DRAFT — requires legal review. Not yet in effect.
Responsible Use
Last updated: TODO: date
Scan only what you are allowed to scan
You may scan only sites you own or are authorized to test. Scanning someone else's site without permission may be illegal, including under India's Information Technology Act, 2000.
How our checks are designed
- Read-only. We never write, modify or delete anything on your site or database.
- Surface checks look at what any visitor's browser can already see.
- Database and route checks run only after you prove you own the site.
- We never download real user data. At most we confirm that something is exposed.
What is not allowed
- Scanning sites you do not own or have permission to test.
- Scanning government, banking or critical infrastructure sites.
- Using findings to access, copy or damage another party's data.
- Automating requests to bypass our rate limits.
Reporting misuse or a vulnerability
If you believe VibeSecurity is being misused, or you found a security issue in our own site, contact TODO@example.com. TODO: add disclosure timelines and safe-harbor wording after legal review.