Kavach

Acceptable Use Policy

Part of the Terms of Service. Effective 10 October 2026.

Kavach exists to help website owners secure their own sites. It only ever makes ordinary, read-only requests. This policy sets the rules that keep it that way.

1. Authorisation

You may scan, monitor, report on, guard or publish a Trust Passport for a website or domain only if you own it or hold the express authorisation of its owner. Agencies and consultants must hold that authorisation from each client before adding the client’s domains. Keep evidence of authorisation; we may ask for it.

2. Prohibited conduct

You must not, and must not help anyone else to:

3. Operators of scanned sites

Every request Kavach makes carries the User-Agent KavachScanner with a link to this policy and the contact abuse@kavachscan.com. If you operate a website and do not wish it to be scanned by anonymous users, email us and we will block Public Scans of your domain; verified owners always retain control of their own domains.

4. Enforcement

We may refuse or throttle scans, remove Passports or badges, suspend or terminate accounts, and preserve and disclose relevant records to law-enforcement or affected parties where we reasonably believe this policy has been breached or the law requires it. Report abuse to abuse@kavachscan.com.