Permitted use
Use Domain Signals only for targets you are permitted to assess and for legitimate defensive, governance, supplier or professional-service purposes.
Legal LEG-005
Acceptable use policy sets out the current invite-beta operating position for Customer, security researcher. These operating terms explain the invite-beta service in direct language. They should be read with the product's technical and evidence boundaries, not as a substitute for them.
Bounded, non-exploitative Authorised external assessment.
The useful answer
Acceptable use policy sets out the current invite-beta operating position for Customer, security researcher. Acceptable use policy sets out the current invite-beta operating position for Customer, security researcher. These operating terms explain the invite-beta service in direct language. They should be read with the product's technical and evidence boundaries, not as a substitute for them.
Route-specific context
Current operating document
Use Domain Signals only for targets you are permitted to assess and for legitimate defensive, governance, supplier or professional-service purposes.
Do not use the service for exploitation, credential attacks, harassment, evasion, unlawful surveillance, arbitrary internet-wide collection or attempts to exceed the governed collector boundary.
Do not bypass rate, entitlement, tenant, authority or provider-right controls; interfere with queues or workers; upload hostile content; or probe another customer's account.
Do not present candidate associations as confirmed vulnerabilities, shared infrastructure as customer-owned exposure or an Overall Signals Grade as certification or complete organisational security.
Suspected misuse may be rate-limited, paused, investigated or terminated. Material security events are recorded in the audit trail and may be reported where required.
This is the current founder-adopted invite-beta operating version. It does not claim external legal certification.
A deliberate path
Read who acceptable use policy governs and which version is in force.
Check the operating effect against your intended use: understand prohibited use and assessment limits.
Use the contact route before relying on an unclear term; the product interface does not silently broaden the document.
Evidence before assertion
The applicable record is the version displayed when an action is taken. Material changes are dated, retained and presented before they govern a future use of the service. The exact target, source, observation time, responsibility and evidence state remain available to entitled readers.
Domain Signals performs bounded, non-exploitative authorised external assessments of submitted domains.
Product contract and collector capability registerThe assessment uses direct protocol observations and passive intelligence but stops before exploitation, authentication attempts, brute force and fuzzing.
Collector policy and protocol adapter testsPermission confirmation records the customer's warranty of authority; it is not independent proof of ownership.
Authority contract and audit recordDirect answers
Acceptable use policy sets out the current invite-beta operating position for Customer, security researcher. It establishes only what the governed evidence supports.
It does not prove complete organisational security, exploitability, breach likelihood or the absence of unobserved weaknesses.
Use the linked evidence or capability record to inspect source, observation time, target, responsibility and the condition required for closure.