Acceptable Use Policy
Last updated: June 10, 2026
This Acceptable Use Policy ("AUP") sets out the rules for using Perimeter, the external attack-surface management platform operated by Mithras R&D AS. It forms part of the Terms of Service. Using the service in violation of this AUP is a material breach of the Terms.
1. Authorized targets only
You may only submit for discovery or scanning assets — domains, subdomains, IP addresses, and services — that you own, control, or are explicitly authorized in writing by the owner to have tested. You must be able to demonstrate that authorization on request, and you must remove assets from your inventory promptly if your authorization ends.
2. No attacks on third parties
You must not use findings, scan data, or any other output of the service to attack, exploit, or gain unauthorized access to systems belonging to third parties. Findings exist to help you remediate your own exposure, not to target others.
3. Platform integrity
- Do not attempt to access data belonging to other tenants or to subvert tenant isolation.
- Do not probe, scan, or test the Perimeter platform itself except through an authorized disclosure program.
- Do not circumvent rate limits, usage quotas, or scan-scheduling controls.
- Do not interfere with or disrupt the service, its infrastructure, or other customers' use of it.
- Do not share account credentials or use another user's account without permission.
4. No resale of scan data
You must not resell, sublicense, or commercially redistribute scan results, findings, or other data obtained from the service. Sharing reports with your own auditors, regulators, customers, or service providers in connection with your security program is permitted.
5. Unlawful and abusive use
You must not use the service for any unlawful purpose, including violations of computer-misuse, data-protection, export-control, or sanctions laws, or to facilitate harassment, fraud, or the distribution of malware.
6. Reporting abuse
If you believe the service is being used in violation of this AUP — for example, if your systems are being scanned without your authorization — report it to abuse@mithras.no. Include relevant timestamps, source addresses, and log excerpts so we can investigate quickly. We review all abuse reports and respond to verified reporters.
7. Enforcement and suspension
We may suspend scanning of specific assets, suspend or terminate accounts, and remove data where we reasonably believe this AUP has been violated, where required by law, or where continued operation poses a risk to third parties or to the platform. Where practical we will notify you and give you an opportunity to remedy the violation before suspension, but we may act immediately for serious abuse.
8. Contact
Questions about this policy can be directed to Mithras R&D AS at abuse@mithras.no.