Acceptable Use Policy
Last updated July 2026
FrameScan is a tool for checking your own websites. This policy keeps it that way. Breaking it is grounds for immediate termination and may be reported to authorities.
Scan only what you own
You may only scan a domain you have proven you control. We verify ownership (DNS, file, or meta tag) and re-check it at scan time. Do not attempt to scan, probe, or verify a domain, host, or IP you do not own or have explicit written authorization to test.
Do not use FrameScan to attack others
You must not use the Service — or attempt to make it — to reach internal networks, cloud metadata endpoints, or any third-party system. Our scanners are network-guarded against this, and any attempt to bypass those guards is a serious breach.
Detection is not exploitation
Self-serve scans are non-destructive detection only. You may not use the Service to conduct active exploitation. Active penetration testing is available solely as a manual, contracted engagement under a signed Rules-of-Engagement and liability waiver — it is never automated or self-serve.
Fair use
Don’t use the Service to generate excessive load, resell scanning capacity, or circumvent rate limits. We may throttle or suspend accounts that do.
By using FrameScan you agree to this policy and the Terms of Service.