Abuse Reporting and Opt-Out
Effective and last updated: August 22, 2026 · Version 1.0
DevTools provides passive and limited-active network diagnostics through a separate backend service (currently hosted at Railway; target endpoint api.devtools.tools). We take misuse seriously and respond to credible reports. This page describes what to report, how to opt out, and what we log.
1. What counts as abuse
- Using DevTools backend tools against systems you do not own or lack written permission to test.
- Automated high-volume queries intended to disrupt a target, evade rate limits, or map third-party infrastructure without authorization.
- Submitting malware, illegal content, or personal data through any DevTools channel.
- Attempting to bypass SSRF protections, probe internal networks, or use the service as an open proxy.
Permitted use requires lawful purpose and authorization for the specific target. See our Terms of Service for the full acceptable-use policy.
2. How to report abuse
Email abuse@genithora.com with the subject line Abuse Report. Include:
- The affected domain, IP, or URL.
- Approximate time (UTC) and, if known, the DevTools tool used.
- Evidence such as log excerpts, headers, or request patterns.
- Your contact details and authority to act for the affected resource.
We aim to acknowledge credible reports within 5 business days. Emergency security issues may also be sent to devtools@genithora.com.
3. Opt-out for site owners
If you operate a website or domain and do not want DevTools passive checks against it, you may:
- Add
User-agent: DevToolsBotandDisallow: /to yourrobots.txt, then notify us at abuse@genithora.com. - Email an opt-out request with proof of domain control (DNS TXT or registrar correspondence).
Opt-out applies to DevTools-initiated checks only. It does not block end users from running lookups on public data about your domain through other means.
4. What we log
Backend access logs retain a masked client IP (last octet redacted), request path, timestamp, and error metadata for up to 7 days for security and abuse investigation. User-entered targets (domains, URLs, IPs) needed to perform the check are processed transiently; we do not store tool input content beyond short operational caches documented in our Privacy Policy.
5. Enforcement
We may rate-limit, block targets, block client IPs or ranges, or suspend access where needed to protect the service, third parties, or comply with law. Repeat or severe abuse may be referred to hosting providers or authorities.