Terms of use — exposure check
1. Scope
These terms govern your use of the free exposure-check tool provided on this website ("the check"). They do not govern any paid services, which are agreed separately in writing. By using the check you accept these terms. If you do not accept them, do not use the check.
2. Authorised use only
The check may be used only against a domain that you own or that you are explicitly authorised, in writing, to assess. By running a check you confirm and warrant that this is the case. Using it against any other target may constitute unauthorised access to, or interference with, information systems under applicable law (including §202a–202c StGB in Germany and comparable provisions elsewhere) and is strictly prohibited. You are solely responsible for ensuring your use is lawful and authorised.
3. What the check does — and does not do
The check reads only publicly available information: Certificate-Transparency logs, public DNS records, and version information that servers disclose to any unauthenticated visitor. It does not port-scan, brute-force hostnames, bypass or test authentication, send attack or exploit payloads, or attempt to access protected data. It performs a small number of ordinary, unauthenticated GET requests to well-known public endpoints of a fixed allowlist of self-hosted business applications, and reads the web server's own banner.
The check is not a penetration test, a security audit, or a vulnerability assessment within the meaning of those terms, and must not be relied upon as one.
4. No guarantee of accuracy (conditional findings)
Results are informational only and are produced by matching a self-disclosed version against published vulnerability data. A version shown as "affected" is not proof of a live, exploitable vulnerability: a backported fix, a vendor patch that does not change the reported version, network restrictions, a disabled feature, or other mitigations may already address it. Conversely, the absence of a finding is not a guarantee that a system is secure — the check sees only what a server volunteers and only the applications on its allowlist. Every finding is therefore conditional ("unless already patched or otherwise mitigated"). The check is a starting point for a conversation, not a verdict.
5. No stored third-party results
We do not retain the results of checks performed against third-party domains. Results are computed and shown to you, then discarded. We do not build or keep a database of third-party exposure. See the privacy notice.
6. Acceptable use & rate limits
Automated, bulk, scripted, or abusive use is prohibited. Input of raw IP addresses or network ranges is not supported. We may rate-limit, throttle, or block any use that appears automated, abusive, or directed at systems without authorisation, and may withdraw or change the check at any time without notice.
7. Liability
The check is provided free of charge, "as is" and "as available", without any warranty of accuracy, completeness, availability, or fitness for a particular purpose, to the fullest extent permitted by law. To the extent permitted by law, we are not liable for any decisions made, or action or inaction taken, on the basis of its output, nor for any indirect or consequential loss. Nothing in these terms limits liability that cannot be limited by law (including liability for intent, gross negligence, injury to life, body or health, or mandatory consumer-protection and product-liability rules).
8. Governing law
These terms are governed by the laws of Spain, without prejudice to the mandatory consumer-protection rules of your country of residence.
Last updated: 11 October 2026.