Effective 2026-07-20

Use the evidence. Respect the boundary.

Permitted

  • Auditing a public website you own, operate, advise, or otherwise have a legitimate reason to assess.
  • Using a report for remediation, vendor evaluation, agency discovery, research, or interoperable software-agent workflows.
  • Sharing a reviewed, authorized report or a clearly labeled synthetic sample.

Prohibited

  • Submitting private, local, link-local, reserved, credential-bearing, or nonstandard-port targets.
  • Attempting to evade robots.txt, rate limits, target access controls, HTTP 402, or WebsiteIQ report authorization.
  • Using WebsiteIQ for denial of service, vulnerability exploitation, credential discovery, surveillance, harassment, or unlawful data collection.
  • Automating submissions in a way that exceeds published limits or disguises identity/origin.
  • Presenting heuristic scores as search-engine, legal, accessibility, security, or regulatory certifications.
  • Reselling or publishing target data in violation of law, contract, confidentiality, or the target owner’s rights.

Enforcement

WebsiteIQ may reject or stop a crawl, reduce limits, revoke report access, preserve necessary security evidence, or block clients to protect targets, users, and the service. Good-faith mistakes can be discussed through the contact form.