Terms of Service & Acceptable Use
These Terms of Service, together with the Acceptable Use Policy in Section 04 (collectively, the "Terms"), form a binding agreement between you ("you", "Customer") and Sintropyc ("Sintropyc", "we", "us"). By creating an account, running a scan, or otherwise using the Sintropyc platform, agent, API, or website (the "Service"), you accept these Terms in full. If you do not agree, do not use the Service.
Sintropyc is an autonomous security-testing tool. It sends real attack traffic to the systems you point it at. Directing it at a system you are not authorised to test is illegal in most jurisdictions and may constitute a criminal offence. You — not Sintropyc — are responsible for ensuring you have the right to test every Target you submit.
01 Definitions
- "Target" — any application, host, API, domain, or system you submit to the Service for testing.
- "Scope" — the explicit set of Targets you have authorised for a given run.
- "Run" — a single execution of the agent against a defined Scope, producing one Report.
- "Report" — the deliverable produced by a Run: what was tested, what was proven, recommended remediation, and re-test results.
- "Finding" — an individual vulnerability identified and, where applicable, proven during a Run.
- "Content" — data, credentials, configuration, and other material you provide or that the Service processes on your behalf.
02 Eligibility & account
2.1 You must be legally able to enter into a binding contract in your jurisdiction to use the Service. Where you use the Service on behalf of an organisation, you represent that you are authorised to bind that organisation, and "you" refers to that organisation.
2.2 You are responsible for all activity under your account, for keeping your credentials secure, and for every Target you submit. We may require identity or authorisation verification before enabling certain features.
03 Authorisation & scope
3.1 Authorised testing only. You may only submit a Target that you own, or for which you hold current, written authorisation to have it tested. You must be able to produce that authorisation on request.
3.2 Deterministic scope gate. Scope enforcement is a deterministic rule, not a discretionary judgement. The agent operates strictly within the Scope you define and will not intentionally act on hosts, addresses, or assets outside it. You are responsible for defining Scope correctly; a Target you do not control must never be entered.
3.3 Your responsibility for accuracy. If you place a Target in Scope that you are not authorised to test, that is a breach of these Terms and, potentially, of law. The scope gate constrains the agent's behaviour; it does not, and cannot, verify that your authorisation is genuine.
04 Acceptable Use Policy
You agree not to use the Service:
- 4.1 Against any system you do not own or lack written authorisation to test.
- 4.2 Against systems where authorisation is not legally possible to obtain, including but not limited to: government systems, critical national infrastructure, financial-market infrastructure, healthcare/life-safety systems, or third-party infrastructure shared with parties who have not consented.
- 4.3 In violation of any applicable computer-misuse or anti-hacking law, including (without limitation) the U.S. Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act 1990, the EU Directive 2013/40/EU, and equivalent laws in your jurisdiction.
- 4.4 In violation of the acceptable-use, penetration-testing, or vulnerability-testing policies of any hosting or cloud provider on which a Target runs (e.g. AWS, Google Cloud, Microsoft Azure, Cloudflare, or others). You are responsible for obtaining any provider-side authorisation those policies require before a Run.
- 4.5 To exfiltrate, retain, or exploit real data belonging to third parties beyond the minimum required to demonstrate a Finding.
- 4.6 To attack, disrupt, degrade, or gain persistent access to any system, whether or not in Scope, beyond the safe, minimal proof described in Section 05.
- 4.7 To resell, sublicense, or provide the Service to third parties as a testing service without a separate written agreement with us.
We may investigate suspected violations and cooperate with law enforcement. Violation of this Section is grounds for immediate suspension or termination under Section 10, without refund.
05 How the agent operates
We design the Service to be safe by default. The following describes intended behaviour and is not a warranty of any particular outcome (see Section 08).
- 5.1 Read-only by default. The agent reads and probes. Writes, deletions, and any persistent change require an explicit flag and a second confirmation from you.
- 5.2 Minimal, non-destructive proof. Exploitability is demonstrated with the smallest safe effect — a harmless echo, a canary value, a boolean delta. The agent does not run destructive commands, fetch or execute unknown binaries, or leave persistence behind.
- 5.3 Testing on disposable copies. Where the architecture supports it, attacks are directed at a disposable copy rather than the production instance your customers rely on.
- 5.4 Rate limiting and safety controls. Runs are constrained by request-rate limits (≤ 10 requests/second by default), wall-clock timeouts, a circuit breaker that halts on 5xx error storms, and an SSRF guard on internal/private address ranges.
- 5.5 You control the run. You may stop any Run at any time.
- 5.6 Secret redaction. Raw secrets discovered during a Run are kept out of the Report and out of finding logs; only the fact of exposure is recorded. This is separate from operational logging under Section 6.4.
06 Data, findings & retention
6.1 Sensitivity of Reports. A Report describes how a Target can be compromised. You are responsible for storing, transmitting, and sharing Reports securely, and for restricting access on your side.
6.2 What we process. To deliver the Service we process the Content and Targets you submit, and we generate Findings and Reports. We use this to operate, secure, and improve the Service.
6.3 Finding data retention. Findings and Reports are retained for 12 months and then deleted or anonymised, unless you delete them earlier or law requires longer retention. You may request deletion via the contact links in the footer below.
6.4 Operational & abuse logs. Separately from Finding data, we retain operational metadata — which account initiated which Run, against which Target(s), and when — for security, abuse prevention, and legal-defence purposes. These logs are necessary for the Service's integrity and are retained for 24 months. This metadata does not include the redacted secrets referenced in Section 5.6.
6.5 Privacy & data protection. Where the Service processes personal data subject to the GDPR, UK GDPR, or comparable laws, such processing is governed by our Privacy Policy and, where applicable, a Data Processing Addendum. You are responsible for having a lawful basis for any personal data present in a Target you test.
6.6 Confidentiality. We treat your Findings and Reports as confidential and do not disclose them except as permitted in Section 6.7, to operate the Service, as you direct, or as required by law.
6.7 Product improvement & demonstration. You grant Sintropyc a worldwide, royalty-free, perpetual right to access, view, retain, and use the Content, Targets, Findings, Reports, and other results and metadata generated by a Run in order to operate, analyse, develop, and improve the Service and our products, and to demonstrate what the Service is capable of. This includes the right to present examples of what the agent discovered in your systems — including to Sintropyc's personnel, and to our current and prospective investors, advisors, and partners — and to use such material in case studies, product demonstrations, marketing, and investor materials. Wherever practicable we will present such material in a de-identified or aggregated form that does not identify you, and in every case raw secrets and credentials remain redacted as described in Section 5.6. This right survives termination. If you need specific material excluded from this use, contact us at support@sintropyc.com and we will agree reasonable restrictions in writing.
07 Your warranties & indemnification
7.1 Warranties. You represent and warrant, for every Run, that: (a) you own each Target or hold valid written authorisation to test it; (b) your use complies with these Terms, the Acceptable Use Policy, and all applicable laws; and (c) you have satisfied any hosting-provider or third-party authorisation requirements that apply.
7.2 Indemnification. You will defend, indemnify, and hold harmless Sintropyc, its affiliates, and their officers, employees, and agents from and against any claim, demand, investigation, loss, liability, damage, cost, or expense (including reasonable legal fees) arising out of or related to: (a) your use of the Service; (b) any Target you submitted; (c) your breach of these Terms or the Acceptable Use Policy; or (d) your violation of any law or third-party right. This obligation survives termination.
08 Disclaimers
8.1 No warranty of completeness. Security testing is inherently non-exhaustive. The absence of Findings does not mean a Target is secure, and a Report is not a guarantee that a Target is free of vulnerabilities. New vulnerabilities may exist or arise that the Service did not or could not detect.
8.2 "As is". The Service is provided "as is" and "as available", without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement, to the maximum extent permitted by law.
8.3 No professional advice. The Service and its output do not constitute legal, compliance, or professional security-consulting advice. Remediation is recommended; your team decides whether and how to apply it. The agent advises on fixes and never writes to your source code.
09 Limitation of liability
9.1 To the maximum extent permitted by law, Sintropyc and its affiliates will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, or goodwill, arising out of or related to the Service, even if advised of the possibility.
9.2 To the maximum extent permitted by law, Sintropyc's total aggregate liability arising out of or related to these Terms or the Service will not exceed the greater of (a) the total amount you paid us for the Service in the three (3) months preceding the event giving rise to the claim, or (b) USD 100.
9.3 Some jurisdictions do not allow certain limitations; in those jurisdictions our liability is limited to the smallest extent permitted by law.
10 Suspension & termination
10.1 We may suspend or terminate your access immediately, without notice and without refund, if we reasonably believe you have violated these Terms or the Acceptable Use Policy, or where suspension is necessary to protect the Service, other users, or third parties.
10.2 You may stop using the Service at any time. Sections that by their nature should survive termination (including 6, 7, 8, 9, and 11) survive. Refund treatment on cancellation is set out in our Refund Policy.
11 General
11.1 Governing law & disputes. These Terms are governed by the laws of the jurisdiction in which Sintropyc is established, without regard to conflict-of-laws rules, and, where mandatory consumer-protection law of your country of residence grants you stronger protection, that law continues to apply to you. You and Sintropyc will first attempt in good faith to resolve any dispute informally; failing that, the dispute will be subject to the competent courts of Sintropyc's place of establishment, without prejudice to any mandatory right you have to bring proceedings in your home jurisdiction.
11.2 Changes. We may update these Terms. Material changes will be notified by email or an in-product notice. Continued use after changes take effect constitutes acceptance.
11.3 Entire agreement; severability. These Terms, together with our Privacy Policy and Refund Policy, are the entire agreement between you and us regarding the Service and supersede prior agreements. If any provision is held unenforceable, the remainder stays in effect.
11.4 Assignment. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets.
11.5 Contact. Questions, or requests for authorisation records: support@sintropyc.com.