Skip to main content

Legal

Acceptable Use

A free service that fetches websites on request needs a clear position on what it will and will not be used for. This is that position.

Last reviewed 1 August 2026. Where this document changes materially, the revision date changes with it.

01

What these services are for

The analysis and free tools are intended for people trying to understand and improve a website. In practice that means:

  • a website you own or operate;
  • a client website you are engaged to work on;
  • a competitor’s public website, for comparison — this is a normal commercial activity and reads only what that site publishes to everyone;
  • a website you are evaluating as a prospective supplier, partner or acquisition;
  • a website you are considering commissioning work on, before committing to it.

Every one of these reads only information the website already serves to any visitor. Nothing about the analysis is distinguishable from an ordinary page view except that the requester identifies itself honestly.

02

What is not permitted

You must not use these services:

  • as part of reconnaissance for an attack, or to build a target list;
  • to attempt to reach private, internal or non-public network resources;
  • at a volume or frequency that places a burden on the website being analysed;
  • to circumvent access controls, authentication or rate limits on any website;
  • to gather personal information about individuals, or to assemble it for targeting;
  • to harass an organisation or individual, including by repeated analysis of a site you have no relationship with;
  • to test, probe or reverse-engineer IXSEO’s own infrastructure outside the disclosure process;
  • to resell access, to rebuild it as a competing service, or to automate it into another product.

03

What is enforced technically

Several of the limits above are not requests. They are properties of the system:

  • Private targets are refused. Hostnames are resolved and the resulting addresses checked against private, loopback, link-local, reserved and cloud-metadata ranges before any request is made. The check runs again on every redirect hop, so a public host cannot redirect into a private one.
  • Only http and https are requested. Other schemes are rejected during validation.
  • Requests are capped. Every fetch carries a timeout, a byte limit, a redirect limit and a content-type restriction.
  • Crawling is limited. An analysis fetches the home page and a small number of linked pages. It is not a site crawler and cannot be made into one.
  • Rate limits apply. Requests are counted against a salted, truncated hash of the source address. Exceeding the limit returns a clear refusal rather than a degraded result.
  • Nothing state-changing is sent. No forms are submitted, no authentication attempted, no input tested, no port scanned.

04

Active testing is a different service

Port scanning, service enumeration and vulnerability testing are never triggered from a public form, by anybody, for any domain. This is not a limit we may lift for a determined requester.

Where an organisation genuinely requires active technical assessment, it proceeds under a separate signed authorisation naming the legal entity, the authorising individual and their authority to grant it, the exact domains and address ranges in scope, the excluded systems, the testing window, the rate limits, the emergency contact and the stop conditions. Verification of a domain does not substitute for any part of that.

05

If use appears inconsistent with this policy

We may apply a stricter rate limit, refuse specific requests, or block access. We are not obliged to explain the specifics of a restriction to whoever triggered it, since doing so would mainly assist in working around it.

Where use appears to form part of an attack on a third party, we may retain relevant records and cooperate with a lawful request concerning it.

06

Reporting misuse

If you believe IXSEO has been used against your website inappropriately, get in touch through the contact page with the date, approximate time and the address involved. Our analyser identifies itself in its user agent, so it is straightforward to confirm in a server log. If you would simply prefer that we do not fetch your site, tell us and we will honour it.

Questions about this document can be raised through the contact page. Nothing here is intended to restrict rights you hold under applicable law.