Terms of Service & Scanning Warranty
Please read these terms carefully before enrolling assets in SubdomainWatch. Continuous attack surface surveillance requires verifiable authorization.
These terms serve as the standard operational legal baseline for SubdomainWatch. Enterprise customers requiring customized Master Services Agreements (MSAs), bespoke Data Processing Agreements (DPAs), or dedicated liability caps should contact legal@subdomainwatch.com.
1. Nature of the Surveillance Service
SubdomainWatch provides automated external perimeter attack surface management (EASM). The service inspects publicly discoverable domain name system (DNS) records, Certificate Transparency (CT) logs, RFC 7208 SPF records, RFC 7489 DMARC configurations, and validates dangling CNAME targets via non-destructive, RFC-compliant HTTP probes.
SubdomainWatch does NOT perform invasive exploitation, buffer overflows, credential brute-forcing, denial-of-service, or active penetration attacks.
2. Mandatory Domain Ownership & Scanning Authorization Warranty
By enrolling any domain name or asset into SubdomainWatch, you explicitly represent, warrant, and covenant that:
- You are the registered owner of the apex domain name, or an authorized officer or IT administrator acting with express written permission.
- You possess full legal authority to subject the domain and its associated subdomains to automated DNS queries and HTTP response fingerprinting.
- Your enrollment of the domain does not violate the UK Computer Misuse Act 1990 (Sections 1 & 3), the United States Computer Fraud and Abuse Act (18 U.S.C. § 1030), the German Criminal Code (§ 202a StGB), or any applicable regional or international cybercrime statute.
Enrolling assets without legitimate authorization constitutes a material breach of this Agreement and may lead to immediate termination of service, account forfeiture, and referral to relevant cybercrime authorities.
3. Indemnification & Hold Harmless
You agree to defend, indemnify, and hold harmless SubdomainWatch, its operators, directors, and infrastructure providers from and against any claims, liabilities, damages, losses, costs, or expenses (including reasonable legal fees) arising out of or relating to:
- Your enrollment of any domain or digital asset for which you lacked proper authorization;
- Any third-party claim that surveillance activities initiated at your request violated their terms or rights;
- Your breach of any representation, warranty, or acceptable use provision in this Agreement.
4. Acceptable Use Policy
You agree NOT to use SubdomainWatch to:
- Probe critical national infrastructure, military installations, or emergency medical facilities without documented governmental mandate;
- Attempt to reverse engineer, decompile, or extract the proprietary 42-provider takeover signature database;
- Use public diagnostic tools (including the SPF 10-Lookup Counter) to conduct distributed denial-of-service (DDoS) reflection attacks;
- Bypass rate limits, multi-tenant quota controls, or stored procedure access controls.
5. Commercial Pricing, Billing & Cancellation
SubdomainWatch is billed in advance on a month-to-month subscription basis in Great Britain Pounds (£ GBP), Euros (€ EUR), or US Dollars ($ USD) based on your billing jurisdiction.
You may cancel your subscription at any time directly through the Defense Console. Cancellation takes effect at the conclusion of your current billing period. No refunds are issued for partial billing months.
6. Governing Law & Jurisdiction
This Agreement and any dispute arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim.