Terms and Conditions

Last updated: September 24, 2026

1. Who we are

AttackerView is operated by Valerio Baudo, a sole proprietor (eenmanszaak) registered in the Netherlands (KVK: 000058562370). When we say "we", "us", or "AttackerView" in these terms, that's who we mean.

2. What you're agreeing to

By creating an account, running a scan, or using any part of AttackerView, you agree to these terms. If you don't agree, don't use the service. You must be at least 16 years old to use AttackerView.

We may update these terms from time to time - we'll notify you of material changes via email or an in-app notice. Continued use after changes are posted constitutes acceptance.

3. What AttackerView does

AttackerView is an automated security scanning service. It checks web apps and domains for security misconfigurations, outdated software, known vulnerabilities, and other common security issues.

You need to understand what that means:

  • Our scans inspect DNS records, TLS certificates, HTTP headers, publicly accessible pages, email security configuration (SPF, DKIM, DMARC, MTA-STS), and DNSSEC validation.
  • Scans perform technology fingerprinting to identify what software your app runs (web servers, CMS platforms, JavaScript frameworks, WordPress plugins and themes) and check it against known vulnerability databases including the National Vulnerability Database (NVD) and CISA Known Exploited Vulnerabilities catalog.
  • Scans include non-destructive CVE verification probes that confirm whether a known vulnerability is present. These probes are read-only: they test whether a vulnerability exists without exploiting it or modifying any data on the target.
  • Scans check for exposed files and endpoints by requesting well-known paths (such as /.env, /.git/HEAD, /wp-json/) that should not be publicly accessible on a properly configured app.
  • Public scans (anonymous, no account required) run the full set of security checks described above. Public scan results are displayed publicly on /d/[hostname]. Public scans do not perform authenticated crawling (since no credentials are provided).
  • Private scans (account required) run the same security checks but results are visible only to your team. Private scans additionally support authenticated crawling using credentials you provide, giving deeper coverage of access-controlled areas. Paid tiers unlock additional analyzers that detect authorization and session management issues.
  • Scans may discover sensitive information that is already exposed on the target domain. We don't create the exposure - we find it so you can fix it.
  • After a scan completes, we may perform surface discovery - querying public certificate transparency logs, DNS records, and TLS certificates to identify related hosts and services connected to the scanned domain. This helps map your exposure but means we may discover and store information about hosts you didn't explicitly submit for scanning.
  • AttackerView is also available as a command-line tool (CLI) for integration into your development workflow. It connects to the same service and is subject to the same terms. Automated scanning via CI/CD pipelines is an expected use case and is subject to the same rate limits and authorization requirements as interactive use.
  • While our scans are designed to be safe for production environments, any automated interaction with a live app carries some inherent risk. Poorly configured servers, fragile applications, or rate-limiting systems may react to scan traffic.

4. Authorization - this is important

You must have authorization to scan any domain you submit to AttackerView.

  • For all scans (public and private): As described in Section 3, AttackerView scans include active security checks such as CVE verification probes, exposed file detection, and technology fingerprinting. By submitting a target, you represent that you own the domain or have explicit permission from the domain owner to perform security testing, and that you accept responsibility for initiating the scan.
  • For authenticated scans (private, with credentials): You additionally represent that you have the authority to provide the credentials used for authenticated crawling and that the account or session you provide is authorized for testing purposes.
  • For AI-powered penetration testing (any account tier, including an expired trial): See Section 6 for the elevated authorization requirements that apply to pentesting.
  • You are solely responsible for ensuring you have the legal right to scan any target. We are not responsible for any consequences of you scanning domains you don't have authorization for.
  • Using AttackerView to scan targets without authorization may violate computer fraud and abuse laws in your jurisdiction (e.g., the CFAA in the US, the Computer Misuse Act in the UK, or equivalent laws elsewhere). That's on you, not us.

5. Continuous monitoring

Free tier monitoring

Free accounts can monitor up to 3 domains. When you add a domain to your account (including when you sign up to monitor a domain from a public report), you authorize AttackerView to automatically scan that domain once per week until you remove the domain or delete your account. Free monitoring scans run the same passive checks as public scans (no authenticated crawling).

When a weekly scan detects changes (new issues found, previously reported issues resolved), we will send you an email summary with finding counts and a link to your report. Free tier alert emails include finding counts only, not full finding details.

Watchtower monitoring (paid tiers)

Paid subscribers get continuous monitoring: automated scans run multiple times per day across several cadences (frequent lightweight checks, security configuration checks, and full deep scans). Exact scan frequencies may change as we improve the service. The current schedule is always shown in your monitoring dashboard.

When monitoring detects changes (new vulnerabilities, fixed issues, certificate expiration warnings, or newly discovered related hosts), we will notify you via email and/or webhooks based on your notification preferences. Paid tier alert emails include full finding details, severity, and evidence. You can configure alert severity thresholds, opt in or out of weekly digest emails, and manage all notification settings in your account.

Authorization and your responsibilities

By enabling monitoring on a domain (free or paid), you authorize AttackerView to automatically rescan that domain on an ongoing basis until you remove the domain, disable monitoring, or cancel your subscription.

You are responsible for ensuring you maintain authorization to scan all monitored domains for the entire monitoring period. If your authorization is revoked, you must remove the domain from your account immediately.

Scan priority

When our systems are under load, scans from paid subscribers are processed before free tier scans, which are processed before anonymous public scans. This means paid monitoring scans will always run on schedule. Free and public scans may be delayed during periods of high demand.

Pentesting is always manual

Monitoring does not automatically run penetration tests. AI-powered pentesting (any account tier, including an expired trial; see Section 6) must be explicitly triggered by you for each domain and is never initiated automatically by the monitoring system.

6. AI-powered security testing

Any account, including an expired trial, can run a prepared one-off AI penetration test on a domain. This is substantially different from standard scanning and you need to understand what it involves.

How it works

Our pentesting feature uses an AI agent that autonomously probes your application for security vulnerabilities. Unlike our regular scans (which run a fixed set of checks), the AI agent makes its own decisions about what to test, what tools to use, and how to chain findings together. It operates within an isolated container with strict scope boundaries.

What the AI agent can do

  • Send HTTP requests to your application, including crafted payloads designed to trigger vulnerabilities.
  • Use security testing tools including SQL injection testing, parameter fuzzing, vulnerability scanners, and browser automation.
  • Attempt to exploit discovered vulnerabilities to confirm they are real.
  • Chain multiple findings together to discover complex attack paths.

Scope enforcement

The AI agent is restricted to only target the domains you explicitly authorize for pentesting. Network-level controls (proxy allowlisting) prevent the agent from making requests to any other destination. However, like any automated system, scope enforcement relies on technical controls that could theoretically fail. By enabling pentesting on a domain, you accept this residual risk.

Authorization - elevated requirements

Because AI pentesting is significantly more aggressive than standard scanning, you must ensure:

  • You own the target domain or have explicit, written authorization from the owner specifically for penetration testing - not just vulnerability scanning.
  • Your hosting provider and any relevant WAF/CDN providers permit automated penetration testing.
  • You have notified relevant stakeholders that automated pentesting will occur.
  • The target environment can tolerate aggressive testing. We recommend against running pentests on fragile production systems without safeguards.

AI limitations

The AI agent is not infallible. It may:

  • Miss vulnerabilities that a human pentester would find.
  • Produce false positives (report issues that don't actually exist).
  • Make unexpected decisions within its authorized scope.
  • Generate significantly more traffic than standard scans.

Pentest findings are reported with a confidence level ("verified" or "behavioral") that indicates how strongly the evidence supports the finding. See Section 12 for details on confidence levels. We recommend treating "behavioral" findings as leads that warrant manual verification.

We do not guarantee that AI pentesting results are complete, accurate, or equivalent to a manual penetration test by a qualified security professional.

Pentest data

AI pentesting generates additional data beyond standard scans, including a per-run report, test transcripts, HTTP traffic recordings, and cross-session observations about your application. The per-run report remains after a trial or subscription ends and is removed when you delete that domain or your account. Transcripts, HAR recordings, and live events follow the separate periods in our Privacy Policy.

7. Acceptable use

You agree not to:

  • Use AttackerView to attack, exploit, or harm any system or person.
  • Use scan results to conduct unauthorized access, data theft, or any malicious activity.
  • Attempt to overwhelm or disrupt target systems through excessive scanning.
  • Resell, redistribute, or commercially exploit scan results without our permission.
  • Use the service in any way that violates applicable laws or regulations.
  • Reverse-engineer, decompile, or attempt to extract the source code of AttackerView.
  • Create accounts using false or misleading information.
  • Circumvent rate limits, tier restrictions, or other usage controls.
  • Use API keys or webhook endpoints to build a competing service using our scan data.
  • Share API keys with unauthorized third parties.

We reserve the right to suspend or terminate your account immediately if we believe you are violating these terms. We don't need to give you advance notice if we believe there's an urgent safety or legal concern.

8. Accounts, authentication, and multi-tenancy

You sign in via GitHub or Google OAuth. We don't store passwords. You're responsible for maintaining the security of your OAuth accounts. If someone gains access to your account through your OAuth provider, that's not something we can control.

Multi-tenancy: If you sign in with a corporate email address (e.g., [email protected]), your account is placed in a shared organizational tenant with other users from the same email domain. All team members in a shared tenant can see all domains, scans, findings, and settings within that tenant. If you sign in with a personal email (Gmail, Yahoo, etc.), you get a private tenant visible only to you.

If you provide authentication credentials for scanning (e.g., login details for authenticated crawling), those credentials are encrypted at rest using AES-256-GCM. You are responsible for ensuring any credentials you provide are appropriate for testing purposes - don't give us production admin credentials unless you understand what the scan will do with them.

9. API access, CLI, and webhooks

Paid tiers can generate API keys for programmatic access to scan data via our API. API keys are:

  • Hashed before storage (we cannot retrieve your full key after creation - store it securely).
  • Rate-limited on a daily basis. Exceeding rate limits will result in temporary rejection of requests.
  • Subject to the same acceptable use restrictions as interactive access.
  • Your responsibility to keep secure. Treat API keys like passwords.

Our CLI tool is an additional access method for the same API. It authenticates using the same API keys and is subject to the same rate limits, acceptable use restrictions, and terms as direct API access. Output files generated by the CLI are your data, subject to the same intellectual property terms in Section 16.

Paid tiers can also configure webhook endpoints to receive scan results, alerts, and monitoring updates at a URL you specify. Webhook payloads are signed with HMAC-SHA256 so you can verify they came from us. We support both standard JSON payloads and Slack-formatted messages.

You are responsible for the security and availability of your webhook endpoint. We will retry failed deliveries with exponential backoff, but persistently failing endpoints may be paused.

10. Third-party integrations

AttackerView supports integrations with third-party compliance platforms (currently Vanta and Drata). When you enable an integration:

  • You authorize AttackerView to send vulnerability finding data (title, severity, description, remediation guidance, and target URL) to the connected platform.
  • Integration credentials (OAuth tokens or API keys) are encrypted at rest using AES-256-GCM.
  • We do not send raw HTTP traffic, stored scan credentials, or personal data to integration partners. Only structured finding metadata is transmitted.
  • Your use of third-party platforms is subject to their own terms of service and privacy policies. We are not responsible for how those platforms handle data after we deliver it.
  • You can disconnect an integration at any time. Disconnecting stops future data transmission but does not delete data already sent to the third-party platform.

11. Compliance reports and evidence

AttackerView can generate compliance evidence reports that map scan findings to security controls in frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA.

These reports are informational evidence for your compliance programs. They are not audit opinions, certifications, or attestations. AttackerView is a tool for assisting with security and compliance - it does not replace qualified auditors, penetration testers, or compliance assessors. The compliance mappings represent our assessment of which security controls each check relates to, but your auditor makes the final determination of whether a control is satisfied.

We periodically update our compliance mappings as frameworks are revised. Mapping accuracy is provided on a best-effort basis.

12. Artificial intelligence transparency

AttackerView uses artificial intelligence in two distinct ways:

  • Deterministic analysis: Our standard scanning uses rule-based checks (not AI/ML) to detect security issues. These produce consistent, reproducible results.
  • AI-powered pentesting (any account tier, including an expired trial): Our penetration testing feature uses a large language model (LLM) to autonomously test your application. The AI makes decisions about what to test and how, within the scope you authorize.

Finding confidence levels

AI pentesting findings are reported with a confidence level:

  • Verified: The finding has concrete, reproducible proof backed by actual HTTP traffic evidence.
  • Behavioral: The evidence is consistent with exploitation but lacks definitive proof. We recommend you verify these manually.

Findings that cannot be corroborated by any evidence are not reported. Our validation process uses a combination of automated analysis and, in some cases, AI-assisted review (via third-party AI models, used under Do Not Train terms) to determine confidence levels.

We do not use AI to make decisions about your account, billing, access, or any other aspect of the service beyond security testing. We do not use your data to train AI models.

13. Paid subscriptions, billing, and credits

AttackerView offers free and paid tiers. Paid subscriptions are billed monthly or annually via Stripe. By subscribing to a paid plan, you also agree to Stripe's terms.

  • Paid subscriptions are billed immediately upon checkout. We offer a 30-day money-back guarantee on your first payment.
  • Subscriptions renew automatically at the end of each billing period.
  • You can cancel at any time. Cancellation takes effect at the end of the current billing period - you retain access until then.
  • When a paid subscription ends, features that require a paid tier (continuous monitoring, webhooks, API access, integrations) are paused or disabled. Your data is not deleted. One-off prepared AI pentests remain available, including on an expired trial. Per-run pentest reports remain until you delete the domain or the account. Buying a pentest does not enable webhooks.
  • We may change pricing with 30 days' notice. Price changes apply to the next billing cycle after the notice period.

Pentest credits

Any account, including an expired trial, can buy pentest credits at €10 plus applicable VAT per selected HTTP method and canonical route. GET and POST on the same route are two credits. IDs and query values do not add credits. Hunter tier subscribers also receive 20 pentest credits every month. Credits included with Hunter are used before bought credits.

The scope is prepared and validated before purchase. You pay for that selected base, up front or from credits already on the account. Optional extra credits for genuinely new additions are off unless you add them. They are capped, paid up front or covered by your purchased balance, and unused extras stay on the account. They are not charged only if used, and they are not a cash refund.

  • Credits included with Hunter are allocated at the start of each subscription month (counted from the day your subscription started), on monthly and annual plans alike, and expire when that subscription month ends. Unused included credits do not roll over.
  • Bought credits do not expire. They stay on your account on any tier, including an expired trial.
  • If a run is blocked before it starts, its units are restored. If you stop it, units that never started are restored. If it fails on our side, units that did not finish are restored. A completed run restores only units that were not tested. Units already tested are not restored, including when a tested unit found nothing. Optional extras that were not tested are restored. An extra that reached tested is spent. Included monthly credits are restored only while that month is still open. Restoration is not a cash refund.
  • Credits are non-transferable and have no cash value.
  • If you downgrade from Hunter, you stop receiving included credits. The current subscription month's included credits expire when that month ends.
  • Cancelling a subscription or leaving Watchtower does not disable one-off pentests, does not delete bought credits, and does not delete per-run reports. Webhooks and other paid-plan features still follow the subscription. Buying credits does not enable webhooks.

For refund details, see our Refund Policy.

14. Public scan results

When a public scan is performed (whether by you or another user), the results are displayed publicly on AttackerView at /d/[hostname].

Public scans run the full set of security checks described in Section 3, including CVE verification and exposed file detection. The only difference from private scans is that public scans do not perform authenticated crawling (no credentials are provided) and results are publicly visible.

If you are the owner of a domain that has been publicly scanned and you want the results removed, you can submit a report using the "Report abuse" link on the domain's public page, or contact us at [email protected]. We have a takedown process for domain owners who can verify ownership.

15. Abuse reports and complaints

Anyone can submit an abuse report for publicly displayed scan results. Abuse reports are reviewed by our team and may result in content removal (takedown) if the report is valid.

Abuse reports are rate-limited to prevent misuse. We store the reporter's IP address and optional email address for the purpose of processing the report and preventing abuse of the reporting system. We will not use this information for any other purpose.

For takedown requests, abuse complaints, or any other concerns about scan results displayed on AttackerView, contact us at [email protected].

16. Findings and risk acceptance

When our scans detect security issues, they are tracked as findings in your account. Findings persist across scans - if an issue is found, then fixed, then reappears, we track that history. You can mark findings as "accepted" if you've decided the risk is acceptable for your situation.

Accepting a finding risk is your decision and your responsibility. Accepted findings still appear in your dashboard and reports - they are not hidden. Acceptance does not constitute our endorsement that the risk is acceptable.

17. Intellectual property

  • Our stuff: The AttackerView platform, its code, design, analysis methods, attack chain definitions, compliance mappings, and all related intellectual property belong to us.
  • Your data: You own your scan data. We don't claim ownership of the results of your scans. However, you grant us a license to process, store, and display your data as necessary to provide the service, including transmitting finding data to third-party integrations you have configured.
  • Aggregated data: We may use anonymized, aggregated data (e.g., "X% of scanned domains have misconfigured CORS") for research, product improvement, and marketing. This data cannot be traced back to you or any specific domain.

18. Disclaimer of warranties

AttackerView is provided "as is" and "as available", without warranties of any kind, whether express or implied. We specifically disclaim all implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

We do our best to make the service reliable and the scans safe, but:

  • We do not guarantee that scans will find every vulnerability. Security is complex, and no automated tool catches everything.
  • We do not guarantee that scans won't cause issues with the target app. While our scans are designed to be non-destructive, some applications may react unpredictably to automated HTTP traffic. If your app goes down because it can't handle a few extra requests, that's a problem with your app's resilience, not with our scanner.
  • AI-powered pentesting (Section 6) is significantly more aggressive than standard scanning. While scope enforcement limits the AI agent to authorized targets, the AI may make unexpected decisions and generate substantial traffic. We do not guarantee that pentesting will not cause service disruption on the target.
  • We do not guarantee that the service will be uninterrupted, error-free, or available at all times.
  • Scan results are informational only. You are responsible for deciding what to do with them. We are not liable for actions taken (or not taken) based on scan findings.
  • Compliance evidence reports map findings to framework controls on a best-effort basis. They are not audit opinions and should not be relied upon as such.
  • CVE verification probes confirm the presence of known vulnerabilities based on publicly available information. False positives and false negatives can occur.
  • Webhook deliveries, email notifications, and third-party integration pushes are provided on a best-effort basis. We do not guarantee delivery timing or availability of third-party services.

19. Limitation of liability

  • We are not responsible for any losses, damages, or costs arising from your use of the service, including but not limited to: downtime on scanned targets, data disclosed in scan results, or actions taken (or not taken) based on scan findings.
  • We are not liable for any indirect, incidental, special, consequential, or punitive damages, regardless of the cause or theory of liability.
  • Our total liability for any claim related to the service is limited to the amount you paid us in the 12 months before the claim arose, or EUR 100, whichever is greater.
  • We are not liable for the actions of third-party services you connect to AttackerView (including Vanta, Drata, Stripe, Slack, or any webhook endpoint), or for data loss or exposure that occurs after data leaves our platform.
  • We are not liable for damage caused by AI-powered pentesting to target systems that you authorized for testing. You accepted the risks described in Section 6 when you enabled pentesting on a domain.

Nothing in these terms limits liability for fraud, gross negligence, or anything that cannot be limited by applicable law.

20. Indemnification

You agree to indemnify and hold us harmless from any claims, damages, losses, or expenses (including reasonable legal fees) arising from:

  • Your use of the service.
  • Your violation of these terms.
  • Your scanning of targets you weren't authorized to scan.
  • Your use of AI-powered pentesting on targets, including any damage to target systems.
  • Any third-party claims related to your use of scan results.
  • Data you transmit to third-party services via integrations or webhooks you configured.

21. Service availability

We aim for high availability, but we don't guarantee uptime. We may need to take the service offline for maintenance, updates, or in response to security incidents. We'll try to give advance notice when possible, but sometimes things break unexpectedly.

22. Account deletion

You can request deletion of your account at any time through your account settings. Account deletion works as follows:

  • After you submit a deletion request, there is a 90-day retention period during which your account remains active. This gives you time to change your mind.
  • You can cancel a pending deletion request at any time during the retention period.
  • After the 90-day period, your account and all associated data (domains, scans, findings, credentials, integrations, webhooks, API keys) are permanently deleted.
  • If you are the sole user in a tenant, the entire tenant and all its data are deleted. If other users remain in your tenant, your personal data is removed and ownership of shared resources (domains, scans) is reassigned to another tenant member.
  • Active subscriptions should be cancelled separately via Stripe before requesting deletion.

23. Termination

  • By you: You can close your account at any time via the account deletion process described in Section 22. Active subscriptions can be cancelled and will run until the end of the billing period.
  • By us: We can suspend or terminate your account if you violate these terms, if we're required to by law, or if we discontinue the service. We'll try to give reasonable notice except in cases of urgent safety or legal concerns.
  • Effect of termination: Upon termination, your right to use the service ends. API keys are revoked, webhooks are disabled, integrations are disconnected, monitoring schedules are stopped, and remaining pentest credits are forfeit because the account is closed. Ending a subscription does not forfeit bought credits or delete per-run pentest reports. We may delete your data after a reasonable period (typically 30 days, or 90 days for user-initiated deletion). Provisions that should survive termination (like limitation of liability and indemnification) will survive.

24. Governing law and disputes

These terms are governed by the laws of the Netherlands, without regard to conflict-of-law principles.

For any dispute arising from these terms or your use of AttackerView, we both agree to first attempt resolution through good-faith negotiation. If we can't resolve it within 30 days, either party may pursue binding resolution.

  • For disputes involving amounts under EUR 25,000, disputes will be resolved through binding arbitration administered under the rules of the Netherlands Arbitration Institute (NAI), conducted in English, with a single arbitrator. The arbitrator's decision is final and enforceable in any court of competent jurisdiction.
  • For disputes involving amounts over EUR 25,000, or where injunctive relief is sought, the courts of Amsterdam, the Netherlands, have exclusive jurisdiction.

Regardless of the above:

  • If you are an EU/EEA consumer, nothing in these terms limits your mandatory consumer protection rights under the laws of your country of residence, including your right to bring proceedings in the courts of your habitual residence.
  • If you are a California resident, you retain all rights under the California Consumer Privacy Act (CCPA) regardless of this choice of law.
  • Either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect intellectual property rights or prevent imminent harm.

Class action waiver: To the fullest extent permitted by applicable law, you agree that any dispute resolution will be conducted on an individual basis, not as a class action or representative proceeding.

25. General provisions

  • Severability: If any provision of these terms is found to be unenforceable, the remaining provisions remain in full effect.
  • Entire agreement: These terms, together with our Privacy Policy and Refund Policy, constitute the entire agreement between you and us regarding AttackerView.
  • No waiver: Our failure to enforce any right or provision of these terms doesn't constitute a waiver of that right or provision.
  • Assignment: We may assign our rights and obligations under these terms (e.g., in connection with a merger or acquisition). You may not assign yours without our written consent.
  • Force majeure: We are not liable for delays or failures caused by events beyond our reasonable control, including natural disasters, internet outages, third-party service failures, or government actions.

26. Contact

Questions about these terms? Email us at [email protected].