Acceptable Use

Acceptable Use Policy

SurfaceLoop performs active scanning. You may only scan assets you own or are explicitly authorised to assess.

Last updated: 2 July 2026

This is a template. This policy is provided as a starting point and has not been reviewed by a qualified solicitor. Have a solicitor review it before launching self-service scanning.

1. Purpose and scope

This Acceptable Use Policy (the "AUP") governs your use of the SurfaceLoop platform (the "Service"). Because the Service actively scans internet-facing infrastructure — making network connections, fingerprinting services, inspecting TLS, and running vulnerability checks — misuse can cause real harm and legal liability. This AUP forms part of, and is incorporated by reference into, our Terms of Service. Breaching it is a breach of the Terms.

2. Golden rule: scan only what you are authorised to scan

You may only add and scan assets that you own or that you are explicitly authorised in writing to assess. There are no exceptions. If you are not certain you have authorisation for a target, do not add it.

3. Ownership verification

To enforce the golden rule, SurfaceLoop requires a recorded authorisation for each root asset before any scanning begins, and scans will not run against an asset without one. The authorisation is one of the following:

  • DNS TXT record — publish a SurfaceLoop-issued token as a TXT record on the domain you are claiming.
  • HTTPS file challenge — host a SurfaceLoop-issued file at a well-known path over HTTPS on the asset.
  • Attestation — confirm in the app that you own the asset or are authorised by its owner to have it scanned. This is the standard method: it is recorded against your user account and reviewed by SurfaceLoop staff, and it is the basis on which scanning proceeds. Providing a false attestation is a serious breach of this AUP.

An authorisation record reflects a point in time; you remain responsible for ensuring your authorisation stays valid for as long as the asset is in your inventory.

4. Prohibited uses

You must not use the Service to:

  • • scan, probe, or fingerprint infrastructure you do not own or are not authorised to assess, including third-party, shared-hosting, or cloud-provider infrastructure outside your control;
  • • attempt to circumvent ownership verification, or submit false or misleading attestations;
  • • use scan results to attack, exploit, disrupt, or gain unauthorised access to any system;
  • • conduct denial-of-service testing, brute-force credential attacks, or any activity intended to degrade or overload a target beyond ordinary discovery scanning;
  • • scan private, reserved, loopback, or link-local address ranges belonging to others, or otherwise pivot into networks you do not control;
  • • resell, sublicense, or provide the Service to third parties to scan assets those parties are not authorised to assess; or
  • • use the Service in violation of any applicable law, regulation, or third-party right.

5. Unauthorised scanning is illegal

In the United Kingdom, accessing or probing computer systems without authorisation may be a criminal offence under the Computer Misuse Act 1990. Similar laws apply in other jurisdictions. You are solely responsible for ensuring you have lawful authority for every target you submit. SurfaceLoop is a tool that acts on your instructions; you — not SurfaceLoop — bear responsibility for the scope you define.

6. Responsible scanning

The Service is designed to scan responsibly: it applies rate limits and concurrency controls per target, restricts probes to an allowed set of ports, filters out private and reserved address ranges, and sends an identifiable User-Agent for disclosure traceability. Do not attempt to override these safeguards.

7. Reporting misuse

If you believe an asset is being scanned without authorisation, or you become aware of any misuse of the Service, report it immediately to [email protected] (placeholder contact). We investigate reports promptly.

8. Consequences of violation

We take violations seriously. Depending on severity, we may: remove or suspend individual assets; suspend your scanning ability; suspend or terminate your account without refund; preserve relevant records; and cooperate with law enforcement. We may act immediately and without prior notice where we reasonably believe scanning is unauthorised or unlawful, or where continued activity risks harm to third parties or the Service.

9. Changes to this policy

We may update this AUP from time to time. If we make material changes we will provide reasonable notice. Your continued use of the Service after changes take effect constitutes acceptance. See also our Terms of Service and Privacy Policy.