1. Who we are
AttackerView is operated by Valerio Baudo,
a sole proprietor (eenmanszaak) registered in the Netherlands (KVK: 000058562370).
When we say "we", "us", or "AttackerView" in these terms, that's who we mean.
2. What you're agreeing to
By creating an account, running a scan, or using any part of AttackerView, you agree to these terms.
If you don't agree, don't use the service. You must be at least 16 years old to use AttackerView.
We may update these terms from time to time - we'll notify you
of material changes via email or an in-app notice. Continued use after changes are posted
constitutes acceptance.
3. What AttackerView does
AttackerView is an automated security scanning service. It checks web apps and domains for
security misconfigurations, outdated software, known vulnerabilities, and other common security issues.
You need to understand what that means:
- Our scans inspect DNS records, TLS certificates, HTTP headers, publicly accessible pages,
email security configuration (SPF, DKIM, DMARC, MTA-STS), and DNSSEC validation.
- Scans perform technology fingerprinting to identify
what software your app runs (web servers, CMS platforms, JavaScript frameworks, WordPress
plugins and themes) and check it against known vulnerability databases including the
National Vulnerability Database (NVD) and CISA Known Exploited Vulnerabilities catalog.
- Scans include non-destructive CVE verification probes that confirm whether a known vulnerability is present. These probes are read-only: they test
whether a vulnerability exists without exploiting it or modifying any data on the target.
- Scans check for exposed files and endpoints by
requesting well-known paths (such as
/.env, /.git/HEAD, /wp-json/)
that should not be publicly accessible on a properly configured app. - Public scans (anonymous, no account required)
run the full set of security checks described above. Public scan results are displayed
publicly on
/d/[hostname].
Public scans do not perform authenticated crawling (since no credentials are provided). - Private scans (account required) run the same
security checks but results are visible only to your team. Private scans additionally
support authenticated crawling using credentials
you provide, giving deeper coverage of access-controlled areas. Paid tiers unlock additional
analyzers that detect authorization and session management issues.
- Scans may discover sensitive information that is already exposed on the target domain. We
don't create the exposure - we find it so you can fix it.
- After a scan completes, we may perform surface discovery -
querying public certificate transparency logs, DNS records, and TLS certificates to identify
related hosts and services connected to the scanned domain. This helps map your
exposure but means we may discover and store information about hosts you didn't explicitly
submit for scanning.
- AttackerView is also available as a command-line tool (CLI) for integration into your development
workflow. It connects to the same service and is subject to the same terms. Automated
scanning via CI/CD pipelines is an expected use case and is subject to the same rate limits and
authorization requirements as interactive use.
- While our scans are designed to be safe for production environments, any automated interaction
with a live app carries some inherent risk. Poorly configured servers, fragile applications,
or rate-limiting systems may react to scan traffic.
4. Authorization - this is important
You must have authorization to scan any domain you submit to AttackerView.
- For all scans (public and private): As described in Section 3, AttackerView scans include active security checks such as CVE
verification probes, exposed file detection, and technology fingerprinting. By submitting a
target, you represent that you own the domain or have explicit permission from the domain
owner to perform security testing, and that you accept responsibility for initiating the scan.
- For authenticated scans (private, with credentials): You additionally represent that you have the authority to provide the credentials used for
authenticated crawling and that the account or session you provide is authorized for testing purposes.
- For AI-powered penetration testing (any account tier, including an expired trial): See Section 6 for the elevated authorization requirements that apply to pentesting.
- You are solely responsible for ensuring you have the legal right to scan any target.
We are not responsible for any consequences of you scanning domains you don't have authorization for.
- Using AttackerView to scan targets without authorization may violate computer fraud and
abuse laws in your jurisdiction (e.g., the CFAA in the US, the Computer Misuse Act in the UK,
or equivalent laws elsewhere). That's on you, not us.
5. Continuous monitoring
Free tier monitoring
Free accounts can monitor up to 3 domains. When you add a domain to your account
(including when you sign up to monitor a domain from a public report), you authorize
AttackerView to automatically scan that domain once per week until you remove the domain
or delete your account. Free monitoring scans run the same passive checks as public scans
(no authenticated crawling).
When a weekly scan detects changes (new issues found, previously reported issues resolved),
we will send you an email summary with finding counts and a link to your report. Free
tier alert emails include finding counts only, not full finding details.
Watchtower monitoring (paid tiers)
Paid subscribers get continuous monitoring: automated scans run multiple times per day
across several cadences (frequent lightweight checks, security configuration checks, and
full deep scans). Exact scan frequencies may change as we improve the service. The current
schedule is always shown in your monitoring dashboard.
When monitoring detects changes (new vulnerabilities, fixed issues, certificate expiration warnings,
or newly discovered related hosts), we will notify you via email and/or webhooks based on your
notification preferences. Paid tier alert emails include full finding details, severity, and
evidence. You can configure alert severity thresholds, opt in or out of weekly
digest emails, and manage all notification settings in your account.
Authorization and your responsibilities
By enabling monitoring on a domain (free or paid), you authorize AttackerView to automatically
rescan that domain on an ongoing basis until you remove the domain, disable monitoring,
or cancel your subscription.
You are responsible for ensuring you maintain authorization to scan all monitored domains for
the entire monitoring period. If your authorization is revoked, you must remove the domain
from your account immediately.
Scan priority
When our systems are under load, scans from paid subscribers are processed before free
tier scans, which are processed before anonymous public scans. This means paid monitoring
scans will always run on schedule. Free and public scans may be delayed during periods
of high demand.
Pentesting is always manual
Monitoring does not automatically run penetration tests. AI-powered pentesting (any account tier,
including an expired trial; see Section 6) must be explicitly triggered by you for each domain and is never initiated
automatically by the monitoring system.
6. AI-powered security testing
Any account, including an expired trial, can run a prepared one-off AI penetration test on a domain. This is
substantially different from standard scanning and you need to understand what it involves.
How it works
Our pentesting feature uses an AI agent that autonomously probes your application for security
vulnerabilities. Unlike our regular scans (which run a fixed set of checks), the AI agent
makes its own decisions about what to test, what tools to use, and how to chain findings
together. It operates within an isolated container with strict scope boundaries.
What the AI agent can do
- Send HTTP requests to your application, including crafted payloads designed to trigger vulnerabilities.
- Use security testing tools including SQL injection testing, parameter fuzzing, vulnerability scanners, and browser automation.
- Attempt to exploit discovered vulnerabilities to confirm they are real.
- Chain multiple findings together to discover complex attack paths.
Scope enforcement
The AI agent is restricted to only target the domains you explicitly authorize for pentesting.
Network-level controls (proxy allowlisting) prevent the agent from making requests to any
other destination. However, like any automated system, scope enforcement relies on technical
controls that could theoretically fail. By enabling pentesting on a domain, you accept this
residual risk.
Authorization - elevated requirements
Because AI pentesting is significantly more aggressive than standard scanning, you must ensure:
- You own the target domain or have explicit, written authorization
from the owner specifically for penetration testing - not just vulnerability scanning.
- Your hosting provider and any relevant WAF/CDN providers permit automated penetration testing.
- You have notified relevant stakeholders that automated pentesting will occur.
- The target environment can tolerate aggressive testing. We recommend against running pentests
on fragile production systems without safeguards.
AI limitations
The AI agent is not infallible. It may:
- Miss vulnerabilities that a human pentester would find.
- Produce false positives (report issues that don't actually exist).
- Make unexpected decisions within its authorized scope.
- Generate significantly more traffic than standard scans.
Pentest findings are reported with a confidence level ("verified" or "behavioral") that
indicates how strongly the evidence supports the finding. See Section 12 for details on
confidence levels. We recommend treating "behavioral" findings as leads that warrant
manual verification.
We do not guarantee that AI pentesting results are complete, accurate, or equivalent to a
manual penetration test by a qualified security professional.
Pentest data
AI pentesting generates additional data beyond standard scans, including a per-run report,
test transcripts, HTTP traffic recordings, and cross-session observations about your application.
The per-run report remains after a trial or subscription ends and is removed when you delete
that domain or your account. Transcripts, HAR recordings, and live events follow the separate
periods in our Privacy Policy.
7. Acceptable use
You agree not to:
- Use AttackerView to attack, exploit, or harm any system or person.
- Use scan results to conduct unauthorized access, data theft, or any malicious activity.
- Attempt to overwhelm or disrupt target systems through excessive scanning.
- Resell, redistribute, or commercially exploit scan results without our permission.
- Use the service in any way that violates applicable laws or regulations.
- Reverse-engineer, decompile, or attempt to extract the source code of AttackerView.
- Create accounts using false or misleading information.
- Circumvent rate limits, tier restrictions, or other usage controls.
- Use API keys or webhook endpoints to build a competing service using our scan data.
- Share API keys with unauthorized third parties.
We reserve the right to suspend or terminate your account immediately if we believe you are
violating these terms. We don't need to give you advance notice if we believe there's an
urgent safety or legal concern.
8. Accounts, authentication, and multi-tenancy
You sign in via GitHub or Google OAuth. We don't store passwords. You're responsible for
maintaining the security of your OAuth accounts. If someone gains access to your account
through your OAuth provider, that's not something we can control.
Multi-tenancy: If you sign in with a corporate email
address (e.g., [email protected]), your account is placed in a shared organizational tenant
with other users from the same email domain. All team members in a shared tenant can see all
domains, scans, findings, and settings within that tenant. If you sign in with a personal
email (Gmail, Yahoo, etc.), you get a private tenant visible only to you.
If you provide authentication credentials for scanning (e.g., login details for authenticated
crawling), those credentials are encrypted at rest using AES-256-GCM. You are responsible for
ensuring any credentials you provide are appropriate for testing purposes - don't give us
production admin credentials unless you understand what the scan will do with them.
9. API access, CLI, and webhooks
Paid tiers can generate API keys for programmatic
access to scan data via our API. API keys are:
- Hashed before storage (we cannot retrieve your full key after creation - store it securely).
- Rate-limited on a daily basis. Exceeding rate limits will result in temporary rejection of requests.
- Subject to the same acceptable use restrictions as interactive access.
- Your responsibility to keep secure. Treat API keys like passwords.
Our CLI tool is an additional access method for the same API. It authenticates using the same API keys
and is subject to the same rate limits, acceptable use restrictions, and terms as direct API access.
Output files generated by the CLI are your data, subject to the same
intellectual property terms in Section 16.
Paid tiers can also configure webhook endpoints to
receive scan results, alerts, and monitoring updates at a URL you specify. Webhook payloads
are signed with HMAC-SHA256 so you can verify they came from us. We support both standard
JSON payloads and Slack-formatted messages.
You are responsible for the security and availability of your webhook endpoint. We will
retry failed deliveries with exponential backoff, but persistently failing endpoints may
be paused.
10. Third-party integrations
AttackerView supports integrations with third-party compliance platforms (currently Vanta and Drata).
When you enable an integration:
- You authorize AttackerView to send vulnerability finding data (title, severity, description,
remediation guidance, and target URL) to the connected platform.
- Integration credentials (OAuth tokens or API keys) are encrypted at rest using AES-256-GCM.
- We do not send raw HTTP traffic, stored scan credentials, or personal data to integration
partners. Only structured finding metadata is transmitted.
- Your use of third-party platforms is subject to their own terms of service and privacy policies.
We are not responsible for how those platforms handle data after we deliver it.
- You can disconnect an integration at any time. Disconnecting stops future data transmission
but does not delete data already sent to the third-party platform.
11. Compliance reports and evidence
AttackerView can generate compliance evidence reports that map scan findings to security
controls in frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA.
These reports are informational evidence for your compliance
programs. They are not audit opinions, certifications, or attestations. AttackerView is a tool for assisting with security and compliance - it does not replace
qualified auditors, penetration testers, or compliance assessors. The compliance mappings
represent our assessment of which security controls each check relates to, but your auditor
makes the final determination of whether a control is satisfied.
We periodically update our compliance mappings as frameworks are revised. Mapping accuracy
is provided on a best-effort basis.
12. Artificial intelligence transparency
AttackerView uses artificial intelligence in two distinct ways:
- Deterministic analysis: Our standard scanning
uses rule-based checks (not AI/ML) to detect security issues. These produce consistent,
reproducible results.
- AI-powered pentesting (any account tier, including an expired trial): Our
penetration testing feature uses a large language model (LLM) to autonomously test your
application. The AI makes decisions about what to test and how, within the scope you
authorize.
Finding confidence levels
AI pentesting findings are reported with a confidence level:
- Verified: The finding has concrete,
reproducible proof backed by actual HTTP traffic evidence.
- Behavioral: The evidence is consistent
with exploitation but lacks definitive proof. We recommend you verify these manually.
Findings that cannot be corroborated by any evidence are not reported. Our validation
process uses a combination of automated analysis and, in some cases, AI-assisted review
(via third-party AI models, used under Do Not Train terms) to determine confidence levels.
We do not use AI to make decisions about your account, billing, access, or any other
aspect of the service beyond security testing. We do not use your data to train AI models.
13. Paid subscriptions, billing, and credits
AttackerView offers free and paid tiers. Paid subscriptions are billed monthly or annually via Stripe. By subscribing to a paid plan, you also agree
to Stripe's terms.
- Paid subscriptions are billed immediately upon checkout. We offer a 30-day money-back guarantee on your first payment.
- Subscriptions renew automatically at the end of each billing period.
- You can cancel at any time. Cancellation takes effect at the end of the current billing period - you retain access until then.
- When a paid subscription ends, features that require a paid tier (continuous monitoring, webhooks, API access, integrations) are paused or disabled. Your data is not deleted. One-off prepared AI pentests remain available, including on an expired trial. Per-run pentest reports remain until you delete the domain or the account. Buying a pentest does not enable webhooks.
- We may change pricing with 30 days' notice. Price changes apply to the next billing cycle after the notice period.
Pentest credits
Any account, including an expired trial, can buy pentest credits at €10 plus applicable VAT
per selected HTTP method and canonical route. GET and POST on the same route are two credits.
IDs and query values do not add credits. Hunter tier subscribers also receive 20 pentest
credits every month. Credits included with Hunter are used before bought credits.
The scope is prepared and validated before purchase. You pay for that selected base, up front
or from credits already on the account. Optional extra credits for genuinely new additions
are off unless you add them. They are capped, paid up front or covered by your purchased balance,
and unused extras stay on the account. They are not charged only if used, and they are not a cash refund.
- Credits included with Hunter are allocated at the start of each subscription month (counted from the day your subscription started), on monthly and annual plans alike, and expire when that subscription month ends. Unused included credits do not roll over.
- Bought credits do not expire. They stay on your account on any tier, including an expired trial.
- If a run is blocked before it starts, its units are restored. If you stop it, units that never started are restored. If it fails on our side, units that did not finish are restored. A completed run restores only units that were not tested. Units already tested are not restored, including when a tested unit found nothing. Optional extras that were not tested are restored. An extra that reached tested is spent. Included monthly credits are restored only while that month is still open. Restoration is not a cash refund.
- Credits are non-transferable and have no cash value.
- If you downgrade from Hunter, you stop receiving included credits. The current subscription month's included credits expire when that month ends.
- Cancelling a subscription or leaving Watchtower does not disable one-off pentests, does not delete bought credits, and does not delete per-run reports. Webhooks and other paid-plan features still follow the subscription. Buying credits does not enable webhooks.
For refund details, see our Refund Policy.
14. Public scan results
When a public scan is performed (whether by you or another user), the results are
displayed publicly on AttackerView at /d/[hostname].
Public scans run the full set of security checks described in Section 3, including CVE
verification and exposed file detection. The only difference from private scans is that
public scans do not perform authenticated crawling (no credentials are provided) and
results are publicly visible.
If you are the owner of a domain that has been publicly scanned and you want the results removed,
you can submit a report using the "Report abuse" link on the domain's public page, or contact
us at [email protected].
We have a takedown process for domain owners who can verify ownership.
15. Abuse reports and complaints
Anyone can submit an abuse report for publicly displayed scan results. Abuse reports
are reviewed by our team and may result in content removal (takedown) if the report is valid.
Abuse reports are rate-limited to prevent misuse. We store the reporter's IP address and
optional email address for the purpose of processing the report and preventing abuse of
the reporting system. We will not use this information for any other purpose.
For takedown requests, abuse complaints, or any other concerns about scan results displayed
on AttackerView, contact us at [email protected].
16. Findings and risk acceptance
When our scans detect security issues, they are tracked as findings in your account. Findings persist across scans - if an issue is found, then fixed, then reappears,
we track that history. You can mark findings as "accepted" if you've decided the risk is
acceptable for your situation.
Accepting a finding risk is your decision and your responsibility. Accepted findings still
appear in your dashboard and reports - they are not hidden. Acceptance does not constitute
our endorsement that the risk is acceptable.
17. Intellectual property
- Our stuff: The AttackerView platform, its code, design,
analysis methods, attack chain definitions, compliance mappings, and all related intellectual
property belong to us.
- Your data: You own your scan data. We don't claim
ownership of the results of your scans. However, you grant us a license to process, store,
and display your data as necessary to provide the service, including transmitting finding
data to third-party integrations you have configured.
- Aggregated data: We may use anonymized, aggregated
data (e.g., "X% of scanned domains have misconfigured CORS") for research, product improvement,
and marketing. This data cannot be traced back to you or any specific domain.
18. Disclaimer of warranties
AttackerView is provided "as is" and "as available", without warranties of any kind,
whether express or implied. We specifically disclaim all implied warranties of
merchantability, fitness for a particular purpose, and non-infringement.
We do our best to make the service reliable and the scans safe, but:
- We do not guarantee that scans will find every vulnerability. Security is complex, and no
automated tool catches everything.
- We do not guarantee that scans won't cause issues with the target app. While our scans
are designed to be non-destructive, some applications may react unpredictably to automated
HTTP traffic. If your app goes down because it can't handle a few extra requests, that's
a problem with your app's resilience, not with our scanner.
- AI-powered pentesting (Section 6) is significantly more aggressive than standard scanning.
While scope enforcement limits the AI agent to authorized targets, the AI may make
unexpected decisions and generate substantial traffic. We do not guarantee that pentesting
will not cause service disruption on the target.
- We do not guarantee that the service will be uninterrupted, error-free, or available
at all times.
- Scan results are informational only. You are responsible for deciding what to do with them.
We are not liable for actions taken (or not taken) based on scan findings.
- Compliance evidence reports map findings to framework controls on a best-effort basis.
They are not audit opinions and should not be relied upon as such.
- CVE verification probes confirm the presence of known vulnerabilities based on publicly
available information. False positives and false negatives can occur.
- Webhook deliveries, email notifications, and third-party integration pushes are provided
on a best-effort basis. We do not guarantee delivery timing or availability of third-party services.
19. Limitation of liability
- We are not responsible for any losses, damages, or costs arising from your use of the service,
including but not limited to: downtime on scanned targets, data disclosed in scan results,
or actions taken (or not taken) based on scan findings.
- We are not liable for any indirect, incidental, special, consequential, or punitive damages,
regardless of the cause or theory of liability.
- Our total liability for any claim related to the service is limited to the amount you paid
us in the 12 months before the claim arose, or EUR 100, whichever is greater.
- We are not liable for the actions of third-party services you connect to AttackerView
(including Vanta, Drata, Stripe, Slack, or any webhook endpoint), or for data loss or
exposure that occurs after data leaves our platform.
- We are not liable for damage caused by AI-powered pentesting to target systems that you
authorized for testing. You accepted the risks described in Section 6 when you enabled
pentesting on a domain.
Nothing in these terms limits liability for fraud, gross negligence, or anything that
cannot be limited by applicable law.
20. Indemnification
You agree to indemnify and hold us harmless from any claims, damages, losses, or expenses
(including reasonable legal fees) arising from:
- Your use of the service.
- Your violation of these terms.
- Your scanning of targets you weren't authorized to scan.
- Your use of AI-powered pentesting on targets, including any damage to target systems.
- Any third-party claims related to your use of scan results.
- Data you transmit to third-party services via integrations or webhooks you configured.
21. Service availability
We aim for high availability, but we don't guarantee uptime. We may need to take the
service offline for maintenance, updates, or in response to security incidents. We'll
try to give advance notice when possible, but sometimes things break unexpectedly.
22. Account deletion
You can request deletion of your account at any time through your account settings.
Account deletion works as follows:
- After you submit a deletion request, there is a 90-day
retention period during which your account remains active. This gives you time
to change your mind.
- You can cancel a pending deletion request at any time during the retention period.
- After the 90-day period, your account and all associated data (domains, scans, findings,
credentials, integrations, webhooks, API keys) are permanently deleted.
- If you are the sole user in a tenant, the entire tenant and all its data are deleted. If
other users remain in your tenant, your personal data is removed and ownership of shared
resources (domains, scans) is reassigned to another tenant member.
- Active subscriptions should be cancelled separately via Stripe before requesting deletion.
23. Termination
- By you: You can close your account at any time
via the account deletion process described in Section 22.
Active subscriptions can be cancelled and will run until the end of the billing period.
- By us: We can suspend or terminate your account
if you violate these terms, if we're required to by law, or if we discontinue the service.
We'll try to give reasonable notice except in cases of urgent safety or legal concerns.
- Effect of termination: Upon termination, your right
to use the service ends. API keys are revoked, webhooks are disabled, integrations are
disconnected, monitoring schedules are stopped, and remaining pentest credits are forfeit
because the account is closed. Ending a subscription does not forfeit bought credits or
delete per-run pentest reports.
We may delete your data after a reasonable period (typically 30 days, or 90 days for
user-initiated deletion). Provisions that should survive termination (like limitation
of liability and indemnification) will survive.
24. Governing law and disputes
These terms are governed by the laws of the Netherlands, without regard to conflict-of-law principles.
For any dispute arising from these terms or your use of AttackerView, we both agree to first
attempt resolution through good-faith negotiation. If we can't resolve it within 30 days,
either party may pursue binding resolution.
- For disputes involving amounts under EUR 25,000, disputes will be resolved through
binding arbitration administered under the rules of the Netherlands Arbitration Institute (NAI),
conducted in English, with a single arbitrator. The arbitrator's decision is final and
enforceable in any court of competent jurisdiction.
- For disputes involving amounts over EUR 25,000, or where injunctive relief is sought,
the courts of Amsterdam, the Netherlands, have exclusive jurisdiction.
Regardless of the above:
- If you are an EU/EEA consumer, nothing in these terms limits your mandatory consumer
protection rights under the laws of your country of residence, including your right to
bring proceedings in the courts of your habitual residence.
- If you are a California resident, you retain all rights under the California Consumer
Privacy Act (CCPA) regardless of this choice of law.
- Either party may seek injunctive or equitable relief in any court of competent jurisdiction
to protect intellectual property rights or prevent imminent harm.
Class action waiver: To the fullest extent permitted
by applicable law, you agree that any dispute resolution will be conducted on an individual
basis, not as a class action or representative proceeding.
25. General provisions
- Severability: If any provision of these terms is found
to be unenforceable, the remaining provisions remain in full effect.
- Entire agreement: These terms, together with our Privacy Policy and Refund Policy, constitute the
entire agreement between you and us regarding AttackerView.
- No waiver: Our failure to enforce any right or
provision of these terms doesn't constitute a waiver of that right or provision.
- Assignment: We may assign our rights and obligations
under these terms (e.g., in connection with a merger or acquisition). You may not assign
yours without our written consent.
- Force majeure: We are not liable for delays or
failures caused by events beyond our reasonable control, including natural disasters,
internet outages, third-party service failures, or government actions.