person Sign in play_circle Demo sell Pricing Platform Resources Blog

1.Authorization requirement

You may only submit a domain, IP range, or other asset to TUT1 if one of the following is true:

Active scanning (open-port and service fingerprinting, CVE detection) sends traffic directly to the target. Do not enable active scanning against any domain you do not own or are not explicitly authorized to test. Our Oneshot plan and Passive Enumeration capability draw only from public and third-party indexes and DNS data and never send packets to the target — but you must still have a legitimate reason to research that domain.

2.Prohibited targets

3.Prohibited uses

Regardless of authorization to scan a target, you may not use TUT1 or data obtained through it to:

4.Technical boundaries

The Service is intended to discover and report externally visible security signals within the scope you are authorized to assess. You may not use TUT1 to conduct exploitation, credential stuffing, password guessing, denial-of-service activity, payload delivery, destructive testing, evasion of controls, malware activity, social engineering, or any activity intended to alter, impair or obtain unauthorized access to a target.

Active checks, where enabled, must remain within the scope, rate and time window authorized by the asset owner. You are responsible for coordinating any required change-management, maintenance-window or third-party hosting approval before initiating a scan.

5.Sensitive security data

Credential-exposure, dark-web and phishing results may be sensitive even when they are partially masked. Access them only on a need-to-know basis, do not use exposed credentials or tokens to sign in, and do not publish or distribute raw results outside the authorized security, legal or incident-response workflow.

If a result suggests a material incident, preserve the minimum evidence necessary, follow your organization’s response process and use the contact channel below to report an issue with the Service. TUT1 does not authorize retaliation, public disclosure of personal data or testing beyond the approved scope.

6.Evidence of authorization

Before enabling active scanning or beginning manual penetration testing on a domain, we may ask you to demonstrate ownership or authorization — for example, by publishing a DNS TXT verification record, matching WHOIS/registrant information, or providing a signed authorization letter from the asset owner. We may decline or suspend scanning where authorization cannot be reasonably confirmed.

7.Consequences of violation

Violating this AUP is a material breach of our Terms of Service and may result in suspension or termination of your account without refund, in addition to any remedies available to TUT1 or third parties under applicable law. Where we reasonably believe the Service has been used for illegal activity, we may cooperate with, and disclose relevant information to, law enforcement or other competent authorities.

8.Reporting abuse

If you believe TUT1 is being used to scan or target your infrastructure without authorization, or otherwise in violation of this policy, contact contactus at tut1.io.