← Compass Scan

ACCEPTABLE USE · VERSION 2026-10-07

Use Compass lawfully and responsibly.

You may request an assessment only when you have sufficient authority, permission or another lawful basis. A target being publicly reachable does not by itself establish authorisation.

Prohibited use

Current scan boundary

Compass assesses publicly reachable targets through bounded GET, HEAD and OPTIONS-style observation, normal rendered-browser activity and one bounded high-confidence consent-rejection interaction when an unambiguous control is found. It does not log in, submit credentials, escalate privilege, execute exploits, deliberately modify target data, perform credential attacks or make destructive changes. Unsafe methods and WebSocket activity are blocked or bounded. This boundary does not make an otherwise unauthorised assessment permissible.

Evidence and reports

Do not submit secrets as target URLs or use reports to expose confidential data unnecessarily. Reports are informational observations, not penetration tests, audits, certifications, compliance opinions or guarantees that vulnerabilities are absent.

Enforcement

We may reject a target, rate-limit use, revoke an invitation or beta access, preserve relevant audit evidence, or suspend or terminate an account where use threatens a target, Compass, another person or compliance with law. See the Terms and Privacy Notice.