Acceptable use policy
Last updated August 2026. This policy is incorporated into the terms of service and applies to everyone using Fortify Core.
Connect only infrastructure you are authorised to manage
You may connect cloud accounts and repositories only where you hold authorisation from their owner. Scanning third-party infrastructure without permission is prohibited and will be treated as a security incident.
Prohibited activity
Do not use the platform to probe, scan or test the vulnerability of systems you do not control; to circumvent rate limits or quotas; to store or transmit malware, unlawful content, or special categories of personal data; to resell scan capacity; or to reverse engineer the service outside the limits permitted by applicable law.
Credential hygiene
Cloud roles connected to Fortify Core must be read-only unless you deliberately enable a self-healing class. Never paste long-lived secrets into support tickets, comments or environment descriptions.
Automated remediation responsibility
You remain responsible for reviewing generated pull requests before merge and for the classes of drift you allow to heal automatically. Fortify Core provides controls, delays and volume ceilings; configuring them appropriately is your decision.
Fair use
Plan limits apply to resource counts and scan frequency. Sustained use materially beyond your plan may trigger throttling; we contact you before taking any action.
Reporting and enforcement
Report abuse or a suspected vulnerability to security@fortifycore.io; we acknowledge within one business day and do not pursue good-faith researchers. Violations may result in suspension, and severe or repeated violations in termination under the terms of service.