Guardrails
Authorized scanning only
Each scan requires a stored attestation that you own the network or have the owner’s permission. That is a legal representation, not a technical proof of IP ownership. Size and schedule limits reduce casual abuse. We can pause or cancel a schedule after a complaint.
The contract
When you create or update a scan you must attest:
I certify that I own this network, or I am authorized by its owner to scan it, and I take full responsibility for this scan request.
We store that text with your user, customer account, the exact target string, the time, and the IP address of the request. The schedule is then marked authorized so the dedicated scanner may run it on the next run date.
What this is not
Attestation is not DNS verification, not a well-known HTTP challenge, and not a signed PDF of corporate identity. We do not claim to have proven that you control every address in the range. If you cannot honestly attest, do not submit the scan.
Limits that still apply
- IPv4 only: a list of at most 20 public addresses, or a CIDR of
/20or more specific. Private and non-public addresses are rejected. Larger lists require a support request. - Combined host count at most 4,096.
- The website does not launch nmap. Runs are scheduled (6 or 12 months).
Why this exists
Unauthorized scanning can implicate the Computer Fraud and Abuse Act (US) and equivalent statutes elsewhere, and it violates most ISP and cloud acceptable-use policies. You are responsible for the targets you submit, including any notice your cloud provider requires.
If we receive an abuse report, we may pause or cancel the schedule and, if needed, the account. We can show the attestation record to answer who requested the traffic.
What we still expect of you
- Only submit addresses and CIDRs you control or have written authorization to test.
- Pause or cancel a scan if the block is reassigned or your authorization ends.
- Do not use PortSweep to probe third-party networks.
See also the Terms of Service and how it works.