Legal · Version 1.0 · Effective 27 July 2026

Acceptable use policy

What you may point the firmware analysis engine at, and the small number of things that get an account suspended.

This policy forms part of the terms of service. It is short because there are only a few rules and all of them matter.

Upload only what you have the right to analyse

That means your own firmware, or firmware you have written authorisation from the rights holder to examine. Firmware supplied to you by an ODM for a product you sell counts: it is in your product and you are the manufacturer placing it on the market.

Do not upload a competitor’s product to see what is in it. Do not upload something you pulled off a device you do not own. We cannot tell from a binary image whether you were entitled to analyse it, which is why the terms make that your responsibility and put the indemnity where it is.

Do not use the engine as a general file-analysis service

The analysis endpoint exists to produce a software bill of materials for a product you are documenting. Upload authorisation is a signed token bound to one scan and expiring in 15 minutes, specifically so that this endpoint cannot become an open malware sandbox. Do not try to work around that.

Do not use it to attack anyone

  • No using findings from the product to attack a system you are not authorised to test.
  • No uploading malware for the purpose of distributing it.
  • No attempting to break, overload or gain unauthorised access to the service or to another customer’s account.
  • No probing other customers’ trust pages, export links or determination links for data that is not yours. Those links are unguessable tokens, and treating them as a puzzle is not research.

Reporting a vulnerability in our service in good faith is welcome and is not a breach of this policy. Email us with "security" in the subject. We acknowledge within two working days, and we will not threaten you for telling us.

Do not put a false fact into a compliance artifact

The product refuses to present a rehearsal case as a filing, and it marks every gap in a document rather than filling it in with something plausible. Do not defeat those safeguards. A technical file with an invented component version or a rehearsal dressed up as a real notification is worse than no file at all, and it is the one misuse of this product that could hurt somebody other than you.

Fair use of the API

There is no rate limit on the API today. That is a gap rather than an invitation, and we say so on the API documentation page rather than advertising a limit we do not enforce. Use it at a sane rate. If we ever need to add a limit we will publish it before it starts.

Binary scans are metered per plan and that limit is enforced.

Crawlers

We do not block AI crawlers on this site, deliberately and permanently, and our robots.txt says so. Crawl what robots.txt allows, at a reasonable rate. Signed-in pages and customer data are not public and are not open to crawling.

What happens if you break this

We email you and ask you to stop. If the harm is immediate, or if there is a real risk to another customer, we suspend first and email straight after. Suspension does not delete anything, and you can still export your data.

We do not refund an account suspended for breaking this policy.

Version history

VersionDateWhat changed
1.027 July 2026First published.

DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America. Questions about this document go to hello@synthworx.com and a person answers.