By creating an account or using Caspint (the "Platform") you confirm that you are an authorized representative of an organization, that you are using the Platform on that organization's behalf, and that you accept these Terms and our Privacy Policy. If you do not agree, do not use the Platform.
Caspint provides cyber threat-intelligence for organizations, which may include: monitoring of credentials and data exposed in third-party breaches and leaks; dark-web and closed-source monitoring; threat-actor, ransomware and defacement intelligence; brand and executive protection (look-alike domains, leaked documents, impersonation); indicator (IOC) intelligence; and external attack-surface assessment of your organization's internet-facing assets. Features may be added, changed, or withdrawn over time. Access is granted at our discretion following review and approval of each request.
The Platform aggregates information from publicly accessible sources and third-party breach/leak datasets already in circulation, and monitors dark-web forums, marketplaces, paste and leak sites, and closed messaging channels where data or claims relating to your organization may appear. Caspint observes and records these sources for defensive reporting only; it does not hack, breach, phish, intercept, purchase, trade, or otherwise unlawfully acquire data, does not participate in or facilitate any criminal activity or marketplace, and does not solicit or commission any such activity. Material surfaced from these sources may reference unlawful, offensive, or disturbing third-party content that Caspint did not create and does not endorse. All data is provided solely for defensive cybersecurity purposes - to help organizations identify and remediate their own exposure. An organization may request that exposure records relating to it be removed from the Platform; see our Privacy Policy for how to make a removal request.
Where attack-surface assessment is enabled for your account, you instruct and authorize Caspint to perform external, non-intrusive reconnaissance and scanning of the internet-facing assets associated with the domain(s) you register - for example, discovering subdomains and hosts, fingerprinting services, software versions and certificates, and checking for known exposures.
You represent and warrant that you own, or are duly authorized to permit the scanning of, those assets, and that submitting them does not infringe any third party's rights. Scanning is limited to passive and lightweight external techniques: Caspint does not exploit vulnerabilities, attempt to gain unauthorized access, or perform intrusive, brute-force, or denial-of-service testing. You are solely responsible for the accuracy of the scope you provide; Caspint accepts no liability for the scanning of, or any impact upon, assets you do not own or were not authorized to submit. You may request that scanning of any asset be paused or excluded at any time.
You agree to use the Platform only for lawful, defensive security purposes relating to your own organization. You are solely responsible for your use of any information obtained through the Platform and for ensuring that use complies with all applicable laws.
You must not:
Intelligence and scanning are scoped to your own organization's domain(s) and assets. You represent that you are authorized to receive intelligence concerning, and to permit scanning of, those domains and assets.
You are responsible for safeguarding your credentials, for all activity under your account, for the accuracy of the domains and assets you submit, and for any breach-notification or remediation obligations your organization may have. You must notify us promptly of any unauthorized use of your account.
We may suspend or terminate access at any time, without notice, where we reasonably believe these Terms have been breached - including any attack on, or abuse of, the Platform. Automated controls may immediately suspend an account that exhibits attack behaviour.
The Platform and all intelligence and scan results are provided "as is" and "as available", without warranty of any kind. We do not warrant that data or findings are complete, accurate, current, or fit for any particular purpose, that scanning will discover every exposure, or that the Platform will be uninterrupted or error-free. Intelligence is informational and does not replace your own security judgment.
To the maximum extent permitted by law, Caspint and its operators shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss arising from your use of, or inability to use, the Platform, its data, or its scanning, or from any misuse of data by you or any third party.
You agree to indemnify, defend, and hold harmless Caspint and its operators from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or related to your use of the Platform, your violation of these Terms, your submission of assets you were not authorized to have scanned, or your unlawful or unauthorized use of any data obtained through the Platform.
These Terms are governed by the laws of the Republic of Azerbaijan, and any dispute shall be subject to the exclusive jurisdiction of the competent courts of Azerbaijan, without prejudice to mandatory consumer or data-protection rights.
We may revise these Terms. The version and date above indicate the current edition. Continued use after a change constitutes acceptance of the revised Terms.