Provision record
OneLogin · OneLogin Terms of Service · View original document ↗

Prohibition on vulnerability scanning or penetration testing

High severity High confidence Explicit document language Common · 281 of 352 platforms

Key Facts

What does OneLogin prohibit users from attempting to do?
OneLogin prohibits users from attempting to probe, scan, or test the vulnerability of any systems related to the Service, including through penetration or load tests.
Can users probe, scan, or test the vulnerability of systems related to the Service?
OneLogin prohibits users from attempting to probe, scan, or test the vulnerability of any systems related to the Service, including through penetration or load tests.
Stay ahead of the changes
Track OneLogin and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This prohibition bars users from conducting security assessments—including standard penetration testing—on any Service-related systems.

Consumer impact (what this means for users)

You may not attempt to probe, scan, or test the vulnerability of any systems related to the Service, including by running penetration or load tests.

How other platforms handle this

Tinder Medium

You may not display any personal contact, banking, or peer-to-peer payment information, whether in relation to you or any other person (for example, names, home addresses or postcodes, telephone numbers, email addresses, URLs, credit/debit card...)

ActiveCampaign Medium

Bypass or ignore instructions contained in our robots.txt file that controls automated access to portions of our Services;

Mailchimp Medium

Send content created in Mailchimp through another service.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
...attempt to probe, scan or test the vulnerability of any systems related to the Service, including penetration or load tests...

Excerpt from OneLogin's Terms of Service

Applicable regulations

CFAA
United States Federal
DSA
European Union

Provision details

Document information
Document
OneLogin Terms of Service
Entity
OneLogin
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-072951
Document ID
CA-D-00693
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7fec8f5039b9547d3ee03e85420719b8d7abdb572670a9cc49c418788ea277cf
Analysis generated
July 12, 2026 15:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OneLogin
Document: OneLogin Terms of Service
Record ID: CA-P-072951
Captured: 2026-07-12 15:54:33 UTC
SHA-256: 7fec8f5039b9547d…
URL: https://conductatlas.com/platform/onelogin/onelogin-terms-of-service/provision/CA-P-072951/prohibition-on-vulnerability-scanning-or-penetration-testing/
Accessed: Aug. 18, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does OneLogin's Prohibition on vulnerability scanning or penetration testing clause do?

This prohibition bars users from conducting security assessments—including standard penetration testing—on any Service-related systems.

How does this clause affect you?

You may not attempt to probe, scan, or test the vulnerability of any systems related to the Service, including by running penetration or load tests.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 281 platforms. See the full comparison.

Is ConductAtlas affiliated with OneLogin?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.