Acceptable Use Policy

Last updated: 5 October 2026

This policy sets out what you can and cannot do with TrustDyne. It is part of the Terms of Service. Security testing can do damage when it hits the wrong target, so the authorisation rules are strict.

1. Only assess what you are authorised to assess

  • Upload files, register domains and connect cloud accounts only if you own them or have the owner's explicit written permission to assess them.
  • Active testing runs only against targets whose ownership you have verified through the platform. Verification and the consent you record are your authorisation record.
  • Do not register a target because it shares hosting, an IP address or a network with something you control. For example, a hosting account that also serves other businesses' sites does not give you permission to test those sites.
  • Where you act for someone else, you must hold written authority from them before you register their assets, and give us a copy if we ask.

2. Do not

  • Use the Service to attack, disrupt, access or gather data from systems you are not authorised to test, or to support anyone who does.
  • Upload malware or exploit code for any purpose other than analysing it as part of your own security work, or upload content that is unlawful or infringes others' rights.
  • Bypass or probe the Service's own controls, rate limits, plan limits or authorisation checks, or test our systems other than through our disclosure programme.
  • Share your credentials or API keys, or let people use your account who are not part of your organisation.
  • Submit special category personal data or payment card data unless we have agreed it in writing.
  • Use the Service or its outputs to build or train a competing product, or resell raw results as your own service without our written agreement.
  • Present automated results as a certification, penetration test sign-off or compliance guarantee that they are not.

3. Use scan results responsibly

Findings may describe exploitable weaknesses in your own systems. Keep them confidential, share them only with people who need them, and report vulnerabilities you find in other people's products to the vendor responsibly.

4. Enforcement

If we think this policy has been broken, we can remove content, pause scans, suspend the account or report unlawful activity to the authorities. Where practical we will tell you why and give you a chance to explain, but we can act immediately where there is risk to others. Report misuse to security@trustdyne.com.