Terms of Service
By using External Recon you agree to these terms.
1. Authorized targets only
You will only run scans against domains you own, operate, or have explicit written authorization to assess. External Recon is a passive OSINT platform, but many jurisdictions (including the US Computer Fraud and Abuse Act) treat unauthorized reconnaissance as a violation regardless of technique. You are solely responsible for the legality of any target you submit.
2. Attribution & logging
Every scan is logged with the initiating account, IP address, user agent, and target. These records are retained for abuse investigation, compliance, and potential disclosure in response to lawful process or third-party abuse reports.
3. Free tier limits
Free-tier scans are limited to 3 per rolling 24-hour period. Repeat scans of the same domain by an account whose verified email does not match that domain will be blocked unless the operator explicitly approves the target.
4. Sensitive targets
Certain classes of targets (government TLDs such as .gov and .mil, education, and any domains the operator flags as sensitive) require explicit operator approval before any scan will run.
5. Who you are contracting with
External Recon is operated by External Recon Labs LLC ("we", "us"). By continuing to use the platform you accept these terms on behalf of yourself and, where applicable, the organization you represent — and you confirm you have authority to do so.
6. Subscription plans
Paid products are the Essential plan ($3,600 per year) and the Advanced plan ($7,200 per year), each priced per monitored domain, billed annually and renewing until cancelled. Both include a baseline audit at purchase, weekly checks, a full monthly audit and the Prioritized Remediation Playbook at no extra cost. Existing one-off reports and monitoring subscriptions purchased before the plans were introduced remain valid on their original terms. Prices are shown at checkout in your local currency where supported, exclusive of any tax that is calculated and displayed before you pay. Reports are delivered as a fresh audit run against the target you nominated at checkout. Multi-factor authentication is required for operator-initiated audits.
Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. Payment, billing, tax, cancellation and refund mechanics are governed by the Paddle Buyer Terms, together with our Refund Policy.
7. Acceptable use
This section defines what you may and may not do with External Recon. It applies to every plan, including free scans, and to anyone acting on your behalf.
7.1 Permitted use
You may use External Recon to assess the publicly observable attack surface of domains you own, operate, or have documented written permission to assess, and to share the resulting reports inside your own organization or with the client whose authorization you hold.
7.2 Authorized targets only
You are solely responsible for holding authorization for every target you submit, and you must be able to produce evidence of it on request. Submitting a target you are not authorized to assess is a material breach of these terms.
7.3 Prohibited use
You will not, and will not permit anyone else to:
- use the platform for any unlawful purpose, or in breach of any applicable sanctions, export control, privacy, or computer-misuse law;
- use the platform or its output to stage attacks, exploit systems, gain or attempt to gain unauthorized access, or otherwise prepare intrusion — External Recon observes publicly available signals only;
- stalk, dox, harass, profile, or conduct surveillance of any individual;
- commit or facilitate fraud, phishing, spam, or the distribution of malware;
- infringe the intellectual property, confidentiality, or privacy rights of any third party;
- upload or submit content that is illegal, hateful, defamatory, sexually exploitative, or that you have no right to submit;
- resell, republish, sublicense, or incorporate reports or platform output into a competing product or service;
- reverse engineer, decompile, or attempt to derive the platform's source code, methodology, or models;
- script, scrape, or automate access to the platform, share accounts, create multiple accounts, or evade the 3-scan-per-24-hour free-tier limit or any other technical or usage limit;
- probe, penetration test, or interfere with the security, integrity, or availability of the platform or its infrastructure;
- scan government, military, education, or operator-flagged domains without explicit approval, as described in section 4.
7.4 Retrieval of suspect third-party pages
Paid audits may retrieve and analyze publicly served pages hosted on domains that appear to impersonate your brand, and may search public source code repositories for material referencing your domains. This retrieval is limited to content any member of the public can load, is read-only, and is performed solely to assess impersonation and exposure risk to you. It does not involve authentication, exploitation, or any attempt to access non-public content.
7.5 Reporting abuse
If you believe the platform is being misused, or that a report infringes your rights, contact us at support@externalreconlabs.com. We investigate every report and will remove or restrict content and access where appropriate.
7.6 Enforcement
We may investigate suspected violations and, at our discretion, restrict features, remove content, suspend, or terminate accounts — immediately and without refund where the violation is serious or repeated. Serious abuse may be reported to affected parties and to the relevant authorities.
8. Intellectual property and license
External Recon Labs LLC retains all rights in the platform, its scanning methodology, report templates, playbook content and branding. You receive a limited, non-exclusive, non-transferable right to use the platform and to use the reports you purchase inside your own organization. You may not resell, redistribute or reverse engineer the platform or its outputs.
9. Service level and warranties
External Recon reports on publicly observable signals only. We do not guarantee uninterrupted or error-free operation, complete coverage of your attack surface, or that any finding is exhaustive or free of false positives. To the fullest extent permitted by law, all implied warranties (including merchantability and fitness for a particular purpose) are disclaimed. Nothing here excludes liability for fraud, death or personal injury.
10. Suspension and termination
We may suspend or terminate access for material breach of these terms, non-payment, suspected fraud or security risk, or repeated or serious policy violations. On termination you may export your reports for 30 days, after which data is deleted in line with our Privacy Policy.
Effective date: version 2026-08-14. See also our Privacy Policy and Refund Policy.