Legal

Acceptable Use Policy

Last updated June 17, 2026

SecNxt is a security testing platform whose scanning engines can send active, intrusive traffic to the targets you specify. This Acceptable Use Policy (AUP) sets out how the platform may and may not be used. It forms part of, and is incorporated into, our Terms of Service. By using SecNxt you agree to this policy.

1. Authorization is mandatory

You may only scan, probe, or test systems, repositories, websites, APIs, mobile apps, networks, hosts, IP addresses, or cloud accounts that you own or for which you hold explicit, current, written authorization from the owner to perform security testing.

For each active target you configure, you must confirm this authorization. That confirmation is recorded with your account, the time, and your IP address. Providing a false authorization confirmation is a serious breach of these terms and may be unlawful.

2. Prohibited targets and activities

You must not use SecNxt to: test third-party systems without permission; scan critical national infrastructure, government, financial, or healthcare systems you are not authorized to test; attempt to gain unauthorized access to data; exfiltrate, alter, or destroy data that is not yours; conduct denial-of-service attacks; or use the platform to facilitate any illegal activity.

Scanning of internal, private (RFC 1918), loopback, link-local, or cloud-metadata addresses from our cloud scanners is restricted. Testing of internal networks must be performed through a self-hosted runner you operate within a network you are authorized to test.

3. Self-hosted runners

If you enroll a self-hosted runner, you are solely responsible for the targets it tests and for ensuring it operates only against assets within your authorized scope. Rules of engagement you record are your responsibility to honor.

4. Lawful and responsible use

You are responsible for complying with all laws applicable to you and to the systems you test, including computer-misuse, data-protection, and export-control laws in every relevant jurisdiction. Security testing of systems you do not own or are not authorized to test may be a criminal offence.

5. Findings, secrets and data

Scan findings may contain sensitive data such as code excerpts, request/response captures, and partial secrets. You are responsible for handling exported findings securely, sharing them only with authorized recipients, and rotating any credentials a scan reveals.

6. Enforcement

We may suspend or terminate accounts, cancel scans, and report activity to relevant authorities where we reasonably believe this policy has been breached. We may do so without notice where necessary to prevent harm. Authorization confirmations and scan activity are logged to support accountability.

7. Changes & contact

We may update this policy as the platform evolves; continued use after changes means you accept them. Questions? Reach us through the Contact page. SecNxt is a product of Olwayz24 Technologies Pvt. Ltd.