Acceptable Use Policy
This policy sets out what you may and may not do with VigiLayer. The short version: only check websites you own or are formally authorised to manage. Everything else here follows from that one rule.
1. The core rule
You may only add and monitor a domain if you own it, or you are authorised in writing by its owner to manage it.
This is not a formality. It is the reason VigiLayer requires you to prove control of a domain, by adding a DNS record, before it will run any checks beyond the ones any ordinary web browser performs. If you cannot add that record, you do not have the access this service assumes you have.
2. What VigiLayer does, and does not do
VigiLayer performs passive, non-invasive checks. It reads information your website already publishes to anyone who visits it: response headers, certificate details, public DNS records, and public registry data. It behaves like a visitor, not an intruder.
VigiLayer does not, and you must not attempt to make it:
- Attack, exploit, or break into any website
- Submit forms, place orders, create accounts, or log in anywhere
- Guess or test passwords
- Send large volumes of traffic, or anything resembling a denial-of-service
- Access parts of a website that are not publicly reachable
- Read, copy, or extract the contents of a database
If you need genuine penetration testing, that is a different service requiring explicit scoped permission from the site owner. VigiLayer is not it, and does not claim to be.
3. Prohibited uses
You must not use VigiLayer to:
- Check a domain you do not own or manage, including a competitor's, a former client's, or one belonging to an organisation you are researching
- Gather information for an attack, whether on a site you control or anyone else's
- Circumvent the verification step, or attempt to claim a domain by any means other than proving control of its DNS
- Resell, white-label, or redistribute VigiLayer's output except under an Agency plan that permits it
- Scrape, bulk-export, or automate against the service outside the documented interface
- Interfere with the service, its infrastructure, or other customers' use of it
- Use it in a way that breaks any law that applies to you or to the website being checked
4. If you manage websites for clients
Agencies and freelancers are welcome, and are a large part of who VigiLayer is for. If you add a domain belonging to a client:
- You confirm you have your client's authorisation to monitor it
- You remain responsible for everything done under your account
- You should remove a domain when your relationship with that client ends, and not continue monitoring a site you no longer have authority over
We recommend keeping a written record of that authorisation. If a site owner ever queries why their website is being checked, that record is what resolves it.
5. Being a good citizen of the internet
VigiLayer identifies itself. Our checks carry a recognisable user agent so any site owner or hosting provider can see who we are, and we keep a log of every check we run and who requested it. We do this so that if a host ever asks why their server was contacted, we can answer honestly.
We also apply rate limits. These protect the websites being checked as much as our own infrastructure, and they are not negotiable per account.
6. What we do if this policy is broken
Depending on what has happened, we may:
- Remove a domain from your account
- Suspend your ability to add new domains
- Suspend or close your account, without refund where the breach was deliberate
- Preserve and disclose relevant logs where the law requires it, or where a genuine attack appears to have been attempted
For a clear, deliberate breach, such as repeatedly trying to monitor domains you do not control, we will usually act immediately rather than warn first.
7. Reporting misuse
If you believe someone is using VigiLayer against a website they do not own, or you are a site owner who wants to know why your website was checked, contact us at vigilayer@meltoninternational.com. Include the domain and an approximate date, and we will investigate against our logs.
Site owners may also ask us to block their domain from being added by anyone who has not proved control of it.
8. Changes
We may update this policy as the service changes. We will update the date at the top, and tell you about significant changes before they take effect.
See also our Terms of Service and Privacy Policy.