Acceptable Use Policy
1. Purpose
This Acceptable Use Policy protects Scan Shield Cloud FZCO, approved customers, upstream providers, networks, infrastructure owners and third parties from unlawful, abusive or unauthorized activity.
2. Prohibited activity
You must not use the service, directly or indirectly, to conduct, facilitate or knowingly support:
- unauthorized network, port, address-range, vulnerability or service scanning;
- credential stuffing, password guessing, brute-force activity, account takeover or unauthorized access attempts;
- malware delivery, command-and-control activity, phishing, deceptive credential collection or distribution of malicious code;
- denial-of-service attacks, traffic amplification, intentional service disruption or resource exhaustion;
- distribution or hosting of child sexual abuse material or other content whose possession or distribution is unlawful;
- copyright, trademark or other intellectual-property infringement where the customer lacks the required rights or authorization;
- fraud, impersonation, deceptive services, unlawful surveillance or unauthorized interception;
- access to systems, networks or data without the owner’s authorization;
- activity that violates applicable law, sanctions, court orders, contractual restrictions or binding upstream-provider policies; or
- attempts to evade security controls or enforcement imposed in response to prohibited conduct.
3. Security testing
Security research, vulnerability testing and scanning are permitted only where you own the target or have explicit authorization from the target owner, and where the activity is also allowed by the infrastructure provider and applicable law.
4. Origin and content control
Customers are responsible for ensuring that origins, applications, content and traffic they connect to the platform are authorized and lawful. Scan Shield Cloud FZCO may isolate, rate-limit, suspend or disconnect an origin, account, route or service where reasonably necessary to contain an incident or stop prohibited activity.
5. Abuse reports
Security researchers, network owners, rights holders and other third parties may submit abuse or security reports through the website contact form by selecting Abuse / security. Reports should include relevant domains, IP addresses, timestamps, request identifiers and supporting evidence where available.
6. Investigation and enforcement
We may preserve and review relevant operational and security records where reasonably necessary to investigate a report, comply with legal obligations or protect the platform. Enforcement may include warning, additional verification, rate limiting, content or route restriction, temporary suspension or termination, depending on severity and contractual rights.