Free Scan — Terms & Acceptable Use
These terms govern the free security scan offered at /free-pentest. By starting a scan you agree to them.
1. Authorization is required
You may only submit a domain to the free scan if you own it or have written authorization from the owner to test it. By starting a scan you represent and warrant that this is the case. Submitting a domain you are not authorized to test is a breach of these terms and may be unlawful.
2. What the free scan does
The free scan is read-only and non-intrusive. It inspects only publicly available information: DNS records, the TLS/SSL certificate and negotiated protocol, HTTP security response headers, cookie flags, HTTP-to-HTTPS redirection, and published SPF/DMARC email records. It behaves like an ordinary visitor requesting your public homepage.
3. What the free scan does NOT do
The free scan does not attempt to exploit anything, does not perform port intrusion, denial-of-service, brute-force, or credential attacks, does not attempt to access private or authenticated areas, and does not access, store, or exfiltrate your data. Deeper, active testing (for example a full penetration test) is a separate engagement carried out only under a signed rules-of-engagement and defined scope.
4. Rate limits & fair use
The scan is provided as a free convenience. We may rate-limit, queue, or decline requests to protect the service and third parties. Automated or bulk submission of domains you do not control is prohibited.
5. No guarantees
Results are informational and provided “as is”. An automated perimeter scan cannot find every issue and a clean result is not a guarantee of security. Nothing here creates a warranty or a client relationship. Findings are generated automatically; formal engagements include human review.
6. Logging & privacy
To operate the service and prevent abuse, we log the domain submitted, the requesting IP address, browser user-agent, and timestamp. We do not sell this data. See our privacy practices or contact us for questions or deletion requests.
7. Responsible disclosure
If you believe you have found a security vulnerability in our own systems, please report it to [email protected]. Please give us a reasonable time to remediate before any public disclosure. We will not pursue good-faith researchers who follow this policy and avoid privacy violations, data destruction, and service disruption.
Isaac Software Solutions performs security testing only on systems its clients own or are authorized to test, under written agreement. We do not conduct unauthorized testing of any kind.