Grizzly Terms of Service
Last updated: September 28, 2026
Introduction
Grizzly is a phishing-detection service operated by Upstream Labs ("we", "us"). It includes the web scanner at grizzlysec.com, the scan API, the Grizzly Chrome extension, and public scan result pages. By using any of them you agree to these terms. If you don't agree, don't use the service.
Our Privacy Policy explains what personal data we collect and how we handle it. These terms cover what you submit to Grizzly and what happens to it.
The service
You give Grizzly a URL; Grizzly fetches and renders the page, analyzes it, and returns a verdict: phishing, suspicious, nothing suspicious found, or legitimate, with the reasons behind it. Verdicts are produced automatically. They are our best assessment at the time of the scan, not a guarantee, and a page can change after we scan it.
Grizzly is an aid to your judgement, not a replacement for it. Don't rely on a verdict as the sole basis for entering credentials, sending money, or taking action against a site or its owner.
Public scan results
Every scan produces a result page with a permanent, stable link. What that page shows and who can find it depends on the scan's visibility:
- •Public scans are public. The submitted URL, the final URL, the verdict and its reasons, the impersonated brand, and a screenshot of the page are visible to anyone. Public scans with a phishing or suspicious verdict may be listed on grizzlysec.com and indexed by search engines.
- •Unlisted scans are reachable by link.They don't appear in listings or search results, but anyone who has the link can open the result page. There is no sign-in requirement and no way to revoke a link once it has been shared.
- •Scans from the web scanner and the API are public by default. Account holders can mark a scan unlisted. Scans submitted without an account are always public.
- •Extension submissions are unlisted. Pages the Chrome extension sends to Grizzly for a verdict are never listed or indexed.
Because result pages are public, don't submit URLs that carry secrets or personal data, such as session tokens, one-time links, or query strings containing names or email addresses. Anything in the URL you submit becomes part of the result page.
Datasets and feeds
Grizzly improves by learning from what it scans. Every URL submitted to Grizzly, together with the fetched page, its screenshot, and the resulting verdict, may be retained and used in Grizzly's datasets, models, and threat feeds. This applies regardless of visibility: public, unlisted, and extension submissions alike, and submissions made with or without an account.
Datasets and feeds contain the scanned URLs and verdicts. They do not contain the identity of whoever submitted a scan.
Reporting a wrong verdict
Automated classification makes mistakes. Every phishing or suspicious result page has a "Report as misclassified" link. Reports are anonymous and queue the scan for review; we may change the verdict, unlist the page, or leave it as is. If you own a site that you believe is wrongly listed and need a faster answer, email support@grizzlysec.com.
Accounts and the API
- •You are responsible for activity under your account and your API keys. Keep keys secret; rotate a key you think has leaked.
- •Free usage is subject to daily quotas per key and per user. Quotas may change; the current limits are published in the API documentation.
- •Don't circumvent quotas or rate limits, for example by creating multiple accounts or keys for the same use.
Acceptable use
Use Grizzly to check whether pages are safe. Don't use it to:
- •Probe, load-test, or attack a site, or scan sites you are not permitted to access.
- •Reach internal networks, private services, or infrastructure you don't control by making Grizzly fetch them for you.
- •Test phishing kits against Grizzly in order to evade detection.
- •Scrape result pages or listings in bulk. If you need the data, ask about feeds.
We may block requests, revoke keys, or suspend accounts that break these rules.
Content on scanned pages
Result pages show screenshots and details of third-party pages. We show them to document a verdict, not to endorse or republish the content. Screenshots are stored captures, not live views, and links to a flagged site are marked so that browsers and search engines do not treat them as recommendations.
Disclaimer and limitation of liability
Grizzly is provided "as is" and "as available", without warranties of any kind, express or implied, including accuracy, availability, and fitness for a particular purpose. To the fullest extent permitted by law, Upstream Labs is not liable for any indirect, incidental, or consequential loss arising from your use of the service, or from acting or not acting on a verdict.
Changes
We may change these terms as the service evolves. Material changes will be reflected on this page with an updated revision date. Continuing to use Grizzly after a change means you accept the new terms.
Contact
If you have questions about these terms, you may contact:
Upstream Labs
Email: support@grizzlysec.com