Responsible use
Working translation of the canonical Arabic page at
/responsible-use/. The Arabic version governs on any conflict.
zmam.ai is built for safe, narrowly-scoped external scanning of publicly- visible domain configuration. This page explains what use is permitted, what is not, and how we reduce abuse.
Allowed use
- Scanning domains you own, or domains you are explicitly authorised to assess.
- Using reports for defensive purposes: review, remediation, hardening, or raising team awareness.
- Sharing the report inside your organisation or with a trusted security consultancy, with the domain owner’s permission.
Not allowed
- Scanning domains you do not own and have no authorisation to assess.
- Using results for exploitation attempts, harassment, or unauthorised access.
- Attempting to bypass our rate limits, abuse the verification mechanism, or impersonate the domain owner.
- Reselling the reports or presenting them as your own security service without an agreement with zmam.ai.
How we reduce abuse
- Email confirmation before any scan: no scan starts until the requester clicks a link in their inbox.
- Daily and weekly limits: a capped number of scans per IP and per domain.
- Non-disruptive checks: we use external, non-intrusive checks against public configuration (DNS, TLS, security headers, mail authentication) and never test passwords, submit forms, modify, delete, or access protected resources. Deeper active probes (port scanning, known-vulnerability templates, asset discovery) are in development and will require explicit authorisation before they activate.
- Abuse monitoring: our platform watches for repeated-scan patterns and may pause requests that look suspicious.
- Private reports: reports are sent only to the verified requester’s inbox; nothing is published publicly, and sensitive findings never appear on the website.
Currently out of scope
- Deeper active probes (port scanning, known-vulnerability templates, asset discovery) are in development and will only run after additional proof of domain control and written authorisation.
- AI-assisted bug-finding and deeper checks come later, under the same authorisation constraints.
- zmam.ai does not currently provide administrative access, intrusive testing, or full penetration-test reports.
To report suspected abuse of our service, email [email protected] or use the
contact page
.