ScanexAI
Get Started Log in

LEGAL & ETHICS

Responsible Use Policy

This tool is for authorised security testing only.

Unauthorised scanning of systems you do not own or have explicit permission to test is illegal and may result in criminal prosecution.

ScanexAI is a security tool built to help developers, security teams, and consultants identify and fix vulnerabilities in websites and applications they are responsible for. Like any security tool, it comes with a clear responsibility: it must only be used against systems you own or have been given explicit written permission to test. There are no exceptions.

Unauthorised scanning of websites or web applications is illegal in most countries, regardless of whether you believe your intentions are good. Laws such as the Computer Fraud and Abuse Act in the United States, the Computer Misuse Act in the United Kingdom, and similar legislation in other countries apply to automated probing of systems you do not own. Violating these laws can result in serious criminal penalties.

If you are conducting a professional penetration test on behalf of a client, ensure you have a signed statement of work that clearly defines the scope of the engagement before running any scans. If you are a developer testing your own application, ensure it is hosted in an environment you control. When in doubt, do not scan.

Permitted Use

  • Scanning websites and web applications you own outright

  • Testing systems where you have explicit written permission from the owner

  • Authorised penetration testing engagements with a signed statement of work

  • Internal security assessments of your organisation's own infrastructure

  • Educational and research use in isolated lab environments

Prohibited Use

  • Scanning any website or system without prior written authorisation

  • Targeting production systems of third parties without a signed penetration testing agreement

  • Using scan results to exploit, extort, or harm any organisation or individual

  • Distributing or selling reports generated from unauthorised scans

  • Circumventing authentication or access controls beyond the agreed scope

Legal Notices

  • Automated scanning of third-party sites without permission may violate computer fraud laws including the CFAA (US), Computer Misuse Act (UK), and equivalent legislation in your jurisdiction

  • Never use this tool against production systems without a signed penetration testing agreement in place

  • Results are indicative, not exhaustive - always follow up with manual testing and professional review

  • The AI breach narrative is generated for reporting purposes only and does not constitute legal advice

  • ScanexAI accepts no liability for misuse of this platform

Responsible Disclosure

  • If you discover a vulnerability using this tool, notify the affected organisation responsibly

  • Allow a reasonable remediation window (typically 90 days) before public disclosure

  • Follow coordinated vulnerability disclosure (CVD) guidelines from CERT or your national CSIRT

  • Do not exploit discovered vulnerabilities beyond what is necessary to confirm their existence