Acceptable Use &
Scan Authorization
Last updated October 2026
Quick LLC, 30 N Gould St, Ste R, Sheridan, WY 82801
What you agree to when you create a project
By adding a domain to a Pedro project and completing DNS TXT verification, you confirm that you own or are explicitly authorized to request security testing of that domain, and you consent to Pedro running automated security checks against it. This consent is the foundation of the entire service.
1. DNS verification is mandatory
Pedro will not scan any domain that has not been verified via a DNS TXT record placed under your control. This requirement is technical, not optional — the platform cannot initiate a scan until verification succeeds. If you remove the DNS record after verification, scheduled re-scans will be blocked until you re-verify.
This mechanism exists to make authorization cryptographically provable. If you add the DNS record, you controlled that domain's DNS at that moment.
2. What a scan involves
By verifying a domain and initiating a scan, you authorize Pedro to perform the following classes of automated security testing against the verified domain and its directly associated infrastructure:
- Passive reconnaissance — DNS enumeration, subdomain discovery, WHOIS lookups, SSL/TLS certificate inspection.
- Active HTTP surface mapping — crawling publicly accessible pages and endpoints, checking HTTP headers, security policy files (robots.txt, security.txt), and common paths.
- Authentication and access control testing — checking for unauthenticated endpoints, default credentials, missing rate limiting, and broken access control patterns on login and API surfaces.
- API exposure detection — identifying exposed API endpoints, GraphQL introspection, Swagger/OpenAPI documentation, and unauthenticated data returns.
- CMS and framework checks — WordPress, Laravel, Next.js, and other common framework-specific vulnerability patterns.
- Dependency and supply-chain analysis — identifying client-side dependencies with known CVEs, exposed package manifests, and source maps.
- Cloud and infrastructure checks — public S3 buckets, exposed cloud credentials in source, misconfigured storage.
- AI Agent investigation (Professional and Enterprise only) — an LLM-backed agent that adaptively investigates the target surface, chains findings, and probes areas flagged during automated checks.
Scans are automated and bounded by the verified domain. Pedro does not pivot to third-party infrastructure, execute destructive payloads, modify data, or perform denial-of-service testing.
3. Prohibited uses
You may not use Pedro to:
- Scan any domain you do not own or are not explicitly authorized to test.
- Circumvent DNS verification by any technical or procedural means.
- Use findings to attack, extort, or otherwise harm the scanned system or its users.
- Conduct scans on behalf of a third party without that party's written, verifiable authorization.
- Attempt to cause service disruption, data destruction, or denial-of-service against any system.
- Export or redistribute findings in a way that would expose third-party personal data.
Accounts found to be in violation of these restrictions will be suspended immediately. We reserve the right to report apparent unauthorized computer access to relevant authorities.
4. Personal data discovered during scans
Where a scan discovers personal data belonging to your end users or customers (for example, an unauthenticated endpoint that returns email addresses, or a public S3 bucket containing order records), Pedro stores that data against your project to evidence the finding. It is masked by default in your report to prevent unnecessary exposure. This data is never sold, never shared with third parties, and is deleted when you delete your project or account.
You are responsible for notifying any affected individuals and regulators as required by applicable privacy law (GDPR, CCPA, etc.) once a data exposure finding is confirmed. Pedro does not make those notifications on your behalf.
5. Responsible disclosure
Pedro surfaces vulnerabilities to help you fix them, not to publish them. We do not disclose findings from your assessment to any third party unless required by law. We ask that you address critical and high-severity findings promptly; we do not operate a public disclosure timeline, but we reserve the right to notify a platform's users if we discover that user data is actively being exposed and the operator is unresponsive.
6. Record of authorization
Pedro logs the timestamp of DNS verification for each project. This log constitutes a record of your authorization to conduct the associated scan. You may request a copy of this log for any project you own by contacting support.
7. Contact
Questions about this policy, authorization records, or responsible disclosure:
[email protected]
Quick LLC, 30 N Gould St, Ste R, Sheridan, WY 82801