Policy draft

Acceptable use

CertificateScan is for lawful security research, defensive investigation, and administration of systems you are authorized to assess.

Permitted use

You may search public certificate evidence, investigate public infrastructure, monitor assets, and integrate the API into defensive workflows subject to plan limits.

Prohibited use

Active observations

Active observation is limited to conservative, standard TLS connections initiated by the user. CertificateScan may block destinations, reduce concurrency, or suspend access to protect third parties and the service.

Enforcement

Access may be rate-limited or suspended when activity creates security, legal, or operational risk. Production terms should be reviewed by counsel before paid launch.

Draft updated August 21, 2026