For people submitting scans
- Passive-tier scanning is limited to requests an ordinary visitor or search-engine crawler would make — you don't need the target owner's permission to run one.
- Active-tier scanning (endpoint enumeration and deeper probing) requires proof of ownership or control of the target, via a DNS record, a well-known file, or a meta tag. You may only request active tier for sites you own or are explicitly authorized to test.
- Every scan and its underlying tier decision is written to a permanent, append-only audit trail.
- Scan frequency per target and per account is rate-limited. Attempting to circumvent rate limits, authorization checks, or the ownership-verification flow is a violation of this policy.
- Do not use Vigilo to scan infrastructure you know to be internal, non-public, or otherwise off-limits (for example, cloud metadata endpoints or private network ranges) — the service actively blocks known-internal address ranges and this is not something to attempt to bypass.
For site owners: opting out
If you own a site and don't want it scanned by Vigilo — by anyone, at any tier — email abuse@vigilo.io from an address associated with the domain, or from an address you can otherwise demonstrate control of the domain with, and we will add it to our denylist. Today this is a manual, support-handled process rather than a self-service form; we aim to act on opt-out requests promptly.
A denylisted or opted-out target is refused outright — no scan runs, and no account or target record is created for the request — this takes priority over every other authorization check, including a fully verified active-tier proof.
Reporting abuse
If you believe Vigilo is being used to scan a target abusively, or that the service itself is misbehaving toward your infrastructure, email abuse@vigilo.io. For a security vulnerability in Vigilo itself, email security@vigilo.io instead.
Enforcement
Violating this policy may result in denylisting the targets involved, rate-limiting or suspending the account involved, or termination of access to Vigilo, at our discretion.
Contact
General questions about this policy can be sent to support@vigilo.io.