Skip to content

Scan policy

VibeSafely is built for indie projects, startups and commercial apps shipped with AI coding tools. Every scan is an active probe of a live site, so we only run one when two things are true: you confirm you're authorized to test the target, and the target isn't in a protected category.

How a scan is authorized

  1. 1. You explicitly confirm ownership or written permission before the scan starts. That acknowledgement is timestamped and stored with the scan.
  2. 2. The target is checked against the global blocklist below — on the client, on the server, in the public API, and again on every redirect hop the scanner follows.
  3. 3. An AI classifier reviews the hostname as a second layer, so protected organisations on ordinary .com or .org domains — a regional hospital, a defense supplier, a credit union — are refused even when they match no keyword or TLD rule.
  4. 4. Private, loopback, link-local and cloud metadata addresses are refused, so a scan can never be pointed at internal systems.
  5. 5. Probes are read-only, rate limited and time bounded. We never attempt exploitation, brute force, or data modification.
  6. 6. Refused attempts are logged for audit and reviewed for abuse.

Domains we never scan

These categories are blocked worldwide, in every country and language, regardless of who requests the scan — including you, on your own account.

Government & public sector

Any .gov, .gov.*, .gob.*, .go.*, .gouv.*, .govt.*, .gc.ca, .int domain, plus named agencies worldwide.

senate.gov · parliament.gov.uk · gobierno.gob.mx · interpol.int

Military & defense

Any .mil or .mil.* domain, armed-forces sites, and defense contractors and their suppliers.

army.mil · bundeswehr.de · lockheed-martin.com

Healthcare & medical

Hospitals, clinics, health services, patient portals and medical record systems in any country.

nhs.uk · anything containing hospital, clinic, patient, medical

Banking & financial services

Retail and central banks, payment processors, exchanges, insurers and regulated financial platforms.

wellsfargo.com · stripe.com · any .bank or .insurance domain

Critical infrastructure

Power, water, gas, nuclear, telecom backbone, rail, ports, airports and emergency services.

power-plant, water-utility, nuclear, airport-authority, grid operators

Academic & research

Universities and schools: .edu, .edu.*, .ac.* and equivalent academic namespaces.

mit.edu · ox.ac.uk

Why

Unauthorized probing of protected systems can violate the Computer Fraud and Abuse Act (USA), the Computer Misuse Act (UK), and equivalent legislation elsewhere — even when the intent is defensive. Blocking these categories outright protects our users and us. Attempts to bypass the blocklist may be reported to the relevant authorities. See the terms of service.