Türkçe
Seges Trust
Menü

Terms

Terms of use

These terms cover everything on this site: the free instant page check (/critique) and domain verification (/domain-verification), and the two paid products, the signed-in audit and active scanning of a domain you have verified.

Bu sayfa yalnızca İngilizce olarak sunulmaktadır.

Effective date:

Who operates this site

Seges Trust is operated by 吳遠佛界, an individual trading as a natural person in Taiwan. There is no company behind it: “Seges” and “Seges Trust” in these Terms mean that individual. You can reach us at the contact address, which is monitored for legal, privacy, and security matters alike, or at the trading address and telephone number below.

吳遠佛界
10491臺北市中山區朱園里南京東路二段132號4樓
4F., No. 132, Sec. 2, Nanjing E. Rd., Zhuyuan Vil., Zhongshan Dist., Taipei City 10491, Taiwan
Telephone: +886 2 7751 9081 (02-7751-9081 within Taiwan)

What a check actually does

A critique report is not simply a page load. When you submit a URL we open that page in a headless browser, read it the way a visitor's browser would, and follow links on the same host to a small number of further pages on that host, honouring your robots.txt. Every HTTP request we make is a GET. Beyond the pages themselves we request three further files, all of them published files whose stated purpose is retrieval by unrelated parties: /robots.txt, /.well-known/security.txt, and, if your robots.txt names one, a sitemap - at most two of them, and only when the sitemap URL is on the host you submitted. A sitemap your robots.txt points at on some other host is recorded in the report and is not fetched. We also make DNS lookups for your SPF and DMARC records, and open a TLS connection to port 443 to read your certificate and protocol version; neither of those is an HTTP request.

A check does not reach past your host. If the page's own JavaScript names a Supabase or a Firebase project, we record only that the key is published in the page, the same way we record any other credential-shaped string we find there. We do not call that project's database, storage, or rules endpoints, we do not list its tables or buckets, and we do not test whether any of them answer without authentication. This is a change from what we previously described. That capability existed, it ran only for a signed-in owner of a domain-verified host, and it has been withdrawn for everyone: proving control of the host you submitted is not permission to send traffic at a different party's backend, and that party never agreed to be queried at all. Apart from the page itself, the pages we follow on your host, and the published files named above, we address no request of our own to any host other than the one you submitted. Opening your page in a browser still fetches whatever that page itself references, exactly as a visitor's browser would.

All of it is read-only. We use GET only - never a method that could change something - and we do not submit forms, do not attempt to authenticate, do not write or change anything, do not send headers a real browser would not send, and never fetch a path you supply or a path you have not published. But these are still requests nobody asked for, aimed at a host whose operator has not spoken to us, which is why the representation below matters.

You must be authorized to submit a URL

By submitting a URL to /critique, you represent all of the following: that the page is published for public consumption; that you own or operate the host, or hold written authorization from whoever does; and that the authorization covers automated, read-only retrieval of the kind described above, and not merely viewing the page.

We do not verify that authorization before running the public-page check. There is no approval step and no out-of-band confirmation; ticking the box is the whole of it. Domain ownership is checked separately only when you use /domain-verification. A current DNS verification bound to your signed-in account is what unlocks suspected-key details for that exact host. It does not authorize any request to a third-party backend, and the check makes no such request.

Submitting a URL you are not authorized to submit may violate computer-misuse law where you are, where the host is, or both. It is also a material breach of these terms.

Acceptable use

Do not submit a URL or hostname you are not authorized to submit. Do not use these tools to gather information about someone else's systems, a competitor, a former employer, a target of any kind. Do not submit automatically or in bulk: these are self-serve tools for checking your own pages, one at a time.

We can restrict or block your use

We may restrict, suspend, or block your use of the free tools at any time, with or without notice, and we may remove a report or a domain-verification record. We do not have to establish that you broke a rule first: the free tools are run at our discretion and are rate-limited and abuse-prone, and waiting to prove a breach before acting is not workable for one person running them.

Anything you have paid for is different, and we do not claim the same discretion over it. We will suspend or withdraw a paid product only where you have breached these terms, where continuing would break the law or expose us or a third party to real risk, or where you ask us to. If we withdraw something you paid for and you have not breached these terms, we refund it: in full where it has not been delivered, and in proportion to what is left where it has been used in part. Nothing in this section takes away the fourteen-day window in the Refund policy, or any right you have as a consumer where you live.

No warranty

All of these tools are provided “as is,” without warranty of any kind. A critique report is an automated snapshot: one moment, one vantage point, the fixed set of checks described above, not a professional assurance, security audit, or legal compliance review. A clean report does not mean a site is secure. It means these particular checks found nothing at that moment. Checks can also fail, time out, or be wrong in either direction.

What the public badge means

Once a host has been checked, a badge image can be embedded from /api/badge/ followed by the hostname. It reads “seges trust: passing” when, and only when, the most recent stored report for that host had a secret scan that came back genuinely clean and every security-header check returning true. That is the entire test behind it.

The badge is stamped with the date of the report behind it (for example “passing, 2026-08-20”), but carries no other scope statement and no expiry, the report itself may be up to 90 days old, and the site may have changed many times since that date. It says nothing about anything those two checks do not cover, and there is no review, audit, or human judgement anywhere behind it. It is not a certification, an accreditation, or an assurance of any kind, and it should not be read as one.

Report links can be read by anyone holding them

Every critique report is saved under a randomly generated report ID and can be read at its own URL by anyone who has that URL. There is no sign-in and no ownership check on that page. The ID is long and random, so the link is not guessable, but it is not a secret either: whoever you send it to, and whoever they forward it to, can read the whole report, including any findings about your site. Reports are scheduled for deletion 90 days after they are created.

What an active scan actually does

An active scan goes further than a critique. It is only available once a host has a verified domain-ownership record and you are signed in as the account recorded on that verification, there is no free-form target field, and we never scan a host you have not verified.

Some of what an active scan does is broader and more thorough than a critique's passive checks: connection and service probing across the host's network ports, and TLS, certificate, and security-header inspection against a larger, more current set of checks. Other parts go further still: we send crafted inputs designed to determine whether the host's application or the database behind it can be influenced by unexpected data, the technique security researchers call injection testing, including attempts aimed at SQL, NoSQL, operating-system command, and template-based injection points, and at points where a page reflects input back in a way that could be used to inject script. Every request, of every kind, is aimed at the one host you have verified and nowhere else.

An active scan also requests a short, fixed list of paths you have not published. These are the places where configuration and version-control files are most often left reachable by accident: environment files, a container compose file, a JSON configuration file, an operating-system artefact, and the version-control directory itself. The list is set by us and is the same for every scan. It is never set by you: there is no field anywhere on this site that lets you name a path, and a scan never requests one you supply. Each request is a GET, and we read a response only far enough to tell a real file apart from your own “not found” page. This is not part of a critique, which never requests a path you have not published. It is part of an active scan because a file sitting at one of these paths is already readable by anyone on the internet who tries it, and finding it before someone else does is much of the reason to scan a host you own.

Every check we run is individually rate-limited and time-boxed, and only one active scan runs for your account at a time. These limits exist because some of what an active scan does is not read-only, and an unbounded version of it could affect the very host you asked us to check.

You must separately authorize active, non-passive testing

The authorization you give for a critique does not cover an active scan. Before requesting one, you must separately represent that: you own or operate the exact host being scanned, already demonstrated through domain verification, and restated here as its own representation; you authorize this specific, non-passive testing of that host, understanding that it is not read-only and may send requests that could, in principle, affect the host's availability or the data behind it; and you accept that directing this testing may carry computer-misuse-law risk where you are, where the host is, or both.

We do not verify any of this beyond the domain-ownership record itself before running a scan. There is no approval step and no out-of-band confirmation, the representation above, given at the point you request the scan, is the whole of it.

One part of that representation is worth stating on its own, because it is the part a person is least likely to have thought about. An active scan requests a short, fixed list of paths the host has not published, described in the section above. You represent that your ownership of the host, or the written authorization you hold from whoever owns it, covers that specific class of request: retrieval of paths the host has not published, and not merely automated read-only retrieval of pages it has. Where the host belongs to a third party, the written authorization you hold must cover that same specific thing. You are responsible for the URL you submit here, and for what you do with the report we give back to you.

Injection testing can affect your own site and account: a separate acknowledgment

Part of what an active scan does is send inputs designed to reveal whether your application or its database can be influenced by unexpected data. Even run conservatively, and even against a host you own, this carries risks a critique does not:

These risks are materially different from anything a critique, or the passive portion of an active scan, can do to your site. Because of that, authorizing an active scan in general is not enough on its own: running the part of a scan that includes injection testing requires a second, separate acknowledgment that you understand and accept the three risks above for the exact host you are scanning. Without that separate acknowledgment, we do not run this part of the scan.

Active-scan report links are not public

Unlike a critique report, an active-scan report can be read only by the account it was created for. There is no unauthenticated link to an active-scan report of the kind described above for critique reports. Active-scan reports are scheduled for deletion 90 days after they are created, the same as critique reports.

What a signed-in audit actually does

A signed-in audit is operator-conducted work, not a self-serve scan. You agree the scope with us in writing and an operator records that exact approved scope before a scope-bound payment link can be issued. After payment, a second operator action starts the bounded audit job; buying alone never starts work. You create an audit account inside your own product with whatever permissions you decide to give it. The dated report is filed to your Seges Trust account, readable by that account and nobody else, and scheduled for deletion 90 days after it is created, the same as every other report here.

What we do with that account is sign in and read. We open the screens the account can reach and run the same checks the free page check runs, against those screens instead of your public marketing page. It is read-only from first page to last: nothing is submitted, bought, sent, changed, or deleted in your live product. You never give us a password, and deleting the audit account cuts off the access immediately and without asking us. If the account can no longer sign in, the run fails and says so rather than reading a logged-out page and reporting it as clean.

Two limits are worth stating plainly before you buy. No turnaround time is published for this, because none has been agreed: settle timing with us in writing along with the scope, and do not treat the purchase as a deadline. And what an audit covers is the scope you agreed and nothing else. Like every other output here it is an automated snapshot read by a person, not a professional security assurance, a penetration test, or a compliance review.

You must be entitled to authorize this. By agreeing a scope, you represent that you own or operate the product being audited, or hold written authorization from whoever does, and that the authorization covers a third party signing into it and reading customer-facing screens. Where the product holds other people's personal data, that is your decision to make about your own users and your own obligations to them, not one we can make for you.

Limitation of liability

To the maximum extent permitted by law, Seges is not liable for indirect, incidental, or consequential damages arising from use of these tools, including damages arising from acting on a critique report, or from another party's false ownership attestation.

Our total liability for all claims arising from your use of these tools is limited to the greater of the amount you paid to use them in the twelve months before the claim arose and USD 100. All of these tools are free today, so in practice that floor is the figure.

Nothing in these terms excludes or limits liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, or for any other liability that cannot lawfully be excluded or limited. Where a jurisdiction does not allow one of the exclusions or limits above, that exclusion or limit does not apply to you, and our liability is instead limited to the least amount that jurisdiction permits.

Indemnification

If you submit a URL or domain to any of these tools without being authorized to do so, you agree to indemnify Seges against any claim, loss, or expense arising from that submission.

Two situations are worth separating, because they end differently. Where the host you submit belongs to a third party, you indemnify Seges against any claim that third party brings arising from your submission or from the testing you directed, including a claim under computer-misuse or unauthorized-access law, and including one aimed at the retrieval of unpublished paths described above. We do not choose your target, and the only thing we can check is the domain-ownership record: whether you were actually entitled to point us at that host is something only you can know at the moment you submit it.

Where the host is your own, the consequences on your own system are yours. That covers data changed or lost, an action your hosting provider or firewall takes against your own account, and time your site spends unavailable while a scan runs, each of which is described above before you authorize anything. This paragraph allocates the consequences of testing you asked for, on a system you told us is yours. It does not affect the exceptions stated under “Limitation of liability” above, which continue to apply in full.

If we want to rely on that, we will tell you about the claim promptly; if we are late, your obligation is reduced only to the extent the delay actually harmed the defence. You then have sole control of the defence and of any settlement, except that you may not agree to anything that places a non-monetary obligation on Seges, or that admits fault on our part, without our prior written consent. We will cooperate reasonably with the defence, at your expense.

This clause applies even to an individual acting as a consumer for personal, family, or household purposes, except to the extent applicable law in that individual's jurisdiction prohibits enforcing it against such a consumer. Domain verification is anonymous and free to use without signing in; the instant page check and an active scan both require a signed-in account, and an active scan additionally requires a verified owner, so the person most likely to submit a host without authorization is exactly the person a blanket consumer carve-out would otherwise shield, narrowing that carve-out to what the law actually requires, rather than applying it everywhere by default, keeps the indemnity meaningful for that case.

Accounts

A Google sign-in is required to receive a report from /critique, and to request an active scan. Domain verification still works without one. An account also lets you associate verified domains and critique reports you generate with yourself for your own later reference; it grants no elevated verification and no bypass of the domain-ownership checks described above. You are responsible for the security of your own Google account; Seges is not liable for actions taken through your account if your Google credentials are compromised outside our control.

Referral credits

If an account you referred signs up, your account can receive a credit toward a paid product. A credit is a discretionary promotion, not something you bought and not a thing of value in itself: credits have no cash value, cannot be sold, transferred, or exchanged for money, and are not property. We may change what a referral is worth, cap it, expire it, or end the arrangement entirely, and doing so is not a refundable event.

Referring yourself does not work, and it is not meant to. Creating accounts in order to collect your own credits, or referring accounts that are not real people, forfeits the credits and may cost you access to these tools. Where a credit has already reduced what you paid, any refund is worked out on the amount that actually reached us, not on the list price.

Rate limits and availability

All of these tools are rate-limited. The free tools may be changed, restricted, or withdrawn at any time without notice, for any user. A paid product may also be changed or withdrawn, but if we withdraw one you have paid for and not used, we refund it; see “We can restrict or block your use” above and the Refund policy.

Region restrictions

Two restrictions apply, and they are not the same size. From 3 September 2026 the working tools and account features are not available to requests that appear to come from the United Kingdom. Separately, the paid active scan is not available to requests that appear to come from mainland China; the free page check, domain verification and sign-in are unaffected there. Everywhere else, all of these tools are available. The European Union and European Economic Area exclusion this section described before 2 September 2026 no longer exists.

A restriction on the tools is not a restriction on the documents. If you are in a restricted location you can still read this page, the pricing and refund terms, the privacy policy and the accessibility statement, and the contact address still reaches a person. That is deliberate: terms you can be charged under have to be readable where you are, and the route for objecting to something this site did must not be closed to the people most likely to need it.

One part of the mechanism still applies. If your request's location cannot be determined at all, the tools are temporarily unavailable: this is a fail-closed safety default, not a determination about where you actually are, and it can happen regardless of your real location. Restrictions may also be reintroduced at any time under the same terms as any other change to these tools. The Availability page states what is restricted at any given moment and explains what you will see if you are affected.

Governing law

These Terms are governed by the laws of the Republic of China (Taiwan). Which court may hear a dispute is left to the ordinary rules of jurisdiction rather than fixed here, so you keep whatever venue the law of your own country gives you. If you are a consumer, nothing in these Terms takes away a right you have under the consumer law where you live, and nothing here requires you to give up a statutory remedy in order to use these tools.

Paid plans

There is no checkout on this site today, so nothing here can currently charge you. Two products are nevertheless described and priced in advance on the pricing page: the signed-in audit at USD 350 and a pack of active scans at USD 39, both paid once. Nothing here is a subscription and nothing renews. Payment is taken by a Merchant of Record, which becomes the legal seller for that transaction and applies its own terms alongside these.

The Refund policy gives you fourteen days from delivery, for any reason and with no explanation asked for, and sets out what delivery means for each product. If you are in the EU or the UK it also states your right to withdraw. We do not ask you to waive that right, and nothing on this site takes it away.

See also the Privacy page for what data these tools collect and how long it is kept, and the Refund policy for what happens to a payment.