Lexicon Media Holdings LLC d/b/a AllScanTool

Acceptable Use Policy

Last Updated: July 15, 2026 Effective Date: July 15, 2026
This Acceptable Use Policy (AUP) governs your use of the AllScanTool platform at allscantool.com. It is incorporated by reference into the Terms of Use. By using the Service, you agree to this AUP. Violations may result in immediate access termination.

1. Authorized Use

You may use AllScanTool to scan code you own or have permission to scan. That's what we built it for.

The Service is provided for legitimate security analysis of source code you own or are authorized to scan. Authorized uses include:

Your Own CodeScanning source code you wrote or own outright, including personal and commercial projects
Authorized Client CodeCode belonging to a client who has explicitly authorized you to perform a security scan on their behalf
Professional Security AuditsSecurity reviews conducted within your professional responsibilities as a developer, consultant, or auditor
Educational UseLearning about vulnerability patterns using code samples you own or have license to use for educational purposes

You remain responsible for ensuring you have proper authorization before submitting any code for scanning.

2. Prohibited Uses

Don't scan code you don't own, don't try to break our system, and don't resell what we build.
2.1
Unauthorized Code

You may not submit source code you do not own or do not have explicit authorization to scan, including code obtained through unauthorized access, data breaches, intellectual property theft, or reverse engineering of third-party software.

2.2
Malicious Payloads

You may not submit code designed to disrupt, damage, or exploit the Service or its infrastructure, including intentional malware, denial-of-service payloads, exploit code targeting AllScanTool systems, or self-executing scripts designed to compromise the scan environment.

2.3
Automated Abuse

You may not use automated tools, scripts, or bots to submit scans at a volume exceeding normal individual use without prior written authorization from AllScanTool. This includes scraping scan results, probing the scan engine for behavioral fingerprinting, or attempting to map the vulnerability rule set through systematic submissions.

2.4
Reverse Engineering

You may not decompile, disassemble, reverse-engineer, or attempt to derive the source code of the scan engine, its vulnerability rules, its AI/ML components, or any proprietary AllScanTool technology.

2.5
Commercial Exploitation

You may not resell, sublicense, repackage, or commercialize scan results or the scanning capability as a standalone product or service without a separate written agreement with Lexicon Media Holdings LLC.

2.6
Security Circumvention

You may not attempt to bypass, disable, tamper with, or exploit the Unlock URL mechanism, the payment system, the report access controls, rate limiting, or any other security feature of the Service.

2.7
Unlawful Use

You may not use the Service for any purpose that violates applicable law, including scanning code in connection with criminal activity, intellectual property infringement, unauthorized access to computer systems, or any activity prohibited under the Computer Fraud and Abuse Act or equivalent laws in your jurisdiction.

2.8
Live Personal Data in Code

You should not submit code containing live, production personal data — real names, credentials, social security numbers, financial account numbers, health records, or biometric data — unless it is necessary for the security audit and you have a lawful basis for processing that data. You remain solely responsible for the data you submit. AllScanTool processes submitted code in ephemeral memory only and does not extract or store embedded personal data, but transmission to our AI/ML sub-processor occurs during scanning.

3. AI Processing and Your Code

We use AI to scan your code. Your code is never used to train AI models. Here is exactly what happens to it.
✓ AllScanTool's AI Commitment
Your code is not used to train AI models.

Under AllScanTool's paid API plan with our AI/ML sub-processor (Mistral AI), submitted source code is not used to train, fine-tune, or improve any AI model — ours or our sub-processor's.

Your code is not stored by AllScanTool.

AllScanTool processes your code in ephemeral memory only. We do not store, log, cache, or retain it at any stage after results are delivered.

Transmission to our AI sub-processor occurs during scanning.

To perform vulnerability detection, your code is transmitted over TLS to our AI/ML sub-processor (Mistral AI). Mistral AI may retain submitted code for up to 30 days for abuse monitoring purposes under our Data Processing Agreement, after which it is permanently deleted. Mistral AI does not use your code to train its models on AllScanTool's plan.

Any change in AI/ML sub-processor will require a corresponding update to the retention and data handling disclosures in this policy before the new sub-processor begins processing user data.

What You Agree to by Submitting Code

By submitting source code for scanning, you acknowledge and consent to:

  • Transmission of your code to AllScanTool's backend infrastructure over encrypted connections (TLS 1.2+)
  • Processing of your code by our AI/ML sub-processor (Mistral AI) for vulnerability pattern detection
  • Temporary retention of your code by Mistral AI for up to 30 days for abuse monitoring, as governed by the Data Processing Agreement at legal.mistral.ai/terms/data-processing-addendum

Zero Data Retention Option

If you require elimination of the 30-day Mistral AI abuse-monitoring retention window, Zero Data Retention (ZDR) is available on Mistral's Scale plan. Contact privacy@allscantool.com to discuss whether AllScanTool's current plan configuration supports ZDR for your use case.

4. Accessibility Compliance (WCAG)

AllScanTool provides code security scanning and does not create websites. You are responsible for your website's accessibility.

AllScanTool provides automated security scanning services for source code and does not create, host, publish, or maintain websites. Scan results consist of technical findings regarding security vulnerabilities in submitted code and do not constitute guidance on website accessibility compliance.

User Responsibility

Users are solely responsible for ensuring that any website or application built using code scanned by AllScanTool complies with the Web Content Accessibility Guidelines (WCAG) and all applicable accessibility laws and regulations, including:

  • WCAG 2.1 / 2.2 Level AA compliance guidelines
  • Americans with Disabilities Act (ADA) requirements
  • Section 508 of the Rehabilitation Act
  • EU Web Accessibility Directive
  • State and local accessibility mandates

No Accessibility Warranties

AllScanTool makes no representation or warranty regarding:

  • The accessibility compliance of any code scanned through the Service
  • The accessibility of any website or application that incorporates scanned code or uses findings from scan results
  • Whether scan results address accessibility-related vulnerabilities (scan targets security vulnerabilities only)

Limitation of Liability

In no event shall AllScanTool (including any authorized representatives, principals, agents, officers, directors, shareholders, members, partners, employees, associates, successors, assigns, subsidiaries, licensees, and/or owners) be liable to you or to any third party claiming through you or on your behalf for any failure to meet accessibility compliance requirements.

Users agree to take all responsibility related to meeting accessibility compliance for any website or application developed using code scanned through the Service.

5. Enforcement

If you abuse the Service, we will block you. For serious violations we will pursue legal remedies.

AllScanTool reserves the right to take the following enforcement actions for violations of this AUP:

IP-Level BlockingBlock access from IP addresses exhibiting abusive patterns, automated behavior, or policy violations
Unlock URL InvalidationImmediately invalidate Unlock URLs associated with violating sessions, without refund
Rate LimitingApply or tighten rate limits on submissions exhibiting patterns inconsistent with individual use
Legal RemediesReport violations to law enforcement and pursue civil or criminal remedies for material violations

6. Sub-Processor Changes

If we change the AI/ML provider that scans your code, we will tell you before the change takes effect.

AllScanTool currently uses Mistral AI as its AI/ML sub-processor for vulnerability scanning. If AllScanTool adds a new sub-processor or replaces Mistral AI, we will:

  • Post a notice at allscantool.com/sub-processors at least 14 days before the change takes effect
  • Update this policy and the Privacy Policy to reflect the new sub-processor
  • Ensure any replacement sub-processor operates under an equivalent Data Processing Agreement

The current sub-processor list is maintained at allscantool.com/sub-processors.

You may object to AllScanTool's appointment of a new sub-processor during the 14-day notice period by emailing privacy@allscantool.com. If you object, your sole and exclusive remedy is to terminate use of the Service before the new sub-processor takes effect.

7. US State Privacy Rights

If you are in California, Virginia, Colorado, Connecticut, Texas, or other states with privacy laws, you have specific rights.

In addition to California rights covered in our Privacy Policy, the following US state privacy laws may apply depending on your state of residence. AllScanTool honors all applicable state consumer privacy rights regardless of threshold requirements.

StateLawKey RightsHow to Exercise
CACCPA/CPRAAccess, delete, correct, opt out of sale/sharing, non-discriminationprivacy@allscantool.com or allscantool.com/do-not-sell
VAVCDPAAccess, delete, correct, portability, opt out of profilingprivacy@allscantool.com
COCPAAccess, delete, correct, portability, opt out of profiling (GPC honored)privacy@allscantool.com
CTCTDPAAccess, delete, correct, portability, opt out of profilingprivacy@allscantool.com
TXTDPSAAccess, delete, correct, portability, opt out of sale/sharingprivacy@allscantool.com
FLFDBRAccess, delete, correct, portability, opt out of sale/sharingprivacy@allscantool.com
MTMNDPAAccess, delete, correct, portability, opt out of profilingprivacy@allscantool.com
MNMNDPAAccess, delete, correct, portability, opt out of profilingprivacy@allscantool.com
NJNJDPAAccess, delete, correct, portability, opt out of sale/sharingprivacy@allscantool.com
OROCPAAccess, delete, correct, portability, opt out of sale/sharingprivacy@allscantool.com

AllScanTool honors Global Privacy Control (GPC) signals at the infrastructure level where supported. AllScanTool does not sell or share personal information for targeted advertising under any state law definition.

All consumer rights requests are fulfilled within 45 days of receipt. Verification requires your Unlock URL or transaction ID from your payment receipt.

8. Business Transfer

If AllScanTool is ever sold or merged with another company, we will tell you what happens to your data before the transfer happens.

This Policy, together with the Privacy Policy, Terms of Use, and Terms of Sale, may be assigned or transferred in the event of a merger, acquisition, sale of all or substantially all of Lexicon Media Holdings LLC's assets, or any other change of control.

In the event of such a transfer:

  • We will post a notice at allscantool.com at least 30 days before the transfer takes effect
  • Data collected under this Policy will be transferred to the successor entity subject to the same commitments made here
  • If the successor entity's data practices materially differ from AllScanTool's No-Logs Policy, users will be notified and given the opportunity to request deletion of their data before the transfer

9. Dispute Resolution and Escalation

If you have a complaint, start with us. If we can't resolve it, here is how to escalate.

If you believe this AUP or any AllScanTool policy has been violated, or if you have an unresolved privacy concern, use the following escalation path:

Step 1
Contact AllScanToolEmail privacy@allscantool.com. We respond within 30 days.
Step 2
Supervisory AuthorityEU/UK/EEA users may lodge a complaint with their local data protection authority at any time.
Step 3
Legal ProcessFormal disputes governed by the arbitration clause in the Terms of Use.

10. Reporting Violations

Saw something wrong? Tell us.

If you become aware of any use of the Service that violates this AUP, please report it to: abuse@allscantool.com

Reports are reviewed by AllScanTool and investigated where technically feasible given the stateless, no-account architecture of the platform. We take all reports seriously and will take appropriate action where a violation is confirmed.

11. Updates to This Policy

If we change the rules, we will tell you before the changes take effect.

We may update this AUP from time to time. Changes will be posted with a revised Last Updated date. Material changes — including any expansion of prohibited uses, changes to the AI processing section, changes to sub-processor notification commitments, or changes to accessibility provisions — will be announced via a prominent site banner at least 14 days before taking effect.

You can always review the latest version at allscantool.com/aup.

12. Contact

For questions about this Acceptable Use Policy:

Lexicon Media Holdings LLC d/b/a AllScanTool
General: legal@allscantool.com
Privacy: privacy@allscantool.com
Abuse: abuse@allscantool.com
Mailing Address: 1209 Mountain Road PL NE #10912, Albuquerque, NM 87110, USA

Related Policies