Skip to main content

Terms of Use

Effective as of August 2026

The public scan (this page's core service) is and remains free, with no account and no billing. SecureCheck also offers paid add-ons (Badge, Fix-it-for-me, API) — these Terms of Use govern the whole service, including access conditions to the scan engine; the commercial terms specific to the paid offers (pricing, right of withdrawal, cancellation) are set out in our Terms of Sale.

Article 1 — Purpose

These Terms of Use define the conditions under which Kortilabs provides the "SecureCheck" service: a free online tool that runs a passive security scan of a website supplied by the user (HTTP security headers, exposed files, CORS misconfiguration, exposed API keys, TLS certificate).

Article 2 — Authorized use — user responsibility

You may only submit the URL of a website that you own or that you are expressly authorized to scan. Scanning a third-party site without authorization may constitute an offense under the laws applicable to you. The user remains solely responsible for the URLs they submit and for verifying that they have the right to scan them. Kortilabs may block or restrict access to the service for any user in case of suspected abuse.

Article 3 — Nature of the checks and limits

SecureCheck performs only passive HTTP requests (equivalent to a normal browser visit): no port scanning, no intrusion attempt, no exploitation of any vulnerability. The service does not send any authentication attempt, no fuzzing, and does not interact with any system other than the one whose URL was submitted.

SecureCheck does not guarantee the exhaustiveness of the detection performed. The absence of a reported issue does not mean the scanned site is secure: only the checks actually implemented at the time of the scan (security headers, exposed files, CORS, exposed API keys, TLS certificate) are performed. The service does not replace a full security audit or a professional penetration test.

Article 4 — Rate limiting

Access to the public scan endpoint (/api/scan) is subject to a rate limit of 10 scans per minute per IP address, with no authentication required. The authenticated API endpoint (/api/v1/scan, see Article 4bis) is subject to its own, independent limit of 60 requests per minute per license key. These limits protect the service against abuse and mass automated use against third-party targets.

Article 4bis — Authenticated API (/api/v1/scan)

Kortilabs also offers an authenticated API endpoint running the exact same passive scan engine and the same authorization rule as the public scan (Article 2): you may only submit the URL of a website you own or are expressly authorized to scan, whether you call the service through the public form or through the API with a license key. Pricing and commercial conditions for this offer are set out in our Terms of Sale, not in these Terms of Use.

Article 5 — No data retention

Scan results are computed and returned entirely in memory, for the duration of a single HTTP request, and are never persisted, stored, or logged by Kortilabs. See the Privacy Policy for details.

Article 6 — Availability

The service is provided on a best-effort basis, with no uptime guarantee. Kortilabs reserves the right to modify, suspend or discontinue the service at any time, in particular in case of abuse or excessive load.

Article 7 — Liability

Kortilabs cannot be held liable for any direct or indirect damage resulting from the use of the service, including in the event of an incomplete or incorrect scan result, unavailability, or use of the service to scan a target without proper authorization. The user is solely responsible for the consequences of the URLs they submit.

Article 8 — Governing law

These Terms of Use are governed by French law. Any dispute falls under the exclusive jurisdiction of French courts.