← Deep Force Proof

Legal

Terms of service

1. Ownership and authority attestation

Before every assessment, the customer must legally attest that it owns the target or holds current, express written authority from the owner to test it. The attestation must identify the authorized targets and the person granting authority. A subscription, public IP address, or publicly resolvable hostname is not proof of authorization.

2. Technical ownership verification

Deep Force Proof may require DNS, file-based, account-level, or documentary verification before enabling an assessment. Technical verification supplements the customer's legal attestation; it does not expand the permitted scope or replace any third-party approval.

3. Written scope and authorization window

Targets, methods, test windows, rate and concurrency limits, excluded systems, emergency contacts, permitted credentials, and stop conditions must be recorded before testing. Authorization expires at the end of the stated window and must be renewed when ownership, scope, or authority changes. Activity outside the written scope is prohibited.

4. Customer responsibility

The customer is responsible for the accuracy of its ownership and authority statements, all targets it submits, required third-party approvals, backups, incident contacts, and current asset information. The customer must not use the service to assess, access, disrupt, or collect data from systems outside its verified authorization.

5. Unauthorized targets and indemnity draft

If a customer submits a target it does not own or is not authorized to test, the assessment may be stopped immediately and relevant evidence preserved. Subject to counsel's final language and applicable law, the commercial agreement should allocate resulting claims, costs, and losses to the customer whose false or incomplete authorization caused them.

6. Service limits

Security assessment reduces risk but cannot guarantee that a system is secure, vulnerability-free, continuously available, or compliant. Results describe the verified scope and tested time window only.

7. Evidence and retention

Authorization records, scope approvals, test events, reports, and remediation evidence are retained according to the purchased plan and applicable law. Customers should export required records before retention expires.

8. Suspension and emergency stop

Testing may be delayed or stopped when authorization is unclear, verification fails, a target presents an unexpected safety risk, a third party objects, or continued activity could cause harm.

9. Commercial terms and liability

Pricing, service levels, payment terms, confidentiality, data processing, governing law, warranties, liability limitations, indemnities, insurance requirements, and appropriate legal carve-outs must be finalized in the signed order form or master services agreement.