Acceptable use policy
Last updated September 24, 2026
Gryphon makes connections to other people's networks on your behalf: every check you set up has our servers, or your agent, reach out to an address you chose. That is useful when the address is yours and harmful when it is not, so this policy sets out what the Service may be used for. It is part of our Terms of Service, and applies to everyone who uses Gryphon, including everyone on your account.
1. Monitor only what you are allowed to
Point checks, including checks sent by the agent, only at systems that you own or operate, or that their owner has given you permission to monitor. Permission to use a website is not permission to monitor it: a check against someone else's server needs their agreement. If a hosting provider or network you use has rules about monitoring or scanning, follow them.
2. Checks are for monitoring, not for anything else
Do not use Gryphon's checks, the agent, or anything else in the Service to:
- scan, map or probe networks or systems you are not authorized to test, including discovering which addresses or ports are open;
- attack or disrupt any system, including by overloading it, by configuring many checks against one target, or by any form of load or stress testing;
- try to break into any system, guess or test passwords, or exploit vulnerabilities;
- use a check's response to read or extract information from a system you are not authorized to access, for example by repeatedly matching a page or a service's response against text you supply;
- use the TCP checks or any other check to send email, messages or other data to services that are not yours, or to relay traffic through our servers or through an agent;
- reach networks or addresses that our systems are configured to refuse, including private networks and cloud metadata services, or get around any restriction we place on where checks may connect;
- give a database check credentials you are not entitled to use.
3. The agent
Install the agent only on machines you own or are authorized to administer. Do not configure it to reach networks you are not authorized to access, or to turn off the limits it applies by default in order to reach the public internet on someone else's behalf. Do not use it as a proxy or relay. What a script check runs is your responsibility, and scripts must follow this policy too.
4. Status pages
A status page is public, so what you put on it must be lawful and honest. Do not publish a status page that:
- pretends to belong to a company or service you do not operate, or could mislead people about whose page it is;
- is used for phishing, fraud or spam, or links to them;
- misrepresents the state of a service in a way meant to deceive;
- contains anything unlawful, defamatory, hateful, harassing, sexually explicit, or that infringes someone else's intellectual property or privacy, including other people's personal information.
5. Accounts and the Service itself
Do not:
- share one login between several people, or otherwise get around your plan's limits;
- add people to an account, or as alert recipients, without their agreement, or use invitations or alerts to send unwanted messages;
- access another customer's data, or try to;
- interfere with the Service or its infrastructure, get around its rate limits or security, or use automated means to access it other than the apps, the agent and the interfaces we provide;
- resell the Service, or provide it to others as part of your own service, without a written agreement with us;
- use the Service for anything unlawful, or to help anyone else break the law or this policy.
6. Security research
If you believe you have found a security problem in Gryphon, please tell us at support@gocode.ca and give us a reasonable time to fix it before telling anyone else. While looking, do not access or change other customers' data, do not degrade the Service for others, and stop and tell us as soon as you find a problem. Testing that goes beyond what is needed to show a problem exists is not permitted.
7. If Gryphon is checking your systems without your permission
Our checks come from the addresses on our locations page, and our web checks identify themselves with the user agent "Gryphon". If they are reaching a system of yours that you did not agree to, email support@gocode.ca with the address being checked, the address the connections come from, and roughly when you saw them. We will investigate and, where the checks are not authorized, stop them.
8. What we do about breaches
We may investigate anything we reasonably believe breaches this policy. Depending on how serious it is, we may pause or remove the checks involved, take down a status page, suspend or close the account, and report the matter to the relevant authorities or the owner of an affected system. Where it is reasonable, we will tell you first and give you the chance to fix it; where there is a risk of harm to others or to the Service, we may act first and tell you afterwards.
9. Changes
We may update this policy as the Service changes and as we learn how it is used. Material changes will be announced in the same way as changes to the Terms of Service.
Contact
GoCode.ca
Reports and questions: support@gocode.ca