Acceptable Use Policy

Last updated: 18 September 2026

This policy sets out what you may and may not do with VigiLayer. The short version: only check websites you own or are formally authorised to manage. Everything else here follows from that one rule.

Draft for review. This was written to match how VigiLayer actually works, but it has not been reviewed by a lawyer. Fill in every [HIGHLIGHTED] item and have a qualified legal professional check it before you publish.

1. The core rule

You may only add and monitor a domain if you own it, or you are authorised in writing by its owner to manage it.

This is not a formality. It is the reason VigiLayer requires you to prove control of a domain, by adding a DNS record, before it will run any checks beyond the ones any ordinary web browser performs. If you cannot add that record, you do not have the access this service assumes you have.

2. What VigiLayer does, and does not do

VigiLayer performs passive, non-invasive checks. It reads information your website already publishes to anyone who visits it: response headers, certificate details, public DNS records, and public registry data. It behaves like a visitor, not an intruder.

VigiLayer does not, and you must not attempt to make it:

If you need genuine penetration testing, that is a different service requiring explicit scoped permission from the site owner. VigiLayer is not it, and does not claim to be.

3. Prohibited uses

You must not use VigiLayer to:

4. If you manage websites for clients

Agencies and freelancers are welcome, and are a large part of who VigiLayer is for. If you add a domain belonging to a client:

We recommend keeping a written record of that authorisation. If a site owner ever queries why their website is being checked, that record is what resolves it.

5. Being a good citizen of the internet

VigiLayer identifies itself. Our checks carry a recognisable user agent so any site owner or hosting provider can see who we are, and we keep a log of every check we run and who requested it. We do this so that if a host ever asks why their server was contacted, we can answer honestly.

We also apply rate limits. These protect the websites being checked as much as our own infrastructure, and they are not negotiable per account.

6. What we do if this policy is broken

Depending on what has happened, we may:

For a clear, deliberate breach, such as repeatedly trying to monitor domains you do not control, we will usually act immediately rather than warn first.

7. Reporting misuse

If you believe someone is using VigiLayer against a website they do not own, or you are a site owner who wants to know why your website was checked, contact us at vigilayer@meltoninternational.com. Include the domain and an approximate date, and we will investigate against our logs.

Site owners may also ask us to block their domain from being added by anyone who has not proved control of it.

8. Changes

We may update this policy as the service changes. We will update the date at the top, and tell you about significant changes before they take effect.


See also our Terms of Service and Privacy Policy.