Legal
Acceptable Use Policy
Rules governing acceptable use of WhiteHat Software's website, APIs, quote service, and future SaaS products. Effective June 25, 2026. Last updated June 26, 2026.
This Acceptable Use Policy is a draft provided for general information. It is not a substitute for legal advice. WhiteHat Software recommends that you consult with a qualified attorney to ensure compliance with all applicable laws and terms of service in your jurisdiction.
1. Overview
This Acceptable Use Policy ("AUP") applies to all users of WhiteHat Software's website, services, APIs, quote systems, and any future SaaS products or applications. It establishes rules for lawful, ethical, and responsible use of our platforms and services. Violation of this policy may result in suspension or termination of access without notice.
2. Prohibited uses — general
You agree not to use WhiteHat Software's website, services, or APIs for any of the following purposes or in any of the following ways:
2.1 Illegal activity
- Any use that violates local, national, or international laws or regulations
- Facilitating, promoting, or assisting in illegal activity (fraud, money laundering, human trafficking, etc.)
- Circumventing or bypassing any legal restrictions or obligations
- Using our services to create, distribute, or access illegal content (child exploitation material, stolen data, counterfeit goods, etc.)
2.2 Malicious technical activity
- Transmitting viruses, malware, trojans, worms, ransomware, spyware, or any harmful code
- Attempting to gain unauthorized access to our systems, networks, databases, or accounts
- Performing denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks
- Scanning or probing our systems for vulnerabilities
- Reverse-engineering, decompiling, or attempting to discover source code
- Interfering with the normal operation of our services
- Attempting to compromise the confidentiality, integrity, or availability of our infrastructure
- Installing backdoors, exploits, or unauthorized access mechanisms
2.3 Abuse and harassment
- Threatening, harassing, bullying, or abusing any individual or group
- Engaging in hate speech, discrimination, or incitement to violence based on race, religion, gender, sexual orientation, disability, or other protected characteristics
- Stalking, doxxing, or publishing private information without consent
- Sending unsolicited bulk communications (spam)
- Impersonating, deceiving, or misrepresenting your identity or affiliation
2.4 Intellectual property infringement
- Infringing copyrights, trademarks, patents, trade secrets, or other intellectual property rights
- Distributing pirated software, movies, music, or other copyrighted content
- Using our services to facilitate or encourage intellectual property infringement by others
- Removing, altering, or obscuring copyright, trademark, or proprietary notices
2.5 Fraud and deception
- Providing false, misleading, or fraudulent information
- Phishing, pretexting, or social engineering attacks
- Creating fake accounts or using multiple accounts to circumvent restrictions
- Engaging in payment fraud, chargebacks, or billing disputes without legitimate cause
- Scamming, confidence schemes, or other fraudulent schemes
- Misrepresenting your eligibility to use our services
2.6 Data and privacy violations
- Collecting, storing, or processing personal data without proper consent or legal basis
- Violating GDPR, CCPA, PIPEDA, or other applicable data protection laws
- Accessing, using, or disclosing others' personal information without authorization
- Circumventing privacy controls or security measures
- Selling, renting, or trading personal information in violation of applicable laws
- Creating databases of email addresses, phone numbers, or other personal data through scraping or other unauthorized means
2.7 Content and expression violations
- Posting, uploading, or distributing obscene, sexually explicit, or pornographic material
- Creating, distributing, or promoting illegal content (drugs, weapons, explosives, etc.)
- Defamatory, libelous, or slanderous content that damages reputation without legal basis
- Content that violates rights of publicity or privacy
- Spam, marketing, or promotional content (unless explicitly permitted)
2.8 Regulatory and sanctions violations
- Violating trade sanctions, export controls, or embargoes (e.g., OFAC sanctions, BIS export controls)
- Operating from or providing services to sanctioned countries or entities
- Facilitating business with terrorist organizations, drug traffickers, or other blacklisted parties
- Violating anti-money laundering (AML) or know-your-customer (KYC) regulations
2.9 Commercial and scraping violations
- Scraping, crawling, or harvesting data from our website without permission (except for search engines respecting robots.txt)
- Using our services for competitive intelligence or reverse engineering our business model
- Reselling our services without authorization
- Creating derivative services that clone or closely mimic our functionality
- Bulk downloading of content or data
3. Prohibited uses — specific to APIs and SaaS products
3.1 API misuse
If you access any WhiteHat Software API (including our Quote API or future APIs):
- Do not exceed rate limits or quota allocations
- Do not use the API for purposes other than those documented in the API specification
- Do not cache or store API responses beyond documented retention periods
- Do not attempt to extract the complete database or dataset through repeated API calls
- Do not use the API to train AI/ML models without explicit permission
- Do not sell or redistribute API access
- Do not use the API to build competing services
3.2 SaaS product abuse
If you use any WhiteHat Software SaaS product or application:
- Do not exceed the resources, storage, or computational limits specified in your subscription
- Do not create or exploit loopholes to bypass usage restrictions
- Do not share your account credentials with unauthorized users
- Do not use the service to store illegal content or data
- Do not use the service for high-frequency automated access unless explicitly permitted
- Do not resell the service or feature it as part of your own offering without authorization
3.3 Quotation and consultation form abuse
When using our quotation request form:
- Provide truthful, accurate information about yourself and your project
- Do not submit multiple requests for the same project to bypass our quotation process
- Do not submit requests on behalf of others without their knowledge and consent
- Do not submit test submissions, spam, or abusive content
- Do not use the form to collect responses for competitive purposes
4. Monitoring and enforcement
4.1 Monitoring
We monitor use of our website, services, and APIs to detect and prevent abuse. This may include:
- Analyzing traffic patterns for anomalies or excessive usage
- Reviewing submitted content for policy violations
- Investigating reports of abuse from users or third parties
- Cooperating with law enforcement on criminal investigations
4.2 Enforcement actions
If we detect a violation of this policy, we may take action including (in order of severity):
- Warning: Notice of the violation with a request to stop
- Temporary restriction: Limiting access to certain features or rate limiting API calls
- Account suspension: Temporarily disabling access to your account
- Account termination: Permanent deletion of your account and access
- Legal action: Criminal referral or civil suit for damages
We may take enforcement action without notice for severe violations (security threats, illegal activity, fraud) or repeat offenses. For less severe violations, we will typically provide notice and an opportunity to comply (where practicable).
4.3 No liability for enforcement
We are not liable for any loss, damage, or inconvenience resulting from enforcement of this policy, including account termination, service suspension, or content removal.
5. Reporting violations
If you become aware of a violation of this Acceptable Use Policy, please report it immediately to:
Abuse and Compliance
Email: hello@whitehatsoftware.com
Phone: 604-200-3676
Location: British Columbia, Canada
Provide as much detail as possible, including the user account, API key, or specific content in violation. We will investigate and take appropriate action.
6. Innocent access and reasonable use
6.1 Security research exemption
Security researchers who discover vulnerabilities in our systems are exempt from the prohibition on unauthorized access provided they:
- Act in good faith and disclose vulnerabilities responsibly
- Do not access, modify, or delete data (only test for vulnerability existence)
- Do not exploit vulnerabilities for personal gain or to affect others
- Promptly disclose the vulnerability to WhiteHat Software before public disclosure
- Allow reasonable time for us to patch before responsible disclosure
Contact us at hello@whitehatsoftware.com for a responsible disclosure agreement and security research guidelines.
6.2 Reasonable use of resources
Casual, human-scale use of our website is always permitted. Rate limiting and abuse detection are implemented only to prevent automated abuse, not to restrict legitimate use.
7. Third-party content and links
We are not responsible for content, practices, or policies of third-party websites, applications, or services linked from our website. Your use of third-party services is subject to their acceptable use policies, privacy policies, and terms of service.
8. Jurisdiction and legal cooperation
8.1 Legal compliance
We comply with applicable laws in British Columbia, Canada, including:
- Criminal Code of Canada (prohibitions on fraud, harassment, exploitation, etc.)
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- British Columbia Personal Information Protection Act (BC PIPA)
- Anti-spam legislation (Canada's Anti-Spam Law, CASL)
8.2 Cooperation with authorities
We may disclose user information and cooperate with law enforcement, regulatory agencies, and court-ordered requests as required by law. We will provide notice where legally permitted.
9. Changes to this policy
We may update this Acceptable Use Policy at any time by posting the revised version on our website with a new "Last updated" date. Continued use of our services constitutes acceptance of the updated policy. We will provide notice for material changes.
10. Related policies
This Acceptable Use Policy is part of our terms governing your use of our services. Please also review:
- Privacy Policy — How we handle your personal information
- Terms of Service — General terms governing use of our website and services
- Cookie Policy — How we use cookies and tracking technologies
11. Definitions
- Personal data: Any information relating to an identified or identifiable natural person
- Malware: Software designed to disrupt, damage, or gain unauthorized access to systems
- DDoS attack: Flooding a system with traffic from multiple sources to overwhelm it
- Phishing: Fraudulent attempts to acquire sensitive information through deceptive communications
- Spam: Unsolicited, typically bulk, electronic communications
- Scraping: Automated extraction of data from a website without authorization
12. Questions and contact
If you have questions about this Acceptable Use Policy or believe there is a violation, please contact us:
WhiteHat Software Inc.
Email: hello@whitehatsoftware.com
Phone: 604-200-3676
Location: British Columbia, Canada
Website: whitehatsoftware.com
Disclaimer: This Acceptable Use Policy is a draft provided for general information and is not a substitute for legal advice. We strongly recommend consulting with qualified legal counsel to ensure this policy aligns with your business needs, jurisdiction, and applicable laws. Enforcement of acceptable use policies is complex and may require coordination with law enforcement, regulatory bodies, and affected third parties.