Legal
Rules for using AtRisk scanning, monitors, GitHub agents, Findings, MCP, CI deploy gate, free tools, and related services. This policy is part of, and incorporated into, our Terms of Service.
Last updated: September 9, 2026 · Effective: September 9, 2026
This Acceptable Use Policy ("AUP") governs your use of atrisk.dev, app.atrisk.dev, APIs, MCP endpoints, free tools, and related AtRisk services (the "Services"). It is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings in the Terms. Violation of this AUP is a material breach and may result in suspension or termination, refusal of refunds, referral to authorities, and other remedies available at law.
You may only use the Services to scan, analyze, or monitor a website, application, domain, repository, or system that you own or for which you have obtained, before initiating the scan, all authorizations required from the owner. You are solely responsible for verifying authority. Unauthorized scanning may violate computer-misuse and unauthorized-access laws (including equivalents of the U.S. Computer Fraud and Abuse Act, UK Computer Misuse Act 1990, and similar laws) and may expose you to civil and criminal liability.
Default scanning and repository analysis are read-only. You must not use Findings or Outputs to attack, exploit, extort, or harm any system or person. See also our General Disclaimer.
You may not, and may not permit others to, use the Services to:
If you discover a vulnerability affecting a third party while using the Services, handle that information lawfully and responsibly. Prefer private disclosure and a reasonable remediation window before any public disclosure. Do not use information from the Services to gain unauthorized access, extort, defraud, or harm anyone.
To report a security issue in AtRisk itself, follow our vulnerability disclosure policy or email contact@atrisk.dev.
Your plan defines quotas for scans, monitors, credits, seats, apps, repos, MCP, retention, and other resources. You must stay within those limits. We may apply additional rate limits, throttling, queuing, or temporary blocks to protect the Services and other users. "Unlimited" marketing language, if any, still requires ordinary, lawful, good-faith use and does not permit abusive automation, account sharing, infrastructure overload, or resale of access.
Report suspected AUP violations or illegal activity involving the Services to contact@atrisk.dev with subject "Abuse Report". Include URLs, timestamps, account details, and evidence where available. We will investigate promptly and take appropriate action.
We may investigate suspected violations, remove or disable content or access, and suspend or terminate accounts, with or without notice, without liability. We may cooperate with law-enforcement and produce information as required by lawful process. We may pursue other legal or equitable remedies, including injunctive relief and recovery of damages and reasonable attorneys' fees.
We may modify this AUP from time to time. The current version is always available at /acceptable-use with a "Last updated" date. Continued use after a change takes effect constitutes acceptance.
See also: Terms· Privacy· Disclaimer.
Contact: contact@atrisk.dev