Eleion / Scanner
Pricing Trust Terms Privacy
← Back

Terms of Service

Last updated: 2026-04-19. Version 2.0. Governed by Italian law.

The single rule that governs every scan: you may only request scans against assets you own or are explicitly authorized to test. Every scan records an immutable proof of ownership. Violations are reported to competent authorities and result in immediate account termination.

1. Parties

These Terms bind you (the "Customer") and Eleion (the "Operator"), an Italy-based security product currently in pre-incorporation phase. The Italian corporate entity that will operate the Service is registered at the Chamber of Commerce; current operator identity, VAT ID and legal seat are disclosed on request at legal@eleion.io. The Operator will be formally named in invoices issued under the Sistema di Interscambio.

2. Service

Eleion Scanner ("Service") runs automated vulnerability scans (nuclei engine, OWASP-aligned templates) against web assets that the Customer owns or is authorized to test. Service is delivered from AWS Frankfurt (eu-central-1). All customer data remains in the European Economic Area.

3. Authorization and ownership — mandatory

Before the first scan on any target, the Customer must pass one of these proofs:

  • DNS TXT record under _eleion-scanner.<target> with the token we issue;
  • HTTP file at https://<target>/.well-known/eleion-scanner.txt;
  • Or a manually-reviewed CIDR allowlist signed by the asset owner.

You warrant and represent that you have the authority to submit each target. You indemnify Eleion against any third-party claim arising from unauthorized scans you requested.

4. Prohibited uses

  • Scanning third-party assets without written authorization;
  • Denial-of-service, high-rate brute force, or stress testing beyond our rate limits;
  • Targeting critical infrastructure (energy grid, hospitals, government systems) without specific written authorization;
  • Attempting to bypass ownership verification;
  • Reselling Service output or API access without a written reseller agreement;
  • Using the Service to support or develop intrusion software as defined by EU Reg. 2021/821 (dual-use).

5. Abuse response

If the Service is alleged to be scanning your assets without authorization, email abuse@eleion.io. We acknowledge within 4 business hours and investigate within 24 hours. If a scan is confirmed without valid ownership proof, we suspend the requesting tenant immediately, preserve all logs, and share the sanitized audit trail with the affected party on valid request.

6. Data and audit logs

We retain scan metadata, findings and ownership proofs for 12 months (EU fiscal and abuse-investigation retention). Customer accounts can be deleted on request; audit logs required for legal/fiscal retention remain.

7. Fees, VAT, refunds

Prices listed in EUR. EU B2B customers with valid VIES-registered VAT ID benefit from reverse-charge (Art. 7-ter D.P.R. 633/72). Extra-EU customers: out-of-scope VAT. Italy: invoice issued via Sistema di Interscambio (SdI). Cancellations effective at end of current billing period. No refunds except for documented Service unavailability exceeding 72 consecutive hours. B2B customers are excluded from the 14-day B2C withdrawal right (Art. 45 Codice del Consumo).

8. Warranties and liability

Service is provided as is. We do not warrant that all vulnerabilities will be detected, that all reported findings are valid, or that absence of findings means absence of vulnerabilities. To the maximum extent allowed by law, total aggregate liability is limited to fees paid by you in the 3 months preceding the claim. Nothing limits liability for willful misconduct, gross negligence, or statutory rights that cannot be waived.

9. Intellectual property

You retain ownership of your data and scan findings. We retain ownership of the Service, including all software, priority heuristics, UI, templates curation, and aggregate anonymous metrics.

10. Export control — dual-use

The Service is a passive vulnerability scanner. It does not generate, deliver or include intrusion software as defined in EU Reg. 2021/821 Annex I categories 4.A.5 / 4.D.4 (dual-use). Our self-assessment is on record. The Service is not made available to parties on EU sanctions lists or to embargoed territories (RU, BY, IR, KP, SY and derivative sanctions).

11. Changes

We may update these Terms. Material changes are notified by email at least 30 days before they take effect. Continued use after the effective date constitutes acceptance.

12. Governing law and jurisdiction

These Terms are governed by Italian law. Any dispute shall be submitted to the exclusive jurisdiction of the competent courts of Milan, Italy, except where mandatory provisions of the Customer's country of residence apply.

13. Contact

Legal: legal@eleion.io
Privacy: privacy@eleion.io
Abuse: abuse@eleion.io
Security vulnerabilities in the Service itself: security@eleion.io

ELEION
AUTHORIZED SECURITY SCANNING
Terms Privacy DPA Cookies Abuse Sub-processors
Eleion, independent product. Italian corporate entity registration in progress — current operator details on request at legal@eleion.io. Service hosted on AWS Frankfurt (eu-central-1). Primary customer data stays inside the EU.
Contacts: privacy@eleion.io · abuse@eleion.io · security@eleion.io · legal@eleion.io
Strictly necessary cookies only. Designed to support GDPR obligations (Regulation EU 2016/679) and the Italian Codice della Privacy — DPA, sub-processors and Transfer Impact Assessment published. Self-assessment EU 2021/821 (dual-use): passive scanner, no intrusion software nor exploit generation.

We use only strictly necessary cookies (session, CSRF, captcha). No analytics, no advertising, no third-party tracking. Read more.