Scope
This Acceptable Use Policy (“AUP”) governs your use of the ShipReady website, dashboard, APIs, MCP server, IDE integration, and related services (the “Service”). It is part of, and incorporated by reference into, our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
Violating this AUP is a material breach of the Terms. It may result in immediate suspension or termination of your account without refund, referral to law enforcement, and any other remedy available to us.
1. Authorization to Scan
Scan only what you own or are authorized to scan
Before you start a scan, you must own the target — the website, endpoint, repository, or backend project — or hold express authorization from its owner. You are solely responsible for verifying that authority. We do not verify it for you.
Unauthorized scanning may violate computer-misuse and unauthorized-access laws in many jurisdictions, including the U.S. Computer Fraud and Abuse Act (18 U.S.C. § 1030), the UK Computer Misuse Act 1990, Section 202a of the German Criminal Code, Articles 323-1 et seq. of the French Penal Code, and Section 43 and Section 66 of the Indian Information Technology Act, 2000. It can expose you to civil and criminal liability.
2. Prohibited Conduct
You may not, and may not permit any third party to, use the Service to:
- Scan, probe, exploit, attack, or attempt to gain unauthorized access to any system, network, account, or device without explicit authorization.
- Develop, test, host, or distribute malware, spyware, ransomware, worms, rootkits, keyloggers, or any other malicious code.
- Conduct, plan, or facilitate any cyberattack, including denial-of-service, credential stuffing, brute-force, phishing, business-email compromise, supply-chain compromise, or social engineering.
- Bypass or circumvent any authentication, access control, paywall, rate limit, encryption, or other technical protection measure — whether ours or a third party’s.
- Violate anyone’s rights, including intellectual property, privacy, data protection, contractual, or employment rights.
- Facilitate fraud, identity theft, money laundering, terrorism financing, or any other illegal activity.
- Harass, stalk, dox, threaten, intimidate, discriminate against, or harm any person or group.
- Harvest or compile personal data, business intelligence, or competitive information about third parties without a lawful basis.
- Target government, military, intelligence, election, healthcare, financial-services, energy, water, telecommunications, transport, or industrial-control systems without our prior written consent and a separately agreed arrangement.
- Develop, train, fine-tune, evaluate, or benchmark a competing scanning product or any machine-learning model.
- Reverse-engineer, decompile, or attempt to derive the source code, detection rules, or scoring models of the Service, except where mandatory law permits it.
- Resell access to the Service, sublicense our software, or commercially exploit Service output beyond what your plan permits.
- Access the Service with bots, scrapers, or headless browsers other than through our documented APIs and within their published rate limits.
- Publish benchmarks, comparative reviews, or competitive analyses of the Service without our prior written consent.
- Upload or transmit content that is unlawful, infringing, defamatory, obscene, hateful, deceptive, or that contains harmful code.
- Impose a disproportionate load on our infrastructure, interfere with other users’ access, or endanger the security, integrity, or availability of the Service.
- Violate export-control, sanctions, anti-bribery, anti-money-laundering, consumer protection, or data protection laws of any applicable jurisdiction.
- Impersonate any person, misrepresent your affiliation with an organization, register with false identity information, or operate multiple accounts to evade quotas, restrictions, or pricing.
3. Responsible Disclosure
If you discover a vulnerability affecting a third party while using the Service, handle it lawfully and responsibly. Where the third party runs a published vulnerability disclosure or bug bounty program, follow its rules. Where it does not, report the issue privately and give a reasonable period to remediate before any public disclosure. Never use information discovered through the Service to gain unauthorized access, extort, or cause harm.
To report a security issue in ShipReady itself, email us with the subject “Security” and please refrain from public disclosure for a reasonable period while we remediate.
4. Quotas, Rate Limits & Fair Use
Your plan defines quotas for scans, projects, integrations, API calls, and report retention. You must stay within them. We may additionally apply rate limiting, throttling, or queuing to protect the Service and other users. Where a limit is described as generous or unmetered, use must remain ordinary, lawful, and in good faith — it does not permit abusive automation, account sharing, infrastructure overload, or resale of access. We may throttle or suspend disproportionate use.
5. Reporting Abuse
To report a violation of this AUP, suspected abuse, or illegal activity involving the Service, email us with the subject “Abuse Report” and as much detail as you can provide — URLs, timestamps, account information, and evidence. We investigate reports promptly.
6. Enforcement
We may (but are not obliged to) investigate any suspected violation, remove or disable access to content, and suspend or terminate any account, with or without notice. We may cooperate with law enforcement and produce information in response to lawful process. We may also pursue any other legal or equitable remedy available to us, including injunctive relief and recovery of costs.
7. Changes
We may modify this AUP from time to time. The current version is always at /acceptable-use with a “Last updated” date. Continued use after a change takes effect constitutes acceptance.