Terms of Service

Last updated: March 2026

Welcome to SecurityOwl. These Terms of Service ("Terms") govern your access to and use of the SecurityOwl web security scanning platform, including our website, APIs, scan engine, reports, and all related services (collectively, the "Service"). By accessing or using the Service, you agree to be bound by these Terms. If you do not agree to these Terms, you may not access or use the Service.

SecurityOwl is operated by SecurityOwl ("we," "us," or "our"). The terms "you" and "your" refer to the individual or entity accessing or using the Service.

1. Description of Service

SecurityOwl is a software-as-a-service (SaaS) platform that provides automated web security vulnerability scanning. The Service analyzes websites and web applications for potential security vulnerabilities, misconfigurations, and exposures by performing external, non-destructive reconnaissance techniques. Scan results are presented as informational findings intended to assist website owners and authorized security professionals in identifying and remediating potential security issues.

The Service includes, but is not limited to: automated security checks across multiple vulnerability categories, AI-powered risk analysis and correlation, scan result reporting, PDF report generation, scan history and dashboard access, and remediation guidance.

2. Account Registration

To access certain features of the Service, you must create an account. You agree to provide accurate, current, and complete information during registration and to keep your account information up to date. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to notify us immediately of any unauthorized use of your account.

You must be at least 18 years of age or the age of legal majority in your jurisdiction to create an account and use the Service. By creating an account, you represent and warrant that you meet this age requirement.

3. User Obligations and Authorization

You represent and warrant that you have proper authorization to scan any target you submit to the Service. By initiating a scan, you confirm that:

  • You are the owner of the target website or web application, or you have obtained explicit, written authorization from the owner to perform security testing;
  • Your use of the Service against the target complies with all applicable laws, regulations, and contractual obligations;
  • You have reviewed and understand the scope of the scans performed by the Service;
  • You accept full responsibility for any consequences arising from scanning the target.

We do not verify your authorization to scan any target. The responsibility for ensuring proper authorization rests solely with you. Unauthorized scanning of websites or systems may violate applicable computer fraud and abuse laws, including but not limited to the Computer Fraud and Abuse Act (CFAA) in the United States, the Computer Misuse Act in the United Kingdom, and equivalent legislation in other jurisdictions.

4. Authorization Disclaimer

THE SERVICE IS PROVIDED SOLELY AS A TOOL FOR AUTHORIZED SECURITY TESTING AND INFORMATIONAL PURPOSES. SecurityOwl does not authorize, endorse, or encourage the scanning of any website or system without proper authorization. We are not responsible for determining whether you have the legal right to scan any particular target.

By using the Service, you acknowledge that you are solely responsible for obtaining all necessary permissions and authorizations before initiating any scan. SecurityOwl shall not be liable for any legal consequences, damages, or claims arising from your unauthorized use of the Service against any target.

5. Prohibited Use

You agree not to use the Service to:

  • Scan any website, web application, server, or network without proper authorization from the owner or operator;
  • Conduct any illegal activity, including but not limited to unauthorized access to computer systems, data theft, or violation of any applicable laws;
  • Perform or facilitate denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks against any target;
  • Attempt to exploit, weaponize, or take advantage of any vulnerabilities identified by the Service;
  • Use the Service to harass, threaten, extort, or blackmail any individual or organization;
  • Interfere with, disrupt, or attempt to gain unauthorized access to the Service, its infrastructure, or other users' accounts;
  • Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Service;
  • Resell, redistribute, or sublicense access to the Service or scan results without our prior written consent;
  • Use the Service in a manner that could damage, disable, overburden, or impair our servers or networks;
  • Use automated means (bots, scrapers, or similar tools) to access the Service beyond the intended API interfaces;
  • Circumvent or attempt to circumvent any rate limits, access controls, or security measures implemented by the Service.

6. Subscription Plans and Payment

The Service is offered through various subscription tiers, including a free tier with limited functionality and paid tiers with additional features. Details of available plans, pricing, and features are described on our pricing page and may be updated from time to time.

Paid subscriptions are billed on a recurring monthly basis. By subscribing to a paid plan, you authorize us to charge your designated payment method for the applicable subscription fees. All payments are processed through Stripe, a third-party payment processor, and are subject to Stripe's terms of service and privacy policy.

Subscription fees are non-refundable except as required by applicable law. You may cancel your subscription at any time through your account settings or via the Stripe customer portal. Cancellation will take effect at the end of the current billing period.

7. Limitation of Liability

SCAN RESULTS ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS FOR INFORMATIONAL PURPOSES ONLY. The Service does not guarantee the detection of all vulnerabilities, and the absence of reported findings does not constitute a certification or guarantee that a target is secure. Security scanning is inherently limited and cannot substitute for comprehensive security audits, penetration testing, or professional security consulting.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, SECURITYOWL AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AND AFFILIATES SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR RELATED TO YOUR USE OF OR INABILITY TO USE THE SERVICE.

IN NO EVENT SHALL OUR TOTAL LIABILITY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE EXCEED THE AMOUNT YOU HAVE PAID TO US IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE LIABILITY, OR ONE HUNDRED DOLLARS ($100), WHICHEVER IS GREATER.

We do not warrant that the Service will be uninterrupted, error-free, or free of harmful components. We are not responsible for any damage to your computer systems, loss of data, or other harm resulting from your use of the Service.

8. Data Handling

We collect, store, and process certain data in connection with your use of the Service, including account information, scan target URLs, scan results, and usage data. Our collection and use of personal data is governed by our Privacy Policy, which is incorporated into these Terms by reference.

Scan results and target information are stored securely and are accessible only to you through your authenticated account. We do not share your scan results with third parties except as described in our Privacy Policy or as required by law.

9. Intellectual Property

The Service, including its design, features, functionality, scanning engine, algorithms, AI models, documentation, branding, and all related intellectual property, is and shall remain the exclusive property of SecurityOwl and its licensors. These Terms do not grant you any right, title, or interest in the Service except for the limited right to use the Service in accordance with these Terms.

You retain ownership of any data you submit to the Service, including scan target URLs. Scan results generated by the Service are provided to you under a limited license for your internal use. You may not reproduce, distribute, or publicly display scan results for commercial purposes without our prior written consent, except for sharing results with your own team, clients, or stakeholders in the ordinary course of security management.

10. Account Termination

We reserve the right to suspend or terminate your account and access to the Service at any time, with or without notice, for any reason, including but not limited to:

  • Violation of these Terms, the Acceptable Use Policy, or any applicable laws;
  • Scanning targets without proper authorization;
  • Engaging in prohibited activities as described in Section 5;
  • Non-payment of subscription fees;
  • At our sole discretion, if we believe your use of the Service poses a risk to us, other users, or third parties.

Upon termination, your right to access the Service will immediately cease. We may, but are not obligated to, delete your account data, including scan results and history, upon termination. Sections of these Terms that by their nature should survive termination shall survive, including but not limited to Sections 4, 5, 7, 9, 11, and 12.

11. Third-Party Services

The Service integrates with and relies upon certain third-party services, including but not limited to:

  • Stripe — for payment processing and subscription management. Your payment information is handled directly by Stripe and is subject to Stripe's Terms of Service and Privacy Policy.
  • Anthropic AI — for AI-powered analysis and risk correlation of scan results. Scan data may be processed by Anthropic's AI models to generate insights and recommendations. Use of AI features is subject to Anthropic's usage policies.
  • GitHub — for OAuth-based authentication. If you choose to sign in with GitHub, your authentication is subject to GitHub's terms of service and privacy policy.

We are not responsible for the practices, policies, or availability of any third-party services. Your use of third-party services is at your own risk and subject to the respective third party's terms and conditions.

12. Governing Law and Dispute Resolution

These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws principles.

Any dispute, controversy, or claim arising out of or relating to these Terms or the Service shall first be attempted to be resolved through good-faith negotiation between the parties. If the dispute cannot be resolved through negotiation within thirty (30) days, either party may submit the dispute to binding arbitration administered by the American Arbitration Association (AAA) in accordance with its Commercial Arbitration Rules. The arbitration shall be conducted in the State of Delaware.

Notwithstanding the foregoing, either party may seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation, or violation of intellectual property rights or confidential information.

YOU AGREE THAT ANY DISPUTE RESOLUTION PROCEEDINGS WILL BE CONDUCTED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION. If for any reason a claim proceeds in court rather than in arbitration, you waive any right to a jury trial.

13. Indemnification

You agree to indemnify, defend, and hold harmless SecurityOwl and its officers, directors, employees, agents, and affiliates from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Service; (b) your violation of these Terms; (c) your violation of any applicable laws or regulations; (d) your scanning of any target without proper authorization; or (e) any claim by a third party related to your use of the Service.

14. Modification of Terms

We reserve the right to modify these Terms at any time. If we make material changes to these Terms, we will notify you by posting the updated Terms on the Service and updating the "Last updated" date at the top of this page. We may also notify you via email or through the Service interface.

Your continued use of the Service after the effective date of any modifications constitutes your acceptance of the updated Terms. If you do not agree to the modified Terms, you must discontinue your use of the Service and close your account.

15. Severability

If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the original intent of the parties.

16. Entire Agreement

These Terms, together with our Privacy Policy and Acceptable Use Policy, constitute the entire agreement between you and SecurityOwl regarding the Service and supersede all prior and contemporaneous agreements, proposals, or representations, written or oral, concerning the Service.

17. Contact Information

If you have any questions about these Terms of Service, please contact us at legal@securityowl.io.

SecurityOwl — Security scanning you can trust.