Terms of Service

Draft pending legal review · updated 18 July 2026 · plain-language by intent

1. Who we are and acceptance

SurakshaScan ("we", "us") is a website health-and-safety check owned and operated by SurakshaScan, in India. By using SurakshaScan (the "Service") you agree to these Terms. If you use it for an organisation, you confirm you are authorised to bind it.

2. What SurakshaScan is

A passive, external, point-in-time health check of a website you ask us to scan: the same observations a browser makes when it visits a site (DNS, TLS/SSL, HTTP headers, technology, reputation signals). It returns a health score, a grade, and the top findings in plain language. Scans run when you request one. If you add a site you are authorised to assess to your watch list, we re-run the same passive check on a schedule and record what changed between checks. We never crawl beyond the check you asked for.

3. What it is not

  • Not a guarantee of security or safety. A score is a point-in-time observation, not a promise.
  • Not a penetration test. We never exploit, log in, brute-force, fuzz, or attack. We only observe.
  • Not a compliance certification or audit. We do not certify that your site meets any standard (DPDP, CERT-In, ISO, PCI, etc.). Reports support your own posture; the compliance claim is yours.
  • Not a statement that you have been compromised. A finding describes a visible configuration, not a breach.

4. Eligibility

The Service is for website owners and operators who are at least 18 and able to enter a binding contract. It is not directed at children.

5. Free check and private beta access

The free health check is available to everyone without an account: it returns the score, grade, and top findings for the address you enter. The full report, scan history, and dashboard are part of an invite-only private beta: that access requires Google sign-in and inclusion on our allowlist, and is personal, non-transferable, and revocable at any time. The beta is for evaluation, may change or be discontinued, and carries no availability or service-level commitment.

6. Authorized use only

Scan only websites you own or are explicitly authorised to assess. You are responsible for that authority for every target. You must not: scan third parties without permission; plan or support any attack or unauthorised testing; circumvent rate limits, the access gate, or the target protections; automate, scrape, resell, or build a competing dataset from the Service; reverse engineer it (except where law allows); or submit internal, private, or metadata addresses (blocked by design). We may suspend access for any suspected breach.

7. Your responsibilities

For every scan, you represent that you own the target domain or are explicitly authorised to have it assessed, and that your use complies with all applicable laws. The decisions you make from a report are yours.

8. Intellectual property

The Service, engine, scoring logic, explanations, and interface are owned by SurakshaScan. You get a limited, non-exclusive, revocable licence to use the Service and its reports for your own internal purposes. You may not republish or resell reports or present them as a third-party certification.

9. What we store

For the scan, the website address you enter and the sanitized result (findings, scores, timestamps). We do not read or store page content. Because beta access needs Google sign-in, we also store your Google account email to verify you against the allowlist, and your scans are linked to your account so you can see your history. We record your authorisation attestation (that you confirmed you may scan the sites you submit) and, with it, your consent to a sanitised, non-personal product-improvement record of what scans find. If you use the watch list, we store the sites you watch and the changes we detect. We never sell your data. Full detail in the Privacy Notice, which forms part of these Terms.

10. Data location and third parties

Scan data is stored in India. Sign-in is handled by Google / Firebase Authentication, which may process authentication data outside India (see the Privacy Notice). Reputation checks use Google Web Risk, which receives only the address being checked, never personal data.

11. Cookies and similar technologies

We do not use advertising, analytics, or cross-site tracking cookies. The Service uses only what it needs to work:

  • Bot protection (free check). The free scan is protected by Google reCAPTCHA Enterprise, which tells humans and automated traffic apart. Google may set cookies (such as _GRECAPTCHA) and collect device and interaction signals for this purpose, under the Google Privacy Policy and Terms of Service. If these are blocked — for example in a private/incognito window or with cookies disabled — the scan may fail verification; enable cookies and reload to try again.
  • Sign-in state (beta members). Google / Firebase Authentication keeps your sign-in session in your browser's local storage so you stay signed in. This is first-party and essential; it is not used for tracking.

Blocking these technologies may stop parts of the Service from working, but you are free to do so in your browser settings.

12. Disclaimers

The Service is provided "as is" and "as available," without warranties of any kind. We do not warrant it will be uninterrupted or error-free, or that findings are free of false positives or negatives. A scan is a point-in-time, external observation only.

13. Liability and indemnity

To the maximum extent permitted by law, we are not liable for indirect or consequential loss, or for any loss arising from reliance on a result, a security incident, or a compliance determination; our total liability is capped as set out in the full Terms. You will indemnify us against claims arising from your misuse of the Service or from scanning any target you were not authorised to assess.

14. Changes, governing law, and grievances

We may update the Service and these Terms; material changes appear here with a new date. These Terms are governed by the laws of India; the courts of competent jurisdiction in India apply (a specific jurisdiction will be set when a formal entity is established). For abuse reports, takedowns, questions, or any grievance, contact contact@surakshascan.com.

Abuse, takedown, or questions: contact@surakshascan.com