Acceptable Use Policy
Last updated August 2026 · Effective August 2026
In short
This summary is here to help you understand the page. The full text below is what actually applies.
This is the most important page on this site. Profscann is a security tool. Security tools can be misused, and the law in most countries treats unauthorised scanning as a criminal offence — not a civil dispute. Please read this before you scan anything.
1. The authorisation rule
You may only use Profscann against a website, server, domain, or codebase that:
- you personally own; or
- is owned by an organisation you work for or represent, where you have authority to commission security testing; or
- you have explicit, documented permission from the owner to test.
"Documented" means something you could show a third party — an email, a signed contract, a written scope of work. A verbal "sure, go ahead" is not enough to protect you if it is later disputed.
By starting a scan you are confirming to us that one of the above is true. We take that confirmation at face value, and you are responsible for it being accurate.
Why we are strict about this
Unauthorised access to, or testing of, a computer system is a criminal offence under laws including the Computer Fraud and Abuse Act (United States), the Computer Misuse Act 1990 (United Kingdom), the Electronic Transactions Act 2008 (Ghana), and equivalent legislation almost everywhere else. Penalties can include imprisonment. These laws generally do not care whether you caused any damage, whether you had good intentions, or whether the tool you used was designed for legitimate purposes.
We would rather lose your business than have you find that out the hard way.
2. Prohibited uses
You must not use Profscann to:
- Scan, probe, or test any system you are not authorised to test.
- Attempt to gain unauthorised access to any system, account, or data.
- Conduct reconnaissance in preparation for an attack, whether or not the attack is carried out.
- Circumvent, disable, or interfere with security controls on any system, including ours.
- Run scans at a volume or frequency intended to degrade, disrupt, or deny service to a target.
- Harvest personal data, credentials, or confidential information belonging to others.
- Scan systems belonging to critical national infrastructure, government, healthcare, or financial institutions unless you are formally engaged to do so.
- Resell, white-label, or present Profscann reports as your own work product without disclosing the tool used, where doing so would mislead the recipient.
- Use the service to build a competing product, including by systematically extracting our findings, guidance text, or generated remediation code.
- Upload source code to the code audit feature that you do not have the right to share with a third party.
3. The Sentinel guard and Tripwire
Sentinel generates code that you install on your own server. Tripwire generates bait that you plant in your own files. Both are yours to deploy — and both must only ever be deployed on systems you control.
Specifically, you must not plant Profscann Tripwire tokens, or install the Sentinel guard, on any system belonging to someone else, whether to monitor them, to attribute activity to them, or for any other purpose.
Sentinel is a defensive tool. It observes requests arriving at your own site and can block them. It does not attack, retaliate against, or reach out to any other system, and you must not modify it to do so.
4. Deep scanning
Some Profscann features perform more intrusive testing than a passive header check — in particular the optional OWASP ZAP and Nuclei scans, and the Digital Twin exploit demonstrations.
These are disabled by default and must be explicitly enabled per scan. Enabling them is a further confirmation that you are authorised to conduct active security testing against that target. Active scanning can, in rare cases, affect a site's availability or create unexpected records in its database. Do not enable it against a production system you cannot afford to disturb.
5. Fair use of a free service
Profscann is currently free. Free does not mean unlimited. We apply rate limits and may apply usage caps to keep the service available for everyone.
Please do not automate scan submission, run scans in a loop, or operate multiple accounts to work around limits. If you have a legitimate need for higher volume, email support@profscann.com and ask — we would rather find a sensible arrangement than play cat and mouse.
6. Enforcement
If we believe this policy has been breached we may, at our discretion and without prior notice:
- refuse or cancel a scan;
- suspend or permanently terminate your account and delete its data;
- block your IP address or network range;
- retain records of the activity, including IP addresses and scan targets, for as long as necessary to deal with the matter;
- report the activity to the target's owner, to your internet service provider, or to law enforcement.
Where the breach is serious — for instance, an apparent attempt to attack a third party — we will generally report it. We will not tip off the person responsible before doing so.
If you think we got it wrong
Automated abuse detection makes mistakes. If your account was suspended and you believe it was in error, email support@profscann.com with the details. We will look at it properly and reinstate you if we were wrong.
7. Reporting misuse
If you believe someone has scanned your site through Profscann without your authorisation, please tell us at support@profscann.com. Include the date, approximate time, and the domain that was scanned. We will investigate and act.
If you are a site owner and you would prefer Profscann never scanned your domain at all, email us and we will add it to a block list.
8. Changes
We may update this policy as the service changes or as we learn about new forms of misuse. Material changes will be announced on this page with a new effective date. Continuing to use Profscann after a change means you accept the updated policy.
One last thing. If you are learning security and want somewhere safe to practise, do not practise on strangers. Set up your own site, or use a purpose-built legal target such as OWASP Juice Shop, DVWA, or a platform like HackTheBox or TryHackMe that provides systems you are explicitly authorised to attack. Profscann will happily scan your own test site all day.
Questions about this page?
Email support@profscann.com. We aim to reply within a few working days.