Public Offer Agreement
Effective date: May 30, 2026 · Last updated: May 30, 2026
1. General Provisions
1.1. This Public Offer Agreement, hereinafter referred to as the “Agreement”, is an official public offer of PentestForge, hereinafter referred to as the “Provider”, addressed to any individual, sole proprietor, legal entity, or other person, hereinafter referred to as the “Customer”, to conclude an agreement for the provision of paid digital services under the terms set forth below.
1.2. This Agreement is a public offer within the meaning of applicable Ukrainian civil law, including Article 633 and Article 641 of the Civil Code of Ukraine, where applicable.
1.3. By creating an account, selecting a paid plan, making a payment, starting a scan, using Deep Pentest AI, generating a report, or otherwise using paid PentestForge services, the Customer fully and unconditionally accepts this Agreement.
1.4. Acceptance of this Agreement has the same legal effect as signing a written agreement between the Provider and the Customer.
1.5. If the Customer does not agree with this Agreement, the Customer must not purchase or use the paid Services.
1.6. The Provider may update this Agreement from time to time. The current version is published on the PentestForge website and applies from the date specified as the “Last updated” date, unless otherwise stated.
2. Definitions
For the purposes of this Agreement, the following terms have the meanings set out below:
Platform means the PentestForge online platform available through the Provider's website, application, APIs, dashboards, and related systems.
Services means paid and free digital services provided through the Platform, including vulnerability scanning, penetration-testing assistance, AI-powered triage, security assessment, report generation, asset management, and related functionality.
Customer means any person or entity that creates an account, purchases, accesses, or uses the Services.
Personal Account means the Customer's registered account on the Platform.
Subscription means a paid plan that provides access to the Services for a specified billing period and within defined usage limits.
Billing Period means the period for which the Customer pays for a Subscription, including monthly or annual billing periods.
Scan Credits means usage units that allow the Customer to initiate scans or use specific Platform functionality according to the selected plan.
Asset means a domain, subdomain, IP address, CIDR range, application, API endpoint, or other target added by the Customer to the Platform for assessment.
Authorized Asset means an Asset that the Customer owns, controls, or is legally authorized to test.
Scan means an automated or semi-automated security check, vulnerability scan, validation, or related assessment initiated through the Platform.
Report means a scan result, vulnerability report, executive summary, technical finding, export, or other output generated by the Platform.
Deep Pentest AI means an AI-powered feature or agent used for vulnerability validation, analysis, prioritization, exploitation assistance within permitted boundaries, and report generation.
AI Resources means Deep Pentest AI tokens, AI minutes, AI-generated outputs, or other usage-based AI capacity.
Payment Provider means a third-party payment processor used to accept payments, including Stripe and Monobank acquiring / plata by mono.
Refund Policy means the Provider's refund policy published separately on the Platform.
Terms of Service means the Provider's general terms governing access to and use of the Platform, where published separately.
3. Subject of the Agreement
3.1. The Provider undertakes to provide the Customer with access to the Services according to the selected plan, Subscription, or one-time purchase.
3.2. The Customer undertakes to pay for the Services and use them only in accordance with this Agreement, the Terms of Service, the Refund Policy, applicable law, and any technical limits displayed on the Platform.
3.3. The Services are digital services provided remotely through the Platform. No physical goods are supplied under this Agreement.
3.4. The exact scope of Services, plan limits, available features, Scan Credits, AI Resources, and pricing are displayed on the Platform or checkout page before payment.
3.5. The Provider may improve, update, modify, suspend, or replace individual Platform features, provided that such changes do not materially deprive the Customer of the core paid functionality during the active Billing Period.
4. Customer Authorization and Security Responsibility
4.1. The Customer may use the Services only for Authorized Assets.
4.2. By adding an Asset, starting a Scan, using Deep Pentest AI, or generating a Report, the Customer represents and warrants that the Customer has all required rights, permissions, and legal authority to perform such assessment.
4.3. The Customer is solely responsible for obtaining proper authorization before scanning any domain, IP address, network, system, application, API, or infrastructure.
4.4. The Customer must not use the Services for unauthorized scanning, attacks, exploitation, disruption, data theft, credential harvesting, malware activity, spam, phishing, or any illegal or harmful activity.
4.5. The Provider may suspend or terminate access to the Services if the Provider reasonably believes that the Customer uses the Services unlawfully, abusively, or against unauthorized targets.
4.6. The Provider may request proof of authorization for an Asset. Failure to provide sufficient proof may result in suspension or termination of access to related Services.
5. Service Provision
5.1. Access to paid Services is provided after successful payment confirmation by the relevant Payment Provider.
5.2. Subscription access is provided for the selected Billing Period: monthly, annual, or another period displayed at checkout.
5.3. Monthly Subscriptions are generally active for 30 calendar days from the payment date unless another period is shown at checkout.
5.4. Annual Subscriptions are generally active for 365 calendar days from the payment date unless another period is shown at checkout.
5.5. The Customer understands that Scan results, AI-generated outputs, Reports, and other Platform outputs may require technical interpretation and must not be treated as a guarantee that an Asset is secure, fully tested, or free from vulnerabilities.
5.6. The Provider uses commercially reasonable efforts to maintain Platform availability but does not guarantee uninterrupted or error-free operation.
5.7. Scheduled maintenance, emergency maintenance, third-party outages, hosting provider issues, Payment Provider issues, internet disruptions, force majeure events, and Customer-side issues may affect availability.
5.8. Unless otherwise stated, Scan results and Reports may be retained for up to 90 days after Subscription expiry or account inactivity, after which they may be deleted or anonymized.
6. Pricing and Payment
6.1. Prices for paid Services are displayed on the Platform, pricing page, checkout page, invoice, or payment page.
6.2. The Provider may offer monthly Subscriptions, annual Subscriptions, one-time purchases, Scan Credit packages, AI Resource packages, or other paid plans.
6.3. The final payable amount, currency, payment method, and Payment Provider are displayed before payment confirmation.
6.4. Payments may be processed through the following Payment Providers, depending on availability at checkout:
- Stripe: Visa, Mastercard, Apple Pay, Google Pay, and other payment methods supported by Stripe, usually in USD.
- Monobank acquiring / plata by mono: Visa, Mastercard, and other payment methods available through plata by mono, usually in UAH.
6.5. The active Payment Provider is determined by the Provider and displayed at checkout.
6.6. The Customer is responsible for reviewing the price, currency, plan limits, billing period, and payment terms before confirming payment.
6.7. Unless otherwise stated, all applicable acquiring fees, Payment Provider fees, or commissions are included in the displayed price.
6.8. The Provider does not store full card details. Card and payment data are processed by the relevant Payment Provider.
7. Payment Processing Through Stripe
7.1. When Stripe is the active Payment Provider, payments are processed by Stripe or its affiliates according to Stripe's own terms, rules, and technical procedures.
7.2. Payments through Stripe may be processed in USD or another currency displayed at checkout.
7.3. The Provider does not control Stripe's internal payment authorization, anti-fraud checks, payment acceptance, payment decline decisions, refund settlement timing, or card issuer processing.
7.4. The Customer may receive a payment confirmation, receipt, or invoice through Stripe, the Platform, or email.
8. Payment Processing Through Monobank Acquiring / plata by mono
8.1. When Monobank acquiring / plata by mono is active, payments are processed by АТ «Універсал Банк» through the Monobank acquiring / plata by mono payment service.
8.2. Payments through Monobank acquiring / plata by mono are generally processed in Ukrainian Hryvnia (UAH).
8.3. If prices are displayed in USD or another currency on the Platform, the final amount payable in UAH is displayed on the payment page before confirmation.
8.4. The Provider does not store full card details. Card and payment data are processed by the Payment Provider.
8.5. A fiscal receipt, payment confirmation, or other payment document may be sent to the Customer's email where required by applicable law, Payment Provider rules, or technical availability.
8.6. The Provider does not control Monobank's internal payment authorization, anti-fraud checks, payment acceptance, payment decline decisions, refund settlement timing, or card issuer processing.
9. Subscriptions, Renewal, and Cancellation
9.1. Subscription terms, billing periods, included limits, renewal rules, and prices are displayed on the Platform or checkout page.
9.2. If automatic renewal is enabled for a Subscription, the Customer authorizes recurring charges according to the selected plan until the Subscription is cancelled.
9.3. The Customer may cancel a Subscription at any time through the Personal Account or by contacting support.
9.4. Cancellation stops future billing but does not automatically refund the current Billing Period unless the Customer qualifies for a refund under the Refund Policy or applicable law.
9.5. After cancellation, the Subscription remains active until the end of the paid Billing Period unless access is suspended or terminated due to violation of this Agreement or applicable law.
9.6. The Provider may change Subscription pricing or plan limits for future Billing Periods by providing notice where required by applicable law or Payment Provider rules.
10. Refunds and Right of Withdrawal
10.1. Refunds are governed by the Refund Policy published on the Platform.
10.2. The Customer may request a refund by contacting:
10.3. The Customer may have a right of withdrawal within 14 calendar days where applicable under consumer protection law and subject to the Refund Policy.
10.4. The right of withdrawal or refund eligibility may be reduced or lost if the Customer requested immediate performance of the digital service and the Service has already been provided, consumed, or partially consumed.
10.5. By starting a Scan, generating a Report, using Deep Pentest AI, consuming Scan Credits, consuming AI Resources, or otherwise using paid digital functionality, the Customer expressly requests immediate performance of the Services and acknowledges that refund eligibility may be reduced or lost for the consumed portion.
10.6. Refunds may be full or partial depending on the payment method, Payment Provider capabilities, consumed Services, used Scan Credits, AI Resources consumed, generated Reports, and applicable law.
10.7. For Stripe payments, approved refunds are returned to the original payment method according to Stripe and card issuer processing rules.
10.8. For Monobank acquiring / plata by mono payments, approved refunds may be initiated through the Monobank merchant cabinet or API, where supported for the relevant transaction.
10.9. The Provider does not control bank-side or card-network processing times after a refund has been initiated.
10.10. Opening a chargeback, payment dispute, or bank investigation may result in temporary suspension of the related account or Services while the dispute is being reviewed.
11. Customer Rights
The Customer has the right to:
11.1. Use the Services within the limits of the selected plan, Subscription, or purchase.
11.2. Receive access to the Personal Account after successful registration and payment, where applicable.
11.3. Receive technical support by contacting:
11.4. Cancel the Subscription according to this Agreement.
11.5. Request a refund according to the Refund Policy.
11.6. Exercise the right of withdrawal where applicable under consumer protection law.
11.7. Export or delete personal data according to the Privacy Policy and applicable data protection law.
11.8. Receive information about material changes to this Agreement where required by law or where such changes materially affect Customer rights.
12. Customer Obligations
The Customer undertakes to:
12.1. Provide accurate account, billing, and contact information.
12.2. Keep account credentials, API keys, tokens, and access data confidential.
12.3. Use the Services only for Authorized Assets.
12.4. Obtain and maintain all required permissions for any Scan or security assessment.
12.5. Not use the Services for illegal, harmful, abusive, unauthorized, or malicious purposes.
12.6. Not bypass Platform limits, abuse Scan Credits, abuse AI Resources, or interfere with Platform operation.
12.7. Not resell, sublicense, or provide access to the Services to third parties unless expressly permitted by the Provider in writing.
12.8. Pay all applicable fees for the selected Services.
12.9. Immediately notify the Provider of any unauthorized access to the Personal Account or API keys.
12.10. Comply with all applicable laws, including cybersecurity, privacy, data protection, export control, sanctions, and computer misuse laws.
13. Provider Rights
The Provider has the right to:
13.1. Receive payment for the Services.
13.2. Suspend, restrict, or terminate access to the Services if the Customer violates this Agreement, the Terms of Service, the Refund Policy, or applicable law.
13.3. Refuse or cancel scans of Assets that appear unauthorized, abusive, dangerous, or unlawful.
13.4. Request proof of authorization for Assets.
13.5. Apply technical limits, rate limits, safety checks, anti-abuse controls, and fraud prevention measures.
13.6. Modify, improve, update, or discontinue specific Platform features, provided that such changes do not materially deprive the Customer of the core paid functionality during the active Billing Period.
13.7. Involve third-party providers for hosting, payment processing, analytics, security, support, email delivery, and infrastructure operation.
13.8. Provide payment records, usage logs, account activity, and service consumption data to Payment Providers, banks, or competent authorities where necessary for dispute resolution, fraud prevention, legal compliance, or enforcement of this Agreement.
14. Provider Obligations
The Provider undertakes to:
14.1. Provide access to the Services according to the selected plan and technical availability.
14.2. Use commercially reasonable efforts to maintain Platform operation and security.
14.3. Protect Customer data according to the Privacy Policy.
14.4. Review refund requests within 5 business days and, if approved, initiate the refund according to the Refund Policy.
14.5. Respond to support inquiries within a reasonable time, usually within 24 business hours.
14.6. Notify Customers of material changes to this Agreement where required by applicable law or where such changes materially affect Customer rights.
15. Prohibited Use
The Customer must not use the Services to:
15.1. Scan, test, attack, exploit, or assess any Asset without proper authorization.
15.2. Damage, disrupt, overload, degrade, or compromise any system, network, service, or data.
15.3. Conduct denial-of-service attacks, brute-force attacks, credential stuffing, phishing, spam, malware activity, botnet activity, or unauthorized exploitation.
15.4. Attempt to gain unauthorized access to third-party systems, accounts, data, networks, or infrastructure.
15.5. Exfiltrate, steal, modify, destroy, or misuse data.
15.6. Circumvent Platform limits, security controls, rate limits, billing mechanisms, or access restrictions.
15.7. Share, resell, sublicense, or transfer account access, API keys, or generated outputs in violation of this Agreement.
15.8. Use the Services in violation of sanctions, export control laws, cybersecurity laws, privacy laws, or other applicable laws.
15.9. Misrepresent authorization, ownership, identity, billing information, or payment details.
15.10. Use the Services in any way that may expose the Provider, Payment Providers, hosting providers, infrastructure providers, or other Customers to legal, technical, security, or reputational risk.
16. Reports, AI Outputs, and No Security Guarantee
16.1. Reports, Scan results, Deep Pentest AI outputs, severity ratings, recommendations, and other outputs are provided for informational and security assessment purposes.
16.2. The Provider does not guarantee that any Report, Scan, or AI output is complete, error-free, exhaustive, or sufficient for compliance certification.
16.3. The absence of detected vulnerabilities does not mean that an Asset is secure or free from vulnerabilities.
16.4. AI-generated outputs may contain inaccuracies, incomplete analysis, false positives, or false negatives.
16.5. The Customer is responsible for independently validating findings before taking remediation, disclosure, legal, operational, or business action.
16.6. The Services are not a substitute for a full manual penetration test, legal review, compliance audit, or professional security assessment unless expressly agreed in a separate written agreement.
17. Intellectual Property
17.1. All rights to the Platform, software, design, algorithms, interfaces, databases, documentation, trademarks, trade names, logos, and other intellectual property of the Provider remain the exclusive property of the Provider or its licensors.
17.2. The Customer receives a limited, non-exclusive, non-transferable, revocable right to use the Services during the active Subscription or paid access period.
17.3. The Customer may use Reports generated for the Customer's Authorized Assets for internal security, compliance, remediation, and business purposes.
17.4. The Customer must not copy, reverse engineer, modify, distribute, sell, lease, sublicense, or create derivative works from the Platform unless expressly permitted by law or written agreement.
18. Personal Data and Privacy
18.1. The Provider processes personal data according to the Privacy Policy published on the Platform.
18.2. The Customer is responsible for ensuring that any data submitted to the Platform is provided lawfully and with all required permissions.
18.3. The Customer must not upload unnecessary personal data, sensitive data, secrets, passwords, private keys, or confidential third-party data unless strictly required and legally permitted.
18.4. The Provider may process technical logs, account information, payment metadata, usage data, Scan metadata, and support communications for service provision, security, compliance, billing, fraud prevention, and dispute resolution.
19. Confidentiality
19.1. The Provider and the Customer undertake to keep confidential information received from the other party confidential, except where disclosure is required by law, court order, competent authority, Payment Provider rules, or necessary for the performance of this Agreement.
19.2. Confidential information includes non-public technical information, Reports, vulnerability findings, account data, API keys, business information, and other information marked or reasonably understood as confidential.
19.3. Confidentiality obligations do not apply to information that is publicly available, independently developed, lawfully received from a third party, or required to be disclosed by law.
20. Limitation of Liability
20.1. The Services are provided on an “as is” and “as available” basis to the maximum extent permitted by applicable law.
20.2. The Provider is not liable for:
- Customer's unlawful or unauthorized use of the Services;
- Customer's failure to obtain authorization for Assets;
- actions or omissions of the Customer or third parties;
- incorrect, incomplete, or outdated information provided by the Customer;
- false positives, false negatives, or incomplete Scan results;
- Customer's remediation decisions based on Reports or AI outputs;
- loss of profits, revenue, business opportunity, goodwill, data, or indirect damages;
- third-party service failures, including hosting providers, Payment Providers, banks, card networks, internet providers, DNS providers, email providers, or cloud infrastructure providers;
- force majeure events.
20.3. To the maximum extent permitted by applicable law, the Provider's total liability under this Agreement shall not exceed the amount actually paid by the Customer for the Services during the 12 months preceding the event giving rise to the claim.
20.4. Nothing in this Agreement excludes liability that cannot be excluded under applicable law.
21. Force Majeure
21.1. The Provider is not liable for failure or delay in performance caused by events beyond reasonable control, including war, hostilities, cyberattacks, natural disasters, fires, floods, epidemics, government actions, power outages, internet disruptions, cloud provider outages, Payment Provider outages, banking system failures, strikes, or other force majeure events.
21.2. The affected party must use reasonable efforts to minimize the impact of force majeure where possible.
22. Termination
22.1. The Customer may terminate this Agreement by cancelling the Subscription and ceasing to use the Services.
22.2. The Provider may suspend or terminate the Customer's access immediately if the Customer violates this Agreement, uses the Services unlawfully, abuses the Platform, fails to pay, initiates fraudulent payments, or creates legal, technical, or security risk.
22.3. Upon termination:
- access to paid Services may cease immediately or at the end of the paid Billing Period, depending on the reason for termination;
- unused credits may expire unless otherwise required by the Refund Policy or applicable law;
- data may be retained for up to 90 days and then deleted or anonymized, unless longer retention is required for legal, accounting, tax, security, fraud prevention, or dispute resolution purposes.
23. Chargebacks, Disputes, and Fraud Prevention
23.1. If the Customer believes that a payment was made in error, the Customer should first contact:
23.2. If the Customer initiates a chargeback, payment dispute, or bank investigation, the Provider may suspend access to the related Services while the matter is being reviewed.
23.3. The Provider may provide payment records, invoices, receipts, account activity, usage logs, Scan activity, generated Report records, IP logs, authorization records, and communication history to Payment Providers, banks, card networks, or competent authorities where necessary for dispute resolution, fraud prevention, or legal compliance.
23.4. Fraudulent payments, unauthorized use of payment methods, identity misuse, or chargeback abuse may result in account termination without refund for consumed Services.
24. Governing Law and Dispute Resolution
24.1. This Agreement is governed by the laws of Ukraine, unless otherwise required by mandatory consumer protection laws applicable to the Customer.
24.2. The parties shall attempt to resolve disputes through good-faith negotiations.
24.3. Written claims must be sent to:
or
24.4. The Provider will review written claims within 10 business days unless a longer period is reasonably required due to the complexity of the matter.
24.5. If the Customer qualifies as a consumer under applicable law, the Customer may have the right to contact the competent consumer protection authority, including the State Service of Ukraine on Food Safety and Consumer Protection, where applicable.
24.6. If the dispute cannot be resolved through negotiation, it shall be resolved by the competent court according to applicable procedural law, unless mandatory law provides otherwise.
25. Changes to the Agreement
25.1. The Provider may update this Agreement by publishing a new version on the Platform.
25.2. Material changes that significantly affect Customer rights or obligations may be notified by email, in-account notice, or website notice where required by applicable law.
25.3. Continued use of the Services after the updated Agreement becomes effective means that the Customer accepts the updated Agreement.
25.4. If the Customer does not agree with the updated Agreement, the Customer must stop using the Services and may cancel the Subscription.
26. Contact Information
Provider: PentestForge
Website: https://pentest-forge.com
Support: [email protected]
Legal: [email protected]
