LEGAL & ETHICS
This tool is for authorised security testing only.
Unauthorised scanning of systems you do not own or have explicit permission to test is illegal and may result in criminal prosecution.
ScanexAI is a security tool built to help developers, security teams, and consultants identify and fix vulnerabilities in websites and applications they are responsible for. Like any security tool, it comes with a clear responsibility: it must only be used against systems you own or have been given explicit written permission to test. There are no exceptions.
Unauthorised scanning of websites or web applications is illegal in most countries, regardless of whether you believe your intentions are good. Laws such as the Computer Fraud and Abuse Act in the United States, the Computer Misuse Act in the United Kingdom, and similar legislation in other countries apply to automated probing of systems you do not own. Violating these laws can result in serious criminal penalties.
If you are conducting a professional penetration test on behalf of a client, ensure you have a signed statement of work that clearly defines the scope of the engagement before running any scans. If you are a developer testing your own application, ensure it is hosted in an environment you control. When in doubt, do not scan.
Scanning websites and web applications you own outright
Testing systems where you have explicit written permission from the owner
Authorised penetration testing engagements with a signed statement of work
Internal security assessments of your organisation's own infrastructure
Educational and research use in isolated lab environments
Scanning any website or system without prior written authorisation
Targeting production systems of third parties without a signed penetration testing agreement
Using scan results to exploit, extort, or harm any organisation or individual
Distributing or selling reports generated from unauthorised scans
Circumventing authentication or access controls beyond the agreed scope
Automated scanning of third-party sites without permission may violate computer fraud laws including the CFAA (US), Computer Misuse Act (UK), and equivalent legislation in your jurisdiction
Never use this tool against production systems without a signed penetration testing agreement in place
Results are indicative, not exhaustive - always follow up with manual testing and professional review
The AI breach narrative is generated for reporting purposes only and does not constitute legal advice
ScanexAI accepts no liability for misuse of this platform
If you discover a vulnerability using this tool, notify the affected organisation responsibly
Allow a reasonable remediation window (typically 90 days) before public disclosure
Follow coordinated vulnerability disclosure (CVD) guidelines from CERT or your national CSIRT
Do not exploit discovered vulnerabilities beyond what is necessary to confirm their existence