person Sign in play_circle Demo sell Pricing

1.Authorization requirement

You may only submit a domain, IP range, or other asset to TUT1 if one of the following is true:

Active scanning (open-port and service fingerprinting, CVE detection) sends traffic directly to the target. Do not enable active scanning against any domain you do not own or are not explicitly authorized to test. Our Oneshot plan and Passive Enumeration capability draw only from public and third-party indexes and DNS data and never send packets to the target — but you must still have a legitimate reason to research that domain.

2.Prohibited targets

3.Prohibited uses

Regardless of authorization to scan a target, you may not use TUT1 or data obtained through it to:

4.Evidence of authorization

Before enabling active scanning or beginning manual penetration testing on a domain, we may ask you to demonstrate ownership or authorization — for example, by publishing a DNS TXT verification record, matching WHOIS/registrant information, or providing a signed authorization letter from the asset owner. We may decline or suspend scanning where authorization cannot be reasonably confirmed.

5.Consequences of violation

Violating this AUP is a material breach of our Terms of Service and may result in suspension or termination of your account without refund, in addition to any remedies available to TUT1 or third parties under applicable law. Where we reasonably believe the Service has been used for illegal activity, we may cooperate with, and disclose relevant information to, law enforcement or other competent authorities.

6.Reporting abuse

If you believe TUT1 is being used to scan or target your infrastructure without authorization, or otherwise in violation of this policy, contact contactus at tut1.io.