Acceptable Use Policy
Effective from 1 September 2026. Sitewarden sends requests to systems that belong to other people, so this policy is part of the Terms of Service and not an optional extra.
1. Audit only what you are entitled to audit
You may audit a domain if any of the following is true:
- You own or operate it.
- You have permission from the person who does — a client engagement is enough.
- It is a public reference target being used to evaluate the product, and the volume stays at the level of a demonstration.
2. What the audit actually does
We think it is fair to be precise about this, because it bounds what you are agreeing to. An audit performs a normal DNS resolution, completes a standard TLS handshake, and issues a small number of ordinary HTTP GET requests — the site root, /robots.txt and /sitemap.xml — identifying itself as SitewardenBot/1.0.
It does not, under any plan:
- attempt to authenticate, or use credentials of any kind;
- submit forms or send anything other than GET requests;
- probe for vulnerabilities, fuzz parameters or attempt injection of any sort;
- enumerate paths, directories or subdomains beyond the two well-known files above;
- generate enough traffic to affect the availability of the target.
See about our crawler for the technical detail, including how to block it.
3. Prohibited uses
- Using the service as a step in reconnaissance for an attack, or against a target you have no relationship with.
- Scripting the product, or a shared account, to produce scanning volume that a normal customer would not.
- Reselling raw access to the scanning engine, or wrapping it in a competing product.
- Circumventing quotas, rate limits or the authentication that enforces them.
- Uploading or entering data you have no right to process.
- Anything unlawful under Serbian law or the law that applies to you.
4. Rate limits
Plan quotas are documented on the pricing page. In addition, the unauthenticated demo is limited to three audits per IP address per hour, and we apply a per-account concurrency limit so one customer cannot monopolise the workers. Hitting a limit returns an explicit error; it is never billed as a failed audit.
5. Reporting abuse
If you believe Sitewarden has been used against a system you are responsible for, email abuse@aicour.site with the timestamp and the target hostname. We keep request logs for 90 days, will investigate, and will tell you what we found.
6. Enforcement
Where a breach is capable of remedy we contact you first and give you a reasonable chance to fix it. For breaches that put third parties at risk we suspend immediately and ask questions afterwards. Termination for a serious breach does not entitle you to a refund of the current period.