1. Why this policy exists
Most ToolsXpo tools are pure computation — formatting, encoding, converting — and carry no risk to anyone. But some reach out over the network to a target you name: DNS and WHOIS lookups, port checks, URL scans, HTTP status checks, TLS and certificate inspection.
Those are ordinary diagnostic tools, and they are also the first step in attacking someone. This policy draws the line. It forms part of the Terms of Service, and breaching it is a material breach of that agreement.
2. The rule for network tools
Only scan or probe systems you own, or have documented permission to test."It was only a port scan" is not a defence — unauthorised scanning is a criminal offence in many jurisdictions, including under the UK Computer Misuse Act and the US Computer Fraud and Abuse Act.
You must not use the Service to:
- scan, probe or enumerate infrastructure you are not authorised to test;
- map a target's attack surface in preparation for an intrusion;
- generate load intended to degrade or deny service to anyone;
- evade a network block, rate limit or geographic restriction imposed by a third party; or
- obscure the origin of traffic in order to make abuse harder to trace back to you.
We log the calling IP address for every request. If we are contacted about abuse originating from the Service, those logs identify the account responsible.
3. General prohibited use
Do not use the Service to:
- break the law in any jurisdiction that applies to you or your target;
- infringe intellectual property or misappropriate trade secrets;
- process material that is unlawful to possess or distribute — in particular child sexual abuse material, which we report to the authorities;
- harass, threaten, defame or dox anyone;
- build or distribute malware, phishing pages, or credential-harvesting infrastructure;
- send spam, or generate content intended to deceive people about who is contacting them; or
- process personal data you have no lawful basis to process.
4. Protecting the Service
Do not:
- exceed your plan's rate limits deliberately, or spread traffic across accounts to get around them;
- create multiple accounts to farm free credits or evade a suspension;
- share, resell or sublicense API keys, or resell the API as your own service without a written agreement;
- attempt to reverse engineer, disassemble or extract the implementation of the Service;
- probe our own infrastructure for vulnerabilities without contacting us first (see §6); or
- use payment methods you are not authorised to use.
5. What happens if you breach it
Our response is proportionate to what happened:
- Accidental or minor — we contact you and ask you to stop.
- Serious or repeated — we suspend the account pending explanation.
- Illegal activity or harm to others — we terminate immediately, without notice, and unused credits are forfeited.
Where activity appears criminal, or where someone is at risk, we cooperate with law enforcement and preserve the relevant records.
6. Reporting
To report abuse originating from the Service, or a security vulnerability in it, email support@toolsxpo.com. Include timestamps and IP addresses where you have them.
We welcome good-faith security research against our own infrastructure. Contact us before you start, do not access other customers' data, and give us reasonable time to fix what you find. We will not pursue researchers who follow that.