This policy says what a scan costs, when the cost is taken, and what happens to the cost when a scan ends early. It applies to every organisation using Cloudheal.
Your provider sets the figures for your organisation. This policy says how those figures are applied.
What a scan costs
A scan costs a fixed number of credits. It is one credit unless your agreement says otherwise.
The cost does not change with the size of the domain. A domain with three assets and a domain with two thousand assets cost the same. The number of subdomains, addresses, certificates or findings a scan discovers makes no difference to what you pay.
Scanning is all or nothing: one scan runs every check the platform has. The modules your organisation holds decide what you can read, not what the scan does, so they make no difference to the cost either.
When the cost is taken
The credits are taken when the scan starts. They are not taken when it finishes.
They are then held against that scan until the scan reaches an ending. The hold is not a deposit. It is the charge, waiting to be confirmed.
We take the credits at the start because that is when the work is commissioned. A scan runs for 6 to 8 hours and sometimes longer, and the cost of running it is incurred the moment it is accepted.
A scan that is refused costs nothing
A scan is authorised only when all of these are true:
- you have accepted the confirmation shown before a scan, in the wording in force at the moment you accepted it;
- your role may spend credits, which the Operator and Viewer roles may not;
- the domain is on your organisation's scan scope;
- the domain has not been removed from your list;
- no other organisation is part way through a scan of the same domain name;
- you have not started more scans in the last few minutes than one person may;
- your organisation is below its limit on scans running at once;
- your organisation is not blocked from scanning;
- your balance covers the charge;
- the charge is within your organisation's per-scan ceiling, which is described below.
If any of these refuses, the scan is not authorised, nothing is charged, and the reason is shown to you on your domains screen. Where the refusal is about another organisation holding the same domain name, you are told only that the domain is not available to scan, because naming the reason would tell you something about a customer that is not yours to know.
What happens at each ending
- The scan completes. The credits are spent.
- You stop the scan. The credits stay held, because a stop is a pause and not an ending.
- You resume a scan you paused, and it completes. The credits are spent, and no second charge is taken for the resume.
- You remove a scan you paused yourself, or its domain leaves your scope, or the organisation is closed. The credits are spent.
- You leave a pause of your own past the hold period. The credits are spent, and the scan can no longer be resumed.
- The scan fails. The credits stay held, and are returned only when a platform administrator approves it.
- The scan cannot finish, because a different scan of the same domain has taken its place. The credits stay held, and are returned only when a platform administrator approves it.
- Cloudheal pauses the scan at its running-time limit. The credits stay held, and they stay held until a platform administrator acts.
- A platform administrator stops the scan. The credits are returned in full.
One sentence carries the whole list. You bear the cost of an ending you chose. An ending nobody chose is settled by a person, not by a timer.
The endings that spend your credits happen on their own. The endings that hold them wait for a platform administrator, and the credits sit where they are until one decides.
A removal only ever spends a pause you chose. Where the scan had already failed, or the platform had paused it at the running-time limit, the credits stay held, and removing the scan, its domain or the organisation does not change that. Tidying up an ending you did not choose is not choosing to pay for it.
Stopping a scan pauses it
When you stop a scan, Cloudheal pauses it and keeps its place. You can resume it later and it carries on from where it reached. Resuming takes no new credits, because the scan was charged once when it started.
Its credits stay held for as long as the pause can still be resumed. The hold period is fourteen days unless your provider has set a different one.
After the hold period the pause is treated as abandoned. The credits are spent and the scan can no longer be resumed. This is recorded on your organisation's audit log at the time it happens. If you want the scan to continue, resume it before the period runs out. If you no longer want it, you do not need to do anything.
A stopped scan produces no results. Results are produced only when a scan completes. A paused scan keeps its place and produces its results when it is resumed and finishes. You can resume a pause of your own; a pause the platform took at the running-time limit is resumed by a platform administrator and not by you.
When Cloudheal pauses a scan that has run too long
A scan that runs past the platform's running-time limit is paused by Cloudheal itself. The limit is twelve hours unless your provider has set a different one.
You get notice before this happens, and you can decline it. An hour before the limit, by default, the person who started the scan and your organisation's administrators are emailed. The email carries a link to keep the scan running. If anybody uses it, the scan is not paused and runs to its own end, with a quiet reminder from time to time that it is still going.
If nobody declines, the scan is paused at the limit and the pause is recorded on your organisation's audit log.
The credits stay held and they never expire into a charge. This is not a pause you chose, so the hold period above does not apply to it, whatever the calendar says. You cannot resume this kind of pause yourself. A platform administrator either resumes the scan, in which case it is charged if and when it finishes, or returns the credits to your balance.
When a scan fails
A scan can fail because the scan itself fell over, or because a different scan of the same domain has taken its place and ours can therefore never finish.
Neither is your doing, so neither is charged automatically and neither is returned automatically. The credits stay held until a platform administrator looks at the scan and decides. A return requires a written reason, which is recorded.
When a platform administrator stops your scan
A platform administrator can stop any running scan at any time, without notice. The scan is ended, it cannot be resumed, and the credits are returned to your balance in full. A reason is required and is recorded on your organisation's audit log.
The per-scan ceiling
Your organisation has a ceiling on what a single scan may cost. A scan whose charge would exceed it is refused and you are not charged for it. The ceiling exists so that no single scan can drain an allocation.
Balance, blocks and adjustments
Your balance cannot go below zero by scanning. No scan is authorised that your balance does not cover.
A balance can go below zero only when your provider records a correction or an offline billing event against your organisation. Where that happens, your organisation is blocked from starting further scans until a platform administrator clears the block. Credits already spent are not clawed back, because they were genuinely spent.
Credits are added to your organisation by your provider. Cloudheal does not take payment, raise invoices or manage subscriptions.
The record is append only. Every credit movement is an entry naming the scan or the administrator's action behind it. A mistake is corrected by a new entry, never by editing an old one, so the history of your organisation's credits cannot be rewritten.
Where you can see your credits
There is no credit balance screen in Cloudheal today. Ask your provider for your balance and your usage.
Two things do reach you in the product:
- a scan refused for want of credit says so, on your domains screen, at the moment you ask for it;
- every act a platform administrator takes on your credits, and every ending the platform decides for you, is recorded on your organisation's audit log. Where an administrator stops your scan, returns a held credit, or resumes a scan the platform paused, a written reason is required and is recorded with it.
Changes to this policy
The date this wording took effect is at the top of this page. When the policy changes, the new wording is published with its own date, and this one stays at its own address, so that a decision taken under it can still be read.