Authorized audit use
Audits must only be run against the visitor IP, owned domains, or systems the user confirms they administer or are authorized to review. No attacks, brute force, exploitation or mass scanning are performed.
Allowed targets
- Your own public IP address.
- Domains and subdomains you own.
- Servers or systems you administer directly, or where the owner gave explicit authorization.
Prohibited targets
- Third-party systems without explicit authorization, even if publicly accessible.
- Critical, government or essential-service infrastructure without formal authorization.
- Any target where there is reasonable doubt about authorization.
Technical limits
We apply rate limits by IP to prevent abuse and automatically block scans of private, reserved or loopback IP addresses.