Trust & safety

Acceptable Use Policy

Scanlyst is built for defensive security. This policy defines safe, authorized use and activities that are prohibited.

Last updated: September 3, 2026

Permitted purpose

Scanlyst is designed for defensive security, quality assurance, compliance review, monitoring, and remediation of systems you are authorized to assess.

Prohibited activity

  • Scanning or testing systems without explicit authorization.
  • Attempting denial of service, destructive exploitation, credential theft, malware delivery, spam, phishing, or data exfiltration.
  • Circumventing plan limits, access controls, rate limits, or safety mechanisms.
  • Using findings to exploit, extort, harass, discriminate, or cause harm.
  • Reselling access or reports in violation of your plan or misrepresenting automated results as a certification.

Operational safeguards

You must choose safe testing windows, use designated test accounts where appropriate, protect secrets, respect target capacity, and stop a scan if it may cause instability. Production testing remains your responsibility.

Enforcement

We may throttle, pause, investigate, or terminate activity that appears unauthorized, abusive, unlawful, or harmful. We may preserve and disclose relevant records where legally required or necessary to protect people and systems.

Questions about this policy? Email support@scanlyst.dev.