Naunet Scan Portal Terms
Version 2.0. Effective 5 August 2026. These Terms replace all earlier versions.
These Terms govern your use of the Naunet Scan Portal (the “Portal”), operated by Naunet (“Naunet”, “we”, “us”). By creating an account, signing in, submitting a scan request, or using any report or export produced by the Portal, you agree to these Terms. If you do not agree, do not use the Portal.
1. Who these Terms bind
You must be at least 18 years old and legally able to enter into a contract. If you use the Portal for an organisation, you confirm that you are authorised to accept these Terms on its behalf, and “you” means both you and that organisation. Each scan request requires a separate confirmation that you are authorised to assess the submitted assets; that confirmation is recorded with the request.
2. What the Portal actually does
The Portal performs real, active security scanning against live systems that you submit. It is not a simulation and it is not limited to passive data collection. Depending on the scan configuration selected by Naunet operators, a scan may include:
- discovery of domains, subdomains, hosts, addresses, web addresses and publicly available information related to the assets in scope;
- review of your domain name and email security configuration;
- network port and service discovery, including identification of the software and versions you expose;
- testing of your encryption configuration;
- review of your web security configuration;
- web server, web application, technology and content-discovery checks;
- network vulnerability scanning;
- limited, read-only enumeration of file-sharing services that are already confirmed to be publicly reachable;
- inspection of publicly served application files and publicly listable cloud storage for exposed internal addresses and credential material;
- matching the software versions we detect against known vulnerabilities, which sends no traffic to your systems.
Scans are intended to be non-destructive. We do not exploit vulnerabilities, brute-force credentials, write to or modify your systems, or perform denial-of-service testing. Scan traffic originates from Naunet infrastructure, so it will not appear to come from your own network.
3. Authorisation is your responsibility
You may only submit assets that you own or that you are expressly authorised in writing to assess. You are solely responsible for holding that authorisation before you submit a scan request, and for keeping it valid for the whole duration of the scan, including retries and repeated scans you have enabled.
Before submitting, you must confirm that:
- every submitted domain, host, URL and IP range is within your legal and contractual scope;
- you have any consent required from hosting providers, cloud providers, CDNs, managed service providers and other third parties whose systems or acceptable-use policies are affected;
- scanning the assets does not breach any law, regulation, contract or policy that applies to you or to them.
Unauthorised scanning may be a criminal offence in many jurisdictions. You accept full responsibility for the assets you submit and for the consequences of submitting assets you were not authorised to assess.
4. Scope, verification and blocked targets
A scan request carries its own declared scope: a primary domain and, optionally, further domains you own, IP ranges you own, and exclusions. Each domain requires its own ownership verification. Domains that are not verified are withheld from the scan, and the reason is shown on the scan page. An exclusion always takes precedence over an inclusion.
The Portal applies its own restrictions on top of your declaration. Addresses announced by content delivery networks and other shared edge providers are kept in the inventory but withheld from active scanning, because they are not your assets. Government and military names, and other names on our block list, are rejected; assessing high-traffic, government or protected third-party domains requires a separate, explicitly agreed engagement. These controls are safeguards for our benefit and do not reduce your obligations under section 3; you must not rely on them to establish that a target is authorised.
5. Acceptable use
You must not, and must not allow anyone else to, use the Portal to:
- scan, probe, enumerate or gather information about any asset you do not own or are not authorised to assess;
- perform reconnaissance against competitors, customers, suppliers, former employers, public figures, private individuals or any other third party;
- circumvent or attempt to circumvent scope declarations, ownership verification, the target block list, plan limits, duplicate-scan rules or any other control in the Portal;
- submit false, borrowed or misleading ownership, authorisation or contact information;
- share, sell or transfer account access, or let others submit scans through your account;
- create multiple accounts to obtain additional free scans or to evade a suspension;
- use findings to attack, extort, harass, publicly shame or otherwise harm the operator of any system;
- resell, sublicense or present Portal output as an independent audit, certification or penetration test unless we have agreed that in writing;
- scan, load-test, attack or attempt to gain unauthorised access to the Portal itself or to Naunet infrastructure, or interfere with other customers’ use of the service;
- reverse engineer, scrape, or use automated means to extract data from the Portal beyond its documented interfaces;
- upload malicious content, or use free-text fields to attempt injection against the Portal, our staff or downstream tooling;
- use the Portal in breach of applicable sanctions or export-control rules, or for any unlawful purpose.
Naunet may report suspected unlawful activity to the relevant authorities and to affected asset owners, and may disclose the account data, scan records and audit logs necessary to do so.
6. Operational risk you accept
Active scanning generates real network traffic against real systems. Even a non-destructive scan can consume bandwidth and server resources, produce large volumes of log entries and alerts, trigger intrusion detection, rate limiting, WAF rules or automated blocking, generate test records or notification emails, and in rare cases cause fragile or unmaintained services to slow down or stop responding. A scan may run for many hours and may be retried automatically after a failure.
You are responsible for choosing an appropriate time, for informing your own operations, security and provider teams, and for having working backups and recovery procedures. You accept these risks and their consequences for the assets you submit.
7. Accounts and sign-in
Sign-in uses our identity provider and, where enabled, third-party identity providers. You are responsible for the security of the account and identity provider you use to reach the Portal, for the accuracy of your profile and contact details, and for all activity under your account. Tell us promptly if you suspect unauthorised access. Sensitive actions, including session revocation, profile updates and scan lifecycle changes, are recorded in an audit log.
8. Plans, limits and repeated scanning
Free use is limited. A free account is limited to a single scan request, and a given domain can be claimed for a free scan only once; a further scan of the same domain, or a second concurrent scan, requires a paid plan or our explicit agreement. A domain that already has a queued or running scan cannot be submitted again until that scan finishes. Where repeated scanning is available and you enable it, scans repeat on the interval you choose within the supported range of 14 to 90 days, and each repeat is a new scan request under these Terms, including the authorisation obligations in section 3. You may disable repeated scanning at any time.
9. Notifications
We send service email about your scans and account. If you provide a mobile number and enable SMS notification, we send scan-ready messages through our SMS provider, subject to quiet hours in your configured timezone. Message and data rates from your carrier are your responsibility, and delivery is not guaranteed. You can turn SMS off, or unsubscribe from scan reminders, at any time. Where scheduling is offered, meeting bookings are handled by a third-party scheduling provider.
10. What you submit, and what we keep
The Portal stores the identifiers, preferences, scan targets and declared scope, state transitions, results and exports needed to operate the service, and logs scan requests for audit, abuse prevention, troubleshooting and service improvement. The detailed raw data collected during a scan is deleted automatically after 90 days; the results and exports stored in the Portal are retained until you or we delete them.
Do not submit credentials, secrets, API keys, regulated personal data, or other sensitive information that the scan does not need, in notes or any other free-text field. Where a scan legitimately surfaces credential-like material from your own publicly served files, it is handled as a finding and shown in redacted form. Our handling of personal data is described in the Privacy notice.
11. What the results are, and are not
A report, finding, risk index, CSV or PDF export from the Portal is a point-in-time output based on what the scan could observe from the internet at that moment. It is not exhaustive. Coverage may be reduced by systems that cannot be reached, by blocking from your own defences, by restrictions at your providers, and by parts of a scan timing out or failing; where we can detect this, we record it in the result rather than hiding it.
Some findings are inferred rather than proven. Findings derived from detected software versions are marked as unconfirmed and may be false positives. Absence of a finding is not evidence that a system is secure. All output requires competent human review before you act on it, and it is not a penetration test, a compliance certification, an audit opinion, or legal advice.
12. Intellectual property
Naunet retains all rights in the Portal, the scanner, our finding and report content, and everything else we make available, including the structure and wording of findings. You may use the reports and exports for your own internal security, remediation and compliance purposes, and share them with advisers and auditors under a duty of confidentiality. Any other redistribution or commercial use needs our written permission. You keep your rights in the data you submit and grant us the licence needed to run the scan and provide the results.
13. Third-party services and tools
The Portal relies on third-party infrastructure and on established security tools, and results depend on their behaviour and on third-party vulnerability data. We are not responsible for the accuracy, availability or conduct of third-party services, and their inclusion does not imply any endorsement or warranty.
14. Suspension and termination
We may limit, pause, suspend or terminate access, cancel a queued or running scan, or withhold results at any time, including on suspected misuse, unauthorised targeting, complaints from an asset owner, security risk, abusive load, non-payment or maintenance need, and where required by law. Where practical we will tell you why. You may stop using the Portal at any time. Sections 3, 5, 10, 11, 12, 15, 16 and 17 survive termination.
15. No warranty
The Portal is provided on an as-is and as-available basis. To the maximum extent permitted by law, Naunet disclaims all warranties, express or implied, including accuracy, completeness, fitness for a particular purpose, uninterrupted or error-free operation, merchantability and non-infringement. We do not warrant that a scan will identify every vulnerability, misconfiguration or exposed asset, or that it will run without interruption.
16. Limitation of liability
To the maximum extent permitted by law, Naunet is not liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost business, loss of goodwill, service interruption, or loss or corruption of data, arising from or connected to your use of the Portal, even if we were told such damage was possible.
Our total aggregate liability for all claims relating to the Portal is limited to the greater of the amounts you paid us for the Portal in the twelve months before the event giving rise to the claim, or EUR 100. Nothing in these Terms excludes liability that cannot be excluded by law, including liability for death or personal injury caused by negligence, for fraud, or for wilful misconduct.
17. Misuse: no responsibility, and your indemnity
Naunet accepts no responsibility or liability for any misuse of the Portal, its scanning capability, or its output, whether by you, by anyone using your account, or by anyone to whom you pass results. This includes scanning assets without authorisation, any disruption, alerting, blocking, contractual breach, regulatory action or third-party claim resulting from a scan you requested, and any use of findings to attack, extort or otherwise harm a system operator. You use the Portal at your own risk and on your own authority.
You will indemnify and hold harmless Naunet and its personnel against all claims, proceedings, losses, damages, fines, penalties and reasonable costs, including legal fees, arising from your breach of these Terms, your submission of assets you were not authorised to assess, your use or disclosure of scan results, or your unlawful use of the Portal.
18. Changes
The Portal is under active development, and scan behaviour, checks, limits and features may change. We may update these Terms; the version and effective date at the top of this page always show the current text. Material changes will be notified through the Portal or by email where we can. Continued use after a change takes effect means you accept the updated Terms, and each new scan request is accepted under the version in force at the time.
19. Language
These Terms are published in English and in Hungarian. The two versions are intended to say the same thing. If they differ, the English version prevails, except where the law that applies to you requires otherwise.
20. Governing law and contact
These Terms are governed by the laws of Hungary, and the courts of Hungary have exclusive jurisdiction, without affecting any mandatory consumer-protection rights you have where you live. If a provision is unenforceable, the rest stays in force. Questions about these Terms: mate.torok@naunet.eu.