Legal Document
Legal Notice
Scanner transparency, responsible use and vulnerability disclosure · Version 2.1
This notice explains the nature of Coruzen Security, how our scanner technically operates, how to identify and block it, and how to safely report vulnerabilities and cases of misuse.
1. Purpose of this notice
This document supplements the Terms of Use and Privacy Policy, detailing the technical and operational aspects of the Coruzen Security scanner for system administrators, security teams and domain owners who may be the target of an authorized analysis.
2. Nature of the Service: best-practices checking — not a pentest
Coruzen Security is a best-practices and security-hygiene assessment tool for developers who want to evaluate their own websites, SaaS products and applications — including applications built with the help of AI.
Coruzen Security is NOT a penetration testing (pentest) tool, does NOT perform brute-force attacks against credentials, does NOT perform denial-of-service (DoS/DDoS) attacks, and does NOT actively exploit vulnerabilities. The Service only identifies improvement opportunities and best-practice deviations through public, passive checks, without causing any damage or instability to systems, whether the User's own or a third party's.
3. How the scanner operates
Coruzen Security performs exclusively passive, non-invasive checks:
- Standard HTTP/HTTPS requests only (GET/HEAD);
- No payload injection, exploitation or credential testing;
- No brute-force or denial-of-service actions;
- Respect for robots.txt directives;
- Request volume limited so as not to impact your server.
4. Identification
Our scanner identifies itself with the following User-Agent:
CoruzenSecurityScanner/1.0 (+https://security.coruzen.com/legal/security-notice)
5. Blocking the scanner
To prevent analyses of your domain, add this to your robots.txt:
User-agent: CoruzenSecurityScanner Disallow: /
You can also ask to have your domain added to our permanent blocklist by emailing security@coruzen.com.
6. Exclusive use on your own or authorized domains
We reiterate that Coruzen Security is intended exclusively for analyzing domains owned by the requester or domains for which the owner has granted express authorization, as set out in Clause 5 of our Terms of Use. We do not perform, and do not authorize use of the platform to, hunt for vulnerabilities in third-party systems without authorization.
7. Responsible disclosure
Found a vulnerability in the Coruzen Security platform itself? Please report it responsibly to security@coruzen.com.
We follow a 90-day coordinated disclosure policy and will not pursue legal action against good-faith research that respects this policy (safe harbor).
8. Reporting misuse against your domain
If you have identified misuse of our platform against your domain, send the evidence to security@coruzen.com. We will block the offender and cooperate with the authorities where appropriate.
9. Informational nature of reports
Reports are informational and do not constitute legal advice, a formal audit or a security certification. Implementing any fix is the User's sole responsibility, preferably carried out by a qualified professional — see the detailed limitation of liability in the Terms of Use.
Contact the security team
Vulnerability reports answered within 48 hours.