What we keep, and what you are responsible for

This service can reach other people's infrastructure, so the terms are specific rather than general. This page says what is stored, what is refused and where the responsibility sits.

Lookups

A DNS or address lookup is answered and not kept against your account. We record that the service was used, in aggregate, because that is how anything is operated — but not a per-account history of what you looked up.

Scans and scrapes

These are kept: the account, the target, the timestamp and the authorisation you gave. That record is what an abuse report from an upstream provider is answered with, and it is retained rather than rotated away for exactly that reason. It is not sold, shared or used for anything else.

What you are responsible for

Authorisation. You state per scan that you may test that target, and that statement is what we rely on. Using this against infrastructure you do not control is a breach of these terms as well as, in many places, the law — and it is grounds for us to suspend the account and to answer a report with your details.

What we refuse regardless

Private, loopback, link-local and metadata ranges, our own infrastructure, and anything on the denylist. There is no tier that lifts those, and no support request will.

Questions

Is port scanning legal?

It depends where you and the target are, and scanning a host you are not authorised to test is unlawful in many jurisdictions regardless of intent. That is why scanning here needs an account and a per-scan statement that you are authorised to test that target — and why every scan is logged against the account that ran it.

What will you refuse to scan?

Private, loopback and link-local ranges, the cloud metadata address, our own infrastructure, and anything on the denylist. Those refusals are not configurable by a customer, and a range larger than the per-scan cap is refused before any packet is sent.

Do you store what I look up?

A lookup is answered and not kept against you. A scan is kept — the account, the target, the time and the authorisation statement — because that record is what an abuse report is answered with, and keeping it is the condition of offering the feature at all.