You may
- Scan domains your organization owns or controls.
- Scan domains you have written authorization to assess, for example a supplier that agreed to it.
- Share reports about your own domains with buyers, auditors and insurers.
You may not
- Add domains you don't own or aren't authorized to assess, or give false verification details.
- Use the service to find targets for attack, or combine it with attack tools.
- Try to get around rate limits, verification or scan scope.
- Upload malware, or content you have no right to share, such as other organizations' confidential files or special category personal data.
- Probe, scan or test the security of Shorward itself, except as allowed on Security.
- Present a lapsed, altered or third-party report as current or as your own.
- Use reports or ratings to mislead anyone, including by suggesting that Shorward certifies, endorses or advises you.
- Resell the service, or scrape it to build a competing product.
Enforcement
We may pause scans, remove content, or suspend or close accounts that break this policy, and report illegal activity to the authorities. Where it's reasonable, we'll tell you first and give you a chance to fix it.
Reporting misuse
If you think Shorward is being used against you, email [email protected].