Acceptable use
You must be authorized to scan the host#
If you rent the server, authorization usually also means checking your provider's policy on port scanning your own instance.
The design limits misuse#
- There is no field to type a target. The connecting IP is the only target.
- Shared address space is refused, so a scan cannot hit a neighbour behind the same CGNAT.
- Proxy, VPN and Tor origins are refused on a best effort basis, so the connecting IP is more likely to be a host you actually control.
Reporting a problem#
Security disclosures, false positives and opt out requests go through qsa.sh/contact, which routes to the support queue. There is no inbound email server, so mail sent to a qsa.sh address is not received.
Next#
- Data retention
- Target detection
- Back to the index