Terms.
Acceptance
These Terms of Service ("Terms") are a legal agreement between you ("Customer," "you") and AutoAttack ("AutoAttack," "we," "us"), which operates the autoattack.ai platform. By creating an account, deploying an agent, or using any part of the service, you agree to these Terms and our Privacy Policy. If you do not agree, do not use the service.
Service Description
AutoAttack is an autonomous adversary. You deploy an agent locally inside your network, and it red-teams toward real objectives — discovering assets, executing attack techniques, and reporting confirmed attack achievements with full proof chains. The service is provided on a commercially reasonable efforts basis with no guaranteed uptime or service level agreement.
Account Requirements
- You must be at least 18 years of age and have the legal capacity to enter into a binding agreement.
- A valid business email address is required. Consumer email providers (Gmail, Yahoo, Hotmail, Outlook, etc.) are not accepted.
- Each organization has one account. Multi-user access is not currently supported.
- You must provide accurate and complete information and keep your account credentials secure. You are responsible for all activity under your account.
- If you are accepting these Terms on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms. "You" and "Customer" refer to the organization in that case.
Authorization to Test
By deploying an AutoAttack agent inside a network, you represent and warrant that:
- You have legal authority to authorize an autonomous adversary and security testing on that network.
- You own the network or have explicit, documented authorization from the owner to conduct offensive security testing against it.
- You understand that AutoAttack agents will perform active attack techniques, including but not limited to: network discovery, port enumeration, service fingerprinting, credential spraying, LLMNR/NBT-NS poisoning, Kerberoasting, lateral movement, privilege escalation, data exfiltration, and other red team techniques designed to test your defenses.
- You acknowledge and accept that active attacks will interact with your production systems and could affect service availability, cause account lockouts, trigger security alerts, or temporarily degrade network performance. You assume all risk of operational impact resulting from an authorized autonomous adversary on your network.
- You acknowledge that the agent container requires elevated permissions (including host networking, raw socket access, and time synchronization capabilities) and accept the security implications of running such a container in your environment.
- You are designating AutoAttack as your authorized agent to perform such testing on your behalf. This authorization constitutes your consent under applicable computer access laws, including but not limited to the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. 1030), the Computer Misuse Act 1990 (UK), and equivalent legislation in other jurisdictions.
Once deployed, the agent begins discovering assets and executing attack campaigns immediately. The agent operates autonomously and will attempt to reach any system accessible from its deployment point. During lateral movement, the agent authenticates to and operates from compromised hosts — meaning attack traffic may originate from IP addresses other than the original deployment host. The deployment host maintains an outbound HTTPS connection to AutoAttack's API (agent.autoattack.ai) to report findings and receive campaign configuration. You are solely responsible for configuring campaign scope and network exclusions to ensure the agent only interacts with systems you are authorized to test. AutoAttack is not liable for agent activity on systems that were reachable but outside your intended scope if you failed to configure appropriate exclusions.
Deploying agents on networks you do not own or have authorization to test is a violation of these Terms and will result in immediate account termination without refund. You acknowledge that unauthorized testing may violate criminal and civil laws, and you accept sole responsibility for ensuring proper authorization. AutoAttack reserves the right to report suspected unauthorized testing to relevant law enforcement authorities and to cooperate with any resulting investigation, including by providing account information, campaign data, and audit logs.
Free Campaign
AutoAttack offers a free campaign for new accounts. You may deploy an agent and run a full campaign. Free usage is subject to all Terms, including Authorization to Test and Acceptable Use. The free campaign determines your discovered host count, which sets your subscription tier. Subscribing reveals the hostnames, techniques, and proof behind each finding, and enables report downloads. AutoAttack reserves the right to modify, suspend, or discontinue the free campaign offering — or to terminate any free account — at any time, for any reason, without notice or liability.
Subscription and Billing
- Pricing — AutoAttack uses graduated per-host pricing based on discovered host count. All customers receive the same features. Pricing is published on our pricing page and billed annually. For networks exceeding 10,000 hosts, contact us for custom pricing.
- Host-based billing — your subscription quantity equals the number of unique hosts discovered by the agent during your current billing period. This count automatically increases as new hosts are discovered; increases are prorated for the remainder of your billing period.
- Auto-renewal — subscriptions automatically renew at the end of each billing period at the then-current rate unless you cancel before the renewal date. If you do not cancel before the renewal date, you accept the updated pricing.
- Payment — all payments are processed by Stripe. By subscribing, you agree to Stripe's terms of service.
- Refunds — all fees are non-refundable except as required by applicable law. No refunds or credits are provided for partial billing periods or unused agent capacity.
- Grace period — if a payment fails, you have a 7-day grace period to update your payment method before your subscription is canceled.
- Cancellation — you can cancel anytime via the Stripe billing portal (accessible from Settings). Upon cancellation, your subscription and deployed agents continue operating until the end of your current billing period. After that date, agents are deactivated and your account transitions to read-only mode (view existing findings, download reports). No further campaigns are conducted after the billing period ends.
Acceptable Use
You agree to:
- Only add targets that you own or are explicitly authorized to test.
- Not use findings or evidence to attack, exploit, or cause damage to any system.
- Not attempt to circumvent platform security, rate limits, or access controls.
- Not create multiple accounts to bypass plan limits or account restrictions.
- Not resell, redistribute, or publicly disclose findings or reports.
- Not extract, copy, or reuse any tools, binaries, or attack methodology from the agent container, or use knowledge of the agent's internals to build or assist competing products or services.
- Not publish benchmarks or comparative analyses that include confidential finding data, campaign evidence, or proprietary platform metrics without prior written consent from AutoAttack.
- Not use the service for any purpose that violates applicable law.
Monitoring and Abuse Detection
AutoAttack reserves the right to monitor agent activity, campaign metadata, and platform usage to detect violations of these Terms, including unauthorized testing, abuse of the free campaign offering, and attempts to extract or reverse-engineer agent container contents. Monitoring may include automated analysis of campaign scope, target patterns, and agent behavior.
Confidentiality of Findings
All findings, evidence, and campaign reports are confidential. AutoAttack will not disclose your findings to third parties except as required by law or as necessary to investigate or report suspected violations of these Terms (including unauthorized testing). You agree to handle findings responsibly and use them solely for improving the security posture of your own organization.
Intellectual Property
- Platform — the AutoAttack platform, agent software, and all related technology are the intellectual property of AutoAttack. Nothing in these Terms grants you any right to our platform, trademarks, or proprietary technology.
- Agent software — you may not reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, algorithms, data structures, or internal logic of the AutoAttack agent binary or any component thereof. You may not extract, copy, or redistribute the agent binary or any component thereof. You may not use automated tools, debuggers, memory forensics utilities, or network interception techniques to capture, intercept, reconstruct, or analyze the agent binary from memory, network traffic, process state, or any other source. You may not circumvent or attempt to circumvent any technical protection measures implemented in the agent, including but not limited to in-memory execution, privilege boundaries, binary obfuscation, or anti-tampering mechanisms. You may not modify, adapt, translate, or create derivative works based on the agent. You may not redistribute, sublicense, or make the agent available to any third party except as necessary to deploy it within your authorized network.
- Agent container contents — the agent container includes proprietary and third-party tools, binaries, configurations, and attack methodology. You may not extract, copy, or export any files, tools, or binaries from the running or stopped agent container. You may not inspect, dump, or enumerate the container's filesystem, process memory, or internal configuration beyond what is necessary to verify the container is running. You may not use knowledge of the agent's internal tooling, techniques, or attack strategies for any purpose other than interpreting your own campaign results.
- API and communications — the protocol between the agent and the AutoAttack platform is proprietary. You may not intercept, record, reverse engineer, or replicate the agent's API communications, except to the extent required for your own network security monitoring. You may not use intercepted API traffic to build competing products or services.
- Detection and enforcement — AutoAttack reserves the right to implement technical measures to detect unauthorized extraction, reverse engineering, tampering, or circumvention of protection measures applied to the agent software or container contents. Such measures may operate without prior notice. Any violation of the Intellectual Property provisions of these Terms may result in immediate termination of your account and all associated services without refund, and AutoAttack reserves the right to pursue legal action under applicable trade secret, copyright, and intellectual property law, including claims for injunctive relief, damages, and recovery of legal fees.
- Third-party components — the agent container may include third-party open-source or licensed components. These components are provided under their respective licenses and without additional warranty from AutoAttack. AutoAttack makes no representations regarding the suitability, security, or licensing of third-party components for any purpose other than their use within the agent container as part of the service.
- Your data — findings, evidence, and reports generated from campaigns on your networks are yours for internal use. You retain all rights to your campaign data.
- Feedback — any suggestions, feature requests, bug reports, or other feedback you provide about the service become the property of AutoAttack. We may use, modify, and incorporate feedback into the service without attribution, compensation, or obligation to you. This does not apply to any intellectual property you owned prior to providing such feedback.
You acknowledge that any breach of the Intellectual Property provisions would cause irreparable harm to AutoAttack for which monetary damages would be inadequate. AutoAttack is entitled to seek injunctive or other equitable relief in any court of competent jurisdiction, without the requirement of posting bond or proving actual damages, in addition to any other remedies available at law or in equity.
Indemnification
You agree to indemnify, defend, and hold harmless AutoAttack and its personnel, contractors, and representatives from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or related to:
- Your deployment of agents on networks you were not authorized to test.
- Any third-party claims resulting from an autonomous adversary deployed on networks where you deployed agents, including claims for service disruption, data loss, or unauthorized access.
- Your violation of these Terms, including the Acceptable Use and Intellectual Property provisions.
- Your misuse of findings, evidence, or reports, including any harm to third parties resulting from your disclosure or weaponization of campaign results.
- Your extraction, redistribution, or misuse of agent container contents, bundled tools, or proprietary attack methodology.
Disclaimers
To the maximum extent permitted by applicable law:
- The service is provided "as is" and "as available" without warranty of any kind, whether express, implied, or statutory, including but not limited to warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and completeness.
- AutoAttack is not a guarantee of security. No autonomous adversary can discover all attack paths. We do not guarantee that the service will identify every weakness in your network.
- We do not warrant that the service will be uninterrupted, error-free, or available at any particular time.
- AutoAttack is not responsible for any damage to your systems or third-party systems resulting from an authorized autonomous adversary operating within the scope of your deployment. This includes, without limitation, account lockouts caused by credential testing, network disruption caused by poisoning or relay attacks, alerts triggered in your security monitoring systems, and temporary service degradation on targeted hosts.
- Findings are point-in-time results reflecting the state of your network during the campaign. Network changes, patches, or configuration drift after a campaign may render findings outdated. AutoAttack does not guarantee that findings remain accurate after the campaign completes.
- The service does not constitute a compliance audit, certification, or attestation. Campaign results and reports are not a substitute for professional security assessments required by regulatory frameworks. AutoAttack is not liable for any compliance failures, regulatory penalties, or audit outcomes.
- Informational content published as research briefs is provided for educational purposes only and does not constitute professional security advice. We make no guarantees about the accuracy, completeness, or applicability of published content to your specific environment.
Limitation of Liability
To the maximum extent permitted by applicable law:
- AutoAttack's total aggregate liability for any and all claims arising from or related to the service is limited to the total fees you actually paid to AutoAttack in the 12 months immediately preceding the event giving rise to the claim. If you have not paid any fees (including free campaign usage), AutoAttack's total liability is limited to zero.
- In no event shall AutoAttack be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill, regardless of the theory of liability.
- These limitations apply even if AutoAttack has been advised of the possibility of such damages and even if a remedy fails of its essential purpose.
Nothing in these Terms excludes or limits liability for fraud, gross negligence, willful misconduct, or any liability that cannot be excluded or limited under applicable law.
Export Controls and Sanctions
The service, including the agent software, may be subject to export control and sanctions laws, including the U.S. Export Administration Regulations (EAR), the EU Dual-Use Regulation, Singapore's Strategic Goods (Control) Act 2002, and the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies. You represent and warrant that:
- You are not located in, organized under the laws of, or a resident of any country or territory subject to comprehensive trade sanctions (including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine).
- You are not listed on any applicable restricted or denied party list, including the U.S. Treasury Department's Specially Designated Nationals (SDN) List, the U.S. Commerce Department's Entity List, or equivalent lists maintained by the EU, UK, or other applicable jurisdictions.
- You will not use, export, re-export, transfer, or provide access to the service or agent software in violation of any applicable export control or sanctions laws, or to any person, entity, or jurisdiction prohibited under such laws.
Violation of export controls or sanctions is grounds for immediate termination without refund and may result in criminal penalties under applicable law.
Account Deletion
You can delete your account from Settings at any time. Upon deletion: your subscription is canceled, deployed agents stop operating, your sessions are invalidated, and your account is immediately inaccessible. Your email address and password are permanently and irreversibly overwritten after 30 days. Campaign data may be retained for a limited period as described in our Privacy Policy. You are solely responsible for exporting any data you wish to retain before deleting your account. AutoAttack is not responsible for data that becomes inaccessible after account deletion.
Termination
We reserve the right to suspend or terminate your account immediately if you violate these Terms, particularly the Authorization to Test, Acceptable Use, or Intellectual Property provisions. In cases of termination for cause, no refund will be issued. Upon termination, your right to use the service ceases immediately and you must destroy all copies of the agent software in your possession. The following sections survive termination: Authorization to Test (representations), Acceptable Use, Confidentiality of Findings, Intellectual Property (including Feedback), Indemnification, Disclaimers, Limitation of Liability, Export Controls and Sanctions, Governing Law, and Dispute Resolution.
Governing Law
These Terms are governed by and construed in accordance with the laws of Singapore, without regard to conflict of law principles. For customers located in the European Union, nothing in these Terms affects your rights under mandatory consumer protection laws of your country of residence.
Dispute Resolution
Any dispute arising from or relating to these Terms or the service shall be resolved as follows:
- Informal resolution — you agree to first attempt to resolve any dispute informally by contacting us at security@autoattack.ai.
- Jurisdiction — if informal resolution fails, disputes shall be submitted to the exclusive jurisdiction of the courts of Singapore, except where prohibited by applicable law.
- Class action waiver — you agree that any dispute resolution proceedings will be conducted only on an individual basis and not in a class, consolidated, or representative action, to the extent permitted by applicable law.
- Time limitation — any claim arising from or related to the service must be filed within one (1) year after the cause of action arises, or it is permanently barred. This limitation does not apply to claims for indemnification under these Terms, which may be brought within the applicable statute of limitations under Singapore law. This limitation applies to the extent permitted by applicable law.
Assignment
You may not assign or transfer your rights or obligations under these Terms without our prior written consent. AutoAttack may assign these Terms in connection with a sale of the business, incorporation, reorganization, or transfer of substantially all assets to a successor entity, without your consent. Any permitted assignment is binding on successors.
Changes to These Terms
We may update these Terms from time to time. We will provide at least 30 days notice of material changes via email. Continued use of the service after changes take effect constitutes acceptance of the updated Terms. If you do not agree to the revised Terms, you must stop using the service and cancel your account before the changes take effect.
General Provisions
- Entire agreement — these Terms, together with the Privacy Policy, constitute the entire agreement between you and AutoAttack regarding the service and supersede all prior agreements, understandings, and communications.
- Severability — if any provision of these Terms is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
- Waiver — the failure of AutoAttack to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision. Any waiver must be in writing and signed by AutoAttack.
Contact
For questions about these Terms, contact us at security@autoattack.ai.