Terms of use
Last updated 1 September 2026.
draft
This is a working draft, not reviewed by a lawyer. It describes what Sloptic actually does today and is written for accuracy. The sections on testing sites you do not own, and on liability, are the ones a lawyer should see before this is relied on.
What Sloptic is
Sloptic grades a deployed web app from outside it, over the public internet, with no source code and no access to your systems. It returns a slop score, a breakdown, and a report. It is operated by Ian Sun. Contact: hello@sloptic.org.
What you may point it at
Submit a URL only if you own the app, are authorized to test it, or are running an event the app was entered into. This is the central rule of this document. You are responsible for the addresses you submit, and by submitting one you confirm you have the right to have it tested.
Two tiers exist because they carry different risk. The default tier is passive. It reads only what the app already serves to any visitor, which is no different from loading the site in a browser, and it runs no attacks of any kind. The active tier sends real attack traffic, including injection payloads and malformed input, and it runs only after ownership of the domain has been proven or an event organizer has verified the event.
You may not use Sloptic to test infrastructure you do not control, to attempt denial of service, to work around a bot challenge or a rate limit, or to gather information for unauthorized access. We may refuse or stop any grade.
Events
An organizer who verifies control of an event may grade the entries in it and publish a board. Verification means publishing a link we issue on the event's own pages, which only its administrators can edit. That link is also the notice to participants that entries are graded, and it explains what an active grade does.
Active grading of an event requires that the disclosure was published before the submission window closed. A notice shown after an event ended was shown to nobody. Entries are taken from the addresses teams published themselves. An entry that points at a third party product is skipped, because a team cannot consent on another company's behalf. A team may opt out of being graded.
Reports
A report lives at an unguessable link, and that link is the only thing that opens it. Anyone holding it can read the report and can delete it. Treat it as private and share it deliberately. We ask search engines not to index report pages.
A report from a grade no account has claimed is deleted 30 days after it runs. Sign in and save a grade to keep it. See the privacy policy for what is kept and for how long.
If your app was graded and you did not ask
Anyone can run a passive grade on a public URL, so a report may exist about an app you built without your involvement. You can delete it yourself using its link, or write to hello@sloptic.org and we will remove it. You do not need an account and you do not need to explain why.
What a grade does not claim
A grade is not a security certification. A score of 0 means nothing was found. Sloptic checks a fixed floor, it cannot see everything, and a clean passive result in particular means only that nothing was visible from the outside, because the passive tier runs no security attacks at all. Treat any score as a minimum.
The service is provided as is, without warranties of any kind, and may be unavailable, change, or lose queued work. Grading runs on limited hardware and we may refuse, delay, or drop grades. To the extent the law allows, we are not liable for damages arising from use of the service or reliance on a grade.
These terms may change. Continued use after a change means you accept it, and the date at the top says when it last moved. Governing law and jurisdiction are to be settled before this leaves draft.