This document is being finalised with our legal counsel; contact legal@codereviewer.cloud with questions.
This Acceptable Use Policy applies to everyone who uses CodeReviewer. It is part of our Terms of Service. If we believe it has been breached, we may suspend or restrict access.
Security testing
CodeReviewer can scan web applications for security weaknesses. Some scans are passive: they observe responses without sending attack traffic. Others are active: they send attack-style requests.
- You may run active scans (and any load or stress testing we offer) only against domains you own, or are explicitly authorised in writing to test, and have verified in CodeReviewer. Verification uses a DNS record or a file hosted on the domain, and it is re-checked regularly.
- Do not try to get around domain verification. Do not verify a domain you do not control. Do not point scans at third-party services, shared infrastructure you don’t control, or other customers’ systems.
- Passive scans must still only target applications you are authorised to assess.
- Schedule intensive scans with care, and coordinate with your hosting provider where its terms require it.
- You are responsible for any testing you direct, and for its effect on the systems you target.
Code and repositories
- Only connect repositories, applications and databases you are authorised to grant access to.
- Do not submit content that you have no right to use or share, or that infringes others’ rights.
Prohibited uses
You may not use the Service to:
- break the law, or help anyone else break it;
- develop, test or distribute malware, or deliberately generate exploits against systems you are not authorised to test;
- access, or try to access, other customers’ data, workspaces or accounts;
- probe, scan or test the security of the Service itself, except under our responsible disclosure process at security@codereviewer.cloud;
- disrupt or overload the Service, or get around usage limits, allowances or access controls;
- resell or sublicense the Service without our written agreement;
- scrape or reverse engineer the Service, or use it to build a competing product;
- store secrets or credentials in the Service for systems you are not authorised to access.
Test credentials and data
Use dedicated test accounts wherever you can. Where possible, avoid pointing test suites or Bug Explorer at production data containing personal information.
Reporting
To report abuse or a suspected breach of this policy, email abuse@codereviewer.cloud. To report a security vulnerability in CodeReviewer, email security@codereviewer.cloud.