# Disclaimer and terms of use

QACyberWatch produces **automated heuristic findings** from public data: Certificate Transparency logs, public DNS, registration data and open reputation feeds.

1. **A finding is not an accusation.** A flagged hostname is a candidate for human review. Legitimate services, subsidiaries, hosting previews and ordinary words in other languages appear among the results, and the scoring makes no claim about the intent of whoever registered a name.
2. **Verify before acting.** Do not block, report, publish or attribute a finding without independent verification. Where a finding looks like a live campaign against a Qatari organisation, share it with the organisation and with the National Cyber Security Agency before publishing it.
3. **Brand names.** The names of banks, payment services, telecom operators, ministries and other organisations are used only to identify what the tool protects. They remain the property of their owners. QACyberWatch is an independent open-source project and is not affiliated with, endorsed by or acting on behalf of any of them.
4. **No warranty.** The software, the website, the console and the published relay feed are provided as is, without warranty of any kind and without liability for any decision taken on the basis of their output.
5. **Privacy.** The browser console stores its data only in your browser. The website sets no cookies and runs no analytics. The relay feed contains observations of public certificate data only.
6. **Lawful use.** Use the tool only to protect organisations and users. Do not use it to interfere with systems you are not authorised to test.

By using the software, the website or the feed you accept these terms.
