Perimeterwatch Sign in
Perimeterwatch

Legal and policy documents

These are the terms the service intends to work under. They describe what the software does today, and they say plainly what is not settled yet.

DraftsNot legal advice, not yet reviewed by a lawyer, and not yet in force. The service is in beta. Every open point is marked in the text, so that nothing unsettled reads as a promise.

Terms of service

The agreement between the operator and an organisation that uses the service.

For: Organisations using the service · 15 open points

Privacy policy

What personal data is handled, why, and what rights people have.

For: Organisations, their staff, the public · 28 open points

Scanning authorisation and acceptable use

What proving control of a domain authorises, the three scan depths, and what is forbidden.

For: Organisations, operators of scanned hosts · 5 open points

Opt-out for operators of scanned hosts

How the operator of a host that received traffic can make it stop.

For: Operators of scanned hosts · 1 open point

Data retention

What is kept, for how long, and how it is deleted.

For: Organisations, lawyers · 13 open points

Data processing agreement: outline

Outline of a data processing agreement under GDPR Article 28.

For: Organisations, lawyers · 27 open points

Vulnerability disclosure

How to report a security problem in the service itself.

For: Security researchers · 1 open point

Legitimate interest assessment: template

A template an organisation can adapt for its own records.

For: Privacy or security leads · 1 open point

How open points are marked

Not yet decided a fact or choice the operator has not settled To be confirmed a proposed value Not yet built something the text needs that the software does not do yet For legal review a point that needs a lawyer's judgement

The source of every document is in the public repository, with its history. To ask about any of them, write to hello@perimeterwatch.org.