Skip to content

Legal

Hoshiro Labs Acceptable Use Policy

Effective date: 21 August 2026

1. Purpose

This Acceptable Use Policy protects Hoshiro Labs, Hoshiro ARC customers, third-party website operators and the integrity of the scanning and monitoring service. It applies to all use of Hoshiro ARC and related APIs, accounts and features.

2. Authorised website assessment only

You may scan, monitor or request remediation for a website only where you own, operate, manage or have permission or another lawful basis to assess that website. You must not use ARC as an unauthorised vulnerability scanner, penetration-testing platform, scraping service or reconnaissance tool against systems you are not authorised to assess.

3. Prohibited technical activity

  • Attempting to scan localhost, private networks, cloud metadata services, internal infrastructure or other targets that ARC blocks for safety.
  • Attempting to bypass authentication, rate limits, anti-bot controls, scan allowances, concurrency controls or other technical restrictions.
  • Using automated requests at a volume that degrades Hoshiro or third-party infrastructure.
  • Submitting malware, malicious URLs or instructions intended to exploit Hoshiro systems, third-party websites or other users.
  • Attempting to reverse engineer security controls or obtain secrets, credentials or data belonging to other customers.
  • Using ARC to facilitate denial-of-service activity, credential attacks, unlawful surveillance or any other harmful or illegal conduct.

4. Accounts and free-scan limits

You must not create or coordinate multiple accounts, clear identifiers, rotate infrastructure or use other techniques for the purpose of defeating free-scan, rate-limit or commercial restrictions.

5. Content and instructions

You must not submit content or instructions that are unlawful, fraudulent, defamatory, infringing, abusive, discriminatory, deceptive or intended to cause harm. You must have the rights necessary for any materials you provide to Hoshiro for remediation or publication.

6. Remediation access

Access supplied for implementation must be lawfully provided and limited to what is reasonably required for the agreed work. Do not send passwords, private keys or confidential credentials through public forms or report fields. Follow the secure access process specified for the engagement.

7. Resale and white-labelling

You may use ARC reports for your internal business purposes and may share them with legitimate advisers or service providers. You must not resell access, white-label Hoshiro services, reproduce Hoshiro report templates at scale or commercially exploit ARC methodology without written permission.

8. Monitoring and enforcement

Hoshiro may use technical controls and logging to detect abuse, protect customers and enforce this Policy. We may rate-limit, reject, suspend or terminate activity reasonably believed to violate this Policy or create material risk. Where appropriate, we may preserve evidence, cooperate with lawful authorities or notify affected service providers or customers.

9. Reporting concerns

To report suspected abuse or a security concern involving Hoshiro ARC, contactsupport@hoshirolabs.com. Legal notices may be sent tolegal@hoshirolabs.com.