Terms of Service

Last updated: December 19, 2025

⚠️ Important: Authorization Required

Penetration testing without proper authorization is illegal. By using PentestMate, you expressly confirm and warrant that you have obtained all necessary permissions and authorizations to perform security testing on any domain, system, or infrastructure you submit to our service. Unauthorized security testing may violate federal and state laws, including the Computer Fraud and Abuse Act (CFAA), and may result in criminal prosecution and civil liability.

1. Introduction and Acceptance

Welcome to PentestMate ("PentestMate", "we", "us", or "our"). These Terms of Service ("Terms") govern your access to and use of our website at pentestmate.com and our penetration testing services, including any associated software, APIs, and tools (collectively, the "Service").

By accessing or using the Service, you agree to be bound by these Terms. If you do not agree to these Terms, you may not access or use the Service. If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms.

2. Description of Service

PentestMate provides automated penetration testing services using artificial intelligence and security scanning tools. Our Service identifies potential security vulnerabilities in web applications, APIs, and cloud infrastructure. The Service is designed to help organizations improve their security posture through continuous security monitoring and testing.

3. Authorization and Domain Verification

3.1 Domain Ownership Verification

Before initiating any penetration testing, you must complete our domain ownership verification process. This process requires you to demonstrate control over the domain(s) you wish to test by placing a verification token in your DNS records or at a specified URL path.

3.2 Authorization Warranty

By completing domain verification and using our Service, you represent and warrant that:

  • You own the domain(s) and associated infrastructure, or have obtained explicit written authorization from the owner to perform penetration testing;
  • You have the legal authority and all necessary permissions to authorize security testing on the specified systems;
  • You have reviewed and complied with any applicable laws, regulations, and contractual obligations regarding security testing;
  • If the infrastructure is hosted by a third party (cloud provider, hosting company, etc.), you have obtained any required permissions from that third party;
  • You will not use our Service to test any systems or domains for which you do not have explicit authorization.

3.3 Scope of Testing

Our testing is limited to the specific domains and systems you have verified and authorized. You are responsible for ensuring that any subdomains, APIs, or related systems included in testing are also within scope of your authorization.

4. User Responsibilities

As a user of our Service, you agree to:

  • Provide accurate and complete information during registration and verification;
  • Maintain the security of your account credentials;
  • Notify us immediately of any unauthorized use of your account;
  • Use the Service only for lawful purposes and in accordance with these Terms;
  • Not attempt to circumvent our domain verification process;
  • Not use the Service to attack, disrupt, or damage systems you do not own or have permission to test;
  • Take appropriate precautions before testing production systems, including having backups and a rollback plan;
  • Review and address vulnerabilities discovered through our Service in a timely manner.

5. Prohibited Uses

You may not use our Service to:

  • Perform unauthorized security testing on any system, network, or domain;
  • Test systems belonging to third parties without their explicit written consent;
  • Launch denial-of-service attacks or intentionally disrupt services;
  • Access, steal, or exfiltrate data from systems under test;
  • Violate any applicable laws, regulations, or third-party rights;
  • Circumvent or attempt to circumvent any security measures of our Service;
  • Reverse engineer, decompile, or disassemble our software;
  • Resell, redistribute, or sublicense access to our Service without authorization;
  • Use our Service for any malicious, fraudulent, or illegal purpose.

6. Subscription and Payment

6.1 Pricing

Our Service is offered on a subscription basis. Current pricing and plan details are available on our website. We reserve the right to modify pricing with 30 days' notice to existing subscribers.

6.2 Billing

Subscriptions are billed in advance on a recurring basis (monthly or annually, depending on your selected plan). You authorize us to charge your payment method for all applicable fees.

6.3 Cancellation

You may cancel your subscription at any time through your account settings or by contacting us. Cancellation will take effect at the end of the current billing period, and you will retain access until that time.

6.4 Refunds

Subscription fees are generally non-refundable. However, we may consider refund requests on a case-by-case basis. Please contact our support team at founders@updates.pentestmate.com for assistance.

7. Intellectual Property

The Service, including all software, content, designs, and documentation, is owned by PentestMateand is protected by intellectual property laws. You are granted a limited, non-exclusive, non-transferable license to use the Service in accordance with these Terms.

Reports and vulnerability data generated through the Service for your verified domains are your property. We retain no ownership rights to your security reports.

8. Disclaimer of Warranties

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. WE DISCLAIM ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

We do not warrant that:

  • The Service will detect all security vulnerabilities;
  • The Service will be uninterrupted, error-free, or completely secure;
  • The results of security testing will be accurate or complete;
  • The Service will meet your specific requirements or expectations.

Security testing is inherently limited, and no automated tool can guarantee complete security. Our Service should be used as part of a comprehensive security program.

9. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, PENTESTMATE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, USE, OR GOODWILL, ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICE.

Our total liability for any claims arising from the Service shall not exceed the amounts you paid to us in the twelve (12) months preceding the claim.

10. Indemnification

You agree to indemnify, defend, and hold harmless PentestMate, its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:

  • Your use of the Service;
  • Your violation of these Terms;
  • Your violation of any applicable laws or regulations;
  • Any unauthorized security testing conducted through your account;
  • Your failure to obtain proper authorization for penetration testing;
  • Any claims by third parties related to your use of the Service.

11. Termination

We may suspend or terminate your access to the Service at any time, with or without cause, including for violation of these Terms. Upon termination, your right to use the Service will immediately cease. Provisions that by their nature should survive termination shall survive, including ownership, warranty disclaimers, and limitations of liability.

12. Changes to Terms

We reserve the right to modify these Terms at any time. We will notify you of material changes by posting the updated Terms on our website and updating the "Last updated" date. Your continued use of the Service after changes become effective constitutes acceptance of the revised Terms.

13. Governing Law and Dispute Resolution

These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law provisions. Any disputes arising from these Terms or your use of the Service shall be resolved through binding arbitration in accordance with the rules of the American Arbitration Association.

14. Severability

If any provision of these Terms is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.

15. Contact Information

If you have any questions about these Terms of Service, please contact us at:

PentestMate
Email: founders@updates.pentestmate.com
Website: pentestmate.com