Legal and policy documents
These are the terms the service intends to work under. They describe what the software does today, and they say plainly what is not settled yet.
Terms of service
The agreement between the operator and an organisation that uses the service.
For: Organisations using the service · 15 open pointsPrivacy policy
What personal data is handled, why, and what rights people have.
For: Organisations, their staff, the public · 28 open pointsScanning authorisation and acceptable use
What proving control of a domain authorises, the three scan depths, and what is forbidden.
For: Organisations, operators of scanned hosts · 5 open pointsOpt-out for operators of scanned hosts
How the operator of a host that received traffic can make it stop.
For: Operators of scanned hosts · 1 open pointData retention
What is kept, for how long, and how it is deleted.
For: Organisations, lawyers · 13 open pointsData processing agreement: outline
Outline of a data processing agreement under GDPR Article 28.
For: Organisations, lawyers · 27 open pointsVulnerability disclosure
How to report a security problem in the service itself.
For: Security researchers · 1 open pointLegitimate interest assessment: template
A template an organisation can adapt for its own records.
For: Privacy or security leads · 1 open pointHow open points are marked
Not yet decided a fact or choice the operator has not settled To be confirmed a proposed value Not yet built something the text needs that the software does not do yet For legal review a point that needs a lawyer's judgement
The source of every document is in the public repository, with its history. To ask about any of them, write to hello@perimeterwatch.org.