This page is a draft written to get review started, not a finished legal document. It has not been approved by a lawyer and must not be relied on as one.
This Terms of Service page was drafted by an engineering agent responding toissue #188 , from the codebase and product behaviour as they exist today. It is not legal advice, it has not been reviewed by counsel, and several clauses below are marked as needing a real legal answer rather than an engineer's best guess. Do not treat this page as binding until that review has happened and this notice has been removed.
These terms apply to your use of BGPScout - the website at bgpscout.io, the account-based application behind sign-in, the public REST API, and the MCP (Model Context Protocol) server - operated by Hive Data Center Inc. ("BGPScout", "we", "us"), Montreal, Quebec, Canada. By creating an account or otherwise using the service you agree to these terms.
Account creation is by OAuth only, through Google or PeeringDB. BGPScout does not offer local email/password accounts and does not store a password for your account. You are responsible for the security of the Google or PeeringDB account you sign in with; a compromise of that account is a compromise of your BGPScout account.
You may delete your own account and its associated data at any time from the account page. Deletion removes your API keys, watchlist, saved searches, favourites and watch rules. Traceroute measurements you submitted are not deleted, because they are also other people's shared network-measurement data; the link to your account is removed instead.
You agree not to:
We may suspend or terminate access for a breach of this section. See Termination below.
Limits are enforced per session or API key and, for unauthenticated traffic, per IP address, on a 15-minute rolling window unless noted:
/mcp, /mcp/tools, /mcp/call/*): 60 requests / minute, per API key where one is presented, otherwise per IP.These figures are read from the running rate-limiter configuration and will drift if that configuration changes; the limiter's own response headers (RateLimit-*, Retry-After) are the authoritative source at any given moment. Sustained or automated breach of a limit is a violation of Section 3.
A personal API key, the public REST API and the MCP server are available to every signed-in account today, at no charge, as part of "Demo access" (see Section 6). Access is tied to your account; do not share your API key. Revoke a key immediately from the account page if you believe it has leaked.
The MCP server exposes the same underlying data as the web application and the REST API, in a form intended for AI agents and other automated tools. The acceptable-use terms in Section 3 apply identically to requests made through MCP, the API, and the browser.
"Demo access" is the current default plan for every signed-in account: unlimited use of every search, map and analysis tool on the platform, no advertising, and a personal API key with access to the public REST API and MCP server, at no charge and with no credit card or trial clock. This reflects the product's current stage - it is offered "free while we deploy features" - and is not a permanent commitment. We may introduce paid tiers, seat limits or usage-based pricing in the future; existing account holders will be given notice before any such change takes effect for their account, on terms to be confirmed with counsel.
An "Organization" plan - a shared workspace with org-wide API keys, member roles and higher limits - is available on request and is provisioned individually; its terms are agreed separately with each organization and are not covered by this page.
BGPScout's own right to redistribute the data it shows you is limited by the licences of the sources it aggregates - see /data-sources for the full list and the exact licence text. Some of those licences are redistribution-friendly with attribution (RouteViews, CC BY 4.0); some grant only revocable permission with conditions (RIPE RIS); at least one restricts redistribution of the underlying data outright (MaxMind GeoLite2's EULA); and at least two state no licence at all (bgp.tools, the CDN-mapping research post). A clause here cannot honestly promise customers rights BGPScout does not itself hold. The wording below is deliberately conservative until counsel has confirmed, source by source, what BGPScout can lawfully sublicense.
Subject to that limitation, and unless we agree otherwise with you in writing:
You may stop using the service and delete your account at any time. We may suspend or terminate your access, with or without notice, for a breach of Section 3, for non-payment on a paid plan (once such plans exist), for legal or security reasons, or if the service or a plan is discontinued. Sections that by their nature should survive termination (including Section 7's data-use restrictions and Section 9's liability limits) continue to apply after your account is closed.
The paragraph below is a conventional SaaS liability-limitation clause, not language drafted or reviewed for this company, this data, or Quebec/Canadian consumer-protection law. Network measurement and geolocation data is inherently probabilistic and sourced from third parties BGPScout does not control (see /data-sources); how much liability can actually be disclaimed for decisions made on that basis is a question for counsel, not for this page.
The service, including all data, analysis and geolocation estimates, is provided "as is" and "as available", without warranty of any kind, express or implied, including accuracy, completeness, or fitness for a particular purpose. To the maximum extent permitted by law, BGPScout and Hive Data Center Inc. will not be liable for indirect, incidental, special, consequential or punitive damages, or for any decision made in reliance on data obtained through the service.
These terms are governed by the laws of the Province of Quebec and the laws of Canada applicable in Quebec, without regard to conflict-of-law principles. Subject to counsel's review, disputes are intended to be submitted to the courts of the judicial district of Montreal, Quebec.
We will post changes to this page and update the "last updated" date below. Material changes will be flagged in a reasonable way to signed-in accounts once such notice mechanisms exist; none currently does, which is itself one of the gaps this draft surfaces for the owner.
Questions about these terms: [email protected].
Draft prepared 2026-08-21, from the codebase as it stood that day. Not yet reviewed by counsel. Do not remove the draft banner above until it has been.