Why this schedule exists
A Cloudheal scan is not passive observation. It runs many thousands of active checks against live infrastructure, and it attempts to confirm what it finds rather than only noting it. Running that against infrastructure you are not authorised to test may be unlawful in the place where the infrastructure sits, whoever pressed the button.
The platform treats the list of domains an organisation may scan as a security control rather than a billing one. This schedule is the obligation behind that control.
Authorisation
The customer warrants that, for every root domain it adds and every asset discovered beneath it that is included within the scope of testing, the customer either owns the relevant infrastructure or holds valid written authorisation from the person who does. That authorisation must permit the active security testing performed through Cloudheal and must be sufficient to authorise Cloudheal and its service providers to perform such testing on the customer's instructions. The customer will keep that authorisation for as long as the domain remains in scope, and will produce it to us within seven days of being asked.
The customer will remove a domain from scope as soon as the authorisation ends, and will tell us if it has reason to believe a domain in scope is no longer covered.
We do not verify authorisation before a scan runs, and we do not warrant that a domain in scope is one the customer is entitled to test. A platform administrator approves what goes on the scope list, and that approval is an operational control rather than a legal opinion.
Reliance on customer authorisation
We are entitled to rely on the customer's warranty and representations concerning its ownership of, or authority to test, infrastructure, but may request evidence of authorisation or suspend or refuse a scan where we reasonably consider it necessary to protect Cloudheal, its service providers or any third party. The customer acknowledges that a confirmation pop-up screen will appear before any new scan starts, requiring the user to explicitly declare their authorisation on behalf of the customer before the scan can proceed.
The customer indemnifies us against claims brought by a third party liabilities, losses, damages and reasonable legal costs arising from or in connection with the scanning or testing of infrastructure that the customer did not own or was not authorised to test, except to the extent that the claim or loss was caused by our breach of this agreement, negligence or wilful misconduct.
What the customer must not do
- Add a domain the customer neither owns nor holds written authorisation to test.
- Use the platform to test a third party's infrastructure, including a supplier's or an acquisition target's, without that party's written authorisation.
- Use exposure information the platform reports to gain unauthorised access to any system, whether the customer's own or another party's.
- Attempt to reach another customer organisation's data, or to circumvent the separation between organisations.
- Share an account, or give access to a person the customer has not invited through the platform.
- Resell, redistribute or publish the platform's findings as a service to others, except as we have agreed in writing.
- Copy, decompile or reverse engineer any part of the platform, or attempt to derive how it works, except to the extent the law permits despite this restriction.
- Use the platform in a manner intended to damage, disrupt, overload, degrade or interfere with any system, network, service or infrastructure.
- Introduce or transmit malware, malicious code or other harmful material through or in connection with the platform.
- Use the platform or its findings for any unlawful, fraudulent or malicious purpose.
- The customer must ensure that its Authorised Users comply with this schedule and is responsible for their use of Cloudheal.
- The customer must use Cloudheal and any information obtained through it in accordance with applicable laws and regulations and must obtain and maintain all permissions, consents and authorisations required for its use of the platform.
Dark web information
Where the platform reports an exposure found on the dark web, that information concerns real people, who may include the customer's own staff and may include people outside the customer's organisation.
The customer will use dark web and breach exposure information only for legitimate cybersecurity, incident response and remediation purposes relating to systems, accounts or persons for which it is authorised to act. The customer must not use such information to attempt unauthorised access to any account or system, for credential exploitation or other unlawful purposes, or republish or disclose it except where reasonably necessary for remediation, notification of affected persons or compliance with applicable law.
Every request to reveal a dark web value is recorded with the reason given and the person who asked. The customer will make sure the reasons its people give are accurate, because that record is the evidence of why an exposure was opened.
Reporting a problem
If anyone finds a fault or a security weakness in Cloudheal itself, write to admin@cloudheal.com. We will acknowledge within two working days and keep the reporter informed. We will not initiate legal action solely in respect of good-faith security research conducted in accordance with this section where the reporter avoids unnecessary access to, modification of or deletion of data, does not disrupt or degrade the platform or any third-party system, does not exploit the vulnerability for any purpose other than demonstrating it to us, promptly reports the vulnerability to us, and gives us a reasonable opportunity to investigate and remediate it before making it public.
If this schedule is breached
We may suspend access immediately where we reasonably believe this schedule has been breached, and may remove a domain from scope. Where we do, we will tell the customer what we believe happened.
Where a breach is capable of remedy, we may require the customer to remedy it within fourteen days. Access may be restored once the breach has been remedied to our reasonable satisfaction. We may terminate the agreement in accordance with its termination provisions where the breach is material, repeated, not remedied within the period specified, or is of a nature that cannot reasonably be remedied.
This schedule is version V1, issued on 30 September 2026.