Privacy Policy

Acceptable Use Policy (AUP)

Effective Date: July 19, 2025

This Acceptable Use Policy (“AUP”) outlines acceptable and prohibited uses of the WASViking platform and services. All users must comply with this AUP as a condition of using the WASViking service.
By accessing or using WASViking, you agree to abide by this AUP. If you violate this policy, your account may be suspended or terminated without prior notice.

1. Purpose

The purpose of this policy is to ensure responsible, lawful, and ethical use of the WASViking platform, tools, APIs, and associated services. It protects our customers, infrastructure, and the broader digital ecosystem.

2. Acceptable Use

You may use WASViking only for lawful and authorized purposes, including:

  • Scanning, monitoring, and analyzing domains, APIs, and systems that:
    • You own;
    • You have explicit, written permission to analyze (e.g., via an engagement contract or letter of authorization);
  • Conducting internal vulnerability assessments or compliance checks for your organization or authorized clients;
  • Using scan results solely for defensive and corrective purposes.
3. Prohibited Use

You may not use WASViking to:

  • Scan or test systems, APIs, or web applications that you do not own or control, unless explicitly authorized in writing by the owner.
  • Launch denial-of-service (DoS), brute force, or stress-testing attacks.
  • Attempt to gain unauthorized access to any data, system, or network.
  • Use WASViking to exploit vulnerabilities or extract data beyond standard discovery.
  • Circumvent, disable, or attempt to bypass usage limits, rate limits, or licensing restrictions.
  • Resell, sublicense, share, or offer WASViking services as part of a competing product.
  • Interfere with or disrupt the operation of WASViking services or networks.
  • Submit content that is unlawful, infringing, defamatory, or violates any third-party rights.
  • Use WASViking in violation of U.S. export control laws or other applicable regulations.
3.1 Authorized Security Providers

WASViking may be used by Managed Security Service Providers (MSSPs), consultants, or other authorized third-party security professionals to perform scanning, analysis, and reporting on behalf of their end clients, provided that:

  • - The provider has obtained valid, explicit, and written authorization from the asset owner (e.g., signed contract, statement of work, or letter of authorization);
  • - The provider ensures that all scanning activity is limited to the agreed scope of engagement;
  • - The provider complies with all terms outlined in this Acceptable Use Policy and the WASViking Terms of Use;
  • - The provider maintains sufficient documentation of client authorization and is able to produce it upon request by WASViking or relevant authorities.

WASViking reserves the right to request such documentation at any time to verify authorization and to suspend or terminate access if such proof is not provided or if misuse is suspected.

The use of WASViking in violation of these conditions, or to provide services to third parties without proper authorization, constitutes a material breach of this Acceptable Use Policy.

3.2 Exposure Intelligence Usage

The Exposure Intelligence feature may provide access to data derived from publicly available sources or third-party datasets related to credential exposure and security incidents.

You agree to use such data strictly for legitimate security purposes, including risk assessment, incident response, and remediation of exposures related to your organization or authorized clients.

You may not use Exposure Intelligence data to:

  • Target, profile, or monitor individuals outside of legitimate security use cases;
  • Exploit, disclose, or misuse exposed credentials or personal data;
  • Access or process data without proper authorization or legal basis.

You are solely responsible for ensuring that your use of Exposure Intelligence complies with all applicable data protection, privacy, and employment laws.

4. Account and Access Security

You are responsible for maintaining the confidentiality and security of your access credentials.

You must:

  • Protect access to your account and API keys;
  • Prevent unauthorized access to your scans or reports;
  • Immediately notify WASViking of any suspected misuse or breach.

You are fully responsible for all activities conducted through your account.

5. Monitoring and Enforcement

WASViking reserves the right to:

  • Investigate suspected violations of this AUP;
  • Monitor usage for abuse, misuse, or excessive activity;
  • Log scan metadata and network activity for security auditing;
  • Suspend or terminate any account violating this AUP;
  • Notify affected third parties or law enforcement if applicable.

WASViking may retain scan logs and account activity related to violations for legal, investigative, or operational purposes.

6. Reporting Abuse

If you become aware of any violation of this AUP, please report it immediately to:
WASViking LLC
Orlando, FL, USA
[email protected]

We will review all reports of abuse promptly and take appropriate action.

7. Changes to this AUP

We may update this AUP from time to time. When we do, the updated version will be posted at /acceptable-use-policy. Continued use of WASViking indicates your acceptance of the current version.

Up

Florida, United States