Acceptable Use Policy
Effective June 2026
The short version
Uvy is a tool for testing systems you own or are explicitly authorized to test. Use it for that, and nothing else. This policy is part of our Terms; violating it may result in suspension of your access.
What you may test
Only applications, domains, and assets you own or have explicit, current authorization to assess. You must prove control of each target (the DNS or file check we provide) and confirm you are authorized before any assessment runs. Where a third party hosts or operates the target (a cloud or infrastructure provider, for example), you are responsible for obtaining any permission their policies require.
What you may not do
Do not use Uvy to test, scan, probe, or attack any system you do not own or are not authorized to test. Do not attempt to access, alter, or exfiltrate other customers' data, or Uvy's own systems beyond the intended product surface. Do not use Uvy to break the law, evade another provider's terms or rate limits, conduct denial-of-service against third parties, send spam or malware, or harass anyone. Do not resell or provide the service to others to do any of these.
Use the safety controls as intended
Do not attempt to bypass scope enforcement, the kill switch, the egress controls, or the authorization checks. Pick the test mode appropriate to your environment, and run against staging or a quiet window where intensity could affect availability. You are responsible for testing the right environment and for any precautions or backups you want in place.
Accounts and access
Keep your credentials secure; you are responsible for activity under your account. Tell us promptly if you suspect unauthorized access, and don't share access in a way that circumvents these terms.
Enforcement
We may refuse, suspend, or halt any assessment, and suspend or terminate access, to prevent harm, misuse, or a violation of this policy or the law; where we can, we'll tell you why. Testing systems without authorization can violate computer-misuse laws, and you are solely responsible for ensuring you have the right to test. Your authorization and indemnity obligations in the Terms apply to all testing you initiate, including against third-party-hosted targets.
Reporting and contact
To report abuse or a security concern, email [email protected]. Questions about this policy: [email protected]. We may update this policy; material changes take effect when posted here.