check_circle You are totally welcome to build on top of our public API endpoints, as long as your tools stay legal and don't abuse the server.
check_circle If you want your domain out of our web research scanner, you can just block the "cattie-bot" user-agent via your robots.txt file or drop us a quick email.
check_circle Browsing through Tor is entirely fine by us, provided you aren't cycling identities to get around basic request pacing.
check_circle Everything published here is shared purely for educational use and security defensive research.
check_circle We might update or rewrite these rules down the line as we add more features, so try to check back every once in a while.
cancel Don't try to crash, brute-force, flood, or run heavy automated scrapers against the server.
cancel Don't use headless browsers, custom request header fakes, or client-side storage injection to try and mess with the dashboard or force backend errors.
cancel Do not weaponize our web security research data to run targeted scans, track individual configurations, or exploit discovered setups.
cancel There are absolutely no uptime guarantees, performance promises, or warranties here. Things are run completely "as-is" and can change or go offline without notice.
cancel We reserve the full right to drop a block on specific IP ranges, network endpoints, or user-agents if they cause stability issues.
bug_report
Responsible Disclosure
If you spot a security bug or setup vulnerability in our APIs or server code, please send it over quietly to security@cattie.pro instead of using it disruptively or dropping it publicly.
mail
General Questions
For non-security stuff, standard network inquiries, feedback, or scanner adjustments, reach out to us at contact@cattie.pro.