Acceptable Use Policy
This Acceptable Use Policy ("AUP") sets the rules for submitting targets to, and using data from, the TUT1 platform. It is incorporated by reference into our Terms of Service. TUT1 performs both passive reconnaissance and, on active plans, active scanning against the domains customers submit — so authorization is the foundation this Service is built on.
1.Authorization requirement
You may only submit a domain, IP range, or other asset to TUT1 if one of the following is true:
- You own the asset, or you are an employee or contractor of the organization that owns it, acting within the scope of that relationship; or
- You have obtained explicit, documented authorization from the asset's owner to have it scanned by a third-party tool such as TUT1.
2.Prohibited targets
- Domains or infrastructure you do not own and lack documented authorization to scan.
- Government, military, or critical infrastructure systems, unless you hold explicit, documented authorization from the responsible authority.
- Targets located in, or associated with, a country or entity subject to applicable trade sanctions.
3.Prohibited uses
Regardless of authorization to scan a target, you may not use TUT1 or data obtained through it to:
- Exploit, attack, or gain unauthorized access to any system beyond what is necessary to detect and report an exposure.
- Use exposed or breached credentials to log in to, or otherwise access, any account or system without independent authorization to do so.
- Harass, doxx, stalk, or otherwise target individuals identified in breach, credential, or phishing data.
- Resell, redistribute, or publish raw scan results or breach data obtained through the Service to third parties.
- Reverse engineer, scrape, or build a competing product from the Service.
- Circumvent rate limits, quotas, or other technical controls on the Service.
- Violate any applicable law, including computer misuse and data protection law in Brazil, the United States, or the jurisdiction where a target is located.
4.Evidence of authorization
Before enabling active scanning or beginning manual penetration testing on a domain, we may ask you to demonstrate ownership or authorization — for example, by publishing a DNS TXT verification record, matching WHOIS/registrant information, or providing a signed authorization letter from the asset owner. We may decline or suspend scanning where authorization cannot be reasonably confirmed.
5.Consequences of violation
Violating this AUP is a material breach of our Terms of Service and may result in suspension or termination of your account without refund, in addition to any remedies available to TUT1 or third parties under applicable law. Where we reasonably believe the Service has been used for illegal activity, we may cooperate with, and disclose relevant information to, law enforcement or other competent authorities.
6.Reporting abuse
If you believe TUT1 is being used to scan or target your infrastructure without authorization, or otherwise in violation of this policy, contact contactus at tut1.io.