// Terms & Data_Source_Usage
Last updated August 17, 2026 · v1.0.0-2026-08-17
// Scope
Ransom Scope aggregates publicly reported ransomware activity for defensive research, detection engineering, and threat-informed decision making. Some data originates from third-party providers whose own terms govern how their data may be cached, displayed, exported, and redistributed. Where an upstream term is stricter than ours, the upstream term controls.
// Caching and refresh discipline
All third-party data is ingested server-side into our own cache on a scheduled basis. User searches and page views are served from that cache and are never proxied to upstream providers. Each source has an enforced minimum refresh interval; requests made before that interval elapses are rejected by our ingestion layer rather than sent upstream.
// Attribution
Every record surfaced in the interface carries visible attribution to its originating source with a link back to that source. Attribution is never removed, obscured, or aggregated away.
// Non-Commercial Project Status
RansomScope currently operates as a free, non-commercial defensive research project. It does not charge users, run advertisements, sell access or data, offer paid plans, or request or accept donations. No commercial relationship, sponsorship, endorsement, or affiliation with Ransomware.live is implied.
Current operating state:
- monetization = false
- donations = false
- advertising = false
- sponsorships = false
- paid_api = false
Attribution to a third-party source identifies where data originated. It does not imply endorsement, partnership, sponsorship, or affiliation between that source and RansomScope.
This describes current operation and is not a promise that the service will remain free indefinitely. If monetization, paid services, sponsorships, advertising, affiliate revenue, donations, or other commercial activity are ever considered, RansomScope will first review the applicable source licenses and terms and obtain any required written approvals before that activity begins.
Enabling any commercial or funding flag automatically places Ransomware.live-derived records on a compliance hold until written commercial authorization is recorded in the source registry. Donations and sponsorships trigger the same review even when they are not tied to data access.
This section documents RansomScope's current operating facts and non-commercial posture. It is not a claim of blanket legal compliance, and RansomScope is not described here as a charity, nonprofit organization, or legally recognized nonprofit.
// Commercial use of source data
Ransom Scope operates in non-commercial mode for restricted sources. Data marked as restricted is excluded from any paid tier, resale, or commercial redistribution unless written approval from the upstream provider has been obtained and recorded in our source registry.
// Exports, API, and TAXII
Restricted-source records are withheld from STIX bundles, the TAXII 2.1 collections, RSS output, and the MCP agent tools. Those channels serve only data whose upstream terms permit machine-readable redistribution.
// Source registry
| Source | Status | Refresh floor | Redistribution | Reviewed |
|---|---|---|---|---|
| Ransomware.live | Restricted | 30 min | No raw-data publishing and no API/feed redistribution of its data. No cloning of its site, dashboard, or branding. | August 17, 2026 |
| CISA KEV | Open | 0 min | Permitted | August 17, 2026 |
| NVD (NIST) | Open | 0 min | Permitted | August 17, 2026 |
| abuse.ch ThreatFox | Open | 5 min | Permitted | August 17, 2026 |
| MITRE ATT&CK | Open | 0 min | Permitted | August 17, 2026 |
// Ransomware.live
- Terms
- https://ransomware.live/t&c
- Allowed use
- Defensive research and analysis only, served from RansomScope's own server-side cache. End-user searches are never passed through to the upstream service.
- Attribution
- Required — “Source: Ransomware.live” linking to the source homepage
- Redistribution
- No raw-data publishing and no API/feed redistribution of its data. No cloning of its site, dashboard, or branding.
- Commercial use
- Not permitted without prior written approval from Ransomware.live
- Refresh floor
- 30 minutes
- Restriction code
- RL-RESTRICTED-2026-08-17
- Last reviewed
- August 17, 2026
// CISA KEV
- Terms
- https://www.cisa.gov/privacy-policy
- Allowed use
- US Government public-domain catalog; reuse permitted.
- Attribution
- Requested — “Source: CISA KEV”
- Redistribution
- Permitted
- Commercial use
- Permitted
- Refresh floor
- 0 minutes
- Restriction code
- US-GOV-PD
- Last reviewed
- August 17, 2026
// NVD (NIST)
- Terms
- https://nvd.nist.gov/general/terms-of-use
- Allowed use
- US Government public-domain CVE metadata; reuse permitted.
- Attribution
- Requested — “Source: NVD”
- Redistribution
- Permitted
- Commercial use
- Permitted
- Refresh floor
- 0 minutes
- Restriction code
- US-GOV-PD
- Last reviewed
- August 17, 2026
// abuse.ch ThreatFox
- Terms
- https://abuse.ch/#tos
- Allowed use
- IOC data shared under CC0 for defensive use.
- Attribution
- Requested — “Source: abuse.ch ThreatFox”
- Redistribution
- Permitted
- Commercial use
- Permitted
- Refresh floor
- 5 minutes
- Restriction code
- CC0
- Last reviewed
- August 17, 2026
// MITRE ATT&CK
- Terms
- https://attack.mitre.org/resources/legal-and-branding/terms-of-use/
- Allowed use
- Technique taxonomy; reuse permitted with attribution.
- Attribution
- Required — “Source: MITRE ATT&CK”
- Redistribution
- Permitted
- Commercial use
- Permitted
- Refresh floor
- 0 minutes
- Restriction code
- MITRE-TOU
- Last reviewed
- August 17, 2026
// Takedown and correction requests
Upstream providers, victims, and researchers may request correction or removal of any record. Requests are triaged within two business days. Use the contact form on the About page or write to security@ransomscope.com.
// Methodology
For collection, verification, and confidence scoring detail, see Methodology.