Terms of Service
Effective date: 10 July 2026
These terms govern your use of Cyber Report (the "Service"), operated by amondi Media d.o.o. za usluge, Radnička cesta 47, 10000 Zagreb, Hrvatska ("we", "us" — see the Impressum for full company details). By creating an account you agree to these terms.
1. What the Service is
Cyber Report performs an external, non-intrusive security assessment of a website you own or are authorized to test, and produces a report of its findings. The Service examines only what is publicly reachable from the outside — it does not require, and you must not provide, access credentials to the target site.
2. Your account
You must provide accurate registration information, keep your password confidential, and be at least 16 years old. You are responsible for activity that happens under your account. Notify us promptly at [email protected] if you suspect unauthorized use.
3. Authorization to scan — the important part
Security scanning a system without permission may be unlawful. By submitting a domain you represent and warrant that you own the domain or have the explicit authorization of its owner to have it scanned, and each time you start a scan you re-confirm this. We independently require proof of control before any active scan runs — a DNS record, a file on the site, or a one-time code sent to an email address at the domain. Controlling a mailbox at the domain is the weakest of these signals and does not by itself establish that you are authorized to test the site; whichever method you use, that check supplements — it does not replace — your warranty above.
If you submit a domain you are not authorized to test, you are solely responsible for the consequences, and you will indemnify us against any claims, damages and costs arising from that unauthorized scan. We may suspend or terminate accounts that attempt to scan targets they do not control.
4. Acceptable use
You must not:
- attempt to scan domains you do not own or lack authorization for, or circumvent ownership verification;
- use the Service, its reports or its AI features to prepare or facilitate an attack on any system;
- probe, disrupt or overload the Service itself, or attempt to access other customers' data;
- resell or provide the Service to third parties as your own without our written agreement;
- use the Service in violation of applicable law.
5. How scanning behaves
Scanning is designed to be safe and rate-limited, but it is a security test, not ordinary crawling. To assess your site it sends probe requests that a normal visitor would not, including:
- checks of which HTTP methods your server accepts (for example TRACE, PUT, DELETE, PATCH), sent without a request body so they inspect configuration rather than change data;
- harmless "canary" inputs in URL parameters and query fields to detect injection, open-redirect and reflected-input weaknesses — these are detection markers, not working exploits.
Within those checks, scans do not attempt to log in, submit forms that write data, run working exploits, or deliberately damage anything, and they throttle their request rate per target. Nonetheless, no remote security testing can be guaranteed side-effect-free: some servers, application firewalls or fragile endpoints may react to probe traffic (for example by logging alerts, rate-limiting you, or behaving unexpectedly). You accept this residual risk for the targets you submit, you confirm you are authorized to have them tested (Section 3), and you are responsible for scheduling scans appropriately for your infrastructure.
6. Reports, findings and their limits
A report reflects an automated, point-in-time, outside-in view of the target. It may contain false positives (issues reported that are not exploitable) and false negatives (real issues that automated external scanning cannot see). A clean report does not mean a site is secure, and a finding is not proof of a breach. The Service is not a penetration test, security audit or certification, and does not by itself make you compliant with any standard (PCI DSS, ISO 27001, GDPR or otherwise).
Reports are prepared for you. You may share your own reports freely, but you may not present them as issued or endorsed by us for third-party marketing purposes.
7. AI-generated content
Finding explanations and attack narratives are generated by a large language model (provided by Anthropic). They are drafted from your scan's findings to help you understand and prioritize — they may be imprecise or incomplete and are not professional security advice. Verify before acting on them.
8. Fees
The Service is currently offered without charge while in its early-access phase. We may introduce paid plans; prices and payment terms will be shown before you buy, and these terms will be updated accordingly. Features available to you during early access may change or become paid.
9. Termination and deletion
You can delete your account at any time on your profile page — this permanently erases your account, scans and reports (see the Privacy Policy for details). We may suspend or terminate your access if you materially breach these terms, with notice where practicable. Sections that by their nature should survive termination (warranties, indemnity, liability limits, governing law) survive.
10. Liability
To the maximum extent permitted by law, the Service is provided "as is" and we are not liable for indirect or consequential damages, loss of profits, or loss of data arising from use of the Service, including decisions made (or not made) based on a report. Nothing in these terms limits liability for intent or gross negligence, or any liability that cannot be limited under applicable law. Mandatory consumer-protection rights under Croatian and EU law remain unaffected.
11. Changes to these terms
We may amend these terms as the Service evolves. For material changes we will give notice (on this page and, for significant changes, by email) before they take effect. Continued use after the effective date constitutes acceptance.
12. Governing law and disputes
These terms are governed by Croatian law. Disputes are subject to the jurisdiction of the competent court in Croatia; if you are a consumer in the EU, you retain the protection of the mandatory rules and courts of your country of residence. Information on out-of-court consumer redress in the EU is available at consumer-redress.ec.europa.eu.
13. Contact
Questions about these terms: [email protected].