Skip to content

Terms of Service

The agreement under which SiteGuardia Free is offered.

Version 2026-09-22Updated 2026-09-22

This is a working draft. It describes the system as built and has not yet been reviewed by a qualified lawyer.

This document is a working draft. It has not been reviewed by a qualified lawyer and will be before SiteGuardia operates commercially. Nothing here is legal advice.

The operator

The legal entity operating SiteGuardia, its registered address and the governing law and jurisdiction are not yet established. This section will name them before the service is offered commercially. Until then SiteGuardia is offered as a technical preview.

Who may use the service

You must be old enough to enter a binding agreement where you live. If you use SiteGuardia for an organisation, you confirm you are authorised to accept these terms for it.

What the service is

SiteGuardia Free runs automated, non-destructive checks against publicly observable properties of a website and returns a temporary report. It is a measurement of a public surface. It is not a penetration test, a security audit, a certification, or a compliance assessment, and it must not be described as any of those.

The precise boundary of what runs is set out in the Responsible Scanning Policy, which forms part of these terms.

Your obligations

For every target you submit, one of these must be true and you confirm which before each check:

  • you own the domain and the site it serves; or
  • the person or organisation that does has expressly authorised you to have the checks described on this page run against it.

Nothing else. This clause used to end with "or another lawful basis for doing so", which asked you to reach a legal conclusion about your own conduct and then accepted it. A confirmation that cannot be false is not a confirmation.

Owning a website is not the same as being able to authorise everything these checks touch. The checks read your domain's DNS records, negotiate TLS with whatever server answers for it, and request pages from that server. If your site is on shared hosting, behind a CDN, or served by a platform, those are somebody else's systems answering for your name. Your own contract with them governs what you may have tested against them, and it is your responsibility to know that. The scope here is narrow and non-destructive by design, which makes this unlikely to be a problem in practice and does not make it your provider's decision to skip.

You must not:

  • use SiteGuardia against systems you neither own nor have express authorisation to assess;
  • use results to attack, disrupt, or gain unauthorised access to any system;
  • use the service to harass, intimidate or pressure any person or organisation;
  • automate checks at scale, or attempt to circumvent the daily limits or abuse controls;
  • attempt to interfere with, overload, reverse engineer or gain unauthorised access to SiteGuardia itself, except as permitted by our vulnerability disclosure policy;
  • present a SiteGuardia report as a penetration test, audit or certification.

Our rights

We may refuse, cancel, throttle or block any check, target or visitor, at any time and without notice, where we believe the service is being misused, where a target falls in a category we do not accept, or where we are required to.

Intellectual property and open source

SiteGuardia orchestrates open-source tools, each under its own licence. Those licences are acknowledged in our third-party notices, which are published and kept current. In particular, testssl.sh is licensed under GPL-2.0 and is invoked as a separate process; it is not incorporated into SiteGuardia code.

The report we generate is yours to use. The SiteGuardia name, the interface, the scoring method and the editorial catalog remain ours.

No warranty

The service is provided as is and as available, to the fullest extent the applicable law allows.

We do not warrant that a check will find every issue, or any issue. A report with no findings does not mean a site is secure, has no vulnerabilities, or would withstand an attack. Automated checks observe a subset of a subset. A finding described as inferred or as a version-based hypothesis has not been confirmed, and we do not attempt to confirm it.

We do not warrant that the service will be available, uninterrupted or error free.

Limitation of liability

To the fullest extent the applicable law allows, we are not liable for indirect, incidental, special, consequential or punitive damages, nor for lost profits, revenue, data or goodwill, arising from your use of the service or from reliance on a report.

Nothing in these terms excludes liability that cannot lawfully be excluded, including liability for death or personal injury caused by negligence, or for fraud. The final wording of this section is subject to legal review.

Availability and changes to the service

The service may change, be suspended, or be withdrawn. Reports expire after 48 hours by design; we do not undertake to retain them beyond that, and you should save anything you need before then.

Where these terms apply

SiteGuardia is offered without payment. That is not an exemption from anything.

The GDPR's territorial scope reaches the offering of goods or services to people in the Union whether or not a payment is required, so "it is free" does not put this service outside it, and neither would calling it a preview or a technical demonstration. We assume the obligations rather than argue about them.

Which other regimes apply is a question of facts that are not settled yet, and this page will not pretend otherwise. Where the operator is established, where the infrastructure sits, which markets are actively offered to and what volumes are involved all change the answer, and none of them is decided. A per-market assessment covering the EEA, the United Kingdom, the United States and the Latin American markets in the launch plan is being prepared and a qualified lawyer will review it before SiteGuardia is offered publicly.

Two specific things we will not do in the meantime. We will not claim every privacy law applies automatically, because several have thresholds: the CCPA, for instance, applies to businesses meeting revenue, volume or data-sale criteria, and a service with no customers meets none of them. And we will not claim the opposite either, because a threshold not met today is not a threshold that stays unmet.

Changes to these terms

These terms are versioned. The version in force when a check runs is recorded with that check, and you accept the current version each time you start one. Material changes will be published here with a new version and date.

Notices

Contact details for legal notices will be published with the operator details. Contact for security and abuse matters is at /.well-known/security.txt.