Permitted
- Auditing a public website you own, operate, advise, or otherwise have a legitimate reason to assess.
- Using a report for remediation, vendor evaluation, agency discovery, research, or interoperable software-agent workflows.
- Sharing a reviewed, authorized report or a clearly labeled synthetic sample.
Prohibited
- Submitting private, local, link-local, reserved, credential-bearing, or nonstandard-port targets.
- Attempting to evade robots.txt, rate limits, target access controls, HTTP 402, or WebsiteIQ report authorization.
- Using WebsiteIQ for denial of service, vulnerability exploitation, credential discovery, surveillance, harassment, or unlawful data collection.
- Automating submissions in a way that exceeds published limits or disguises identity/origin.
- Presenting heuristic scores as search-engine, legal, accessibility, security, or regulatory certifications.
- Reselling or publishing target data in violation of law, contract, confidentiality, or the target owner’s rights.
Enforcement
WebsiteIQ may reject or stop a crawl, reduce limits, revoke report access, preserve necessary security evidence, or block clients to protect targets, users, and the service. Good-faith mistakes can be discussed through the contact form.