AUTOATTACK
Deploy

Terms.

Effective 2026-08-04.

Acceptance

These Terms of Service ("Terms") are a legal agreement between you ("Customer," "you") and AutoAttack ("AutoAttack," "we," "us"), which operates the autoattack.ai platform. By creating an account, deploying an agent, or using any part of the service, you agree to these Terms and our Privacy Policy. If you do not agree, do not use the service.

We record the version of these Terms and of the Privacy Policy you accepted, the time of acceptance, and the network address and browser identification from which it was made. That record is admissible as evidence of, and absent manifest error determinative of, the version you accepted and the time of acceptance.

AutoAttack Persons means AutoAttack; each person who at any time carries on or has carried on the business of AutoAttack, whether as sole proprietor, partner, member, shareholder, director, or otherwise; its predecessors, successors, permitted assigns, and permitted transferees; its holding companies, subsidiaries, and affiliates; and each of their respective officers, employees, agents, contractors, sub-processors, insurers, and licensors.

Service Description

AutoAttack is an autonomous adversary. You deploy an agent locally inside your network, and it discovers assets, executes attack techniques, and reports confirmed attack achievements. The service is provided on a commercially reasonable efforts basis with no guaranteed uptime or service level agreement.

Account Requirements

  • You must be at least 18 years of age and have the legal capacity to enter into a binding agreement.
  • A valid business email address is required. Consumer email addresses are not accepted.
  • You represent and warrant that you enter into these Terms in the course of a business and for the purposes of a business, and that you do not deal as a consumer for the purposes of any consumer protection law. The service is offered only to businesses. We rely on this representation in providing the service to you and in setting the fees.
  • Each organization has one account.
  • You must provide accurate and complete information and keep your account credentials secure. You are responsible for all activity under your account.
  • If you are accepting these Terms on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms. "You" and "Customer" refer to the organization in that case.

Authorization to Test

By deploying an AutoAttack agent inside a network, you represent and warrant that:

  • You have legal authority to authorize an autonomous adversary and security testing on that network.
  • You own the network or have explicit, documented authorization from the owner to conduct offensive security testing against it.
  • You have obtained every consent required from any person other than the network owner whose rights or terms the activity described below could affect, including any cloud, hosting, colocation, connectivity, or infrastructure provider whose acceptable-use terms restrict security testing, any managed service provider or outsourcer with contractual control of the systems, any co-tenant of shared infrastructure, and any landlord or property manager; and that the activity will not breach any agreement binding on you. Where you do not own a network within scope, you will identify its owner to us on request, and you procure that the owner is bound by the release, covenant not to sue, and liability limits in these Terms as if it were you. You procure, so far as you are able, that each of your affiliates, group companies, personnel, and contractors, and each person who owns or operates a system within a campaign scope you configure, is likewise bound by the release, the covenant not to sue, the liability limits, the class action waiver, and the time limitation in these Terms. Any amount recovered by any of them in respect of the service, the agent software, or a campaign arising from a scope you configured reduces the limit in Limitation of Liability available to you as if you had recovered it, whoever brings the claim; and Indemnification applies to any such claim.
  • You understand that AutoAttack agents will perform active attack techniques, including but not limited to: network discovery, port enumeration, service fingerprinting, credential spraying, LLMNR/NBT-NS poisoning, Kerberoasting, lateral movement, privilege escalation, data exfiltration, and other red team techniques designed to test your defenses.
  • You acknowledge and accept that active attacks will interact with your production systems and could affect service availability, cause account lockouts, trigger security alerts, or temporarily degrade network performance. You assume all risk of operational impact resulting from an authorized autonomous adversary on your network.
  • You acknowledge that the agent container requires elevated permissions (including host networking, raw socket access, and time synchronization capabilities) and accept the security implications of running such a container in your environment.
  • You are designating AutoAttack as your authorized agent to perform such testing on your behalf. This authorization constitutes your consent under applicable computer access laws, including but not limited to the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. 1030), the Computer Misuse Act 1990 (UK), and equivalent legislation in other jurisdictions. You give that designation, authorization, and consent to AutoAttack and, separately, to each person who operates or has operated the platform as AutoAttack, in each case in respect of the period in which that person operates or operated it. It survives termination of these Terms and any novation of them under Assignment and Novation, and neither event withdraws or supersedes it.

You will maintain insurance covering the operational risks of authorized security testing, will look first to those insurers for any loss, and will procure from each insurer a waiver of subrogation in favor of the AutoAttack Persons in respect of any loss arising from a campaign, and not only the impacts released in this paragraph. You release each AutoAttack Person from, and irrevocably waive, all claims arising from the operational impacts described above — account lockouts, triggered security alerts, transient unavailability, and temporary degradation of network or host performance — and all claims arising from a campaign or from agent activity for loss, corruption, alteration, or unavailability of data, for interruption, degradation, or unavailability of a system or service, and for the cost of restoring or reconstituting data or systems, and you covenant not to commence or fund any such claim.

Once deployed, the agent begins discovering assets and executing attack campaigns immediately. The agent operates autonomously and will attempt to reach any system accessible from its deployment point. During lateral movement, the agent authenticates to and operates from compromised hosts — meaning attack traffic may originate from IP addresses other than the original deployment host. The deployment host maintains an outbound HTTPS connection to AutoAttack's API to report findings and receive campaign configuration. You are solely responsible for configuring campaign scope and network exclusions to ensure the agent only interacts with systems you are authorized to test. AutoAttack is not liable for agent activity on systems that were reachable but outside your intended scope, whether or not you configured exclusions, where the excursion arises from conditions outside our knowledge or control — including routes discovered at runtime, domain or forest trust relationships, dynamic addressing, address translation, and your own configuration — except to the extent the excursion results from our deliberate failure to apply an exclusion you configured through the platform before the campaign began.

Deploying agents on networks you do not own or have authorization to test is a violation of these Terms and will result in immediate account termination without refund. You acknowledge that unauthorized testing may violate criminal and civil laws, and you accept sole responsibility for ensuring proper authorization. AutoAttack reserves the right to report suspected unauthorized testing to relevant law enforcement authorities and to cooperate with any resulting investigation, including by providing account information, Campaign Data, and audit logs.

Free Campaign

AutoAttack offers a free campaign for new accounts. You may deploy an agent and run a full campaign. Free usage is subject to all Terms, including Authorization to Test and Acceptable Use. The free campaign determines your discovered host count, which sets your subscription tier. Subscribing reveals the hostnames, techniques, and proof behind each finding. AutoAttack reserves the right to modify, suspend, or discontinue the free campaign offering — or to terminate any free account — at any time, for any reason, without notice or liability. You acknowledge that the free campaign is provided in consideration of your acceptance of these Terms, the representations you make under Authorization to Test, the rights you grant under Intellectual Property and Monitoring and Abuse Detection, and your obligations under Indemnification, which you agree constitute good and valuable consideration.

Subscription and Billing

  • Pricing — AutoAttack uses graduated per-host pricing based on discovered host count. All customers receive the same features. Pricing is published on our pricing page and billed annually. For networks exceeding 10,000 hosts, contact us for custom pricing.
  • Host-based billing — your subscription quantity equals the highest number of unique hosts the agent has discovered for your organization, measured cumulatively across all campaigns. The quantity increases as new hosts are discovered, prorated for the remainder of the then-current billing period, and carries forward at renewal; it is not reduced during or between billing periods if your network shrinks. At renewal, and only at renewal, we will reduce the quantity to your then-current discovered host count if you request that reduction in writing before the renewal date; absent that request the quantity carries forward unchanged, and the increase described above is unaffected in either case. Where the agent discovers more than 10,000 hosts, we may at our option bill each host above 10,000 at the lowest published per-host rate, suspend campaigns, or terminate the subscription, in each case on notice, until a custom pricing agreement is in place.
  • Measurement and invoice disputes — the host count recorded by the AutoAttack platform is the sole basis for billing and is conclusive absent manifest error. You must notify us in writing of any dispute about an invoice or host count within 30 days of the invoice date, identifying the specific hosts and the grounds; failing that, the invoice is deemed accepted, save for manifest error or fraud. Disputing part of an invoice does not suspend your obligation to pay the undisputed balance when due.
  • Auto-renewal — subscriptions automatically renew at the end of each billing period at the then-current rate unless you cancel before the renewal date. If you do not cancel before the renewal date, you accept the updated pricing.
  • Payment — all payments are processed by Stripe. By subscribing, you agree to Stripe's terms of service.
  • Taxes — all fees are exclusive of taxes. You are responsible for all sales, use, value-added, goods-and-services, digital-services, and similar taxes, levies, and duties imposed on the fees, excluding taxes on AutoAttack's net income. Where you are required by law to withhold or deduct any amount from a payment, you will increase the payment so that AutoAttack receives the full invoiced amount net of the withholding, and you will provide valid receipts for the amount withheld. You will provide your VAT, GST, or other tax registration number on request, and you are responsible for the accuracy of the tax status and address you give us.
  • Refunds — all fees are non-refundable except as required by applicable law. No refunds or credits are provided for partial billing periods or unused agent capacity, except where these Terms expressly provide for a credit.
  • Chargebacks — you will not initiate a payment-card chargeback or reversal for amounts owed under these Terms without first completing the dispute process above. You will reimburse the fees, costs, and legal expenses we incur responding to a chargeback that is resolved in our favor.
  • Grace period — if a payment fails, you have a 7-day grace period to update your payment method before your subscription is canceled.
  • Cancellation — you can cancel anytime via the Stripe billing portal (accessible from Settings). Upon cancellation, your subscription and deployed agents continue operating until the end of your current billing period. After that date, agents are deactivated and your account transitions to read-only mode (read existing findings and campaign reports). No further campaigns are conducted after the billing period ends.

Acceptable Use

You agree to:

  • Only add targets that you own or are explicitly authorized to test.
  • Not use findings or evidence to attack, exploit, or cause damage to any system.
  • Not attempt to circumvent platform security, rate limits, or access controls.
  • Not create multiple accounts to bypass plan limits or account restrictions.
  • Not resell, redistribute, or publicly disclose findings or reports.
  • Not publish any benchmark or comparative performance analysis of the service, and not publish any benchmark or comparative analysis that includes confidential finding data, campaign evidence, or proprietary platform metrics, in either case without prior written consent from AutoAttack.
  • Not use the service for any purpose that violates applicable law.

Restricted Environments

You must not deploy an agent into, or configure any campaign scope that includes, any environment where the activity described in Authorization to Test could cause physical injury, environmental harm, or the loss of a life-safety function — including industrial control systems, SCADA, safety instrumented systems, operational-technology networks, building and fire management systems, medical devices, and clinical or patient-care networks — without our prior written consent.

You represent and warrant that you have identified every such system and segmented it out of every campaign scope, and that before each campaign begins you have obtained every regulatory approval, notification, or authorization required of you in your jurisdiction or by your regulator.

Breach of this section is a breach of Authorization to Test, is a ground for immediate suspension and for termination without refund, and is an indemnity trigger under Indemnification.

Monitoring and Abuse Detection

AutoAttack reserves the right to monitor agent activity, campaign metadata, and platform usage to detect violations of these Terms, including unauthorized testing and abuse of the free campaign offering. Monitoring may include automated analysis of campaign scope, target patterns, and agent behavior.

Confidentiality

All Campaign Data, including findings, evidence, and campaign reports, is confidential. AutoAttack will not disclose Campaign Data to third parties except (a) as required by law, (b) as necessary to investigate or report suspected violations of these Terms (including unauthorized testing), and (c) to our service providers and sub-processors who process it on our behalf under written confidentiality and data-protection obligations, as described in our Privacy Policy. You agree to handle findings responsibly and use them solely for improving the security posture of your own organization.

You authorize AutoAttack to engage sub-processors to process Campaign Data on your behalf. That authorization is general: you do not approve sub-processors individually and have no right to veto one. We will give notice of any change to our sub-processors, and your remedies for objecting to a change are those set out in the Data Processing Agreement and no others.

AutoAttack Confidential Information means non-public information of AutoAttack that you receive or observe in connection with the service, including pricing not published on our pricing page, unreleased features and roadmap, non-public technical and operational information about the platform and the agent, and any vulnerability, weakness, or misconfiguration you identify in the AutoAttack platform or agent. You will keep it confidential using at least reasonable care, use it only to receive the service, and disclose it to no third party. You will not publicly disclose any vulnerability you identify in the AutoAttack platform or agent until we have remediated it or 90 days have passed since you reported it to us, whichever is earlier. This paragraph does not apply to information that is or becomes public through no fault of yours, that you already held, or that you are compelled by law to disclose (provided you notify us promptly where lawful), and it does not restrict a good-faith report to a competent regulatory, supervisory, or law-enforcement authority.

Intellectual Property

  • Platform — the AutoAttack platform, agent software, and all related technology are the intellectual property of AutoAttack. Nothing in these Terms grants you any right to our platform, trademarks, or proprietary technology.
  • Agent software — you may not reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, algorithms, data structures, or internal logic of the AutoAttack agent binary or any component thereof. You may not extract or copy the agent binary or any component thereof. You may not use automated tools, debuggers, memory forensics utilities, or network interception techniques to capture, intercept, reconstruct, or analyze the agent binary from memory, network traffic, process state, or any other source. You may not circumvent or attempt to circumvent any technical protection measures implemented in the agent, including but not limited to in-memory execution, privilege boundaries, binary obfuscation, or anti-tampering mechanisms. You may not modify, adapt, translate, or create derivative works based on the agent. You may not redistribute, sublicense, or make the agent available to any third party except as necessary to deploy it within your authorized network. This bullet does not restrict monitoring, logging, or inspection you perform on your own systems for your own security monitoring purposes, unless that activity is conducted for the purpose of deriving the agent's internal logic or of building or assisting a competing product or service. Nor does it restrict acts you are permitted to perform under mandatory applicable law that cannot be excluded by contract, including the study, observation, and testing of program functioning and decompilation for interoperability; where that law conditions the permission on the necessary information not being readily available to you, you will first request the information from us in writing and may proceed only if we fail to supply it within 30 days.
  • Agent container contents — the agent container includes proprietary and third-party tools, binaries, configurations, and attack methodology. You may not extract, copy, or export any files, tools, or binaries from the running or stopped agent container. You may not inspect, dump, or enumerate the container's filesystem, process memory, or internal configuration beyond what is necessary to verify the container is running. You may not use knowledge of the agent's internal tooling, techniques, or attack strategies for any purpose other than interpreting your own campaign results.
  • API and communications — the protocol between the agent and the AutoAttack platform is proprietary. You may not intercept, record, reverse engineer, or replicate the agent's API communications, except to the extent required for your own network security monitoring. You may not use intercepted API traffic to build competing products or services.
  • Detection and enforcement — AutoAttack reserves the right to implement technical measures to detect unauthorized extraction, reverse engineering, tampering, or circumvention of protection measures applied to the agent software or container contents. Such measures may operate without prior notice. Any violation of the Intellectual Property provisions of these Terms may result in immediate termination of your account and all associated services without refund, and AutoAttack reserves the right to pursue legal action under applicable trade secret, copyright, and intellectual property law.
  • Third-party components — the agent container may include third-party open-source or licensed components. These components are provided under their respective licenses and without additional warranty from AutoAttack. AutoAttack makes no representations regarding the suitability, security, or licensing of third-party components for any purpose other than their use within the agent container as part of the service.
  • Your dataCampaign Data means the data generated from campaigns on your networks, including agent configurations, discovered assets, open ports, operating systems, running services, network topology, findings, evidence, and reports. You retain all right, title, and interest in Campaign Data, subject to the restrictions in Acceptable Use and Confidentiality and to the licenses in this bullet. You grant AutoAttack a worldwide, non-exclusive, royalty-free license to host, store, transmit, process, and display Campaign Data as necessary to provide the service and to comply with law. You further grant AutoAttack a perpetual, irrevocable, worldwide, royalty-free license to create, retain, and use De-identified Data — Campaign Data from which identifiers of you, your personnel, and your networks have been removed, and which has been aggregated so that you cannot be identified from it — for any purpose, including operating and improving the service, benchmarking, security research, and publishing aggregate statistics. De-identified Data is not Campaign Data, and this license survives termination and account deletion.
  • Feedback — any suggestions, feature requests, bug reports, or other feedback you provide about the service become the property of AutoAttack. We may use, modify, and incorporate feedback into the service without attribution, compensation, or obligation to you. This does not apply to any intellectual property you owned prior to providing such feedback.
  • Transfer of these grants — every license, assignment, and right granted to AutoAttack in this section is granted to AutoAttack and its successors, assigns, and permitted transferees, is transferable and sublicensable to a Permitted Transferee as defined in Assignment and Novation, and on a novation under that section takes effect in favor of the Permitted Transferee without further act. No license, assignment, or right granted in this section is personal to AutoAttack.

The restrictions in this section do not apply to any third-party component included in the agent container to the extent that component's own license grants you rights inconsistent with them; as to those components, their licenses govern, and nothing in these Terms restricts, conditions, or adds to the rights they grant. Nothing in this paragraph limits any restriction in this section as it applies to the AutoAttack agent binary, the platform, or AutoAttack's own proprietary tooling, configurations, and attack methodology, which continue to apply in full.

You acknowledge that any breach of the Intellectual Property provisions would cause irreparable harm to AutoAttack for which monetary damages would be inadequate. AutoAttack is entitled to seek injunctive or other equitable relief in any court of competent jurisdiction, without the requirement of posting bond or proving actual damages, in addition to any other remedies available at law or in equity.

Indemnification

You agree to indemnify, defend, and hold harmless each AutoAttack Person from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or related to:

  • Your deployment of agents on networks you were not authorized to test.
  • Any third-party claims resulting from an autonomous adversary deployed on networks where you deployed agents, including claims for service disruption, data loss, or unauthorized access.
  • Any claim by an infrastructure, hosting, connectivity, or managed service provider, by a co-tenant of shared infrastructure, or by a network owner other than you, arising from agent activity on networks you placed in scope.
  • Your violation of these Terms, including the Acceptable Use and Intellectual Property provisions.
  • Your misuse of findings, evidence, or reports, including any harm to third parties resulting from your disclosure or weaponization of campaign results.
  • Your extraction, redistribution, or misuse of agent container contents, bundled tools, or proprietary attack methodology.
  • Any investigation, inquiry, or enforcement action by a supervisory or regulatory authority, and any claim by a data subject or other individual, arising from personal data present in campaign scope, discovered assets, or finding evidence, or from your instructions as controller — including the absence of any lawful basis, notice, or consent you were required to establish. Our costs of defending and responding to any such matter are recoverable in full; any fine or penalty imposed on us is recoverable to the extent it arises from your instructions, your campaign configuration, or your failure to establish a lawful basis, notice, or consent required of you.

You will give us prompt written notice of any claim under this section, and we may at our election assume sole control of its defense and settlement with counsel of our choosing while remaining indemnified. You will not settle, compromise, or admit any matter that imposes an obligation on, or attributes fault to, any AutoAttack Person without our prior written consent. You will cooperate with us and provide all documents and access we reasonably request, including the written authorization you relied on in deploying an agent. You will reimburse our legal costs on an indemnity basis in any proceeding to enforce these Terms and in any claim you bring in breach of the covenant not to sue in Authorization to Test. No limitation of liability in these Terms applies to your obligations under this section.

Disclaimers

To the maximum extent permitted by applicable law, and for the benefit of each AutoAttack Person:

  • The service is provided "as is" and "as available" without warranty of any kind, whether express, implied, or statutory, including but not limited to warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and completeness.
  • AutoAttack is not a guarantee of security. We do not guarantee that the service will identify every weakness in your network.
  • We do not warrant that the service will be uninterrupted, error-free, or available at any particular time.
  • AutoAttack is not responsible for any damage to your systems or to third-party systems resulting from agent activity, whether or not that activity fell within the campaign scope or exclusions you configured, save to the extent stated in Authorization to Test.
  • Findings are point-in-time results reflecting the state of your network during the campaign. AutoAttack does not guarantee that findings remain accurate after the campaign completes.
  • The service does not constitute a compliance audit, certification, or attestation. Campaign results and reports are not a substitute for professional security assessments required by regulatory frameworks. AutoAttack is not liable for any compliance failures, regulatory penalties, or audit outcomes.
  • Informational content published as research briefs is provided for educational purposes only and does not constitute professional security advice. We make no guarantees about the accuracy, completeness, or applicability of published content to your specific environment.

Basis of Dealing

These Terms, the Privacy Policy, and the Data Processing Agreement state the whole of the responsibility each party assumes to the other in respect of the service, the agent software, and every campaign. No AutoAttack Person assumes, or holds itself out as assuming, any responsibility to you other than as those documents expressly state. You acknowledge and agree that you do not rely, and have not relied, on the skill, care, judgment, or advice of any AutoAttack Person other than as those documents expressly state; that no AutoAttack Person owes you a duty of care in tort or in equity that arises independently of those documents, whether concurrently with a contractual duty or otherwise; and that those documents, and no duty arising outside them, govern any loss you suffer. You will bring any claim arising from or related to the service, the agent software, or any campaign under and in accordance with these Terms and on no other basis.

This section defines the basis on which the parties contract and the responsibility each assumes; it is not an exclusion or restriction of a liability that would otherwise arise. Nothing in it excludes or limits liability for fraud or fraudulent misrepresentation, for death or personal injury caused by our negligence, or any other liability that cannot lawfully be excluded or limited, and nothing in it negates a duty that cannot lawfully be negated. Should a court hold that any part of this section operates as an exclusion or restriction of liability, that part is severed and Limitation of Liability continues to apply in full.

Limitation of Liability

To the maximum extent permitted by applicable law, and for the benefit of each AutoAttack Person:

  • AutoAttack's total aggregate liability, whether arising in contract, tort (including negligence and breach of statutory duty), misrepresentation, restitution, equity, or otherwise, and whether in respect of a single claim or many, for any and all claims arising from or related to the service, the agent software, any campaign, or these Terms, is limited to the greater of (a) the total fees you actually paid to AutoAttack in the 12 months immediately preceding the event giving rise to the claim and (b) US$5,000. That limit is a single aggregate limit on the liability of AutoAttack and of every other AutoAttack Person taken together. It is not a limit per claim, per claimant, per defendant, per AutoAttack Person, per campaign, per billing period, or per proceeding, and no combination of claims, claimants, defendants, causes of action, descriptions of the same person, or separate or successive proceedings increases it. Any amount paid or payable by any AutoAttack Person in respect of any claim, and any amount recovered by a person whose recovery reduces this limit under Authorization to Test, exhausts the limit to the extent of that amount, and any amount you recover in one proceeding reduces the limit available in every other.
  • In no event shall AutoAttack be liable for any indirect, incidental, special, consequential, or punitive damages, regardless of the theory of liability.
  • In no event shall AutoAttack be liable, whether the loss is direct or indirect, for: loss, corruption, alteration, or unavailability of data; the cost of restoring, recreating, or reconstituting data or systems; loss of use; business interruption or downtime; loss of production or output; account lockouts or denial of access to accounts or services; loss of profit, revenue, contracts, anticipated savings, or goodwill; or the cost of third-party incident response, forensic, or remediation services.
  • You are solely responsible for maintaining current, tested, offline backups of every system within any campaign scope before an agent is deployed, and for the network segmentation of any system you do not wish an agent to reach.
  • Your recourse in respect of any claim arising from or related to the service, the agent software, any campaign, these Terms, the Privacy Policy, or the Data Processing Agreement is limited to the assets used in or held for the purposes of the AutoAttack business — including the platform and the agent software, the intellectual property in them, the revenue and receivables of the business, the accounts and payment-processor balances through which it is operated, and the equipment and hosting used to provide the service — and to the proceeds of any insurance available in respect of the claim. You covenant that you will not seek to enforce a judgment, award, or settlement in respect of any such claim against any other asset of AutoAttack or of any AutoAttack Person. This bullet does not reduce the amount of any claim and does not deprive you of a cause of action. It does not apply to liability for fraud or fraudulent misrepresentation, to liability for death or personal injury caused by our negligence, or to any liability whose enforcement cannot lawfully be restricted. Should you enforce or seek to enforce in breach of this bullet, you will pay our costs of resisting that enforcement on an indemnity basis, as Indemnification provides.
  • No limit in this section applies to your obligation to pay fees or to your obligations under Indemnification.
  • These limitations apply even if AutoAttack has been advised of the possibility of such damages and even if a remedy fails of its essential purpose. The parties have also agreed the following monetary limits in the alternative, in the order stated: (a) the greater of the fees described in the first bullet and US$25,000; and (b) the greater of those fees and US$100,000. Each is a separate and independent limit, agreed in the alternative to the limit in the first bullet and to the other, and each is a single aggregate limit on the same basis as that limit. Should the limit in the first bullet be held unenforceable, it is severed and the first of (a) and (b) that is enforceable applies in its place; and if (a) is held unenforceable it is severed and disregarded without affecting (b). Should any other limit in this section be held unenforceable, that limit is severed and the remaining limits continue in full force; no exclusion or covenant in this section is replaced by a sum of money.
  • The allocation of risk in this section is made on the basis of the insurance you are required to maintain, and to look first to, under Authorization to Test. You acknowledge that the limits and exclusions in this section were available to you to read in full before you accepted these Terms; that you are better placed than any AutoAttack Person to know, to value, and to insure the systems within a campaign scope, and that you control that scope and its exclusions; and that the loss you could suffer from an operational impact may greatly exceed the fees, which is why that insurance is required of you. Each party acknowledges that these limits and exclusions are a reasonable allocation of risk in the circumstances known to both parties when these Terms were accepted.

Nothing in these Terms excludes or limits liability for fraud or fraudulent misrepresentation, for death or personal injury caused by our negligence, or for any other liability that cannot lawfully be excluded or limited. Subject only to the preceding sentence, the limits in this section apply to all liability however arising, including liability in negligence, and no claim escapes them by reason of being characterized as gross negligence, recklessness, or a fundamental or repudiatory breach. Liability arising under the exception to the out-of-scope exclusion in Authorization to Test is subject to every limit in this section.

Export Controls and Sanctions

The service, including the agent software, may be subject to export control and sanctions laws, including the U.S. Export Administration Regulations (EAR), the EU Dual-Use Regulation, and Singapore's Strategic Goods (Control) Act 2002. You represent and warrant that:

  • You are not located in, organized under the laws of, or a resident of any country or territory subject to comprehensive trade sanctions.
  • You are not listed on any applicable restricted or denied party list, including the U.S. Treasury Department's Specially Designated Nationals (SDN) List, the U.S. Commerce Department's Entity List, or equivalent lists maintained by the EU, UK, or other applicable jurisdictions.
  • You will not use, export, re-export, transfer, or provide access to the service or agent software in violation of any applicable export control or sanctions laws, or to any person, entity, or jurisdiction prohibited under such laws.

Account Deletion

You can delete your account from Settings at any time. Upon deletion: your subscription is canceled, deployed agents stop operating, your sessions are invalidated, and your account is immediately inaccessible. Your email address and password hash, and the network address and browser identification recorded with your acceptance of these Terms, are permanently and irreversibly overwritten after 30 days, except where that data is subject to a legal hold, a preservation order, or an actual or reasonably anticipated dispute, claim, or investigation, as described in our Privacy Policy. The versions of these Terms and of the Privacy Policy you accepted and the time of acceptance are retained after that as evidence that this agreement was formed. Campaign Data may be retained for a limited period as described in our Privacy Policy. You are solely responsible for exporting any data you wish to retain before deleting your account. AutoAttack is not responsible for data that becomes inaccessible after account deletion.

Termination

We reserve the right to suspend or terminate your account immediately if you violate these Terms, particularly the Authorization to Test, Acceptable Use, or Intellectual Property provisions. In cases of termination for cause, no refund will be issued. Upon termination, your right to use the service ceases immediately and you must destroy all copies of the agent software in your possession. The following sections survive termination, expiry, and novation of these Terms: Acceptance (definitions), Authorization to Test (representations, authorization and consent, release, and covenant not to sue), Subscription and Billing (accrued fees, taxes, measurement and invoice disputes, and chargebacks), Acceptable Use, Restricted Environments, Confidentiality, Intellectual Property (including Feedback), Indemnification, Basis of Dealing, Disclaimers, Limitation of Liability, Export Controls and Sanctions, Account Deletion, Governing Law, Dispute Resolution, Assignment and Novation, and General Provisions, together with the Data Processing Agreement to the extent section 16.4 of it provides and any other provision which by its nature is intended to survive.

AutoAttack may, immediately and without liability, suspend or throttle your account, any agent, or any campaign in progress where we reasonably suspect a breach of these Terms; where we receive a complaint or notice from any person asserting that testing is unauthorized; where we receive a legal, regulatory, or law-enforcement demand; where a provider of our infrastructure requires it; or where we reasonably believe continued operation risks harm to any person, system, or network. Suspension under this paragraph is not a breach of these Terms and gives rise to no liability, and we may use monitoring records as evidence in any enforcement action. Where a suspension based on suspected breach proves to have been unfounded, we will credit or extend your subscription for the period of the suspension; otherwise suspension gives rise to no refund, credit, or extension, and we may keep it in place until we are satisfied the cause is resolved.

AutoAttack may elect not to renew your subscription by notice given before the renewal date, may terminate these Terms for convenience on 30 days notice, and may withdraw or discontinue the service or any feature on 30 days notice. Where we terminate for convenience, we will credit prepaid fees for the unused remainder of the then-current billing period as your sole remedy.

Fees and other amounts accrued or payable before termination, suspension, or account deletion survive, become immediately due and payable, and may be invoiced by us after termination. This includes any quantity increase not yet invoiced for hosts already discovered.

Governing Law

These Terms are governed by and construed in accordance with the laws of Singapore, without regard to conflict of law principles. Nothing in these Terms excludes or limits a right or protection that applicable law confers on you and does not permit to be excluded or limited by agreement.

Dispute Resolution

Any dispute arising from or relating to these Terms or the service shall be resolved as follows:

  • Informal resolution — before filing any claim, you must send us a written notice of dispute under the Notices bullet in General Provisions, describing the claim and the relief sought, and the parties will then have 30 days to resolve it. Compliance with this bullet is a condition precedent to your filing any claim. The period in the Time limitation bullet is suspended while those 30 days run.
  • Jurisdiction — you submit to the exclusive jurisdiction of the courts of Singapore for any claim you bring, except where that submission is prohibited by applicable law. AutoAttack may bring proceedings against you in the courts of Singapore or in any other court having jurisdiction over you or your assets, including proceedings to recover unpaid fees and proceedings for injunctive or other equitable relief as reserved in the Intellectual Property section.
  • Class action waiver — you agree that any dispute resolution proceedings will be conducted only on an individual basis and not in a class, consolidated, or representative action, to the extent permitted by applicable law.
  • Time limitation — you must file any claim arising from or related to the service within one (1) year after the cause of action arises, or it is permanently barred. This limitation does not apply to claims for indemnification under these Terms, to AutoAttack's claims for unpaid fees, to AutoAttack's claims for breach of the Acceptable Use, Confidentiality, Intellectual Property, or Export Controls and Sanctions sections, or to any application for injunctive or other equitable relief, each of which may be brought within the limitation period available under applicable law. This limitation applies to the extent permitted by applicable law.

Assignment and Novation

You may not assign or transfer your rights or obligations under these Terms without our prior written consent. AutoAttack may assign its rights under these Terms, in whole or in part, and may subcontract performance, in either case without your consent; an assignment alone does not transfer AutoAttack's obligations or release it from them, and the novation described below is the means by which those obligations transfer. Any permitted assignment or novation is binding on your successors.

Permitted Transferee means a body corporate incorporated by or on behalf of the person or persons then carrying on the business of AutoAttack, or a person that acquires that business or substantially all of its assets, in either case that carries on or will carry on that business and that agrees to be bound as this section provides. AutoAttack may at any time novate these Terms, together with the Data Processing Agreement, in whole and not in part, to a Permitted Transferee. You irrevocably consent now to that novation, you dispense with any requirement for your specific consent at the time it is effected, and you may not withdraw that consent.

The novation takes effect when the Permitted Transferee has signed a notice of novation stating its name and the effective date, being not less than 30 days after the notice is given, and we have given you that signed notice under the Notices bullet. No further act by you is required, and to the extent a further act is needed to give the novation effect you will sign any document we reasonably require. We warrant that at the effective date we have no reasonable grounds to believe the Permitted Transferee is unable or unwilling to perform the obligations it assumes.

On the effective date, and without further act by any party: these Terms are discharged as between you and AutoAttack; a new contract comes into existence between you and the Permitted Transferee on terms identical to these Terms as then in force, in which a reference to AutoAttack is a reference to the Permitted Transferee and the definition of AutoAttack Persons is read accordingly; the Permitted Transferee assumes every obligation and liability of AutoAttack under these Terms and the Data Processing Agreement, accrued and future, as if it had been the original party; your accrued rights and claims transfer to the Permitted Transferee and are enforceable against it to the same extent as they were enforceable against AutoAttack; and every license, assignment, and right granted to AutoAttack under Intellectual Property takes effect in favor of the Permitted Transferee. Where the SCCs apply under section 11.2 of the Data Processing Agreement, the Permitted Transferee becomes the processor and the data importer on the effective date and Annex I.A is amended to record its details; your consent under this section extends to that substitution, and Clause 7 of the SCCs remains disapplied.

On the effective date you release and discharge AutoAttack absolutely from every obligation, liability, claim, and demand under or in connection with these Terms, the Data Processing Agreement, the service, the agent software, and any campaign, whether arising before or after that date, whether in contract, tort (including negligence and breach of statutory duty), misrepresentation, restitution, equity, or otherwise, and whether known or unknown, and you covenant not to commence or fund any such claim against AutoAttack. The consideration for that release is the Permitted Transferee's assumption of those obligations and liabilities and the transfer of your accrued rights to it, and the release takes effect only if and when that assumption and that transfer take effect, so that you are left with the same rights against the Permitted Transferee that you had against AutoAttack. Nothing in this paragraph releases liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, or any other liability that cannot lawfully be released.

Notwithstanding that discharge and that release, every disclaimer, exclusion, limitation of liability, release, waiver, covenant not to sue, indemnity, and time limitation in these Terms, and every provision of Basis of Dealing, continues to apply for the benefit of AutoAttack and of every other AutoAttack Person in respect of the period before the effective date, and each of them may enforce it under the Contracts (Rights of Third Parties) Act 2001.

Changes to These Terms

We may update these Terms from time to time. We will provide at least 30 days notice of material changes via email. Continued use of the service after changes take effect constitutes acceptance of the updated Terms. If you do not agree to the revised Terms, you must stop using the service and cancel your account before the changes take effect.

General Provisions

  • Entire agreement and precedence — these Terms, the Privacy Policy, the Data Processing Agreement, and the pricing published on our pricing page as in effect when you subscribe or renew, together with the checkout you complete, constitute the entire agreement between you and AutoAttack regarding the service and supersede all prior agreements, understandings, and communications. Any additional, different, or conflicting term in a purchase order, vendor onboarding or registration form, procurement or supplier portal, supplier code of conduct, or similar document issued by you or by a third party on your behalf is void and of no effect, even if AutoAttack signs, acknowledges, or references that document or accepts payment under it. That includes any data processing agreement, data processing addendum, standard clauses, security schedule, or questionnaire response so issued: the Data Processing Agreement is the only one in effect between us. On any conflict these Terms prevail, except that the pricing page governs price, the checkout governs quantity, and the Data Processing Agreement prevails to the extent section 17.1 of it provides. Nothing in this bullet supersedes, discharges, or limits anything preserved by the retained-protections paragraph of Assignment and Novation.
  • Non-reliance — in entering into these Terms, and on any renewal, you acknowledge and agree that the only statements, representations, warranties, assurances, and undertakings you rely on are those expressly set out in the documents named in the Entire agreement and precedence bullet, and that you have not relied on any other, whether made on our website, in a research brief, benchmark, comparison, performance figure, timing, or demonstration, or in any presentation or correspondence. Every performance figure, timing, and benchmark result we publish is a measurement taken in the laboratory or fixture identified alongside it; it is not a representation, prediction, or warranty about your own network, which differs in size, composition, configuration, and defensive posture, and it cannot be relied on as one. You acknowledge that where the free campaign described in Free Campaign is or was available to you, you were able to measure the service's performance in your own network before subscribing. Your only remedies in respect of any statement, representation, warranty, assurance, or undertaking are those for breach of these Terms. Nothing in this bullet limits liability for fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited, as Limitation of Liability provides.
  • Relationship of the parties — nothing in these Terms creates a partnership, joint venture, agency, employment, franchise, fiduciary, or trustee relationship between you and AutoAttack or between you and any AutoAttack Person, and no party is the partner, agent, employee, fiduciary, or trustee of another. Neither party may hold itself out as, or purport to bind, the other. No party is jointly, or jointly and severally, liable for an obligation or liability of another, and each is responsible only for its own acts and omissions. The designation of AutoAttack as your authorized agent under Authorization to Test is given solely to constitute your consent and authorization under computer access laws, is limited to that purpose, and imposes on no AutoAttack Person a fiduciary duty or a duty of skill, care, or loyalty beyond the obligations these Terms expressly state.
  • Notices — notices from AutoAttack are effective when sent to the email address associated with your account or posted in the dashboard, whether or not you open or receive them, and you are responsible for keeping that address current, monitored, and able to receive our mail. Notices to AutoAttack are effective on actual receipt at security@autoattack.ai, and a notice of dispute under Dispute Resolution is treated as received no later than the second business day after it is sent to that address. A notice given to any other address does not start or satisfy any period or condition under these Terms. Either party may change its notice address by notice given under this bullet.
  • Electronic records — the parties consent to contract by electronic means. You will not contest the validity, enforceability, or admissibility of our electronic records of your acceptance of these Terms or of your use of the service on the ground that those records are electronic.
  • Severability — if any provision of these Terms is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
  • Waiver — the failure of AutoAttack to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision. Any waiver must be in writing and signed by AutoAttack.
  • Force majeure — neither party is liable for any failure or delay in performance caused by an event beyond its reasonable control, including act of God, natural disaster, war, terrorism, civil unrest, epidemic, labor dispute, government or regulatory action, change in law, sanctions, court order, failure or withdrawal of a third-party service on which the service depends (including cloud infrastructure, artificial-intelligence model providers, payment processors, email providers, and container registries), denial-of-service attack, internet or network failure, or any act or omission of a supplier. The affected party's obligations are suspended for the duration of the event. Where the event continues for more than 30 days, AutoAttack may terminate these Terms on notice and may at its option credit prepaid fees for the unused remainder of the then-current billing period; nothing in this bullet creates a right to a refund.
  • Third parties — every disclaimer, exclusion, limitation of liability, release, covenant not to sue, and time limitation in these Terms, and every provision of Basis of Dealing, applies for the benefit of each AutoAttack Person to the same extent as it applies to AutoAttack, subject to the single aggregate limit stated in Limitation of Liability; each AutoAttack Person may enforce it under the Contracts (Rights of Third Parties) Act 2001 and may plead it as a defense to a claim brought against it. You will bring any claim arising from or related to the service, the agent software, or any campaign against AutoAttack alone and in a single proceeding, whether AutoAttack is named by the name under which it trades, by the name of a person who carries on business under it, or by any other description, and not against any other AutoAttack Person. Should you bring a claim in breach of this bullet, you will pay our costs of defending it on an indemnity basis, as Indemnification provides. Save as stated in this bullet, no person who is not a party may enforce any provision of these Terms, and that Act is excluded. The parties may vary, novate, rescind, or terminate these Terms, and AutoAttack may amend them under Changes to These Terms, without the consent of any third party.

Contact

For questions about these Terms, contact us at security@autoattack.ai.