Skip to content

Acceptable use policy

UPKira sends real requests to the targets you enter. These rules keep those requests pointed at systems you are allowed to check, and keep the platform safe for everyone.

Last updated: October 1, 2026

1. Scope

This policy applies to everyone who uses UPKira: account holders, workspace members, and anyone who calls our heartbeat endpoints, badges or APIs. It is part of our terms of service. Your workspace members must follow it too.

2. Monitor only what you are authorized to monitor

Every monitor makes our probes send requests to the target you enter. You may only point UPKira at targets that:

  • you own or operate; or
  • you have the owner's permission to monitor, for example a client's site you manage under contract; or
  • are public endpoints you rely on, such as a third-party API's health URL. These must be checked at a reasonable interval and in line with that provider's terms.

Do not supply credentials, API keys or authorization headers unless you are authorized to use them for monitoring.

3. No scanning, attacks or SSRF abuse

UPKira is a monitoring tool. You must not use it, or try to use it, to:

  • reach private, loopback, link-local or cloud metadata addresses, or any internal network; this includes using redirects, DNS rebinding, crafted hostnames, or alternative IP notation to get around our request guard;
  • scan ports, look for vulnerabilities, enumerate hosts, or map a network;
  • load test or stress test any system, or contribute to a denial-of-service attack;
  • brute-force or guess passwords, tokens or other credentials, including through repeated monitor or authorization header changes;
  • scrape content or harvest data from a target;
  • send malicious payloads, exploits or malware in request bodies, headers or webhooks.

Our probes refuse private and metadata addresses and re-check every redirect. If you find a way around those checks, report it to us under the responsible disclosure rules. Do not use it.

4. Respect limits and the platform

  • Do not work around plan limits, rate limits or manual-check caps. For example, do not open several Free accounts or workspaces to get more capacity.
  • Do not flood heartbeat URLs, status-page subscription forms, badges or authentication endpoints with traffic.
  • Do not create accounts automatically, or share one account between several people.
  • Do not probe, scan or test the security of UPKira itself, except under our responsible disclosure rules.
  • Do not interfere with other customers' workspaces or data, or try to access them.

5. Status pages and content

Status pages, incident updates, monitor names and logos must not:

  • impersonate another company or brand, or mislead visitors about who runs the page;
  • be used for phishing, fraud or malware distribution;
  • infringe intellectual property, privacy or publicity rights;
  • contain unlawful, defamatory, hateful or harassing material.

6. Alerts, email and subscribers

  • Only add email addresses, chat channels and webhooks that you control or are allowed to send alerts to.
  • Do not use alerts, test alerts or status-page subscriptions to send spam or unwanted messages.
  • Do not subscribe other people to status pages without their consent. Subscriptions use double opt-in, and every email includes an unsubscribe link.

7. Enforcement

If we believe this policy has been broken, we may pause or archive monitors, disable alert channels or status pages, limit features, or suspend or close the account. We usually contact the workspace owner first. We may act without notice to stop ongoing harm, protect a third party, or comply with the law. Serious abuse may be reported to the relevant authorities or network operators.

8. Reporting abuse

If UPKira probes are reaching a system you run without your permission, email hello@upkira.com. Include the target URL or IP address, the time window, and your server logs if you have them. Our HTTP probes identify themselves with the user agent UPKiraMonitor/1.0. We will investigate and stop unauthorized monitoring.