Legal
Terms of Service
Last updated — May 13, 2026
These Terms of Service (“Terms”) govern your access to and use of UpSec.Watch, a SaaS platform providing uptime monitoring and security scanning services operated by UpSec.Watch (“we,” “us,” or “our”). Please read these Terms carefully before using our services. By creating an account or accessing the platform in any way, you agree to be bound by these Terms in full.
1. Acceptance of Terms
By accessing or using UpSec.Watch (the “Service”), you confirm that you have read, understood, and agree to be bound by these Terms and any additional policies referenced herein, including our Privacy Policy. If you do not agree to these Terms, you must not use the Service.
You must be at least 18 years of age to create an account or use the Service. By accepting these Terms, you represent and warrant that you are 18 years of age or older and have the legal capacity to enter into a binding agreement.
If you are accessing or using the Service on behalf of a company, organisation, or other legal entity (“Organisation”), you represent and warrant that you have the authority to bind that Organisation to these Terms. In that case, “you” refers to both you personally and the Organisation. If you do not have such authority, you must not accept these Terms or use the Service on behalf of that Organisation.
Your continued use of the Service after any modification to these Terms constitutes your acceptance of the updated Terms. We recommend reviewing these Terms periodically.
2. Service Description
UpSec.Watch provides a cloud-based platform that combines uptime monitoring and security scanning into a single unified interface. The Service is designed for independent developers, small startups, and digital agencies who need reliable visibility into the availability and security posture of their web assets.
The Service currently includes, or is planned to include:
- Uptime Monitoring: Continuous HTTP/HTTPS and TCP connectivity checks performed via Cloudflare Workers deployed across global regions. Checks execute at user-configured intervals ranging from 1 minute to 24 hours, depending on the subscribed plan.
- Security Scanning (Passive — Free Tier): Lightweight technology detection using httpx, including title extraction and tech-stack fingerprinting. No active probing or vulnerability exploitation is performed on free-tier assets.
- Security Scanning (Active — Paid Tiers): Automated vulnerability scanning using Nuclei high-confidence templates targeting critical and high-severity CVEs and misconfiguration patterns. Active scanning is performed only on assets that have been verified by the account holder.
- Dashboard & Analytics: A real-time dashboard displaying uptime percentages, response time trends, incident history, and security findings for all monitored assets.
- Alerts & Notifications: Configurable notifications delivered via email, Discord, Slack, Telegram, ntfy, or custom webhooks when assets go down, recover, or new security findings are detected.
- Public Status Pages (planned): User-facing public status pages and embeddable security badges for sharing service availability with end users.
The Service is subject to ongoing development. Features, limits, interfaces, and integrations may change at any time. We will endeavour to provide advance notice of material changes that affect existing functionality, but we are not obligated to maintain any specific feature set during the development phase.
3. Account Registration & Security
To access the Service, you must register an account. Registration is performed via a passwordless “Magic Link” email flow powered by Supabase Auth. By registering, you provide a valid email address and agree to receive transactional authentication messages at that address.
You are responsible for maintaining the confidentiality and security of your account, including all authentication links, session tokens, and connected integrations. You agree to:
- Notify us immediately at support@upsec.watch if you suspect unauthorised access to your account.
- Not share your authentication links or session credentials with any other person.
- Not create more than one account per individual without our prior written consent. Team accounts are intended for Organisations and must not be used to circumvent plan limits for personal use.
- Provide accurate, current, and complete information when registering and keep it updated. Providing false or misleading information is grounds for immediate account suspension.
- Not use the Service under a false or misleading identity, or impersonate any other person or entity.
We reserve the right to suspend or terminate any account at our discretion if we reasonably believe the account is being used in violation of these Terms, applicable law, or in a manner that poses a risk to other users or to the integrity of the Service.
5. Prohibited Activities
In addition to the Authorized Use requirements above, the following activities are strictly prohibited when using UpSec.Watch:
- Scanning, probing, or monitoring any third-party system, network, domain, or IP address without explicit written authorisation from the rightful owner.
- Using the Service to facilitate, plan, or conduct denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks against any system.
- Using the Service as a component in spam campaigns, phishing infrastructure, malware distribution, or any other malicious activity.
- Attempting to reverse engineer, decompile, disassemble, or otherwise derive the source code of the UpSec.Watch platform, Cloudflare Worker scripts, or any proprietary components of the Service.
- Circumventing, bypassing, or attempting to defeat plan-based usage limits, rate limits, or feature restrictions through technical means, account manipulation, or any other method.
- Accessing the Service through automated means beyond the documented API, including scraping the dashboard, bulk-creating assets via scripted form submissions, or harvesting scan data outside of authorised API access.
- Reselling, sublicensing, or providing access to the Service to third parties as a standalone product or managed service without a Team plan and without our prior written consent for white-label use.
- Introducing malicious code, viruses, or other harmful material into the Service through webhook payloads, asset metadata, or any other input vector.
- Interfering with or disrupting the integrity or performance of the Service, its infrastructure, or its other users’ data.
- Uploading, storing, distributing, or otherwise processing content that is obscene, pornographic, sexually explicit, constitutes hate speech or incitement to violence, depicts child sexual abuse material, or otherwise violates general standards of public decency and morality (“NSFW Content”). We maintain a zero-tolerance policy toward NSFW Content and reserve the right to report violations to law enforcement authorities.
- Using the Service in any manner that violates applicable local, national, or international law or regulation.
Violations of this section may result in immediate account suspension or termination, withholding of any applicable refunds, and referral to law enforcement authorities where appropriate.
6. Security Scanning Terms
UpSec.Watch offers two tiers of security scanning capability, each with specific technical scope and user obligations. By enabling security scanning on any asset, you acknowledge and agree to the following terms.
Passive Scanning (Hobby / Free Tier): Passive scanning uses httpx to perform lightweight, non-intrusive requests to your assets for the purpose of technology detection (title extraction, server headers, tech-stack fingerprinting). No active probing, vulnerability exploitation, or fuzzing is performed. Passive scans are designed to have minimal impact on target systems and run at a maximum frequency of every 6 hours.
Active Scanning (Plus, Pro, and Team Plans): Active scanning uses Nuclei with a curated set of high-confidence templates targeting known CVEs (critical and high severity), misconfigurations, and exposed services. Active scans are executed from a dedicated scanner VPS and may generate traffic that could be flagged by WAF systems or intrusion detection systems (IDS).
- IP Allowlisting:You are solely responsible for ensuring that your asset’s firewall, CDN, or WAF does not block or rate-limit our scanner VPS IP address. The current scanner IP address is displayed in your account settings. Failure to allowlist this IP may result in incomplete or failed scans, for which we accept no liability.
- Template Scope: We use only high-confidence Nuclei templates in automated scans. Experimental, low-confidence, or destructive-payload templates are never used in automated runs. Manual deep scans (where available) may use a broader template set with your explicit per-scan consent.
- Scan Frequency: Automated active scans run at most once per day (Plus/Pro) or once per hour (Team). On-demand manual scans may be triggered up to the plan-specific concurrent job limit.
- False Positives and Negatives: Scan results are informational only. A clean scan result does not constitute a guarantee that your asset is free of vulnerabilities. Conversely, a positive finding may be a false positive. We strongly recommend manual validation of all findings before taking remediation action.
- No Security Guarantee: UpSec.Watch does not guarantee that scanning your assets will identify all existing vulnerabilities, misconfigurations, or security risks. The Service is a tool to assist with security awareness, not a substitute for a professional penetration test or security audit.
- Third-Party Tool Dependency: Scan quality and accuracy depend on third-party tools (Nuclei, httpx) and their template databases, which are maintained by ProjectDiscovery. We update our template set regularly but do not guarantee coverage of zero-day vulnerabilities or newly published CVEs within any specific timeframe.
We are not liable for any damage to your systems, data loss, service disruption, or any other adverse effect resulting from the execution of scans on your assets. By enabling scanning, you accept all risks associated with the scanning process.
7. Subscription Plans & Billing
UpSec.Watch offers the following subscription tiers. Feature availability, usage limits, and monitoring capabilities vary by plan:
- Hobby (Free): $0/month. Up to 3 monitored assets. Single region (random Cloudflare region). Minimum check interval of 3 minutes. Passive httpx scanning only. 7 days of detailed check history plus unlimited daily aggregate statistics.
- Plus: $19/month. Up to 10 monitored assets. Up to 3 monitoring regions. Minimum check interval of 1 minute. Active Nuclei scanning (critical/high) daily. 30 days of detailed history. Email, Discord, and Slack notifications.
- Pro: $49/month. Up to 50 monitored assets. Up to 9 monitoring regions. Minimum check interval of 1 minute. Active Nuclei scanning (critical/high/medium) daily. 90 days of detailed history. All notification channels including Telegram and ntfy.
- Team: $99/month. Up to 100 monitored assets. All 9 monitoring regions. Minimum check interval of 1 minute. Full Nuclei scanning suite, hourly scans. 365 days of detailed history. All notification channels plus white-label PDF reports.
All paid plans are billed monthly in advance. Your billing cycle begins on the date you subscribe. Payment is processed by our third-party payment processor. You authorise us to charge your designated payment method on a recurring monthly basis until you cancel your subscription.
We reserve the right to adjust pricing for paid plans with at least 30 days’ advance written notice via email to the address associated with your account. Continued use of the Service after the price change takes effect constitutes your agreement to the new pricing. If you do not agree to a price change, you may cancel your subscription before the change takes effect.
If you downgrade your plan, the downgrade takes effect at the start of your next billing cycle. You will retain access to your current plan’s features until that date. Assets, monitoring regions, or check intervals that exceed the limits of your new plan will be automatically adjusted or suspended at the time of downgrade. We are not liable for any monitoring gaps or data loss resulting from a plan downgrade you initiate.
Plan usage limits (asset count, monitoring intervals, regions) are enforced by the backend and cannot be circumvented. Any attempt to circumvent plan limits constitutes a violation of these Terms.
8. Refund Policy
We do not operate a general automatic refund policy. The Hobby (Free) tier is permanently available and provides meaningful uptime monitoring capability so that prospective customers can evaluate the Service before committing to a paid subscription. We encourage all users to take advantage of the free tier to verify the Service meets their needs prior to subscribing.
If you believe you have been charged in error, or if you have experienced a billing issue such as a duplicate charge or a charge following a cancellation, please contact us at support@upsec.watch within 14 days of the charge. We will review all refund requests on a case-by-case basis and, at our sole discretion, may issue a full or partial refund.
Factors we consider when evaluating refund requests include, but are not limited to: the length of time since the charge was made, whether the paid features were actively used during the billing period, whether the request relates to a demonstrable Service failure on our part, and whether the account was in good standing at the time of the request.
Initiating a payment chargeback or dispute through your bank or payment provider without first contacting us to resolve the issue may result in the immediate suspension of your account and any associated accounts. If you initiate a chargeback for a billing period during which you actively used paid features of the Service, we reserve the right to contest the chargeback and provide evidence of service delivery to the payment processor.
9. Data Ownership & Privacy
You retain full ownership of all data you submit to or generate through the Service, including asset configurations, monitoring check results, scan findings, and notification settings (collectively, “User Data”). We do not claim any intellectual property rights over your User Data.
By using the Service, you grant UpSec.Watch a limited, non-exclusive, royalty-free licence to process, store, and transmit your User Data solely for the purpose of providing and improving the Service. This licence terminates when you delete your account or the relevant data.
We may generate aggregate, anonymised statistical data derived from usage patterns across all users (for example, average uptime percentages across asset categories, or most-common vulnerability types detected). Such aggregate data does not identify any individual user or their specific assets and may be used for internal analysis, product improvement, or public reporting.
You may export your monitoring data and scan results from the Service at any time using the data export functionality available in your account settings, subject to plan-specific data retention windows.
Upon account deletion, all personal data and User Data associated with your account will be permanently deleted from our systems in accordance with our data retention policy. Deletion is processed in cascading batches and typically completes within 72 hours of account deletion. Anonymised aggregate data derived from your usage is not considered personal data and may be retained.
For full details of how we collect, process, store, and protect your personal data, please refer to our Privacy Policy.
10. Intellectual Property
The UpSec.Watch name, logo, brand identity, website design, dashboard interface, proprietary source code, Cloudflare Worker scripts, and all associated documentation are the intellectual property of UpSec.Watch and are protected by copyright, trademark, and other applicable intellectual property laws in Hong Kong SAR and internationally.
The Service incorporates a number of open-source software components, including but not limited to Next.js, Supabase client libraries, Nuclei, and httpx. These components retain their respective open-source licences (MIT, Apache 2.0, etc.) and are not affected by these Terms. Nothing in these Terms limits your rights under any applicable open-source licence.
You may not:
- Copy, reproduce, modify, or create derivative works from any proprietary component of the Service without our prior written consent.
- Use the UpSec.Watch name, logo, or brand assets in any manner that suggests endorsement, partnership, or affiliation without our prior written consent.
- Remove, obscure, or alter any copyright, trademark, or other proprietary notices displayed within the Service.
- Attempt to access the underlying source code of any closed-source component of the Service through reverse engineering or other technical means.
User content you create within the Service — including asset names, custom alert configurations, notification channel configurations, and any annotations — remains your property. You grant us only the minimal licence necessary to store and process that content to operate the Service on your behalf.
11. Service Availability
UpSec.Watch is provided on a best-effort basis. We aim to maintain high availability for the dashboard, API, and monitoring infrastructure but do not guarantee any specific uptime level or service level agreement (SLA) unless one has been separately negotiated in writing.
From time to time, we may perform scheduled maintenance that results in temporary unavailability of some or all Service features. We will endeavour to provide advance notice of scheduled maintenance windows via email or an in-app notification where practical, particularly for maintenance expected to last more than 30 minutes.
The uptime monitoring infrastructure relies on Cloudflare Workers and Cloudflare’s global network. You acknowledge that the availability, performance, and geographic coverage of monitoring checks are dependent in part on Cloudflare’s infrastructure, which is outside our direct control. Disruptions to Cloudflare’s network may affect the accuracy or continuity of monitoring data.
We are not liable for any Service unavailability caused by events beyond our reasonable control, including but not limited to: acts of God, natural disasters, war, terrorism, civil unrest, actions of government or regulatory bodies, power failures, internet infrastructure failures, or failures of third-party service providers (collectively, “Force Majeure Events”). In the event of a Force Majeure Event, we will endeavour to restore the Service as quickly as reasonably practicable.
We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice. We will not be liable to you or any third party for any modification, suspension, or discontinuation of the Service, except as expressly stated elsewhere in these Terms.
12. Limitation of Liability
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR UNINTERRUPTED OPERATION.
To the maximum extent permitted by applicable law, UpSec.Watch and its directors, employees, contractors, and agents shall not be liable to you for:
- Any security breach, data breach, vulnerability, or cyberattack that was not detected by the Service, including cases where the Service was actively monitoring the affected asset at the time of the incident.
- Any false positive or false negative scan result, or any action you take (or fail to take) in reliance on scan results provided by the Service.
- Any financial loss, revenue loss, business interruption, loss of customers, or reputational damage arising from the unavailability of your assets or from monitoring downtime.
- Any failure, delay, or inaccuracy in monitoring alerts or notifications.
- Any loss or corruption of your User Data.
- Any failure or interruption of third-party services (including Cloudflare, payment processors, email providers, or notification delivery platforms) that affects the Service.
In no event shall UpSec.Watch’s total aggregate liability to you for all claims arising under or in connection with these Terms or the Service exceed the total fees you paid to UpSec.Watch in the twelve (12) calendar months immediately preceding the event giving rise to the claim. If you are on the Hobby (Free) plan and have paid no fees, UpSec.Watch’s total aggregate liability shall not exceed HKD 100.
In no event shall UpSec.Watch be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, even if we have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of consequential or incidental damages; in such jurisdictions, our liability is limited to the maximum extent permitted by law.
13. Indemnification
You agree to indemnify, defend, and hold harmless UpSec.Watch and its directors, employees, contractors, agents, successors, and assigns from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising out of or relating to:
- Your use of the Service to scan, probe, or monitor any asset without proper authorisation from the asset owner, whether or not you were aware that authorisation was required or absent.
- Any misuse, misinterpretation, or misapplication of scan results produced by the Service, including remediation actions taken or not taken based on those results.
- Any violation by you of these Terms, our Acceptable Use Policy, or any applicable law or regulation.
- Any damage, disruption, or harm caused to any third-party system, network, or data as a result of scanning or monitoring activity initiated through your account.
- Any claim by a third party that your use of the Service infringes their intellectual property rights, violates their privacy rights, or otherwise causes them harm.
- Any content, configurations, or data you submit to or generate through the Service.
We reserve the right, at our own expense, to assume the exclusive defence and control of any matter otherwise subject to indemnification by you, in which case you agree to cooperate fully with our defence of such claim. You may not settle any claim subject to indemnification under this section without our prior written consent.
15. Account Termination
You may delete your account at any time by navigating to Settings › Danger Zone within the dashboard and following the account deletion confirmation flow. Account deletion requires you to confirm your registered email address as an additional safety step. Upon confirmed deletion:
- Your account and all associated assets, monitoring configurations, and notification settings will be permanently removed.
- All stored uptime check data, daily aggregate statistics, scan results, and findings will be deleted in cascading batches within 72 hours.
- Your Supabase Auth session tokens and authentication records will be invalidated and deleted.
- Any active paid subscription will not be automatically cancelled with your payment processor — you must separately cancel your subscription via the billing settings or by contacting us at support@upsec.watch prior to deletion to avoid further charges.
We reserve the right to suspend or permanently terminate your account, with or without notice, for the following reasons:
- Violation of any provision of these Terms.
- Unauthorised scanning or monitoring of third-party assets, including upon receipt of a complaint from the affected asset owner.
- Fraudulent activity, including payment fraud or chargeback abuse.
- Any use of the Service that, in our reasonable judgement, poses a risk to the security, integrity, or reputation of UpSec.Watch or its users.
- Extended non-payment of subscription fees following reasonable notice.
Upon termination for cause, you will not be entitled to a pro-rated refund for any unused portion of the current billing cycle. If we terminate your account without cause, we will provide a pro-rated refund of prepaid fees for the unused portion of your current billing period.
Provisions of these Terms that by their nature should survive termination — including sections on Authorized Use, Limitation of Liability, Indemnification, and Governing Law — shall survive any termination of these Terms or your account.
16. Changes to Terms
We reserve the right to modify these Terms at any time. We distinguish between material and non-material changes:
- Material Changes: Changes that meaningfully affect your rights, obligations, or the core functionality of the Service — for example, changes to the Authorized Use policy, Limitation of Liability, or Governing Law — will be communicated via email to the address associated with your account at least 30 days before the changes take effect. The email will summarise the material changes and link to the updated Terms.
- Non-Material Changes:Minor updates such as typographical corrections, clarifications of existing language, or additions of new sections that do not restrict your existing rights may be made without advance notice, although we will update the “Last updated” date at the top of the Terms.
Your continued use of the Service after the effective date of any updated Terms constitutes your acceptance of the changes. If you do not agree to the updated Terms, you must stop using the Service and delete your account before the changes take effect.
Previous versions of these Terms are available upon request by contacting support@upsec.watch. We retain archived versions of all prior Terms for at least 3 years.
17. Governing Law
These Terms and any dispute, claim, or controversy arising out of or in connection with these Terms or the Service (whether contractual, tortious, or otherwise) shall be governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region (“Hong Kong SAR”), without regard to its conflict of law principles.
Before initiating any formal dispute resolution proceedings, you agree to first contact us at support@upsec.watch and attempt to resolve the dispute in good faith within 30 days of providing written notice of the dispute. Most concerns can be resolved quickly through direct communication, and we are committed to working with you to find a fair resolution.
If a dispute cannot be resolved through good-faith negotiation within the 30-day period, either party may submit the dispute to binding arbitration administered by the Hong Kong International Arbitration Centre (HKIAC) under its administered arbitration rules then in force. The arbitration shall be conducted in English, in Hong Kong. The arbitral award shall be final and binding on both parties.
Class Action Waiver: To the maximum extent permitted by applicable law, you agree that any dispute resolution proceeding will be conducted only on an individual basis, and not as a class action, collective action, consolidated action, or representative action. You expressly waive any right to participate in any class or collective action proceeding against UpSec.Watch. If this waiver is found to be unenforceable in a particular jurisdiction, the remainder of these Terms shall continue to apply.
Nothing in these Terms prevents either party from seeking urgent injunctive or other equitable relief from a court of competent jurisdiction to prevent irreparable harm pending the conclusion of arbitration.
18. Contact Information
If you have any questions about these Terms, wish to report a potential violation, or need to contact us regarding your account or the Service, please use the following contact details:
- General Support & Billing Enquiries: support@upsec.watch
- Legal & Compliance Matters: support@upsec.watch (includes DMCA notices, law enforcement requests, ToS violation reports, and privacy-related enquiries)
- Security Vulnerability Disclosure: support@upsec.watch (responsible disclosure of vulnerabilities in the UpSec.Watch platform itself)
- Registered Address:UpSec.Watch, Hong Kong Special Administrative Region, People’s Republic of China.
We aim to respond to all support enquiries within 2 business days and to legal or compliance matters within 5 business days. Response times may be longer during public holidays observed in Hong Kong SAR.
If you are contacting us regarding a potential unauthorised scanning incident affecting your systems, please include as much detail as possible (originating IP address, timestamps, request logs) so we can investigate promptly. We take all reports of misuse seriously and will take appropriate action, including account termination and cooperation with law enforcement, where warranted.