Terms

Terms of use.

Shipleak is free and needs no account. These are the rules that come with that — most importantly, only scan sites you're entitled to scan.

Last updated 1 August 2026

Who these terms are with

These terms are between you and the team operating shipleak.com. By using the site you agree to them. If you don’t, please don’t use it. Anything unclear, email hello@shipleak.com.

Only scan sites you're allowed to scan

When you submit a URL, we make real HTTP, DNS, and TLS requests to that host from our servers. You must only scan a site that you own, or that you have permission from the owner to test.

Unauthorised scanning of someone else’s infrastructure may be unlawful where you are, where we are, or where they are. You are responsible for having the right to scan what you submit, and you agree to indemnify us against claims arising from scans you run without that right.

What the scanner actually does is deliberately narrow: it requests pages the way a browser or search engine would, reads response headers, checks DNS and TLS configuration, and looks for a fixed list of commonly exposed paths. It does not attempt to log in, submit forms, guess credentials, exploit anything it finds, or alter your site in any way. It is a read-only inspection, not a penetration test.

Fair use

Scanning is free and we intend to keep it that way, which only works if nobody abuses it. Please don’t script bulk scans, run the scanner as part of another product, or attempt to bypass the rate limits. We limit requests per IP address and may block traffic that looks automated.

Reports are shareable, and public to anyone with the link

Each scan gets a permalink with no password on it. Anyone with the link can read the report. Don’t share one containing something you’d rather keep private, and email us if you want a report deleted.

No warranty, and what that actually means

Shipleak is provided as-is. We make no guarantee that it is available, uninterrupted, or error-free, and we may change or withdraw any part of it.

More usefully: a clean report does not mean your site is secure. We run a fixed set of checks against what a site returns over the network. We do not review your source code, your dependencies, your infrastructure, your access controls, or your application logic, and there are entire categories of vulnerability we cannot see from the outside. Treat a good score as evidence that a particular list of mistakes was avoided, not as an audit, a certification, or a substitute for professional security review.

Findings can also be wrong in the other direction. A finding may be a false positive, or may not apply to how your site is actually deployed. Use your judgement before acting on one, especially where the fix touches production.

Fix prompts

Reports include suggested prompts for AI coding tools. They are a starting point, not reviewed advice, and we have no idea what else is in your codebase. Read any change before you apply it — the responsibility for what you ship stays with you.

Liability

To the extent the law allows, we are not liable for indirect or consequential loss, lost profits, lost data, or business interruption arising from your use of Shipleak. Where liability cannot be excluded, it is limited to the amount you have paid us in the twelve months before the claim — which, for the scanner, is nothing.

Nothing here limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.

Sponsors

The site is paid for by sponsor slots. Sponsors have no access to the scan engine and buying a slot cannot change a finding, a severity, or a score. Sponsor links are marked rel="sponsored". If you want to advertise, see the advertising terms.

Changes, and getting in touch

We may update these terms as the product changes; the date at the top of this page is when they last did. If something here affects you and seems wrong, say so — hello@shipleak.com reaches a person, and we would rather fix a term than argue about one.