Legal

Acceptable Use Policy

Rules for safe, authorised and lawful use of ThreatCanary capabilities.

Deterministic evidenceScope-aware executionAdaptive capability
What this covers

Acceptable Use Policy: clear expectations for safe operation.

Plain-language policy content for customers, users, partners and researchers.

01

Allowed use

  • Use ThreatCanary to discover, assess, validate and manage security risk for assets and APIs you are authorised to test.
  • Use platform outputs to improve remediation, reporting, assurance, incident response and defensive readiness.
  • Run offensive or adaptive workflows only within approved scope and configured safety limits.
02

Prohibited use

  • Do not scan, test, exploit, disrupt or access systems without permission.
  • Do not use ThreatCanary to steal data, maintain unauthorised access, evade law enforcement or harm third parties.
  • Do not disable safety controls, falsify scope, misuse credentials or attempt to exfiltrate customer data.
03

Safety requirements

  • Respect rate limits, testing windows, exclusions and production-safety settings.
  • Use human approval for sensitive testing, generated tools or workflows that could affect availability or data.
  • Escalate accidental out-of-scope activity immediately so it can be contained and reviewed.
04

Enforcement

  • ThreatCanary may suspend or restrict access where unsafe, unlawful or unauthorised activity is suspected.
  • Customers should maintain internal approvals and audit records for their use of the platform.
  • Questions about safe use should be directed to ThreatCanary before testing begins.

See ThreatCanary in action

Stop counting vulnerabilities. Start proving compromise paths.

Book a technical demo