Scan what's yours. That's the whole policy.
A security scanner is a dual-use tool. This is the line, and what we do on either side of it.
Last updated 25 July 2026
Scan only what is yours
You may point ShipShape at a site only if you own it, or you have permission in writing from whoever does.
Scanning someone else's system without permission may be a criminal offence — the Computer Fraud and Abuse Act in the US, the Computer Misuse Act in the UK, and equivalents elsewhere. Whether we technically allowed the request is not a defence. This is on you.
We enforce part of this at a technical level: anything that sends an actual attack payload requires you to prove control of the target first, by placing a file we generate at a path on that site. The free instant check does not require that, because it only makes the same plain requests a browser already makes.
What we will not let you point it at
ShipShape refuses to scan internal and reserved addresses — localhost, private networks, and cloud metadata endpoints — at the moment it opens the connection, not just when you type the address. This stops the scanner being used as a way into a network it should not reach.
Do not use ShipShape to test infrastructure you do not control, to stress or overload any system, or as a step in an attack.
If we find something on a site that is not yours
A free scan can be run against any address, so it is possible to point ShipShape at a stranger's site and see a real problem. We have designed around that as far as we reasonably can:
- Secret values are masked until ownership is proved.
- Data from an exposed database is never recorded — only column names and a row count.
- A shareable report link is only ever created for a scan where ownership was proved, so nobody can mint a public page listing someone else's vulnerabilities.
If you find something on a stranger's site
Tell them, not us, and tell them privately. Give them time to fix it before it goes anywhere public. Do not use what you found, do not access their data, and do not ask them for money — that last one is extortion, however it is phrased.
If you cannot find a contact, look for a security.txt file at their domain, which exists for exactly this.
Reporting a flaw in ShipShape itself
We would rather hear it from you than from an attacker. Email hello@shipshapelabs.com with enough detail to reproduce it.
We will acknowledge within five working days, keep you updated, and credit you if you want the credit. We will not take legal action against anyone who reports a flaw in good faith, keeps it to themselves until it is fixed, does not access or modify data belonging to anyone else, and does not degrade the service for other people.
Please do not run automated scanners against our own infrastructure. The irony is noted; the traffic still costs us money.
What happens if you break this
We suspend the account. If the activity looks like an attack on a third party we will cooperate with that third party and, where required, with law enforcement.
These pages describe how ShipShape actually behaves and were written to be accurate rather than to be comprehensive legal cover. They have not been reviewed by a solicitor. Get that review before taking payment.