Acceptable Use Policy
Last updated: 2026-09-08
Scopulars NETA sends real network traffic to real systems. Pointed at a system you are not entitled to test, it can constitute unauthorized access under the computer crime laws of most countries. This policy forms part of the Terms of Service and applies to everyone who uses the Service, on every plan, including the Free plan.
1. The core rule
You may only scan systems that you own, or for which you hold documented written authorization from the owner to perform security testing. There is no third category. “It was publicly reachable”, “it did not cause harm”, “it was only a port scan” and “I was researching a vulnerability” are not authorization.
You are solely responsible for obtaining that authorization, for its scope, and for keeping evidence of it. Authorization must cover the specific hosts, domains, ranges and testing activity you run, and it must be current at the time you run it — permission granted last year for a system that has since changed hands is not permission today. If you are testing on behalf of a client, you are responsible for holding a signed engagement that authorizes the testing.
2. We verify ownership technically — and that is not a substitute for authorization
Before the Service sends traffic to a target, it requires that the target has been verified as belonging to your organization, by proving control through a DNS record or a file served from the host. Unverified targets are refused.
Two things follow, and both matter:
- Circumventing, disabling or attempting to defeat this verification is a material breach of the Terms. This includes falsifying proof of control, abusing shared or delegated infrastructure to claim a host you do not control, exploiting a defect in the verification process, or using the Service through any route intended to bypass the check.
- Passing the technical check does not mean you are legally authorized. The check confirms control of a DNS record or a web root; it cannot confirm that you have the owner’s permission, that your engagement is in scope, or that a hosting provider or upstream network permits the testing. Authorization remains your obligation regardless of what the Service allows.
3. Prohibited uses
You must not use Scopulars NETA to:
- Scan, probe or test any system you do not own or are not authorized to test.
- Attempt to gain unauthorized access to any system, account or data, or to escalate privileges, exfiltrate data or maintain persistence on a system.
- Conduct denial-of-service or any other attack whose purpose or foreseeable effect is to degrade, disrupt or overload a system or network.
- Scan third-party infrastructure, including a provider’s shared hosting, another tenant’s cloud resources, or systems belonging to your customers, employer or competitors without authorization covering exactly those systems.
- Support any unlawful activity, including stalking, harassment, fraud, or violation of export-control or sanctions law.
- Circumvent the target-ownership verification, rate limits, plan entitlements or any other technical control in the Service.
- Resell, sublicense or provide scanning-as-a-service to third parties from your account without our written agreement, or share credentials with anyone outside your organization.
- Interfere with the Service itself: attacking our infrastructure, disrupting other customers, or using automated means to extract data beyond the documented API.
- Upload malware, or store content in scan notes or configuration that is unlawful.
4. Testing the Service itself
Do not run scans or attacks against Scopulars NETA’s own infrastructure. If you want to report a vulnerability in the Service, contact security@scopulars.net and give us a reasonable opportunity to respond before disclosing it. We will not pursue a good-faith reporter who acts within this paragraph.
5. Enforcement
We may investigate suspected breaches and suspend or terminate access without prior notice where we reasonably believe this policy has been breached — in particular where a user has scanned a system they were not authorized to test or has attempted to circumvent ownership verification. We may preserve and disclose records, including audit logs of scans and the account behind them, where we are legally required to do so or where it is necessary to respond to an abuse complaint or to protect our rights or a third party.
We do not owe a refund for a suspension or termination caused by a breach of this policy.
6. Reporting abuse
If you believe your systems were scanned using Scopulars NETA without your authorization, contact security@scopulars.net. Include the affected addresses and the time window with time zone, so we can locate the relevant activity.
7. Changes
We may update this policy; the version identifier at the top of this page changes when we do. Questions: support@scopulars.net.