Acceptable use policy

What this platform may be used for, and what you confirm before a scan begins.

This is the wording in force. It took effect on .

Why this schedule exists

A Cloudheal scan is not passive observation. It runs many thousands of active checks against live infrastructure, and it attempts to confirm what it finds rather than only noting it. Running that against infrastructure you are not authorised to test may be unlawful in the place where the infrastructure sits, whoever pressed the button.

The platform treats the list of domains an organisation may scan as a security control rather than a billing one. This schedule is the obligation behind that control.

Authorisation

The customer warrants that, for every root domain it adds and every asset discovered beneath it that is included within the scope of testing, the customer either owns the relevant infrastructure or holds valid written authorisation from the person who does. That authorisation must permit the active security testing performed through Cloudheal and must be sufficient to authorise Cloudheal and its service providers to perform such testing on the customer's instructions. The customer will keep that authorisation for as long as the domain remains in scope, and will produce it to us within seven days of being asked.

The customer will remove a domain from scope as soon as the authorisation ends, and will tell us if it has reason to believe a domain in scope is no longer covered.

We do not verify authorisation before a scan runs, and we do not warrant that a domain in scope is one the customer is entitled to test. A platform administrator approves what goes on the scope list, and that approval is an operational control rather than a legal opinion.

Reliance on customer authorisation

We are entitled to rely on the customer's warranty and representations concerning its ownership of, or authority to test, infrastructure, but may request evidence of authorisation or suspend or refuse a scan where we reasonably consider it necessary to protect Cloudheal, its service providers or any third party. The customer acknowledges that a confirmation pop-up screen will appear before any new scan starts, requiring the user to explicitly declare their authorisation on behalf of the customer before the scan can proceed.

The customer indemnifies us against claims brought by a third party liabilities, losses, damages and reasonable legal costs arising from or in connection with the scanning or testing of infrastructure that the customer did not own or was not authorised to test, except to the extent that the claim or loss was caused by our breach of this agreement, negligence or wilful misconduct.

What the customer must not do

Dark web information

Where the platform reports an exposure found on the dark web, that information concerns real people, who may include the customer's own staff and may include people outside the customer's organisation.

The customer will use dark web and breach exposure information only for legitimate cybersecurity, incident response and remediation purposes relating to systems, accounts or persons for which it is authorised to act. The customer must not use such information to attempt unauthorised access to any account or system, for credential exploitation or other unlawful purposes, or republish or disclose it except where reasonably necessary for remediation, notification of affected persons or compliance with applicable law.

Every request to reveal a dark web value is recorded with the reason given and the person who asked. The customer will make sure the reasons its people give are accurate, because that record is the evidence of why an exposure was opened.

Reporting a problem

If anyone finds a fault or a security weakness in Cloudheal itself, write to admin@cloudheal.com. We will acknowledge within two working days and keep the reporter informed. We will not initiate legal action solely in respect of good-faith security research conducted in accordance with this section where the reporter avoids unnecessary access to, modification of or deletion of data, does not disrupt or degrade the platform or any third-party system, does not exploit the vulnerability for any purpose other than demonstrating it to us, promptly reports the vulnerability to us, and gives us a reasonable opportunity to investigate and remediate it before making it public.

If this schedule is breached

We may suspend access immediately where we reasonably believe this schedule has been breached, and may remove a domain from scope. Where we do, we will tell the customer what we believe happened.

Where a breach is capable of remedy, we may require the customer to remedy it within fourteen days. Access may be restored once the breach has been remedied to our reasonable satisfaction. We may terminate the agreement in accordance with its termination provisions where the breach is material, repeated, not remedied within the period specified, or is of a nature that cannot reasonably be remedied.

This schedule is version V1, issued on 30 September 2026.