Terms

Terms and acceptable use

Permitted use, reliance limits, public-signal boundaries, sharing rules, affiliation limits, accuracy, freshness and service availability for ThreatScope Check.

In plain English:

  • ThreatScope Check is a public trust-signal triage tool, not a security audit or certification.
  • Results are point-in-time observations based on public domain-layer signals.
  • You may check domains you do not own, but you must use results lawfully, responsibly and in context.
  • You must not use the service for abuse, harassment, unauthorised access, phishing, automated enumeration at scale, or service disruption.
  • You may share results, but not in a misleading way or as proof of safety, fault or compliance.
  • ThreatScope Check may rate limit, restrict or suspend access where reasonably required to protect the service, its infrastructure, users or third-party systems.

Stewardship

ThreatScope Check is an independent public-interest project owned and stewarded by Bryan Chetcuti.

The Vigo Group may provide operational infrastructure and service support under a replaceable arrangement. This operational role does not make ThreatScope Check a Vigo Group product or confer authority over its methodology or findings.

Reliance boundary

ThreatScope Check provides public, point-in-time domain-layer observations for informational and triage purposes. Results are not a security audit, penetration test, compliance assessment, legal opinion, numeric rating, certification, or assurance claim about a domain.

Read the method page for how evidence and limits should be interpreted.

Acceptable use

ThreatScope Check is intended for reasonable, good-faith review of public domain-layer signals. It must not be used as part of offensive activity against systems or people.

You must not use ThreatScope Check to support abuse, harassment, unlawful activity, credential theft, phishing, unauthorised access, automated enumeration at scale, service disruption, or attempts to bypass rate limits or protective controls.

Rate limiting and availability

ThreatScope Check may apply rate limits, restrict requests or suspend functionality where reasonably required to protect the service, its infrastructure, users or third-party systems.

ThreatScope Check is provided as a public utility on a reasonable-efforts basis. Availability, performance and result completeness are not guaranteed.

Third-party domain checks

ThreatScope Check reads public domain-layer information. You do not need to own or control a domain to view public signals about it, but you are responsible for using the service and interpreting results lawfully, responsibly and in context.

Results must not be used to harass, pressure, misrepresent, shame, or make unsupported claims about a person, organisation or domain operator.

Sharing results

You may share ThreatScope Check results, provided they are not altered, misrepresented, presented as certification, or used to imply conclusions the service does not support.

Results should be read with the accompanying evidence, method notes and limitations. A result is a point-in-time observation, not a finding of fault or endorsement.

Affiliation

Unless expressly stated, ThreatScope Check is not operated by, endorsed by, or affiliated with any registry, registrar, DNS provider, mail provider, security vendor, standards body, or government agency. Operational services supplied by the Vigo Group do not create product ownership, methodological authority or endorsement.

Accuracy and freshness

ThreatScope Check results may be incomplete, unavailable, delayed, stale, or affected by DNS propagation, third-party service behaviour, network conditions, rate limits, timeouts, implementation limits, or changes made by the domain operator after the check was run.

A result reflects what ThreatScope Check was able to observe at the time of the check. It should not be treated as a complete or permanent statement about a domain.

Related: Privacy notice and Contact & feedback.