Terms of Service

These terms govern your use of qsa.sh. The core requirement is simple: you may only scan an IP address you own or are expressly authorized to test. By running curl qsa.sh and continuing past the pre-scan countdown, you agree to these terms and to the Acceptable Use Policy.

Effective version: unset. Operated by Tuxxin.

1. Who operates qsa.sh

qsa.sh is operated by Tuxxin (“we”, “us”, the “operator”). Contact us through our contact form for abuse or opt-out requests and for security disclosures. We do not operate an inbound email server, so the form is the way to reach us.

2. Authorization requirement

You may scan only an IP address that you own or are expressly authorized to test. The scan targets the single public IP address that your connection arrives from — the address shown to you in the warning before the countdown. Running the scan and allowing the countdown to reach zero is your representation and warranty that you are authorized to scan that address.

Scanning an address you do not control may be unlawful in your jurisdiction, including under computer-misuse and unauthorized-access laws. You are solely responsible for confirming your authorization before you proceed. If you are not certain you are authorized, press Ctrl-C to decline — nothing is scanned until the countdown ends.

3. Nature of the service

qsa.sh performs an external, outside-in security and port scan of the public IP address your request connects from. It looks only at what the internet can already observe of that host — open ports, service and version banners, TLS posture, and known-CVE indicators.

You cannot direct a scan at a third party. The target IP is derived from your connection at our trusted edge and is technically enforced; there is no target field, and HTTP headers you send cannot change the address that is scanned. Connections we identify as carrier-grade NAT (CGNAT) or a mobile-carrier network — or as an anonymizing proxy, VPN, or Tor/relay — are refused, and IPv6 origins are refused because we cannot yet reputation-check them (run curl -4 qsa.sh to scan your IPv4). These reputation checks are best-effort and IPv4-only. A CGNAT or carrier address fronts many unrelated parties and an anonymizer hides the true origin, so no single user can be authorized for it; by contrast, cloud, hosting, and datacenter IP addresses are not refused, because scanning a server you control is a core use case. See how this is enforced in the Acceptable Use Policy and About pages.

qsa.sh offers three tiers: Free, Full, and Deep (see Pricing). All three scan only the public IP the request connects from. The paid tiers add no “enter a target” capability: a token is redeemed by running the command from the server to be scanned, so the connecting-IP-only rule above holds for paid use exactly as for free use.

3a. Paid access and scan tokens

Paid access is granted as an opaque, revocable token. A token is redeemed by running curl https://qsa.sh/{token} from the server whose own IP is to be scanned; the scan always targets the connecting IP, never a typed target. Tokens are personal and non-transferable — you may not share, resell, or use a token to cause a scan of an address you do not own or are not authorized to test. We may revoke a token for breach of these terms or the Acceptable Use Policy. The same abuse controls and refusals (CGNAT and mobile-carrier ranges, IPv6 origins, connections our data flags as a proxy/VPN/Tor, the opt-out list, the operator deny list, and rate limits) apply to token scans. Paid tiers are not yet enabled.

3b. Fees, billing and refunds

Full is $5 per month, billed via PayPal as a recurring subscription or month-to-month. Deep is $7 per scan, charged one-time — each Deep scan is a separate purchase, with no subscription. Prices may change with notice; a change does not affect a Deep scan already purchased. One-time Deep scans are non-refundable once the scan has run; a Full subscription may be cancelled and remains active until the end of the paid period. Paid tiers are not yet enabled.

4. Zero data retention

Scan results are streamed to you and never written to disk. We do not keep results, scan history, raw IP addresses, or User-Agents. We retain only short-lived, hashed rate-limit and abuse counters and the version of this policy in effect. Full detail is in the Privacy statement.

Free scans remain fully ephemeral. Paid asynchronous results are the one deliberate carve-out from that default — an async scan must briefly hold its result to deliver it; those results are held only in Redis, delivered single-read (deleted when the report is first opened) with an automatic 24-hour expiry as a backstop if never opened, and are never written to our database. See the Privacy statement for detail.

5. Acceptable use

Your use of qsa.sh is additionally governed by the Acceptable Use Policy, which is incorporated into these terms by reference. It sets out prohibited uses, the CGNAT/carrier and anonymizer refusals, rate limits, and enforcement. A conflict between these terms and the Acceptable Use Policy is resolved in favour of the stricter restriction.

6. No warranty; limitation of liability

qsa.sh is provided “as is” and “as available”, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty that scan output is accurate, complete, or identifies every vulnerability. A scan is a point-in-time, external observation and is not a guarantee of security.

To the maximum extent permitted by applicable law, the operator is not liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of data, profits, or goodwill, arising from your use of or inability to use qsa.sh — including any action you take, or fail to take, in reliance on scan output. Nothing in these terms excludes liability that cannot be excluded by law.

7. Indemnification

You agree to indemnify and hold harmless the operator from any claim, demand, loss, or expense (including reasonable legal fees) arising out of your use of qsa.sh in breach of these terms or the Acceptable Use Policy — in particular, scanning an IP address you were not authorized to scan, or attempting to use the service against an address that is not your own connecting address.

8. Governing law and jurisdiction

Governing jurisdiction: State of Florida, United States.

These terms are governed by the laws of the State of Florida, USA, without regard to its conflict-of-laws rules. You and the operator submit to the exclusive jurisdiction and venue of the state and federal courts located in Florida for any dispute arising out of or relating to qsa.sh or these terms.

9. Operator-transmitted scans

The operator (Tuxxin) is the party that actually emits scan packets, from its own infrastructure and its own real, attributable server IP addresses (a transparent-scanner model — see About). In some jurisdictions the act of port scanning can itself be regulated irrespective of a target owner’s authorization. The operator therefore constrains its own posture — bounded scan intensity, refusal of CGNAT, mobile-carrier, and detected-anonymizer connections, honouring opt-outs, and jurisdiction selection — as part of the controls governing this service, in addition to your representation that you are authorized. Your authorization does not, by itself, transfer or discharge the operator’s own responsibilities.

10. Changes to these terms

We may revise these terms. The effective version is identified above and pinned when a scan is admitted, so the version shown to you is recorded (as a version identifier only — never tied to your identity). Material changes take effect on publication; continuing to use qsa.sh after a change means you accept the revised terms.

11. Contact

Abuse reports, opt-out requests, and security disclosures about qsa.sh itself all go through our contact form (choose the matching subject). Owners can permanently exclude an IP address or range they control from scanning — see About.