S/U

Splashbot Utilities

Digital Security & OSINT
TERMS // LEGAL NOTICE
01010100 01000101 01010010 01001101 01010011 00100000 00100110 00100000 01000011 01001111 01001110 01000100 01001001 01010100 01001001 01001111 01001110 01010011

Terms of Service & Operating Policies

Governing rules, authentication mandates, data privacy compliance, and acceptable use guidelines for the Human-in-the-Loop (HitL) Footprinting Service.

01

Service Scope & Deliverables

The Human-in-the-Loop (HitL) Footprinting Service provided by Splashbot Utilities compiles public digital assets, public data breach exposure markers, domain registrations, social media footprints, and related Open Source Intelligence (OSINT).

Execution utilizes automated Command Line Interface (CLI) tools—including but not limited to holehe, h8mail, maigret, ghunt, droopescan, dnsx, and nuclei—paired with manual human oversight to curate results, remove false positives, and omit unconfirmable data.

  • No Paid Data Sourcing: All underlying information is derived exclusively from publicly available indexes and third-party resources providing free access to breach data. No data is purchased by Splashbot Utilities.
  • Report Formatting: Final reports are produced in structured .PDF or .HTML formats. Alternative document formats may be requested upon submission, but generation in requested non-standard formats cannot be guaranteed if rendering issues arise.
02

Self-Audit Mandate & Cryptographic Verification

You may ONLY submit requests to perform footprinting on yourself. Third-party auditing, corporate target scouting, or unconsented reconnaissance on external individuals is strictly prohibited.

To verify ownership and explicit informed consent, multi-step cryptographic token procedures are strictly enforced based on submitted assets:

  • Social Media Profiles: A short, unique cryptographic token generated upon request submission at splashbot.online/submit MUST be placed within the public bio or profile description of every linked social account.
  • Websites & Domains: The generated cryptographic token MUST be placed within the target site's robots.txt file as an active text entry or code comment.
  • Email Verification Sequence: When an email address is provided without social accounts, verification operates via key-pair response:
    1. An automated script sends an initial key to the target email address.
    2. The user visits splashbot.online/auth and inputs the key.
    3. A secondary authorization "Token" is displayed and copied to clipboard.
    4. The user must email this exact Token back to the originating address.

Token Revocation & Expiry: If at any point during investigation a profile token or robots.txt entry is removed, informed consent is deemed immediately withdrawn, and operations cease. If no email confirmation reply is received within 72 hours, the submission is flagged as fraudulent and cancelled.

Investigation execution is aimed for completion within 3 to 5 working days (with a maximum threshold of 15 working days / 3 weeks). Once initial investigation completes, users are notified that social tokens may be removed. Website tokens must remain in robots.txt until full report delivery is confirmed.

03

Compliance with UK Law, DPA / UK GDPR & Critical Alerts

Data processing occurs strictly with explicit consent in alignment with the Data Protection Act 2018 / UK GDPR. Consent may be revoked at any time by requesting deletion of active investigation files. Detailed guidance regarding individual rights is maintained by the UK Information Commissioner's Office (ICO).

Fraud & Misuse Referrals: Where evidence suggests fraudulent submissions, account compromise, server unauthorized access, or coerced token placement (in potential violation of the Computer Misuse Act 1990), Splashbot Utilities immediately halts operations. Raw messaging, submitter metadata, and compiled trace logs will be preserved in a sterile .tar archive and provided directly to platform moderators and UK Law Enforcement agencies.

Critical Credentials Disclosure Protocol: If an investigation uncovers unredacted, exposed, or active plaintext passwords associated with your accounts, primary focus immediately shifts to user notification. Urgent safety notices are issued via direct communication channels formatted as follows:

# WARNING: ## Your password ||password123|| has been found on a breach site at https://breach.site/search?q=username If this is an active password, stop what you are doing and change your password on any site this is used. The report will NOT
continue until you have confirmed that you have taken action in regards to this immediate concern.
04

Prohibited Activities & Law Enforcement Escalation

Splashbot Utilities maintains a absolute zero-tolerance policy for activities violating civil or criminal statutes. Prohibited activity includes but is not limited to:

  • Attempting to stalk, harass, intimidate, or doxx any individual.
  • Coercing, tricking, or manipulating third parties into placing authentication tokens on assets they control.
  • Submitting fraudulently acquired domains, compromised servers, or unauthorized social handles.
⚠ LEGAL NOTICE

In any case where third-party harassment or unauthorized target profiling is identified, Law Enforcement is our FIRST port of call. Splashbot Utilities reserves full rights to proactively notify the Police, National Cyber Force (NCF), Action Fraud, or relevant platform trust & safety teams.

05

Fee Structure & Non-Expedited Processing

At this time, Splashbot Utilities operates strictly as a FREE TO REQUEST, FREE TO RECEIVE platform. No monetary fees are charged, and no payments are accepted under any circumstances.

  • No Expedited Options: Offering payments or compensation to fast-track, prioritize, or alter audit procedures is explicitly refused.
  • Anti-Tamper Warning: Offering financial compensation or requesting expedited delivery will trigger security flags, resulting in processing delays or immediate request cancellation.
  • Turnaround Expectation: Standard turnaround for HitL footprinting is 3 to 5 working days, with an allowable ceiling of up to 15 working days depending on manual verification backlogs and external server responses.
06

Limitation of Liability & Accuracy Disclaimer

Because underlying data is aggregated via third-party repositories, search tools, and external indices, Splashbot Utilities cannot guarantee 100% data accuracy or absolute completeness. While rigorous manual verification steps are taken to strip false positives, users acknowledge that public index data may be stale, mirrored, or inaccurate.

Other than statutory liabilities that cannot be excluded or limited under English and Welsh law, Splashbot Utilities disclaims all liability for actions taken, reliance placed, or security choices made based upon compiled report contents.