ScanHawk™
Terms of Service Acceptable Use Policy Privacy Policy
Acceptable Use Policy
The short version. Use ScanHawk to protect yourself and the people you look after. Do not use it to attack anyone, to check whether your own scam gets past our detection, to submit other people’s private information, or to strip-mine the engine for a product of your own. Break these rules and we can throttle, suspend, or ban your access. This summary is for convenience only and is not part of the policy.
Contents
1. Scope
This Acceptable Use Policy (the “Policy”) governs your use of ScanHawk — the mobile app, web app, browser extension, Outlook add-in, website, engine, and API (the “Service”) — and is incorporated into the Terms of Service. Capitalised terms not defined here have the meaning given in the Terms. Violating this Policy is a breach of the Terms.
This Policy applies to everyone: consumers using the free app, developers calling the API, and organisations deploying ScanHawk internally. If you give others access to the Service under your API key or deployment, you are responsible for their compliance.
2. General obligations
You must:
- use the Service lawfully, and comply with all laws that apply to you — including computer misuse, anti-hacking, privacy, data protection, export control, and sanctions law;
- submit only Content you are entitled to submit;
- keep any credentials or API keys we issue you confidential; and
- cooperate with reasonable requests from us to investigate suspected misuse.
3. Prohibited conduct
3.1 Unlawful and harmful use
Do not use the Service to plan, carry out, support, or conceal any illegal activity, or to facilitate fraud, phishing, extortion, harassment, stalking, human trafficking, child sexual abuse material, or the distribution of malware. Do not use the Service to threaten, defame, or intimidate any person or organisation.
3.2 Evasion testing
You must not use the Service to determine whether malicious content you control, or content you are helping someone else deploy, evades detection.
This includes submitting your own phishing pages, malware droppers, scam landing pages, fraudulent QR codes, look-alike domains, or redirect chains in order to measure, tune, or confirm that ScanHawk does not flag them — whether by hand, in bulk, or programmatically, and whether or not the content is currently deployed against victims. It also includes probing the Service to discover its thresholds, heuristics, model behaviour, or blind spots for the purpose of building content that avoids them.
Attackers testing their own payloads against a detection product is the most damaging misuse of a service like this, and we treat it as grounds for immediate and permanent termination without notice, and for referral to law enforcement.
3.3 Attacking others
Do not use the Service, or information obtained through it, to:
- scan, probe, enumerate, or map infrastructure you do not own or have documented written permission to test;
- use our servers as an intermediary to reach a destination you could not or should not reach yourself, including to obscure the origin of a request, to reach an internal or restricted network, or to relay attack traffic; or
- launch or contribute to a denial-of-service condition against any third party — including by submitting large volumes of URLs pointing at a single target so that our engine fetches it repeatedly.
3.4 Attacking the Service
Do not attempt to gain unauthorised access to the Service, its infrastructure, other users’ data, or any account or key that is not yours. Do not attempt to disrupt, overload, or degrade the Service. Do not introduce malware into it, bypass authentication or rate limits, or exploit a vulnerability beyond the minimum needed to demonstrate it (see §5).
3.5 Privacy and other people’s data
Do not submit Content containing another person’s personal information, credentials, authentication tokens, health or financial records, or confidential business information. Be careful with links that carry secrets in the URL — password-reset links, magic sign-in links, single-use invitation links, and document-sharing links commonly embed a token that grants access to whoever holds it. Submitting such a link sends that token to us and to our processors.
Do not use the Service to build a profile of, surveil, or track any individual.
3.6 Misrepresenting verdicts
Do not misstate, fabricate, or selectively present a Verdict. Specifically, do not:
- claim that ScanHawk has certified, approved, endorsed, or guaranteed any site, business, or link — we make no such claims, and a Safe Verdict is an absence of detected evidence, not a warranty;
- display a Verdict as though it applies to a different URL than the one checked, or present a stale Verdict as current;
- use our name, logo, or Verdicts in marketing or as a trust badge without our written permission; or
- submit deliberately false reports to the Threat Feed, whether to smear a competitor, to poison our data, or to test our moderation.
3.7 Extraction and competitive use
Do not scrape the Service, harvest Verdicts in bulk, or systematically extract the Threat Feed. Do not use the Service or its outputs to train, fine-tune, evaluate, or benchmark a competing detection product, or to reconstruct our detection logic, prompts, scoring, or thresholds. Do not resell or redistribute Verdicts without a written agreement with us.
3.8 Circumvention
Do not evade or attempt to evade any limit, block, suspension, or ban — including by reinstalling to obtain a fresh installation identifier, rotating IP addresses or devices to defeat rate limits, registering additional API keys after a suspension, or using another person’s access.
4. Fair use, rate limits, and automation
The consumer app is intended for ordinary personal use. The API is intended for the volumes
covered by your plan. We apply rate limits and quotas to keep the Service available for
everyone; treat a 429 response as a signal to back off, not an obstacle to route
around.
Automated access is permitted only through the documented API, using a key we issued to you. Do not automate the consumer app, drive the client applications with a script or emulator, or extract and reuse the credentials embedded in a client.
If your legitimate use needs more capacity, ask us at support@twentypin.com rather than working around the limit — we would rather raise it than ban you.
5. Security research
We welcome good-faith security research. If you believe you have found a vulnerability, report it to security@twentypin.com before disclosing it publicly, and give us a reasonable opportunity to fix it.
While researching, stay within these limits: do not access, modify, or delete data belonging to anyone else; do not degrade the Service for other users; do not run automated scanning at volumes that amount to a denial of service; and stop as soon as you have confirmed the issue. Research conducted within these limits and reported to us will not be treated as a violation of this Policy, and we will not pursue action over it.
6. Reporting abuse
To report misuse of the Service, a false or damaging Verdict about a site you operate, or content in the Threat Feed you believe is wrong, email abuse@twentypin.com with the URL in question and a short description. Site operators who believe their domain has been misclassified may request a review, and we will re-evaluate it.
7. Enforcement
When we believe this Policy has been violated we may, at our discretion and in proportion to the conduct:
- throttle or rate-limit the offending access;
- remove or refuse to process Content, or remove Threat Feed entries;
- suspend or permanently terminate access, keys, or a deployment;
- preserve and disclose records where required by law or where necessary to protect users or third parties; and
- refer the matter to law enforcement.
Where the violation is minor and the circumstances allow, we will normally warn you first and give you a chance to correct it. For conduct under §3.1, §3.2, §3.3, or §3.4 we may act immediately and without notice. We are not obliged to monitor use of the Service, and our failure to act on a violation does not waive our right to act on it later.
8. Changes to this policy
We may update this Policy as the Service and the threat landscape change. The version number and date at the top of this page will change with it. Material changes are presented in the app for your renewed agreement in the same way as a material change to the Terms of Service (see Terms §19).