Acceptable Use Policy

  • Effective Date: June 23, 2026
  • Last Updated: June 23, 2026

This Acceptable Use Policy (“AUP”) applies to all use of CipherGap.

CipherGap is designed for authorized security assessment and monitoring. Misuse of the service is prohibited.

1. Authorization Required

You may only scan, monitor, or submit systems that you own, administer, or are authorized to assess.

You may not use CipherGap for unauthorized reconnaissance, surveillance, targeting, harassment, or third-party scanning.

2. Prohibited Activity

You may not use CipherGap to:

  • Break the law.
  • Scan systems without authorization.
  • Conduct exploitation.
  • Attempt credential theft.
  • Attempt authentication bypass.
  • Perform brute-force activity.
  • Conduct denial-of-service or stress testing.
  • Evade rate limits or access controls.
  • Probe non-public systems without permission.
  • Interfere with CipherGap infrastructure.
  • Resell, sublicense, or redistribute CipherGap without permission.
  • Submit intentionally deceptive or malicious scan targets.
  • Use scan results to target or harm third parties.
  • Upload malware, exploit code, or harmful content.
  • Attempt to reverse engineer scanner infrastructure.
  • Abuse support, reporting, or vulnerability disclosure channels.

3. Rate Limits and Operational Safety

CipherGap may enforce rate limits, scan limits, host limits, concurrency limits, and abuse-prevention controls.

You may not attempt to bypass these controls.

We may throttle, block, suspend, or terminate activity that creates operational risk or appears abusive.

4. Third-Party Targets

You are responsible for ensuring you have permission before scanning any target.

If we receive a credible abuse report involving your account, we may suspend scans, restrict access, request proof of authorization, or terminate your account.

5. Research and Testing

Security research against CipherGap itself is governed by our Vulnerability Disclosure Policy.

This AUP does not authorize testing of CipherGap systems beyond what is allowed in that policy.

6. Enforcement

If we believe this AUP has been violated, we may:

  • Limit scan functionality.
  • Remove monitored hosts.
  • Suspend or terminate accounts.
  • Block traffic.
  • Preserve logs.
  • Notify affected parties.
  • Cooperate with lawful investigations.
  • Take other action needed to protect CipherGap, users, or third parties.

7. Reporting Abuse

To report abuse of CipherGap, contact:

abuse@ciphergap.com

Please include:

  • The relevant hostname, account, or activity.
  • Date and time.
  • Logs or evidence, if available.
  • Contact information for follow-up.