ECHOSCAN
UNQ
STB
#···
About Blog

EchoScan Terms of Service

Last updated: July 30, 2026

These terms apply to the EchoScan public website, public Scan, Console, Browser Verifier, APIs, SDKs, Reports, History, and related support services. By accessing or using the service, you agree to these terms and the applicable order, plan, and documentation terms. If you use the service for an organization, you confirm that you can bind that organization to these terms.

Accounts and Console

Ordinary visitors can run the public Scan without an account. Console sign-in is required to create and manage Browser Environments, Secret API Keys, Workspaces, usage, and plans.

You must provide accurate account information, protect sign-in credentials, and take responsibility for authorized activity in your account and Workspace. Contact EchoScan and update affected credentials promptly after discovering unauthorized access. EchoScan may ask you to verify the account, member authority, or control of a Workspace.

Browser Environments

A Browser Environment configures a browser integration, including its public Environment ID and exact Allowed Origins. You are responsible for registering only HTTP or HTTPS Origins that you control or are authorized to use, and for keeping production, test, and local-development settings accurate.

The Environment ID can appear in browser code and cannot query Reports. Disabling an Environment rejects future browser submits. It does not automatically revoke Secret API Keys or delete historical data.

Secret API Key responsibilities

Secret API Keys belong only in a customer backend, server runtime, or suitable secret manager. Do not place a Secret in browser code, a mobile client, a public repository, logs, or configuration that an end user can read.

The plaintext Secret appears once after successful creation. You are responsible for storage, access restrictions, rotation, and revocation. If exposure is suspected, create and deploy a replacement before revoking the affected key. Browser Environments and Secret API Keys have independent lifecycles.

Plans, usage, and features

The plan determines Report depth, access to features such as History, rate limits, and monthly usage limits. Lite and Pro use one Report Endpoint, and the effective plan of the authenticated API Key determines the response. Browser Environment submits and Secret API Key requests have separate usage records.

Plans, quotas, features, and prices shown in Console, at checkout, in an order, or in a written quote form part of the applicable commercial terms. You may not evade rate, quota, entitlement, or billing controls. When a hard limit is reached, the service may reject additional requests until the quota resets, the plan changes, or the parties agree otherwise.

Customers own the final risk decision

EchoScan supplies device identity, continuity, and access-risk results. Report values such as PASS, SUSPICIOUS, DECEPTIVE, and Pro risk reasons provide technical and product context. They do not make a final determination about personal identity, fraud, credit, legal responsibility, or business eligibility.

Customers combine Reports with accounts, transactions, entitlements, payments, verification, and other business information before choosing to allow, challenge, review, or deny. Customers are also responsible for testing their policy, handling false results, and providing an appropriate appeal or support path for affected users.

Lawful and prohibited use

You may use the service for lawful security, risk management, abuse prevention, device continuity, research, and development. You must follow applicable law, hold the rights needed to process submitted data, provide required notices, and respect the privacy and legal rights of end users.

You may not use the service for unlawful surveillance, discrimination, harassment, malicious tracking, unauthorized identity resolution, credential attacks, access-control circumvention, system disruption, malware distribution, or infringement of another person’s rights. You may not probe, publish, or exploit internal thresholds, weights, detection rules, or bypass conditions. Unreasonable load and unauthorized resale of access are also prohibited.

Availability and contract evolution

EchoScan continues to update browser compatibility, detection capability, security measures, and product experience. Maintenance, security incidents, dependency failures, and operational events can make the service temporarily unavailable.

Versioned API documentation and SDK release notes define the stable public contract. EchoScan may add features, correct errors, and deprecate older capabilities. Material changes that affect integrations will be described through reasonable documentation, versioning, or notice. Customers should follow release notes and test upgrades in their own environment.

Subscriptions, fees, and refunds

The price, currency, tax, billing interval, renewal state, and available cancellation method for a paid plan are the details actually shown at checkout, in Console, in an order, or in a written quote. A third-party payment service may handle payment information and checkout under its own terms.

The current public product contract does not define one refund window or automatic-refund promise for every customer and region. Refunds, credits, and early termination follow the commercial terms in effect at purchase, support confirmation, and mandatory legal requirements. Contact EchoScan before purchase if a particular condition needs confirmation.

SDKs, documentation, and site content

An EchoScan SDK or code package is licensed under the terms stated in its repository, package manifest, or accompanying license file. That license covers only the material expressly released under it.

EchoScan and the relevant rights holders retain rights in site text, design, branding, non-public code, internal rules, and other material without a separate license. You may use public documentation for internal evaluation and normal integration. You may not remove rights notices, impersonate EchoScan, or copy and sell site content without authorization.

Suspension and termination

EchoScan may limit, suspend, or terminate access when an account, key, or request violates these terms, creates security risk, carries unpaid fees, exceeds authorization, or requires action under law. Urgent security events may require immediate action.

You can stop using the service and use available Console controls to manage keys, Environments, and subscriptions. Termination does not erase fees, obligations, or records that arose earlier or must be retained under law. Confirm available export, deletion, or migration procedures before termination when they matter to your operation.

Disclaimers and limitation of liability

To the extent permitted by applicable law, the service is provided as currently available. EchoScan does not guarantee suitability for every business, detection of every risk, uninterrupted operation, or freedom from errors. Browsers, networks, and abuse techniques continue to change, and customers need their own controls around the result.

To the maximum extent permitted by applicable law, EchoScan is not liable for indirect, incidental, special, punitive, or consequential loss, or loss of profit, revenue, goodwill, data, or business opportunity. Liability that cannot legally be excluded or limited remains subject to applicable law. A separate commercial agreement may define different liability terms and controls to the extent of a conflict.

Changes and contact

EchoScan may update these terms when the service, commercial model, or legal requirements change and will revise the date at the top of the page. Material changes will be described through an appropriate site, Console, documentation, or customer notice. Continued use after an update indicates acceptance. Stop using the affected service if you do not agree.

For terms and commercial questions, email contact@echoscan.org. For integration and technical support, use support@echoscan.org.