Authorized use
You may submit only systems you own or are explicitly authorized to test. Technical verification of domain control is a safety measure, not proof of legal authority. You must maintain accurate scope and authorization information and immediately pause scanning if that authority changes.
Prohibited use
You may not use the service to test third-party systems without permission, exceed the displayed policy or traffic limits, disrupt services, evade controls, conduct password spraying or brute force, conduct illegal activity, or attempt to access another customer’s data. Any displayed default-credential check remains separately consented, fingerprint-gated, and bounded.
Security-service limitations
Automated scanning is point-in-time and can produce false positives, false negatives, incomplete observations, and target-side effects. The service does not guarantee security or availability, certify compliance, replace a penetration test, or constitute a PCI Approved Scanning Vendor report.
Customer responsibilities
You remain responsible for assessing target safety, maintaining required third-party permissions and backups, evaluating findings, safely applying remediation, and deciding whether the displayed scope is appropriate.
Subscriptions, cancellation, and refunds
Published monthly and annual subscriptions renew automatically for the selected interval until canceled. The hosted billing portal schedules cancellation at the end of the current paid period, and access continues through that period while the subscription remains entitled. We do not promise automatic or prorated refunds. Requests for duplicate or erroneous charges, documented service failure, or legally required refunds should be sent to support@vulnerabilityscan.com within 30 days and are reviewed individually for return to the original payment method. Taxes are added only when configured and legally applicable.
Suspension, termination, and data requests
We may pause or terminate scans and accounts when necessary to address safety, legal, abuse, nonpayment, or platform-integrity concerns. Workspace exports are bounded. A deletion request enters reviewed processing and does not instantly erase identity-provider, billing, audit, legal-hold, or backup records.
Contact
Billing questions may be directed to support@vulnerabilityscan.com. Legal questions may be directed to legal@vulnerabilityscan.com.