← Back to SentriCore Cyber360™

Terms of Service & Acceptable Use Policy

Draft — this is a starting point for your legal counsel to review before commercial launch, not a substitute for legal advice.

1. Authorization to scan

SentriCore Cyber360™ performs active network checks against every asset you add — including DNS resolution, TLS/SSL handshakes, HTTP requests, and TCP port connection attempts. By adding an asset (a domain, subdomain, IP address, or cloud resource) to your account, you represent and warrant that you own that asset or have explicit written authorization from its owner to test it.

Scanning a domain or IP you do not own or have authorization to test may violate the Computer Fraud and Abuse Act (US), the Computer Misuse Act (UK), and equivalent laws elsewhere, and is strictly prohibited under this policy regardless of intent. We reserve the right to suspend any account found to be scanning unauthorized targets.

2. What we check

Our checks are passive-to-light-active: DNS lookups, TLS certificate inspection, HTTP header requests, and TCP connect attempts against a fixed list of commonly-used ports. We do not run exploit code, attempt authentication bypass, or perform denial-of-service testing against any asset. Full detail is published on each report's Methodology tab.

3. Account responsibilities

You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account, including assets added by users you invite. You must promptly remove any asset from your account if you no longer own it or your authorization to test it ends.

4. No warranty on findings

Findings are generated by automated checks against real, live data (DNS, TLS, HTTP responses, open ports, and cross-references against NIST's National Vulnerability Database). A CVE match is a possible match based on keyword/banner detection, not a confirmed exploit — always verify against the linked NVD entry before acting. We do not guarantee completeness: the absence of a finding is not a guarantee of security, only that the specific checks we run did not detect an issue.

5. Data & confidentiality

Reports generated for your workspaces are confidential and accessible only to members of your organisation with the appropriate role. See our Privacy Policy for how we handle personal and organisational data.

6. Limitation of liability

The service is provided "as is". To the maximum extent permitted by law, SentriCore is not liable for any indirect, incidental, or consequential damages arising from use of the platform, including reliance on any report or finding.

Last updated: draft, not yet finalized for commercial launch.