Terms of use
Short and concrete: what you may do with DevOpsNL, what you may expect from it, and what it explicitly is not. Using the service means you agree to this.
Lees deze pagina in het Nederlands
Which domains you may scan
A Quick audit is read-only. It issues GET requests to publicly reachable pages only — exactly what any browser and any search engine does — and never attempts to exploit a weakness it finds. That is why you may run it against any public URL, including a site that is not yours.
Deep and Deepest are emphatically not that. They crawl multiple pages, reach into forms, and in the case of Deepest run active tests with payloads that get sent to a server. Those tiers run only against domains established to be under your control, and are released per domain.
So you may not point Deep or Deepest at a domain that is not yours and for which you hold no demonstrable written authorisation from the rights holder. Unauthorised active testing of someone else's systems can be a criminal offence under the Dutch Computer Crime Act. If we find a user doing it anyway, we close the account and cooperate with any investigation.
What an audit is and is not
An audit is an automated check for known, measurable problems, measured against published standards. Every finding arrives with evidence and with the standard it rests on, and the report states which checks could not run.
An audit is not a penetration test. A tester thinks, combines weaknesses and abuses business logic; no scanner does that. Nor is an audit an accessibility statement, a certification or legal advice. A green report means the machine-testable criteria are in order — not that your site is secure, accessible or compliant.
So do not use the report as evidence of compliance towards a regulator, an insurer or a procurement department without a human having judged the rest.
Availability, beta and pricing
The service is in beta. Functionality may change, outages can happen, and we give no availability guarantee.
The Quick audit is free. Deep and Deepest carry a one-off beta price per bundle of five audits and are available by invitation; there is no subscription and nothing renews automatically. Unused audits in a bundle do not expire while the beta runs.
Liability
We do our best to produce correct findings, but automated checks can both miss something and report something that is not there. You remain responsible for the decisions you take on the basis of a report and for the changes you make to your site.
Our liability is limited to the amount you paid for the audit in question. For free audits that means we are not liable, barring intent or deliberate recklessness on our part.
Abuse and termination
We may block use of the service in case of attempts to overload it, circumvention of domain verification, or use that conflicts with these terms or with the law.
You can stop at any time. If you ask for your data to be deleted, we handle that according to the privacy statement.
Governing law
These terms are governed by Dutch law. Disputes are submitted to the competent court in the Netherlands.