← back to Breachpoint
Terms & Authorised Use
Plain-English summary. Not legal advice — have a lawyer review before charging or scaling.
1. Authorised targets only
You may only run Breachpoint against a website or application that you own, or that you are explicitly authorised to test. Scanning systems you do not control may be illegal in your jurisdiction. By running a scan you confirm you have that authorisation. You are solely responsible for how you use the tool.
2. What Breachpoint does
- It reads only publicly-served resources — the HTML, JavaScript, response headers and public DNS records that any visitor's browser or a search engine can already retrieve.
- It performs read-only checks. It does not log in, submit forms, modify data, or use any credential it happens to find.
- Detected secrets are masked before they are shown to you.
3. No warranty
Breachpoint is provided “as is”, on a best-effort basis. A clean result does not mean your application is secure — the scan covers one class of issues and is not a substitute for a professional security audit or penetration test. We make no guarantee of completeness or accuracy and accept no liability for any loss arising from use of the tool or reliance on its results.
4. Privacy & data
- To run a scan we fetch your app's public resources over the internet.
- We store only a small summary per domain — the domain, the grade, and pass/fail counts — to power the public report and the “Attack-Tested” badge. We do not store your source code, and secret values are never stored in full.
- No cookies and no third-party trackers. We keep simple, aggregate analytics — counts of scans and visits, which domains were scanned, referring sites and coarse country — with no visitor profiles. IP addresses are used only transiently to rate-limit abuse and are not stored.
- If you submit your email to the waitlist, we store it solely to contact you about the product. Ask any time and we'll delete it.
- A basic per-visitor rate limit applies to prevent abuse.
5. Contact
Questions or a security concern? Reach out to the operator of this deployment.
This is an early product. Terms will be expanded and formalised before any paid or public-standard use.