Acceptable Use Policy
Last updated 2026-10-01 · part of the Terms and of every master license agreement
Nexus Studio can send real traffic to the systems it is pointed at. Used against a system you own, that is testing. Used against a system you do not own, the same traffic can be a crime in most countries, including under the Computer Fraud and Abuse Act (United States), the Computer Misuse Act (United Kingdom) and Ley 1273 de 2009 (Colombia). The software cannot tell the difference. You can. This policy says what that means.
It binds everyone who installs, runs or operates Nexus Studio, on a trial or a paid plan, interactively, in CI or on a schedule.
1. Test only what you are authorized to test
You may point Nexus Studio at a system only if, when the run starts, at least one of these is true:
- you own the system;
- your organization owns it and you are acting within your role; or
- you hold explicit, written, current permission from its owner for the kind of testing you are about to run: a signed engagement letter, a scoped penetration-testing authorization, an internal change request, or a bug-bounty program's written scope.
Public reachability is not permission. A login page on the open internet is no more yours to test than one behind a VPN.
2. Active testing needs its own authorization
Some features act on the target, not just observe it:
- Security scans (the Smart Monkey) crawl the target, submit forms and send attack payloads: SQL injection, cross-site scripting, command injection, server-side template injection, XML external entities, server-side request forgery, path traversal, insecure deserialization, weak JWT secrets and probes for sensitive files. To confirm blind findings, the Studio opens a callback listener on your own machine and asks the target to reach it.
- Load testing sends many concurrent requests: a controlled, capped denial of service.
- Chaos testing injects network faults, and pauses, stops, kills or restarts the services you name.
- Stealth mode, when you turn it on, varies timing and the browser's User-Agent so automated runs look less like a bot.
Permission for one is not permission for another. Permission for functional tests is not permission for a security scan, a scan is not a load test, staging is not production, and last quarter is not today. If you are unsure whether your permission covers a run, it does not.
Before any of these sends traffic to a real host, Nexus Studio asks for a recorded basis (proof that you control the host, or a reference to your written permission) and for your explicit confirmation, and it seals a record of the operator, target, parameters and time in your own evidence folder. That record stays on your machine, and no copy is ever sent to us. It helps you show what you did, but it does not make a run authorized: only the owner of the system can do that.
3. What you may not do
- Test, scan, fuzz, load or disrupt a system you are not authorized to test.
- Bypass, disable or patch out the authorization step, the rate caps or the sealed record, including by confirming on behalf of someone else or by setting the CI authorization variable without written permission behind it.
- Go beyond an authorized scope: longer, harder, or against more hosts than agreed.
- Use stealth mode, User-Agent rotation or any other feature to evade a bot defense, rate limit, CAPTCHA, web application firewall or access control of a system you are not authorized to test, or to collect content from a site against its owner's terms.
- Send payloads or callbacks to, or through, infrastructure that neither you nor the owner who authorized the test controls.
- Use Nexus Studio to take a service down when interruption is the goal rather than a measured effect of authorized testing.
- Keep, publish or misuse data of other people that a test surfaces, such as credentials, tokens or personal data in screenshots and logs.
- Use it for, or make it available to, anyone subject to sanctions or export restrictions.
- Bypass the license check, share your license key, or resell or host Nexus Studio as a service, unless a signed agreement with us allows it.
4. Evidence holds other people's data
Screenshots, video, page content and logs from a real application will contain personal data and secrets. That evidence stays on your machines, and you are responsible for who can reach it, how long you keep it and the data protection law that applies to it. We have no access to it.
5. Enforcement
If you break this policy, we may suspend or end your license, up to revoking it. A revoked license stops renewing at once, and every machine on it goes read-only when its current confirmation runs out, within 11 days at most. We decide from what we can see on our side and from reports we receive, never from your local records, which we never receive. Revocation does not limit any other remedy, or your responsibility to anyone you tested without authorization.
6. Reporting abuse
If you believe Nexus Studio was used against your systems without authorization, write to [email protected] with the times and, where you have them, the source addresses. We hold no logs of customer runs and cannot identify an operator from what a target sees, but we will act on the license where we can and cooperate with a lawful request.