Acceptable Use Policy

Draft — not yet reviewed or approved by counsel. Last updated 2026-09-02.

Warning: This is a draft, not a finished legal document

This page states, plainly, the boundaries Wraith enforces technically — see Terms of Service §2 — and what happens if they’re crossed. It has not been reviewed by a lawyer.

Only your own, authorized domains

You may only submit a domain you own or are explicitly authorized to have assessed. Wraith requires proof of control (a DNS TXT record) and an explicit authorization confirmation before any assessment runs — for every domain, every time, with no exception.

What the assessment is limited to

Wraith performs only the specific, non-destructive checks described on the site — reading DNS records, completing a TLS handshake, and one unauthenticated request per authorized hostname over HTTP and HTTPS. It never attempts exploitation, port scanning beyond what those checks require, password guessing, denial-of-service testing, or authenticated access of any kind, and it is not configurable to do otherwise.

Automated or abusive use

Submissions are rate-limited, and repeated attempts to verify domains you do not control, or to abuse the checkout or verification flow, may result in requests being blocked.

What happens if this policy is violated

An order may be blocked before or after payment if authorization cannot be confirmed or is withdrawn. See Terms of Service for how a blocked, paid order is handled.