← BackVersion 2026-08-14

Terms of Service

By using External Recon you agree to these terms.

1. Authorized targets only

You will only run scans against domains you own, operate, or have explicit written authorization to assess. External Recon is a passive OSINT platform, but many jurisdictions (including the US Computer Fraud and Abuse Act) treat unauthorized reconnaissance as a violation regardless of technique. You are solely responsible for the legality of any target you submit.

2. Attribution & logging

Every scan is logged with the initiating account, IP address, user agent, and target. These records are retained for abuse investigation, compliance, and potential disclosure in response to lawful process or third-party abuse reports.

3. Free tier limits

Free-tier scans are limited to 3 per rolling 24-hour period. Repeat scans of the same domain by an account whose verified email does not match that domain will be blocked unless the operator explicitly approves the target.

4. Sensitive targets

Certain classes of targets (government TLDs such as .gov and .mil, education, and any domains the operator flags as sensitive) require explicit operator approval before any scan will run.

5. Who you are contracting with

External Recon is operated by External Recon Labs LLC ("we", "us"). By continuing to use the platform you accept these terms on behalf of yourself and, where applicable, the organization you represent — and you confirm you have authority to do so.

6. Subscription plans

Paid products are the Essential plan ($3,600 per year) and the Advanced plan ($7,200 per year), each priced per monitored domain, billed annually and renewing until cancelled. Both include a baseline audit at purchase, weekly checks, a full monthly audit and the Prioritized Remediation Playbook at no extra cost. Existing one-off reports and monitoring subscriptions purchased before the plans were introduced remain valid on their original terms. Prices are shown at checkout in your local currency where supported, exclusive of any tax that is calculated and displayed before you pay. Reports are delivered as a fresh audit run against the target you nominated at checkout. Multi-factor authentication is required for operator-initiated audits.

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. Payment, billing, tax, cancellation and refund mechanics are governed by the Paddle Buyer Terms, together with our Refund Policy.

7. Acceptable use

This section defines what you may and may not do with External Recon. It applies to every plan, including free scans, and to anyone acting on your behalf.

7.1 Permitted use

You may use External Recon to assess the publicly observable attack surface of domains you own, operate, or have documented written permission to assess, and to share the resulting reports inside your own organization or with the client whose authorization you hold.

7.2 Authorized targets only

You are solely responsible for holding authorization for every target you submit, and you must be able to produce evidence of it on request. Submitting a target you are not authorized to assess is a material breach of these terms.

7.3 Prohibited use

You will not, and will not permit anyone else to:

7.4 Retrieval of suspect third-party pages

Paid audits may retrieve and analyze publicly served pages hosted on domains that appear to impersonate your brand, and may search public source code repositories for material referencing your domains. This retrieval is limited to content any member of the public can load, is read-only, and is performed solely to assess impersonation and exposure risk to you. It does not involve authentication, exploitation, or any attempt to access non-public content.

7.5 Reporting abuse

If you believe the platform is being misused, or that a report infringes your rights, contact us at support@externalreconlabs.com. We investigate every report and will remove or restrict content and access where appropriate.

7.6 Enforcement

We may investigate suspected violations and, at our discretion, restrict features, remove content, suspend, or terminate accounts — immediately and without refund where the violation is serious or repeated. Serious abuse may be reported to affected parties and to the relevant authorities.

8. Intellectual property and license

External Recon Labs LLC retains all rights in the platform, its scanning methodology, report templates, playbook content and branding. You receive a limited, non-exclusive, non-transferable right to use the platform and to use the reports you purchase inside your own organization. You may not resell, redistribute or reverse engineer the platform or its outputs.

9. Service level and warranties

External Recon reports on publicly observable signals only. We do not guarantee uninterrupted or error-free operation, complete coverage of your attack surface, or that any finding is exhaustive or free of false positives. To the fullest extent permitted by law, all implied warranties (including merchantability and fitness for a particular purpose) are disclaimed. Nothing here excludes liability for fraud, death or personal injury.

10. Suspension and termination

We may suspend or terminate access for material breach of these terms, non-payment, suspected fraud or security risk, or repeated or serious policy violations. On termination you may export your reports for 30 days, after which data is deleted in line with our Privacy Policy.

Effective date: version 2026-08-14. See also our Privacy Policy and Refund Policy.