Skip to content
qaitai
Menu
Get started

Draft · not in force · pending review by counsel

DRAFT — not legal advice. Requires review by counsel before publication. Placeholders in [[DOUBLE_BRACKETS]] must be filled first; see docs/legal/README.md.

Acceptable Use Policy

Effective: [[EFFECTIVE_DATE]]

qaitai drives real browsers against real websites. This policy keeps that pointed at apps you are allowed to test. It is part of our Terms of Service.

Only test what you own or are authorized to test

  • Run qaitai only against applications and domains that you own or have written permission to test.
  • qaitai Cloud enforces this with domain verification: a cloud run can only navigate to hosts your workspace has proven it controls (a DNS TXT record, a well-known file, or a preview deployment from a connected repository). Verification is re-checked daily and revoked when the proof disappears.
  • Do not try to get around verification, the egress guard (for example by targeting private network or cloud metadata addresses from a cloud run), run budgets or rate limits.
  • Pages you verify may load third-party resources (CDNs, payment widgets). Don't use qaitai to test those third parties themselves.

Credentials

  • Use test accounts and test credentials you are authorized to use. Don't store real customers' credentials as test secrets.
  • Don't use qaitai for credential stuffing, brute-forcing logins, account takeover, or testing credentials you obtained without authorization.

Don't use qaitai to

  • attack, overload or disrupt any system, including load or denial-of-service testing we have not agreed to in writing;
  • scrape or collect data from sites you don't own, or bypass their access controls, CAPTCHAs or paywalls;
  • create fake accounts, spam, or automate fraud, including payments with stolen cards;
  • process special-category data (health, biometric and similar) or data of children in the apps you test, unless we have agreed to it in writing;
  • break the law, infringe others' rights, or distribute malware;
  • probe or attack qaitai itself (report security issues as described in SECURITY.md instead);
  • resell or share the service outside your organization except as your plan allows.

Self-hosted runs

Runs on your own runners or instance can reach hosts qaitai Cloud does not allow (including private networks). You are responsible for having authorization for every target you configure.

Enforcement

We may stop runs, suspend a workspace, or revoke domain verification when we reasonably believe this policy is being broken, and we may report illegal activity. Where practical we'll contact you first.

Report abuse to abuse@tryqaitai.com.