The golden rule
Only test what you own or are clearly authorized in writing to test. Everything else in this policy follows from that. If you are not certain you are authorized, do not run the Test.
Prohibited uses
You must not use the Service to:
- test, disrupt, degrade, or overwhelm any system that is not an Authorized Target;
- conduct a denial-of-service attack, extortion, or any other attack against a third party, or to assist anyone else in doing so;
- target shared or multi-tenant infrastructure in a way that would affect other customers or users of that infrastructure;
- target critical infrastructure, emergency services, healthcare, or systems where disruption could risk safety, without appropriate authorization and safeguards;
- test systems belonging to another party without their authorization, even if you can technically verify a domain;
- use the Service for fraud, harassment, stalking, surveillance, or to violate anyone's rights;
- violate any applicable law, regulation, sanctions regime, or the terms of any third party;
- evade, disable, or attempt to exceed the Service's safety limits, rate ceilings, or verification controls;
- attempt to send raw, spoofed, malformed, or amplified traffic, or to use the Service to deliver malware or unlawful content;
- resell, sublicense, or provide the Service to third parties as a testing service without our written agreement; or
- misrepresent your identity, authority, or authorization.
Protecting the platform
To keep the Service safe and available for everyone, you must not:
- probe, scan, or test the Service's own infrastructure except with our prior written permission through a designated channel;
- interfere with, or attempt to gain unauthorized access to, other Workspaces, accounts, or data;
- reverse engineer or circumvent Worker limits, domain pinning, or the blocking of private and loopback destinations; or
- automate account creation, or use the Service in a way that places an unreasonable load on it.
Third-party infrastructure
If your Target is hosted, fronted, or protected by another provider — for example a cloud platform, CDN, hosting company, or DDoS-mitigation service — the traffic the Service generates may reach or affect that provider's systems. Many such providers require advance notice or explicit authorization for load or penetration testing. It is your responsibility to review and comply with those policies and to obtain any permissions required before you schedule a Test. Failing to do so is a breach of this policy.
Your operational responsibilities
- Schedule Tests responsibly and inform your own stakeholders, on-call staff, and any managed-service or mitigation providers in advance.
- Understand that testing may degrade or interrupt the Target and dependent systems; maintain backups and a rollback plan.
- Monitor a running Test and stop it if you observe unacceptable impact.
- Ensure that any personal data affected by, or collected during, a Test is handled lawfully.
Reporting abuse
If you believe the Service is being used against a system you operate, or otherwise in breach of this policy, contact us immediately at [email protected] with relevant details (such as the affected domain, timestamps, and observed traffic). We investigate reports of abuse and act on them.
Enforcement
We may investigate suspected violations and take any action we consider appropriate, including cancelling a scheduled or running Test, suspending or terminating your access, removing content, and preserving and disclosing information where required by law or to protect the Service or third parties. We may cooperate with law-enforcement and affected infrastructure providers. Serious or repeated violations will result in permanent termination. Enforcement action does not entitle you to a refund.
Legal backdrop
Directing traffic at systems without authorization can constitute a criminal offence. In the Netherlands this includes computer intrusion (computervredebreuk, Article 138ab of the Dutch Criminal Code) and disrupting the availability of a computer system (Article 161sexies). Comparable laws exist in most jurisdictions (for example the UK Computer Misuse Act and the US Computer Fraud and Abuse Act). This summary is provided for awareness only and is not legal advice.