Enterprise SaaS Agreement

WebChecky Terms & Conditions of Service

Effective Date: January 1, 2026 · Last Updated: 2026 · Version 3.2 · Legally Binding Terms

Please read these Terms & Conditions carefully before accessing or utilizing WebChecky. This agreement governs your use of all cloud monitoring engines, REST APIs, Playwright synthetic browser automation workers, local monitoring agents (webchecky-agent), security scanners, DNS/Email diagnostic tools, cron heartbeat switches, and white-label PDF reporting generators provided by WebChecky (“we,” “our,” or “us”) via https://webchecky.com.

By registering an account, integrating API keys, deploying local monitoring agents, scheduling synthetic journeys, or initiating audits, you signify your unreserved agreement to these Terms. If you do not agree to every provision herein, you must immediately cease all access to the Service.

1 Definitions & Acceptance of Terms

  • “WebChecky”, “Service”, or “Platform”: Refers to the website hosted at https://webchecky.com, all underlying backend scheduling workers, Playwright browser test runners, public API endpoints, database clusters, notification dispatchers, local agent binaries, and reporting tools.
  • “User”, “Customer”, “You”, or “Your”: Any individual, business, agency, developer, or legal entity that registers an account, accesses our dashboard, configures monitoring checks, generates reports, or utilizes our API.
  • “Monitored Target” or “Asset”: Any website URL, hostname, IP address, REST API endpoint, SSL certificate, DNS zone, or cron heartbeat identifier registered by the Customer for continuous inspection.
  • “Synthetic Journey”: An automated multi-step browser user flow orchestrated via headless Playwright engines (e.g. login sequences, shopping cart checkouts, form submissions).
  • “Local Agent”: The standalone webchecky-agent executable software deployed on private customer infrastructure, office LANs, VPNs, or localhost environments.

By using WebChecky, you warrant that you are at least eighteen (18) years of age, legally capable of entering into binding contracts, and authorized to represent any organization on whose behalf you register.

2 Account Registration, Team Workspaces & Credential Security

To access advanced monitoring, automated alerting, and PDF generation, you must create a registered account.

A. Account Integrity & Single Sign-On (SSO)

You must provide accurate, current, and complete information during registration. When using Google OAuth Single Sign-On, you are responsible for maintaining the security of your underlying Google account.

B. Multi-User Team Workspaces & Role-Based Access Control (RBAC)

WebChecky supports collaborative team workspaces with distinct permission tiers (Owner, Admin, Member, Viewer). Workspace Owners and Admins are legally and financially responsible for all actions taken by invited team members, including the addition of monitored targets, configuration changes, and API consumption.

C. Credential Protection & Unauthorized Access

You are strictly responsible for maintaining the confidentiality of your passwords, API keys, and agent pairing tokens. You must immediately notify WebChecky at security@webchecky.com if you suspect any unauthorized access or compromise of your credentials.

3 Comprehensive Scope of WebChecky Monitoring & Diagnostic Engines

WebChecky provides an all-in-one platform engineered to continuously inspect, benchmark, and alert on web systems. You acknowledge and agree to the operational specifications of each module:

3.1 Uptime, Latency & Content Assertion Monitoring

Automated HTTP/HTTPS requests executed at your configured interval (e.g. 1 to 60 minutes). Checks verify HTTP response codes (2xx/3xx), network round-trip latency, custom keyword presence (keyword_must_contain), and absence of critical error strings (keyword_must_not_contain). On consecutive failure thresholds, the system logs incident states and triggers multi-channel alerts.

3.2 REST API Validation & Playwright Synthetic Journeys

Supports complex API monitoring with custom request headers, request bodies, expected status ranges (e.g. 200-299), response time SLA caps, and JSON body path assertions. Headless browser journeys execute multi-step user actions (navigate, click, type, fill, wait, assert text). On assertion failure, automated full-page screenshots and step traces are recorded to provide diagnostic evidence.

3.3 SSL/TLS Certificate Chains & Domain Registration Expiry

Continuous TLS handshake audits verify certificate authority trust chains, expiration timestamps, modern cipher suites, and protocol versions. Proactive warning alerts are dispatched at 30, 14, 7, and 1 day thresholds prior to SSL or WHOIS domain expiration.

3.4 Core Web Vitals (CWV) & Speed Diagnostics

Evaluates Google Core Web Vitals metrics including Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), Time to First Byte (TTFB), First Contentful Paint (FCP), total page byte weight, and resource breakdown distributions.

3.5 DNS Zone Health, Email Security (SPF/DKIM/DMARC) & Blacklists

Queries DNS record types (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, PTR, SRV, DNSSEC). Detects record drift and alerts on changes (e.g. A record IP changes). Deeply analyzes email deliverability, SPF syntax and lookup count limits (RFC 7208), DKIM selector validity, DMARC policy enforcement (p=none, quarantine, reject), and domain reputation across DNSBL blacklists.

3.6 WebChecky Security Center & OWASP Top 10 Scanner

Audits HTTP security response headers (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), insecure cookie flags (Secure, HttpOnly, SameSite), unsafe CORS policies, directory indexing, and publicly exposed .git repositories or environment config files.

3.7 Attack Surface & Vulnerability Exposure Monitor

Probes target hostnames for unintended public exposure of administrative portals (/admin, /wp-admin, /login), XML-RPC APIs (/xmlrpc.php), debug logs, source maps, backup archives (.zip, .sql, .tar.gz), and test/staging subdomains.

3.8 Website Technology Stack Fingerprinting & Evolution

Fingerprints CMS platforms (WordPress, Shopify, Drupal, Joomla, Wix, Webflow), web frameworks (Laravel, Next.js, React, Vue, Django), web servers (Nginx, Apache, IIS, Cloudflare), cloud infrastructure (AWS, Azure, GCP, DigitalOcean), and analytics scripts. Tracks stack drift and alerts when underlying software changes.

3.9 Technical & On-Page SEO Audit Engine

Parses page titles, meta descriptions, heading structure (H1/H2), canonical URLs, robots.txt, sitemap.xml, noindex directives, Open Graph, Twitter cards, Schema.org JSON-LD, hreflang annotations, broken internal links, and image alt attributes.

4 Mandatory Target Ownership & Testing Authorization Warranties

Strict Customer Authorization Warranty

By submitting any URL, domain name, hostname, API endpoint, or server address to WebChecky, you explicitly, irrevocably, and legally warrant that:

  1. You are the registered owner or administrator of the target infrastructure; OR
  2. You have obtained explicit, verifiable written authorization from the legitimate owner to conduct continuous HTTP monitoring, synthetic browser testing, exposure probing, and security audits.

WebChecky disclaims all liability for tests performed on targets added without proper authorization. You agree to fully indemnify and hold harmless WebChecky from any third-party claims arising from unauthorized scanning.

5 Acceptable Use Policy (AUP) & Prohibited Conduct

You agree to use WebChecky solely for legitimate uptime, performance, security, and administrative purposes. You shall NOT:

  • Denial of Service: Use WebChecky to generate excessive request volume, flood targets, or intentionally cause denial of service (DoS/DDoS) to any third-party network or server.
  • Malicious Exploitation: Use diagnostic findings to exploit vulnerabilities, inject malicious payloads, bypass authentication mechanisms, or gain unauthorized administrative access.
  • Spam & Malicious Automation: Configure synthetic journey steps that post automated spam, submit fraudulent financial transactions, scrape copyrighted material, or violate third-party terms of service.
  • Platform Reverse Engineering: Decompile, reverse engineer, disassemble, or attempt to extract the source code or proprietary heuristics of WebChecky's monitoring engine or local agent binaries.
  • Quota & Rate-Limit Abuse: Circumvent subscription tier limits, concurrent check maximums, or rate limiters through multiple trial accounts or automated bot scripts.

We reserve the right to immediately terminate or suspend accounts found in violation of this Acceptable Use Policy without prior notice or refund.

6 Synthetic Browser Automations & Credential Encryption

WebChecky utilizes advanced cryptographic protections for synthetic journey and API authentication secrets:

  • Fernet Symmetric Encryption: All sensitive API bearer tokens, Basic Auth credentials, and synthetic test passwords are encrypted using AES-128/256 Fernet symmetric cryptography prior to persistent storage.
  • Customer Script Responsibility: You are solely responsible for the actions performed by your synthetic journey scripts on your target application (e.g. creating test records, database state mutations, or triggering automated email dispatches on your server).
  • Automated Evidence Capture: You acknowledge that Playwright workers capture visual screenshots of test failures. You should avoid configuring journeys that display sensitive third-party personally identifiable information (PII) on screen during testing.

7 Agency White-Label PDF Reporting & Distribution License

Subscribers with qualifying plans (e.g. Agency, Pro, Enterprise) are granted a non-exclusive, revocable, worldwide license to customize and distribute generated Website Audit PDF Reports:

✓ Authorized Customizations

You may incorporate your agency name, logo, brand color palettes (hex themes), client company names, and custom executive notes into generated PDF reports and deliver them directly to your clients.

✓ Platform Verification Branding

To maintain audit integrity and diagnostic credibility, generated PDFs include verified WebChecky footer branding (WebChecky · Verified Website Audit & Monitoring Platform). You agree not to tamper with, obfuscate, or misrepresent the underlying diagnostic scores or cryptographic verification footers.

8 Cron Job & Heartbeat Monitoring (Dead Man's Switch) Rules

When using WebChecky heartbeat monitoring (/heartbeat/) for scheduled cron tasks and background workers:

  • Timing & Grace Periods: Heartbeats require an expected execution period (e.g. every 60 minutes) and a grace period (e.g. 15 minutes). An overdue alert (🚨 Backup Cron Job Failed) is triggered only after the combined threshold has elapsed without an incoming ping.
  • Failure Pings: Your scripts may explicitly signal task execution failure by hitting the endpoint with /fail or sending JSON payload {"status":"fail"}.
  • Payload Logging: Heartbeat endpoints accept optional request bodies (e.g. execution logs, durations, error traces up to 1,000 characters). You agree not to send sensitive secrets, unencrypted private keys, or illicit content in heartbeat log payloads.

9 Local Agent Software License (webchecky-agent)

WebChecky grants you a personal, non-transferable, non-exclusive license to download, install, and execute the webchecky-agent binary on servers, desktops, or containers under your control for the sole purpose of monitoring internal LAN, staging, or private endpoints.

  • The agent communicates telemetry securely with WebChecky over HTTPS using ephemeral pairing tokens.
  • You are responsible for the network environment and resource utilization (CPU/RAM/network bandwidth) consumed by local agents running on your hardware.

10 Subscriptions, Stripe Billing, Upgrades & Refund Policies

  • Recurring Subscriptions: Paid tiers are billed on a recurring monthly or annual basis in advance via Stripe. By selecting a paid tier, you authorize WebChecky to charge your designated payment method on a recurring basis.
  • Plan Changes: Upgrades take effect immediately with prorated billing. Downgrades take effect at the conclusion of your current prepaid billing cycle.
  • Auto-Renewal & Cancellation: Subscriptions automatically renew unless canceled prior to the billing date via your Account Settings or the Stripe Customer Portal. Upon cancellation, your account retains paid features until the paid period expires.
  • Refund Policy: Because cloud computing instances, multi-location monitoring workers, and headless browser clusters are provisioned immediately upon upgrade, all fees are non-refundable, except where required by mandatory consumer protection law.

11 Service Availability, SLAs & Third-Party Alert Routing Disclaimers

  • 99.9% Uptime Goal: We target 99.9% availability for WebChecky's monitoring infrastructure. Scheduled maintenance windows will be communicated in advance whenever feasible.
  • Third-Party Notification Delivery: WebChecky dispatches incident alerts immediately upon detection. However, we cannot guarantee timely delivery where third-party upstream providers experience delays or outages (e.g. email spam filters, Microsoft Graph throttling, Slack API outages, Discord rate limits, Microsoft Teams webhook downtime, or carrier SMS blocks).
  • Transient Network Hops: Internet routing anomalies, BGP routing flaps, and regional fiber cuts may occasionally produce false-positive or false-negative readings. WebChecky implements multi-retry logic and debouncing to minimize false alerts.

12 Intellectual Property & Data Rights

  • WebChecky IP: All software, algorithms, user interfaces, documentation, logos, and visual designs are the exclusive intellectual property of WebChecky and protected by international copyright, trademark, and trade secret laws.
  • Customer Data Ownership: You retain full ownership of all target configurations, synthetic scripts, and private report notes created under your account. You grant WebChecky a limited license to process and store this data solely to provide the Service.

13 Disclaimers & Limitation of Liability

THE SERVICE IS PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR UNINTERRUPTED AVAILABILITY.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT SHALL WEBCHECKY, ITS DIRECTORS, EMPLOYEES, AFFILIATES, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS, DATA LOSS, BUSINESS INTERRUPTION, DOWNTIME COSTS, OR REPUTATIONAL HARM) ARISING OUT OF OR IN CONNECTION WITH YOUR USE OF THE SERVICE.

WEBCHECKY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF THESE TERMS SHALL NOT EXCEED THE GREATER OF (A) $100 USD OR (B) THE TOTAL FEES PAID BY YOU TO WEBCHECKY IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.

14 Customer Indemnification

You agree to defend, indemnify, and hold harmless WebChecky, its officers, directors, employees, and agents from and against any and all claims, damages, obligations, losses, liabilities, costs, or debt, and expenses (including attorney's fees) arising from:

  • Your use of or access to the Service;
  • Your violation of any provision of these Terms or the Acceptable Use Policy;
  • Your monitoring or security scanning of any target URL, domain, or API without proper authorization; or
  • Any third-party claim that your synthetic test journeys or data violated third-party rights.

15 Suspension, Termination, Governing Law & Dispute Resolution

  • Termination by You: You may close your account at any time by deleting your account from the Settings dashboard.
  • Termination by WebChecky: We may suspend or terminate your account immediately without prior notice if you breach these Terms, fail to pay subscription fees, or engage in malicious scanning activity.
  • Governing Law: These Terms shall be governed by and construed in accordance with the laws of the jurisdiction where WebChecky operates, without regard to conflict of law rules.
  • Mandatory Arbitration & Class Action Waiver: Any dispute arising out of or relating to these Terms shall be resolved through binding individual arbitration rather than in court. You agree to waive any right to participate in a class-action lawsuit or class-wide arbitration.

WebChecky Legal & Governance Office

Legal Inquiries: legal@webchecky.com

Customer Support: support@webchecky.com

Platform URL: https://webchecky.com