ScanHawk

Terms of Service Acceptable Use Policy Privacy Policy

Acceptable Use Policy

Version 1.0.0 · Effective August 19, 2026 · Last updated August 19, 2026

The short version. Use ScanHawk to protect yourself and the people you look after. Do not use it to attack anyone, to check whether your own scam gets past our detection, to submit other people’s private information, or to strip-mine the engine for a product of your own. Break these rules and we can throttle, suspend, or ban your access. This summary is for convenience only and is not part of the policy.

Contents

  1. Scope
  2. General obligations
  3. Prohibited conduct
  4. Fair use, rate limits, and automation
  5. Security research
  6. Reporting abuse
  7. Enforcement
  8. Changes to this policy

1. Scope

This Acceptable Use Policy (the “Policy”) governs your use of ScanHawk — the mobile app, web app, browser extension, Outlook add-in, website, engine, and API (the “Service”) — and is incorporated into the Terms of Service. Capitalised terms not defined here have the meaning given in the Terms. Violating this Policy is a breach of the Terms.

This Policy applies to everyone: consumers using the free app, developers calling the API, and organisations deploying ScanHawk internally. If you give others access to the Service under your API key or deployment, you are responsible for their compliance.

2. General obligations

You must:

3. Prohibited conduct

3.1 Unlawful and harmful use

Do not use the Service to plan, carry out, support, or conceal any illegal activity, or to facilitate fraud, phishing, extortion, harassment, stalking, human trafficking, child sexual abuse material, or the distribution of malware. Do not use the Service to threaten, defame, or intimidate any person or organisation.

3.2 Evasion testing

You must not use the Service to determine whether malicious content you control, or content you are helping someone else deploy, evades detection.

This includes submitting your own phishing pages, malware droppers, scam landing pages, fraudulent QR codes, look-alike domains, or redirect chains in order to measure, tune, or confirm that ScanHawk does not flag them — whether by hand, in bulk, or programmatically, and whether or not the content is currently deployed against victims. It also includes probing the Service to discover its thresholds, heuristics, model behaviour, or blind spots for the purpose of building content that avoids them.

Attackers testing their own payloads against a detection product is the most damaging misuse of a service like this, and we treat it as grounds for immediate and permanent termination without notice, and for referral to law enforcement.

3.3 Attacking others

Do not use the Service, or information obtained through it, to:

3.4 Attacking the Service

Do not attempt to gain unauthorised access to the Service, its infrastructure, other users’ data, or any account or key that is not yours. Do not attempt to disrupt, overload, or degrade the Service. Do not introduce malware into it, bypass authentication or rate limits, or exploit a vulnerability beyond the minimum needed to demonstrate it (see §5).

3.5 Privacy and other people’s data

Do not submit Content containing another person’s personal information, credentials, authentication tokens, health or financial records, or confidential business information. Be careful with links that carry secrets in the URL — password-reset links, magic sign-in links, single-use invitation links, and document-sharing links commonly embed a token that grants access to whoever holds it. Submitting such a link sends that token to us and to our processors.

Do not use the Service to build a profile of, surveil, or track any individual.

3.6 Misrepresenting verdicts

Do not misstate, fabricate, or selectively present a Verdict. Specifically, do not:

3.7 Extraction and competitive use

Do not scrape the Service, harvest Verdicts in bulk, or systematically extract the Threat Feed. Do not use the Service or its outputs to train, fine-tune, evaluate, or benchmark a competing detection product, or to reconstruct our detection logic, prompts, scoring, or thresholds. Do not resell or redistribute Verdicts without a written agreement with us.

3.8 Circumvention

Do not evade or attempt to evade any limit, block, suspension, or ban — including by reinstalling to obtain a fresh installation identifier, rotating IP addresses or devices to defeat rate limits, registering additional API keys after a suspension, or using another person’s access.

4. Fair use, rate limits, and automation

The consumer app is intended for ordinary personal use. The API is intended for the volumes covered by your plan. We apply rate limits and quotas to keep the Service available for everyone; treat a 429 response as a signal to back off, not an obstacle to route around.

Automated access is permitted only through the documented API, using a key we issued to you. Do not automate the consumer app, drive the client applications with a script or emulator, or extract and reuse the credentials embedded in a client.

If your legitimate use needs more capacity, ask us at support@twentypin.com rather than working around the limit — we would rather raise it than ban you.

5. Security research

We welcome good-faith security research. If you believe you have found a vulnerability, report it to security@twentypin.com before disclosing it publicly, and give us a reasonable opportunity to fix it.

While researching, stay within these limits: do not access, modify, or delete data belonging to anyone else; do not degrade the Service for other users; do not run automated scanning at volumes that amount to a denial of service; and stop as soon as you have confirmed the issue. Research conducted within these limits and reported to us will not be treated as a violation of this Policy, and we will not pursue action over it.

6. Reporting abuse

To report misuse of the Service, a false or damaging Verdict about a site you operate, or content in the Threat Feed you believe is wrong, email abuse@twentypin.com with the URL in question and a short description. Site operators who believe their domain has been misclassified may request a review, and we will re-evaluate it.

7. Enforcement

When we believe this Policy has been violated we may, at our discretion and in proportion to the conduct:

Where the violation is minor and the circumstances allow, we will normally warn you first and give you a chance to correct it. For conduct under §3.1, §3.2, §3.3, or §3.4 we may act immediately and without notice. We are not obliged to monitor use of the Service, and our failure to act on a violation does not waive our right to act on it later.

8. Changes to this policy

We may update this Policy as the Service and the threat landscape change. The version number and date at the top of this page will change with it. Material changes are presented in the app for your renewed agreement in the same way as a material change to the Terms of Service (see Terms §19).