview | No verification. Rate limiting, risk-based challenge and abuse controls only. | The preview reads only information the target already publishes to any visitor. It establishes nothing about ownership, and is not treated as an authorized assessment. |
| Continuous domain monitoring | Control of a mailbox at the domain, proven by a single-use expiring link, or an already verified work address at the same registrable domain. | Establishes that someone controlling a mailbox at that domain asked for monitoring. It does not prove corporate ownership, nor that the person had internal authority to request it. |
| Connectors — GitHub, AWS, CI | Credentials, an app installation or an IAM role that you supply and control, with read-only permissions. | Access exists only because you granted it and lasts only while you continue to grant it. Whether you were entitled to grant it is your responsibility. |
| Uploaded penetration-test reports | No verification of the engagement behind the report. | CheckAI processes the document you supply. It does not verify that the test was authorized or that you may share the report. |
We rely on you, and we say so plainly
Domain-email verification is a proportionate check for passive assessment of publicly observable information. It is not proof of ownership and CheckAI does not present it as such. Beyond the controls described above, CheckAI relies on you to be honest and diligent about which assets you submit. That reliance is a stated term of using the service, not an assumption — and it is why the representation in section 2 and the indemnity that follows it exist.
4. What CheckAI does and does not do technically
The design of the product limits the harm a misdirected assessment can cause. These are product constraints, not merely policy statements.
- Assessment of public assets is passive. CheckAI reads
information the target already publishes — DNS records, TLS configuration, HTTP
response headers, email-authentication records, RDAP data and
security.txt. - CheckAI does not perform active exploitation, authenticated scanning, port scanning, site crawling, zone-transfer attempts, denial-of-service testing, or proof-of-concept subdomain-takeover testing.
- Connectors are read-only. CheckAI cannot modify code or cloud resources, dismiss provider findings, rotate secrets, execute commands, invoke functions, read secret material or object storage contents, or apply any remediation.
- Free monitoring performs no subdomain discovery. It assesses the
verified domain and its
wwwhostname only.
5. Prohibited uses
You must not use CheckAI to:
- submit, monitor or connect any asset you do not own or hold documented authorization to assess;
- gather information about a third party's systems for reconnaissance, competitive intelligence, or any purpose the third party has not authorized;
- circumvent, or attempt to circumvent, domain verification, rate limits, challenge mechanisms, entitlement checks, organization boundaries or any other control;
- create multiple accounts or organizations in order to exceed limits, evade a suspension, or obscure who is submitting assets;
- upload a penetration-test report, evidence or framework source you are not licensed or authorized to supply and have processed;
- attempt to access another organization's data, or to test the security of CheckAI itself without prior written permission;
- introduce malware, or attempt to induce CheckAI's AI features to act outside their intended function, including by embedding instructions in uploaded documents, filenames, repository names or asset names;
- resell, white-label or provide CheckAI's output as a service to third parties, except as expressly permitted in a written agreement with us;
- use CheckAI in breach of any applicable law, including computer-misuse, data-protection, export-control and sanctions law.
6. Fair use and technical limits
CheckAI applies rate, concurrency, file-size, processing-time and abuse limits. These exist to protect the service and to prevent cost abuse. They are safety limits, not commercial quotas, and they are set where ordinary use does not reach them. If your normal work routinely meets one, tell us — we treat that as a threshold to correct, not as a customer to throttle.
Deliberately operating at or around these limits, or engineering your use to evade them, is a breach of this policy.
7. Reporting abuse or a disputed assessment
If you believe CheckAI is being used to assess an asset without authorization, including an asset you own, contact misuse@checkai-cloud.com. Tell us the asset concerned and the basis of your interest in it. We will investigate, and we may suspend the assessment while we do.
If you own a domain and want it excluded from the public scan preview, write to misuse@checkai-cloud.com from an address at that domain, or tell us how else you can show control of it. We will action a valid exclusion request within 5 business days, and the exclusion persists until you ask us to lift it.
To report a vulnerability in CheckAI itself, contact security@checkai-cloud.com.
Safe harbour for good-faith security research
If you research CheckAI's own security in good faith and in accordance with this section, we will not pursue legal action against you and will not report you to law enforcement. Good faith means: you act only against CheckAI's own systems and your own account; you make a genuine effort to avoid privacy violations, service disruption and data destruction; you access only the minimum data needed to demonstrate the issue; you do not exfiltrate, retain or disclose any data belonging to CheckAI or another customer; you report promptly to the address above; and you give us reasonable time to remediate before any public disclosure.
This protection does not extend to testing another customer's assets, to denial-of-service testing, to social engineering of our staff or suppliers, or to physical attacks. If in doubt, ask us first — we would rather answer the question than argue about it afterwards.
8. Enforcement, suspension and permanent ban
CheckAI does not tolerate misuse of the service to assess systems without authorization. Where we reasonably believe this policy has been breached we may, at our discretion and without prior notice:
- suspend your organization's access, in whole or in part — including placing purchased modules into a read-only state while we investigate;
- require you to remove an affected asset from CheckAI, and suspend your organization's access if you do not do so promptly;
- terminate the account and any subscription;
- permanently bar the individuals and organization concerned from CheckAI, including through future accounts;
- disclose relevant information to law enforcement or to an affected asset owner where we are legally required to do so, or where we reasonably consider it necessary to prevent or address serious harm.
Why we ask rather than act
CheckAI's own administrators cannot see or alter the contents of your organization's workspace. Access to customer content requires your explicit, scoped and time-limited approval, and every such session is recorded. That boundary protects you, and it is why removing an asset is something we require of you rather than something we do to your data.
We will act proportionately, and where the circumstances allow we will contact the organization's administrators first. A serious or deliberate breach — in particular knowingly submitting assets belonging to a third party — will normally result in immediate termination and a permanent ban.
You can appeal. If you believe a suspension, termination or bar is wrong, write to appeal@checkai-cloud.com setting out why. We will review it and tell you the outcome.
Suspension or termination under this policy does not entitle you to a refund. See the Refunds and Cancellation Policy.
9. Changes to this policy
We may update this policy. Where a change materially affects your rights or obligations we will give notice and, where the change requires it, ask an administrator of your organization to accept the updated policy before continuing to use affected features. The current version is always published here with its effective date.
Questions about this policy: legal@checkai-cloud.com. Reporting misuse: misuse@checkai-cloud.com.