Draft. Review with a qualified lawyer before relying on it.
The core rule
You may direct scanning or assessment features only at systems you own or for which you hold explicit written authorisation from the owner. Scanning systems without authorisation may be a criminal offence.
You may
Receive CVE and dependency alerts for any technology you choose to watch.
Run non-intrusive external assessments on assets you have verified (DNS) or attested authorisation for.
Connect repositories you control using read-only tokens to monitor dependencies.
You may not
Scan, probe, or assess any system you do not own or are not authorised to test.
Attempt exploitation, denial-of-service, brute-force, credential attacks, or any destructive or intrusive technique.
Use findings to attack, extort, or gain unauthorised access to any system.
Provide access tokens with write, admin, or broader-than-read scope.
Upload or process another party's confidential data without authority.
Resell, redistribute, or scrape the Service or its data feeds in breach of their licences.
Use the Service for any unlawful purpose or to circumvent security controls.
How we keep this safe
Assessments are external and non-intrusive by design (no exploitation, DoS, or fuzzing). Targets require ownership verification or a recorded authorisation attestation. The Service does not run exploits.
Consequences
Violations may result in immediate suspension or termination and, where appropriate, referral to authorities. You remain liable for any unauthorised activity you conduct.