shadowperimeter

Terms of service

Last updated: October 7, 2026

In short: we only assess domains you own or are authorized to assess, using public information unless you give us written authorization for more. Our reports are a point-in-time view, not a guarantee of security or a compliance certification. Disputes are first handled by talking.

Acceptance and eligibility

By requesting a snapshot, buying a service or using this site you accept these terms. The services are for businesses and for people over 18 acting on a business's behalf.

The services

Authorization and scope (important)

You confirm that you own each domain you submit or are an authorized representative of its owner, and that you have the authority to authorize its assessment. You must not request an assessment of a domain or system you do not control.

Passive by default. The Snapshot, the Perimeter Report and Monitoring are limited to passive reconnaissance of information that is already public: public DNS records, certificate-transparency logs, and publicly visible web pages and headers requested the way an ordinary visitor's browser would. We do not exploit vulnerabilities, guess or test passwords, run denial-of-service or intrusive scans, bypass access controls, use social engineering, or access non-public data or systems.

Anything beyond passive requires a signed authorization that defines the systems, methods, dates and contacts. Without it, we will not do it.

Email Hardening: we change DNS records only after your written authorization and the access you grant, using a staged plan with a record of the original values so changes can be reversed. You are responsible for keeping your own backup of your DNS zone and for telling us about mail senders we may not know about. Email delivery can be affected by changes to authentication records; we reduce this risk but cannot eliminate it.

Third-party systems (such as your email, hosting or DNS provider) are subject to their own terms; you are responsible for having the right to grant us access to them.

Deliverables and timing

Delivery times we state (for example, a snapshot within 2 business days or a report within 48 hours) are targets, not guarantees, and may be longer if we need information from you.

What the reports are, and are not

A report is a point-in-time view based on public information. It may contain false positives or miss things (false negatives), and it does not cover internal systems. It is not a guarantee that you are secure, a penetration test, a certification or audit (for example PCI DSS, HIPAA, SOC 2, ISO 27001), a cyber-insurance assessment, or legal advice. You decide what to fix and when, and you remain responsible for your systems, data and compliance. "Real-time" or immediate detection is not promised: Monitoring runs periodic checks and alerts are best-effort.

Fees, payments and refunds

Your responsibilities

Confidentiality and findings

We keep your reports and findings confidential and share them only with you (and with people you designate), except where the law requires disclosure. We may use anonymized, aggregated statistics that cannot identify you. We will not name you as a client, quote you or use your findings publicly without your written permission. If we notice signs that your systems are being actively abused, we will tell you promptly.

Intellectual property

You may use your report for your internal purposes. We keep our tools, methods, templates and know-how. The content of this site belongs to Shadow Perimeter.

No warranties

THE SITE, THE SNAPSHOT AND THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE". TO THE EXTENT THE LAW PERMITS, WE MAKE NO EXPRESS OR IMPLIED WARRANTIES (INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT), AND WE DO NOT WARRANT THAT ANY SYSTEM IS OR WILL BE SECURE, THAT ALL VULNERABILITIES WILL BE FOUND, OR THAT EMAIL AUTHENTICATION WILL PREVENT ALL SPOOFING OR FRAUD.

Limitation of liability

TO THE EXTENT THE LAW PERMITS, SHADOW PERIMETER IS NOT LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, OR REPUTATION, OR FOR ANY SECURITY INCIDENT, BREACH OR FRAUD AFFECTING YOU. OUR TOTAL LIABILITY FOR ANY CLAIM WILL NOT EXCEED THE FEES YOU PAID FOR THE SERVICE GIVING RISE TO THE CLAIM IN THE 12 MONTHS BEFORE THE EVENT (OR US$100 FOR THE FREE SNAPSHOT). SOME RIGHTS CANNOT BE LIMITED BY LAW AND THAT DOES NOT CHANGE.

Indemnification

You will defend and reimburse reasonable costs of Shadow Perimeter against third-party claims arising from (a) your misrepresenting your authority over a domain or system, (b) your use of a report to harm others, or (c) your breach of these terms or the law, unless the claim results from our negligence.

Suspension and termination

We may decline, suspend or end a service immediately if we suspect you lack authority over a domain, if you breach these terms, or if continuing creates a legal or security risk. You may cancel Monitoring as described above.

Dispute resolution

Let's talk first. Write to ceo@shadowperimeter.com describing the problem and we both have 30 days to resolve it. If it is not resolved, any dispute will be settled by individual arbitration before the American Arbitration Association (AAA) with a single arbitrator, in Los Angeles County, California (or by video), and not in court or as a class action: you waive class actions and jury trial. Either party may go to small-claims court if the case fits there, and urgent relief may be sought from a court to protect intellectual property or confidential information. You may opt out of arbitration by writing to us within 30 days of accepting these terms.

Governing law

These terms are governed by the laws of the State of California, USA, without regard to its conflict-of-laws rules. For anything not subject to arbitration, the courts of Los Angeles County, California have exclusive jurisdiction.

Credentials, names and trademarks

References on this site to bug-bounty findings are given in line with the disclosure rules of the programs involved. Company and product names mentioned belong to their owners; Shadow Perimeter is independent and is not affiliated with, sponsored or endorsed by them.

General provisions

If any part of these terms is invalid, the rest remains in force. No delay in enforcing a right is a waiver. You may not assign these terms without our permission. Neither party is liable for failures caused by events beyond its reasonable control. These terms and any signed authorization or proposal are the entire agreement, and a signed authorization prevails over these terms where they conflict. You agree to receive notices electronically.

Accessibility

We want everyone to be able to use this site. If something does not work for you, write to ceo@shadowperimeter.com and we will help or provide the information another way.

Changes and contact

We may update these terms; the new version will be published here with its date, and continued use means you accept it. Questions: ceo@shadowperimeter.com. See also our privacy policy and vulnerability disclosure policy.