Terms, privacy, and safety policy
These are the operating boundaries and prohibited uses for using KensaOps as a read-only public website QA reporting service. This text is operational guidance, not legal advice.
Application-based pilot terms
- KensaOps is offered as an application-based pilot for web production and maintenance agencies that manage or have explicit review permission for client sites.
- Before production scanning is enabled, a non-secret approval note, email subject, internal ticket, Notion link, or similar confirmation record is required.
- Targets that cannot be safely confirmed as approved public websites may be rejected, paused, or removed.
- Reports are operational evidence for agencies and clients. They are not legal compliance certificates.
Read-only scan scope
- KensaOps crawls only public pages reachable without login or internal network access.
- Production forms are not submitted. Explicitly approved test forms or fixtures are the only exception.
- localhost, private IP, metadata endpoints, file URLs, dangerous schemes, reserved documentation hosts, and unapproved targets are blocked.
- robots.txt, crawl limits, redirects, target-host allowlists, and customer authorization records are production scan safety boundaries.
Privacy and stored data
- KensaOps stores accounts, organizations, billing state, approved target information, scan results, screenshots, generated reports, AI summaries, and operational events as needed to provide the service.
- Logs and evidence should use non-secret references only. API keys, connection strings, webhook URLs, and session secrets must not be saved into artifacts.
- Analytics events are minimized and must not include customer URLs, domains, email addresses, secrets, or raw scan evidence.
- During the pilot, report artifacts and operational evidence are retained only while the account is active or while support, billing, security, abuse prevention, or audit review requires them.
Limitations and disclaimers
- KensaOps checks only broken links, metadata basics, screenshots, performance signals, accessibility basics, form risk, and reportable anomalies.
- It is not penetration testing, vulnerability assessment, SEO rank tracking, uptime SLA monitoring, legal accessibility auditing, or a guarantee of WCAG, privacy, security, or search compliance.
- AI summaries are based on saved scan results. They must not add unsupported claims, legal guarantees, or remediation promises.
- False positives and missed issues can happen. Agencies should review evidence and recommendations before sharing reports with clients.
Prohibited targets and uses
- Do not scan websites you do not own, manage, or have written or equivalent permission to review.
- Do not target login-only apps, admin panels, staging systems with confidential data, internal hosts, private networks, metadata endpoints, URLs with credentials, or systems that prohibit automated access.
- Do not use KensaOps for DoS testing, scraping, credential testing, attack research, spam, harassment, or large-scale crawling outside the approved scope.
- Do not post report share links to public channels if screenshots or findings may contain non-public client context.
Support and changes
- Pilot support is provided through the onboarding and support channel agreed with each agency.
- Important changes to scan policy, billing, monitoring, data handling, or target approval should update the production readiness review before wider public release.
- KensaOps may update this policy as the product, provider integrations, and safety boundaries evolve.