Legal
Terms of service
Draft for counsel review · 31 August 2026
1. Ownership and authority attestation
Before every assessment, the customer must legally attest that it owns the target or holds current, express written authority from the owner to test it. The attestation must identify the authorized targets and the person granting authority. A subscription, public IP address, or publicly resolvable hostname is not proof of authorization.
2. Technical ownership verification
Deep Force Proof may require DNS, file-based, account-level, or documentary verification before enabling an assessment. Technical verification supplements the customer's legal attestation; it does not expand the permitted scope or replace any third-party approval.
3. Written scope and authorization window
Targets, methods, test windows, rate and concurrency limits, excluded systems, emergency contacts, permitted credentials, and stop conditions must be recorded before testing. Authorization expires at the end of the stated window and must be renewed when ownership, scope, or authority changes. Activity outside the written scope is prohibited.
4. Customer responsibility
The customer is responsible for the accuracy of its ownership and authority statements, all targets it submits, required third-party approvals, backups, incident contacts, and current asset information. The customer must not use the service to assess, access, disrupt, or collect data from systems outside its verified authorization.
5. Unauthorized targets and indemnity draft
If a customer submits a target it does not own or is not authorized to test, the assessment may be stopped immediately and relevant evidence preserved. Subject to counsel's final language and applicable law, the commercial agreement should allocate resulting claims, costs, and losses to the customer whose false or incomplete authorization caused them.
6. Service limits
Security assessment reduces risk but cannot guarantee that a system is secure, vulnerability-free, continuously available, or compliant. Results describe the verified scope and tested time window only.
7. Evidence and retention
Authorization records, scope approvals, test events, reports, and remediation evidence are retained according to the purchased plan and applicable law. Customers should export required records before retention expires.
8. Suspension and emergency stop
Testing may be delayed or stopped when authorization is unclear, verification fails, a target presents an unexpected safety risk, a third party objects, or continued activity could cause harm.
9. Commercial terms and liability
Pricing, service levels, payment terms, confidentiality, data processing, governing law, warranties, liability limitations, indemnities, insurance requirements, and appropriate legal carve-outs must be finalized in the signed order form or master services agreement.
This public draft is transparent product guidance—not legal advice or a final contract. Qualified counsel must adapt it to the operating company, jurisdictions, insurance, and actual service before paid onboarding begins.