Legal

Acceptable Use Policy

Rules for using AtRisk scanning, monitors, GitHub agents, Findings, MCP, CI deploy gate, free tools, and related services. This policy is part of, and incorporated into, our Terms of Service.

Last updated: September 9, 2026 · Effective: September 9, 2026

1. Incorporation

This Acceptable Use Policy ("AUP") governs your use of atrisk.dev, app.atrisk.dev, APIs, MCP endpoints, free tools, and related AtRisk services (the "Services"). It is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings in the Terms. Violation of this AUP is a material breach and may result in suspension or termination, refusal of refunds, referral to authorities, and other remedies available at law.

2. Authorization to scan

You may only use the Services to scan, analyze, or monitor a website, application, domain, repository, or system that you own or for which you have obtained, before initiating the scan, all authorizations required from the owner. You are solely responsible for verifying authority. Unauthorized scanning may violate computer-misuse and unauthorized-access laws (including equivalents of the U.S. Computer Fraud and Abuse Act, UK Computer Misuse Act 1990, and similar laws) and may expose you to civil and criminal liability.

Default scanning and repository analysis are read-only. You must not use Findings or Outputs to attack, exploit, extort, or harm any system or person. See also our General Disclaimer.

3. Prohibited conduct

You may not, and may not permit others to, use the Services to:

  • Scan, probe, exploit, attack, attempt unauthorized access to, or interfere with any system without explicit authorization
  • Develop, test, or deploy malware, ransomware, spyware, keyloggers, or other malicious code
  • Conduct or facilitate cyberattacks (including DDoS, credential stuffing, phishing, or social engineering)
  • Bypass authentication, rate limits, paywalls, entitlements, encryption, or other technical protections of the Services or any third-party system
  • Violate intellectual-property, privacy, data-protection, contract, or other third-party rights
  • Facilitate fraud, identity theft, money laundering, terrorism financing, or other illegal activity
  • Harass, stalk, dox, threaten, intimidate, or harm any individual or group
  • Harvest personal data or competitive intelligence from third parties without lawful basis
  • Target government, military, intelligence, election, healthcare, financial-services, energy, water, telecom, transport, or other critical-infrastructure systems without our prior written consent and a separate written agreement
  • Train, fine-tune, evaluate, or benchmark competing security products or foundation models using non-public aspects of the Services
  • Reverse-engineer the Services except where mandatory law cannot be waived
  • Resell, sublicense, or commercially redistribute access to the Services or Outputs as a paid audit product without written permission
  • Use bots or scrapers against the Services except through documented APIs within published rate limits
  • Upload or transmit unlawful, infringing, defamatory, hateful, deceptive, or malware-laden content
  • Impose unreasonable load on our infrastructure or interfere with other users
  • Violate export-control, sanctions, anti-bribery, or data-protection laws
  • Impersonate others, use stolen identity information, share accounts, or operate multiple accounts to evade limits
  • Submit Prohibited Data as defined in the Terms into prompts, free tools, or unnecessary fields
  • Represent Outputs as human-vetted certification, penetration-test results, or approval by AtRisk

4. Responsible disclosure

If you discover a vulnerability affecting a third party while using the Services, handle that information lawfully and responsibly. Prefer private disclosure and a reasonable remediation window before any public disclosure. Do not use information from the Services to gain unauthorized access, extort, defraud, or harm anyone.

To report a security issue in AtRisk itself, follow our vulnerability disclosure policy or email contact@atrisk.dev.

5. Quotas, rate limits & fair use

Your plan defines quotas for scans, monitors, credits, seats, apps, repos, MCP, retention, and other resources. You must stay within those limits. We may apply additional rate limits, throttling, queuing, or temporary blocks to protect the Services and other users. "Unlimited" marketing language, if any, still requires ordinary, lawful, good-faith use and does not permit abusive automation, account sharing, infrastructure overload, or resale of access.

6. Reporting abuse

Report suspected AUP violations or illegal activity involving the Services to contact@atrisk.dev with subject "Abuse Report". Include URLs, timestamps, account details, and evidence where available. We will investigate promptly and take appropriate action.

7. Enforcement

We may investigate suspected violations, remove or disable content or access, and suspend or terminate accounts, with or without notice, without liability. We may cooperate with law-enforcement and produce information as required by lawful process. We may pursue other legal or equitable remedies, including injunctive relief and recovery of damages and reasonable attorneys' fees.

8. Changes

We may modify this AUP from time to time. The current version is always available at /acceptable-use with a "Last updated" date. Continued use after a change takes effect constitutes acceptance.

See also: Terms· Privacy· Disclaimer.

9. Contact

This Acceptable Use Policy is effective as of September 9, 2026. Product-aligned legal copy - have counsel review before relying on it for regulated or enterprise deals.