Skip to main content
Soryvex
Product Guides Methodology Pricing
Sign in Scan free
Product Guides Methodology Pricing Sign in Scan free
  1. Home
  2. Terms of Service

Legal

Terms of Service

Last updated: September 2026

1. Service Overview

Soryvex performs automated external security assessments of public websites and domains. An assessment inspects publicly reachable, externally observable surface area, such as DNS records, email security configuration, TLS posture, HTTP security headers, cookies, exposed technologies, subdomains, and related signals, and generates a report with findings, supporting evidence, and remediation guidance. The Service may also let you re-run an assessment to verify that a fix took effect.

2. Eligibility and Accounts

You must be at least 18 years old and able to form a binding contract. If you use the Service on behalf of a company or organization, you confirm that you are authorized to bind it to these Terms.

You must be able to receive email at the address you register. You are responsible for the accuracy of your account information, for keeping your credentials confidential, and for all activity under your account. You must not share account credentials with third parties. Notify us promptly at the address in Section 18 if you suspect unauthorized access.

3. Authorization to Assess

You may request an assessment only of a domain or website that you own or are expressly authorized to assess. This is your responsibility as a matter of contract and law, and it applies to every assessment, whether or not the Service asks you for proof of control.

Two levels of check. Running an assessment and unlocking the full check surface are separate things:

  • A basic assessment can be run on any public web address straight away, without proof of control. It covers the checks an outside observer can make unauthenticated.
  • The full check surface is unlocked only after you prove you control the domain, by publishing a verification record we issue in your domain's authoritative DNS zone. Proof of control is required for the full level; it is not required for the basic one.

Every report states which of the two levels it ran at, so a report can always be read in the right context. We may decline, suspend, or cancel an assessment where we have reason to believe authorization is missing, and we may require proof of control at any time.

By submitting a target, you represent and warrant that:

  • you own the target or have the owner's prior, explicit, written permission to have it assessed by the Service, including permission for the requests described in Section 4;
  • you will comply with all applicable laws, including computer misuse and unauthorized-access laws, and with any third-party hosting, cloud, or network provider rules that apply to the target; and
  • you will not use the Service, or any report, to gain unauthorized access to, disrupt, or harm any system, or to help anyone else do so.

You are solely responsible for any assessment you request. We may decline, suspend, or cancel any assessment at our discretion, including where we have reason to believe authorization is missing.

4. How Assessments Work

Assessments are performed from our infrastructure using standard, non-intrusive network requests to the target's public-facing services (for example, DNS queries, TLS handshakes, and HTTP requests). We design the Service to avoid exploitation, credential guessing, denial-of-service, or intentionally disruptive activity, and to refuse private, internal, or reserved addresses and hostnames. However, assessment traffic will appear in the target's logs and may trigger monitoring, firewall, or intrusion-detection alerts. You are responsible for informing the relevant parties on your side and for any effects on the target.

5. Reports and Results

Reports are produced from automated scanning and analysis of the target as observed at the time of the scan, and may use automated or machine-learning-assisted tools to organize and explain results. Scan evidence is the basis of every finding, but automated tools have limits: findings may include false positives or miss issues (false negatives), severity ratings and confidence levels are estimates, and the target's state may change after the scan. You should independently review findings and remediation guidance before acting on them.

A report is not a penetration test, red-team engagement, code review, compliance audit, certification, or guarantee that a system is secure or free of vulnerabilities.

6. Plans, Payment, and Refunds

Access to the Service depends on the plan or assessment pack you purchase. Features, limits, and allowances are described at checkout and may vary by plan. Prices are in U.S. dollars and exclude any applicable taxes, which you are responsible for. Payments are processed by third-party payment providers; we do not store full payment card details.

Assessment allowances. An assessment that the Service is unable to complete does not count toward your allowance.

Recurring plans. If you purchase a recurring subscription, it is billed in advance and renews automatically each billing period until you cancel. You can cancel at any time in your account settings, and cancellation takes effect at the end of the current billing period. We will notify you in advance of any price change, which applies from your next billing period.

Refunds. Except where required by applicable law or stated otherwise at checkout, fees are non-refundable. If you believe you were charged in error, contact us within 30 days of the charge.

7. Suspension and Termination

We may suspend or terminate your account or access to the Service, with or without notice, if you breach these Terms, if we reasonably suspect unauthorized or unlawful use, or if required by law. You may stop using the Service and close your account at any time.

If we terminate your account for breach, unused allowances are forfeited. If we terminate your account without cause, we will refund the value of unused prepaid allowances. Sections that by their nature should survive termination (including 3, 9, 12 through 15) will survive.

8. Reports, Data, and Privacy

The detailed report is available only to the account that initiated and paid for the assessment, while signed in to that account. We do not publish or index reports. We may access and retain assessment and report data to operate, secure, and improve the Service, to prevent abuse, to comply with legal obligations, and as described in our Privacy Policy, which explains how we collect and use personal information.

9. Intellectual Property

We and our licensors own the Service, including its software, scan logic, report templates, and branding. We grant you a limited, non-exclusive, non-transferable, revocable license to use the Service and to use reports you receive for your own internal security and business purposes, including sharing them with your own team, contractors, and advisors. You may not resell the Service or reports as your own service, copy or reverse engineer the Service, or use it to build a competing product.

10. Acceptable Use

You agree not to:

  • assess any account, server, network, or domain you are not authorized to assess, or submit private, internal, or reserved hostnames or IP addresses;
  • use the Service to attack, disrupt, or gain unauthorized access to any system, or to develop or deliver malicious tooling;
  • interfere with or overload the Service, bypass usage limits, or circumvent our security or authorization controls;
  • use automated means (other than any API we provide) to access the Service, or use the Service in violation of applicable law.

11. Requests from Domain Owners

If you own or control a domain and believe it was assessed without your authorization, or want us to stop assessing it, contact us at the address in Section 18 with the domain and reasonable proof of control. We will review the request promptly and may block further assessments of that domain.

12. Disclaimers

THE SERVICE AND ALL REPORTS ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, COMPLETENESS, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE, THAT ALL VULNERABILITIES OR MISCONFIGURATIONS WILL BE DETECTED, OR THAT ANY TARGET IS OR WILL BE SECURE. ASSESSMENTS REFLECT CONDITIONS AT THE TIME OF THE SCAN.

13. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, SORYVEX AND ITS OWNERS, OFFICERS, EMPLOYEES, AND AFFILIATES WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, OR GOODWILL, ARISING FROM OR RELATED TO THE SERVICE OR THESE TERMS, EVEN IF ADVISED OF THE POSSIBILITY. OUR TOTAL LIABILITY FOR ALL CLAIMS RELATING TO THE SERVICE WILL NOT EXCEED THE AMOUNT YOU PAID US IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. Some jurisdictions do not allow certain limitations, so parts of this section may not apply to you.

14. Indemnification

You agree to defend, indemnify, and hold harmless Soryvex and its owners, officers, employees, and affiliates from any claims, damages, losses, and expenses (including reasonable attorneys' fees) arising from your breach of these Terms, your violation of law, or any assessment you requested of a target you were not authorized to assess.

15. Governing Law and Disputes

These Terms are governed by the laws of the State of Israel, without regard to its conflict-of-law rules. Any dispute arising out of or relating to these Terms or the Service shall be subject to the jurisdiction of the competent courts in the Tel Aviv District, Israel, to the extent permitted by applicable law.

Before bringing a claim, you agree to contact us at [email protected] and make a good-faith effort to resolve the dispute informally for at least 30 days, unless applicable law permits or requires a claim to be brought sooner.

16. Changes to the Service and These Terms

We may modify the Service or these Terms at any time. When we make material changes, we will update the "Last updated" date and notify you by email or through the Service. Continued use after changes take effect means you accept the updated Terms. If you do not agree, stop using the Service.

17. General

These Terms and the Privacy Policy are the entire agreement between you and Soryvex regarding the Service. If any provision is found unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. We are not liable for delays or failures caused by events beyond our reasonable control.

18. Contact

Questions about these Terms, authorization or removal requests, and legal notices: [email protected]

Soryvex Security Ltd. is a company registered in Israel. Soryvex was founded and is owned by Tomer Grinberg.

Soryvex

Automated external security assessments for websites and domains.

Product

  • Website security scanner
  • What we check
  • How it works
  • Free security check
  • Pricing

Use Cases

  • For agencies and MSPs
  • Security headers checker
  • TLS and SSL checker
  • DNS and email checker
  • WordPress security scan

Resources

  • Example security report
  • Methodology
  • Guides

Company

  • External attack surface
  • Security
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
© 2026 Soryvex Security Ltd. Reports are viewable online by the account that ran the assessment.