Aegis — Acceptable Use Policy
Incorporated into the Terms of Service. Bracketed items [LIKE THIS] need your decision.
Version: [1.0] · Effective: [DATE]
The one rule that matters most
Only submit targets you own or are expressly authorised in writing to test.
Aegis sends real security-testing traffic. Pointed at someone else's system, that is an attack — and in most jurisdictions a criminal offence. DNS verification is our technical control, but it is not a substitute for your authority to test the underlying systems.
You must
- Prove control of every target through the DNS verification we issue.
- Hold authorisation from every party with an interest in the target — including your hosting, cloud and CDN providers, and, where the system is operated for someone else, that client.
- Comply with your providers' security-testing policies (DigitalOcean, AWS, Azure, Google Cloud, Cloudflare and others each publish their own; they change, so check them).
- Select the correct tier: state-changing (aggressive) testing only against non-production targets.
- Maintain backups and a rollback plan before any state-changing test.
- Keep a contact reachable during a testing window, and stop testing if you observe adverse effects.
- Use dedicated, low-privilege test accounts for authenticated testing — never a real customer, administrator or privileged production account — and rotate those credentials afterwards.
- Keep your account credentials secure and report suspected compromise promptly.
You must not
- Submit a target you do not own or are not authorised to test — including "just to see", a competitor's site, a former employer's system, or a target you believe is abandoned.
- Attempt to test infrastructure belonging to a provider rather than the application: Cloudflare, DigitalOcean, AWS, Azure, Google Cloud and equivalents are never in scope. Aegis will refuse these; do not attempt to circumvent that refusal.
- Target systems that process
[HIGH-RISK CATEGORIES — e.g. medical devices, industrial control systems, safety-critical or life-supporting systems]without a separate written agreement with us. - Use the Service to conduct denial-of-service, load, stress or flooding testing.
- Use the Service against private, reserved, loopback or internal addresses except via an approved private-agent deployment.
- Circumvent, disable or attempt to defeat any safety control, rate limit, quota, ownership verification, entitlement gate or emergency stop.
- Share, resell or provide access to the Service to third parties except as permitted by your plan, or use it to provide testing services to others without a written reseller or partner agreement.
- Use the Service to develop a competing product, or to scrape, reverse-engineer or extract its detection logic.
- Represent an Aegis report as a security certification, an accreditation, or as proof that a system is free of vulnerabilities.
- Use the Service unlawfully, or to harass, extort or damage any person or organisation.
Automated enforcement
The Service enforces much of this in code, and fails closed by design: unverified targets are refused; provider infrastructure and private ranges are blocked; state-changing tests are refused against production; per-tenant quotas and rate limits apply; and every approval decision is recorded.
Reporting abuse
If you believe Aegis is being used against a system you own, contact
[abuse@backbonesolutions.ca] with the target and any evidence. We investigate and can
suspend an account immediately.
Consequences
We may suspend or terminate access immediately, without refund, for breach of this policy, and may be required to preserve and disclose records to law enforcement. You remain liable for loss arising from your breach, including under the indemnity in the Terms of Service.