Terms of Service & Acceptable Use
These Terms of Service, together with the Acceptable Use Policy in Section 04 (collectively, the "Terms"), form a binding agreement between you ("you", "Customer") and the Sintropyc contracting entity identified in your Order Form, invoice, or enterprise agreement ("Sintropyc", "we", "us"). We do not begin a paid or enterprise engagement until that document identifies the contracting entity as described in Section 12.2. By creating an account, running a scan, or otherwise using the Sintropyc platform, agent, API, or website (the "Service"), you accept these Terms. If you do not agree, do not use the Service.
You own your Content, scope records, Findings, and Reports. We use them only as needed to deliver and secure the Service, follow your documented instructions, and meet legal obligations. We do not use them for AI training, marketing, case studies, investor materials, or product demonstrations unless you separately opt in in writing.
01 Definitions
- "Target" — any application, host, API, domain, or system you submit to the Service for testing.
- "Scope" — the explicit set of Targets you have authorised for a given run.
- "Run" — a single execution of the agent against a defined Scope, producing one Report.
- "Report" — the deliverable produced by a Run: what was tested, what was proven, recommended remediation, and re-test results.
- "Finding" — an individual vulnerability identified and, where applicable, proven during a Run.
- "Content" — data, credentials, configuration, and other material you provide or that the Service processes on your behalf.
02 Eligibility & account
2.1 You must be legally able to enter into a binding contract in your jurisdiction to use the Service. Where you use the Service on behalf of an organisation, you represent that you are authorised to bind that organisation, and "you" refers to that organisation.
2.2 You are responsible for all activity under your account, for keeping your credentials secure, and for every Target you submit. We may require identity or authorisation verification before enabling certain features.
03 Authorisation & scope
3.1 Authorised testing only. You may only submit a Target that you own, or for which you hold current, written authorisation to have it tested. You must be able to produce that authorisation on request.
3.2 Deterministic scope gate. Scope enforcement is a deterministic rule, not a discretionary judgement. The agent operates strictly within the Scope you define and will not intentionally act on hosts, addresses, or assets outside it. You are responsible for defining Scope correctly; a Target you do not control must never be entered.
3.3 Your responsibility for accuracy. If you place a Target in Scope that you are not authorised to test, that is a breach of these Terms and, potentially, of law. The scope gate constrains the agent's behaviour; it does not, and cannot, verify that your authorisation is genuine.
04 Acceptable Use Policy
You agree not to use the Service:
- 4.1 Against any system you do not own or lack written authorisation to test.
- 4.2 Against systems where authorisation is not legally possible to obtain, including but not limited to: government systems, critical national infrastructure, financial-market infrastructure, healthcare/life-safety systems, or third-party infrastructure shared with parties who have not consented.
- 4.3 In violation of any applicable computer-misuse or anti-hacking law, including (without limitation) the U.S. Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act 1990, the EU Directive 2013/40/EU, and equivalent laws in your jurisdiction.
- 4.4 In violation of the acceptable-use, penetration-testing, or vulnerability-testing policies of any hosting or cloud provider on which a Target runs (e.g. AWS, Google Cloud, Microsoft Azure, Cloudflare, or others). You are responsible for obtaining any provider-side authorisation those policies require before a Run.
- 4.5 To exfiltrate, retain, or exploit real data belonging to third parties beyond the minimum required to demonstrate a Finding.
- 4.6 To attack, disrupt, degrade, or gain persistent access to any system, whether or not in Scope, beyond the safe, minimal proof described in Section 05.
- 4.7 To resell, sublicense, or provide the Service to third parties as a testing service without a separate written agreement with us.
We may investigate suspected violations and cooperate with law enforcement. Violation of this Section is grounds for immediate suspension or termination under Section 10, without refund.
05 How the agent operates
We design the Service to be safe by default. The following describes intended behaviour and is not a warranty of any particular outcome (see Section 08).
- 5.1 Read-only by default. The agent reads and probes. Writes, deletions, and any persistent change require an explicit flag and a second confirmation from you.
- 5.2 Minimal, non-destructive proof. Exploitability is demonstrated with the smallest safe effect — a harmless echo, a canary value, a boolean delta. The agent does not run destructive commands, fetch or execute unknown binaries, or leave persistence behind.
- 5.3 Testing on disposable copies. Where the architecture supports it, attacks are directed at a disposable copy rather than the production instance your customers rely on.
- 5.4 Rate limiting and safety controls. Runs are constrained by request-rate limits (≤ 10 requests/second by default), wall-clock timeouts, a circuit breaker that halts on 5xx error storms, and an SSRF guard on internal/private address ranges.
- 5.5 You control the run. You may stop any Run at any time.
- 5.6 Secret redaction. Raw secrets discovered during a Run are kept out of the Report and out of finding logs; only the fact of exposure is recorded. This is separate from operational logging under Section 6.4.
06 Data, findings & retention
6.1 Sensitivity of Reports. A Report describes how a Target can be compromised. You are responsible for storing, transmitting, and sharing Reports securely, and for restricting access on your side.
6.2 What we process and why. To deliver the Service, we process the Content, Target and Scope information you submit and generate Findings and Reports (together, "Customer Data"). We process Customer Data only to provide, secure, troubleshoot, and support the Service, follow your documented instructions, and comply with law. Where Customer Data includes personal data that we process on your behalf, you are the controller and Sintropyc is the processor.
6.3 Retention and deletion SLA. Unless an Order Form specifies a shorter period, Findings and Reports are retained for up to 12 months so you can access and re-test them. Following a verified deletion request or termination, we will delete Customer Data from active systems within 30 days and from backups within 90 days. We may retain only data that law requires us to keep, or narrowly scoped security and abuse records needed to establish, exercise, or defend legal claims; any retained data remains protected, is isolated from ordinary use, and is deleted when the exception ends.
6.4 Operational & abuse logs. We retain the minimum operational metadata needed to attribute authorised Runs, secure the Service, prevent abuse, and defend legal claims. Raw secrets are excluded as described in Section 5.6. Operational records are normally retained for no more than 12 months; when Customer Data is deleted, direct Target identifiers are deleted or irreversibly de-identified within the active-system deadline in Section 6.3 unless an exception there applies.
6.5 Privacy, DPA & subprocessors. Our Privacy Policy describes processing for which we act as controller. Our Data Processing Addendum automatically applies where we process personal data on your behalf and controls in the event of a conflict about that processing. We use only the providers identified on our Subprocessor List, subject to the notice and objection process in the DPA. You are responsible for having a lawful basis for personal data present in a Target you authorise us to test.
6.6 Confidentiality. We treat Customer Data as your Confidential Information. We disclose it only to personnel and approved subprocessors who need it to provide the Service and are bound by confidentiality obligations, as you direct, or where law requires disclosure. Where legally permitted, we will notify you before a compelled disclosure and reasonably assist you in seeking protective treatment.
6.7 Your ownership; limited service licence. As between the parties, Customer retains all right, title, and interest in Customer Data. To the extent Sintropyc creates any right in a Finding or Report specifically for you, Sintropyc assigns that right to Customer upon payment, excluding our pre-existing software, testing methods, templates, tools, and general know-how. You grant us a limited, non-exclusive right to process Customer Data only for the purposes in Section 6.2 and only for as long as reasonably necessary to provide the Service or satisfy the deletion and legal obligations in Section 6.3. This licence is not transferable except to approved subprocessors acting for us and ends when the relevant Customer Data is deleted.
6.8 No training, marketing, or demonstration use by default. We do not use Customer Data to train general-purpose or shared AI models, improve products for other customers, advertise the Service, create a case study, demonstrate a vulnerability, or prepare investor materials. Any such use requires your separate, specific, prior written opt-in, is not a condition of receiving the Service, and may be withdrawn prospectively at any time. An opt-in for one item or purpose does not authorise any other use.
6.9 De-identified service metrics. We may create and use aggregate operational statistics that do not contain Customer Data, personal data, Target identifiers, vulnerability details, Report text, credentials, or information that could reasonably identify Customer or a Target. These statistics may be used to understand reliability, latency, safety controls, and aggregate Service usage. We will not attempt to re-identify them.
07 Your warranties & indemnification
7.1 Warranties. You represent and warrant, for every Run, that: (a) you own each Target or hold valid written authorisation to test it; (b) your use complies with these Terms, the Acceptable Use Policy, and all applicable laws; and (c) you have satisfied any hosting-provider or third-party authorisation requirements that apply.
7.2 Indemnification. You will defend, indemnify, and hold harmless Sintropyc, its affiliates, and their officers, employees, and agents from and against any claim, demand, investigation, loss, liability, damage, cost, or expense (including reasonable legal fees) arising out of or related to: (a) your use of the Service; (b) any Target you submitted; (c) your breach of these Terms or the Acceptable Use Policy; or (d) your violation of any law or third-party right. This obligation survives termination.
08 Disclaimers
8.1 No warranty of completeness. Security testing is inherently non-exhaustive. The absence of Findings does not mean a Target is secure, and a Report is not a guarantee that a Target is free of vulnerabilities. New vulnerabilities may exist or arise that the Service did not or could not detect.
8.2 "As is". The Service is provided "as is" and "as available", without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement, to the maximum extent permitted by law.
8.3 No professional advice. The Service and its output do not constitute legal, compliance, or professional security-consulting advice. Remediation is recommended; your team decides whether and how to apply it. The agent advises on fixes and never writes to your source code.
09 Limitation of liability
9.1 To the maximum extent permitted by law, Sintropyc and its affiliates will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, or goodwill, arising out of or related to the Service, even if advised of the possibility.
9.2 To the maximum extent permitted by law, Sintropyc's total aggregate liability arising out of or related to these Terms or the Service will not exceed the greater of (a) the total amount you paid us for the Service in the three (3) months preceding the event giving rise to the claim, or (b) USD 100.
9.3 Some jurisdictions do not allow certain limitations; in those jurisdictions our liability is limited to the smallest extent permitted by law.
10 Suspension & termination
10.1 We may suspend or terminate your access immediately, without notice and without refund, if we reasonably believe you have violated these Terms or the Acceptable Use Policy, or where suspension is necessary to protect the Service, other users, or third parties.
10.2 You may stop using the Service at any time. Sections that by their nature should survive termination (including 6, 7, 8, 9, 11, and 12) survive. Refund treatment on cancellation is set out in our Refund Policy.
11 Fees & refunds
11.1 Fees. You agree to pay the fees stated at checkout for the Service you purchase. Fees are due in advance, and payments are processed by our payment provider, Paddle, which acts as merchant of record. Unless stated otherwise, fees are exclusive of any taxes, which are added where applicable and shown at checkout.
11.2 Real-time performance. The Service is provided on demand and performed in real time: when a Run begins, we immediately commit and consume computing resources and agent-work to test your Target as the Run executes. Performance cannot be un-done or returned once it has started.
11.3 Non-refundable once a Run begins. Because of the real-time nature of the Service, once a Run has begun the corresponding fee is non-refundable. A limited or clean Report is still a delivered Run: as set out in Section 08, security testing is non-exhaustive and the absence of Findings is not a failure to deliver and is not, by itself, grounds for a refund.
11.4 Before a Run begins. Because we confirm scope with you in writing before any testing starts, there is a clear window before a Run begins in which no work has been performed; if you have paid but we have not yet started your Run, you may request a full refund. If, through no fault of yours, we are unable to deliver a Run you paid for, we will offer a re-run when practical or a refund of the amount paid for that undelivered Run.
11.5 Your statutory rights. Nothing in this Section removes any refund or cancellation right you have under mandatory consumer-protection law that cannot be waived; where such law grants you a stronger right, that right prevails. Full details, including subscriptions and how to request a refund, are in our Refund Policy.
12 General
12.1 Governing law & disputes. Unless an Order Form expressly states otherwise, these Terms and any non-contractual obligations arising from them are governed by the laws of England and Wales, without regard to conflict-of-laws rules. You and Sintropyc will first attempt in good faith to resolve a dispute informally. Subject to any mandatory right that cannot be waived, the courts of England and Wales have exclusive jurisdiction.
12.2 Contracting entity & order of precedence. Before any paid or enterprise engagement begins, the applicable Order Form, invoice, or enterprise agreement must identify Sintropyc's full legal name, registration number (where applicable), registered address, and any agreed governing jurisdiction. No such engagement is formed until those details are provided. If documents conflict, the Order Form controls for commercial terms and the DPA controls for processing of Customer Personal Data, followed by these Terms.
12.3 Changes. We may update these Terms prospectively. We will give at least 30 days' notice of a material change by email or in-product notice. A change cannot retroactively grant us rights in Customer Data or replace the written opt-in required by Section 6.8.
12.4 Entire agreement; severability. These Terms, the applicable Order Form, our Data Processing Addendum, Privacy Policy, and Refund Policy are the entire agreement between you and us regarding the Service and supersede prior agreements. If any provision is held unenforceable, the remainder stays in effect.
12.5 Assignment. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets, provided the assignee remains bound by our confidentiality, data-use, and deletion obligations.
12.6 Contact. Questions, deletion requests, or requests for authorisation records: [email protected].