Terms of Service

Effective date: May 30, 2026 · Last updated: May 30, 2026

1. Introduction

These Terms of Service, hereinafter referred to as the “Terms”, govern access to and use of the PentestForge website, platform, dashboards, APIs, vulnerability scanning tools, AI-powered security features, reports, subscriptions, and related services.

These Terms apply to all users, including visitors, registered users, customers, organizations, team members, administrators, and any person or entity that accesses or uses PentestForge.

By accessing, registering, purchasing, starting a scan, using Deep Pentest AI, generating a report, or otherwise using PentestForge, you agree to these Terms.

If you do not agree with these Terms, you must not access or use PentestForge.

2. Related Documents

These Terms should be read together with the following documents:

If there is a conflict between these Terms and the Public Offer Agreement regarding payment, subscription, or refund mechanics, the Public Offer Agreement and Refund Policy will apply to those specific issues.

If there is a conflict between these Terms and the Privacy Policy regarding personal data processing, the Privacy Policy will apply to privacy-specific issues.

3. Who We Are

Provider: PentestForge

Website: https://pentest-forge.com

Support: [email protected]

Legal: [email protected]

Privacy: [email protected]

PentestForge provides digital security testing tools, vulnerability scanning, AI-assisted analysis, report generation, and related cybersecurity services.

4. Definitions

For the purposes of these Terms:

Platform means the PentestForge website, application, APIs, dashboards, infrastructure, software, databases, and related systems.

Services means all services provided by PentestForge, including vulnerability scanning, AI-assisted security assessment, AI-powered triage, asset management, report generation, integrations, dashboards, APIs, and related features.

User, Customer, you, or your means any person or entity accessing or using the Services.

Account means a registered PentestForge user account.

Organization Account means an account used by a company, team, organization, or other legal entity.

Subscription means a paid plan that provides access to the Services for a defined billing period and within defined usage limits.

Scan Credits means units used to initiate scans or access certain scanning features.

AI Resources means Deep Pentest AI tokens, AI minutes, AI-generated outputs, AI validation actions, or other usage-based AI capacity.

Asset means a domain, subdomain, IP address, CIDR range, URL, API endpoint, application, system, or infrastructure target submitted to the Platform.

Authorized Asset means an Asset that you own, control, operate, administer, or have explicit legal permission to test.

Scan means an automated, semi-automated, or AI-assisted security check, vulnerability scan, validation, or assessment initiated through the Platform.

Report means any scan result, finding, vulnerability report, technical output, executive summary, export, screenshot, evidence artifact, remediation recommendation, or other output generated by the Platform.

Deep Pentest AI means AI-powered functionality used for vulnerability analysis, validation, prioritization, exploitability reasoning within permitted boundaries, and report generation.

Payment Provider means a third-party payment processor, including Stripe and Monobank acquiring / plata by mono.

5. Eligibility

5.1. You must have legal capacity to enter into these Terms.

5.2. If you use PentestForge on behalf of a company, organization, employer, customer, or other entity, you represent and warrant that you have authority to bind that entity to these Terms.

5.3. You must not use PentestForge if you are prohibited from doing so under applicable law, sanctions rules, export control rules, cybersecurity laws, or payment provider requirements.

5.4. PentestForge is not intended for children. You must not use the Services if you are under the legal age required to enter into a binding agreement in your jurisdiction.

6. Account Registration

6.1. To access certain Services, you may need to create an Account.

6.2. You agree to provide accurate, current, and complete information during registration, checkout, support communication, and account management.

6.3. You are responsible for keeping your Account information up to date.

6.4. You are responsible for maintaining the confidentiality of your login credentials, API keys, access tokens, session data, and other authentication information.

6.5. You are responsible for all activity that occurs under your Account, whether authorized by you or not, unless the activity results directly from PentestForge's proven failure to apply reasonable security measures.

6.6. You must immediately notify us at [email protected] if you suspect unauthorized access to your Account, API keys, or organization workspace.

6.7. We may suspend or restrict an Account if we reasonably believe that the Account is compromised, used unlawfully, used abusively, or creates security, legal, payment, or operational risk.

7. Organization Accounts and Team Use

7.1. If you create or use an Organization Account, the organization may control access to the workspace, assets, reports, billing, scans, API keys, and team permissions.

7.2. Organization administrators may be able to:

7.3. If you join an Organization Account using an email address controlled by your employer or organization, you understand that the organization may manage or access data associated with that workspace.

7.4. The organization is responsible for ensuring that its users comply with these Terms.

8. Authorized Use Only

8.1. PentestForge may be used only for lawful security testing of Authorized Assets.

8.2. You may start scans only against Assets that you own, control, administer, or have explicit written or otherwise legally sufficient permission to test.

8.3. By adding an Asset, starting a Scan, using Deep Pentest AI, or generating a Report, you represent and warrant that:

8.4. You must keep evidence of authorization where appropriate.

8.5. We may request proof of authorization for any Asset at any time.

8.6. If you fail to provide sufficient proof of authorization, we may suspend or terminate scans, restrict access, remove assets, disable reports, or suspend your Account.

8.7. We reserve the right to refuse or stop scans that appear unauthorized, abusive, dangerous, unlawful, or inconsistent with these Terms.

9. Prohibited Use

You must not use PentestForge to:

9.1. Scan, probe, test, attack, exploit, or assess any Asset without authorization.

9.2. Conduct denial-of-service attacks, distributed denial-of-service attacks, stress testing, traffic flooding, or overload testing without explicit written approval from the target owner and from PentestForge where required.

9.3. Gain or attempt to gain unauthorized access to systems, networks, accounts, applications, databases, APIs, devices, or data.

9.4. Exfiltrate, steal, modify, delete, corrupt, encrypt, ransom, or misuse data.

9.5. Deploy, distribute, test, or facilitate malware, ransomware, spyware, botnets, worms, trojans, credential stealers, or other malicious code.

9.6. Conduct phishing, credential harvesting, social engineering, spam, fraud, identity theft, or payment abuse.

9.7. Perform brute-force attacks, credential stuffing, password spraying, account enumeration, or authentication bypass attempts against systems you are not authorized to test.

9.8. Circumvent Platform restrictions, rate limits, billing limits, scan limits, anti-abuse controls, safety controls, API limits, or access restrictions.

9.9. Use the Services to violate applicable law, sanctions, export controls, cybersecurity regulations, privacy laws, payment provider rules, or third-party terms.

9.10. Use generated Reports, AI outputs, findings, payloads, or technical artifacts for unlawful exploitation or unauthorized activity.

9.11. Use the Services to target critical infrastructure, government systems, healthcare systems, financial systems, emergency services, telecommunications networks, or other sensitive infrastructure without proper authorization.

9.12. Misrepresent your identity, affiliation, authorization, asset ownership, billing information, or payment method.

9.13. Resell, sublicense, lease, rent, or provide commercial access to the Services without written permission from PentestForge.

9.14. Share Account access, passwords, API keys, tokens, or credentials with unauthorized parties.

9.15. Interfere with, disrupt, reverse engineer, copy, scrape, overload, or damage the Platform or its infrastructure.

9.16. Use automated tools, bots, scripts, crawlers, or scrapers against the Platform except through approved APIs and within allowed rate limits.

9.17. Upload or process unlawful, stolen, confidential, sensitive, or third-party data without proper authorization.

9.18. Use the Services in a way that creates legal, technical, reputational, operational, security, payment, or compliance risk for PentestForge, its providers, its users, or third parties.

10. Scan Safety and Technical Limits

10.1. PentestForge may apply technical limits to scans, including rate limits, concurrency limits, scope limits, timeout limits, request limits, payload limits, AI usage limits, and target restrictions.

10.2. These limits are designed to protect customers, third parties, infrastructure, payment providers, and the Platform.

10.3. You must not bypass or attempt to bypass these limits.

10.4. Scan results may be incomplete if:

10.5. You are responsible for ensuring that scans do not violate your internal policies, customer agreements, bug bounty rules, hosting provider rules, or third-party terms.

11. Deep Pentest AI and AI Features

11.1. Deep Pentest AI is provided to assist with vulnerability validation, prioritization, technical analysis, remediation recommendations, and report generation.

11.2. AI outputs may be inaccurate, incomplete, outdated, or contain false positives or false negatives.

11.3. You must independently review and validate AI outputs before relying on them for remediation, disclosure, legal decisions, business decisions, compliance decisions, or production changes.

11.4. You must not use Deep Pentest AI to generate, request, automate, or facilitate unlawful exploitation, malware, credential theft, phishing, unauthorized access, destructive actions, persistence, evasion, or harmful activity.

11.5. You must not submit unnecessary secrets, passwords, private keys, tokens, personal data, regulated data, or confidential third-party information to AI features unless legally permitted and strictly necessary.

11.6. Deep Pentest AI may consume AI Resources, tokens, AI minutes, or other usage units according to your plan.

11.7. Consumed AI Resources are generally non-refundable except as required by the Refund Policy or applicable law.

11.8. We may monitor AI usage for abuse prevention, security, fraud prevention, debugging, quality control, and enforcement of these Terms.

12. Reports and Findings

12.1. Reports are provided for informational cybersecurity assessment purposes.

12.2. Reports may include vulnerability descriptions, severity ratings, technical evidence, remediation suggestions, AI-generated analysis, screenshots, request/response samples, affected endpoints, and risk explanations.

12.3. Reports are not a guarantee that an Asset is secure, compliant, fully tested, or free from vulnerabilities.

12.4. Reports may contain false positives, false negatives, incomplete information, or findings requiring manual verification.

12.5. You are responsible for validating findings before taking action.

12.6. You are responsible for safely applying remediation recommendations and ensuring that changes do not damage systems or data.

12.7. PentestForge is not responsible for damage caused by your use, misuse, misunderstanding, or implementation of Report recommendations.

12.8. Unless otherwise stated, Reports may be retained for up to 90 days after subscription expiry, cancellation, or account inactivity, after which they may be deleted or anonymized.

13. No Emergency or Guaranteed Security Service

13.1. PentestForge is not an emergency incident response service unless expressly agreed in a separate written agreement.

13.2. PentestForge does not guarantee that it will detect all vulnerabilities, misconfigurations, exposures, threats, or security weaknesses.

13.3. PentestForge does not guarantee compliance with any specific security framework, certification, legal standard, industry standard, insurance requirement, or audit requirement.

13.4. The Services are not a substitute for a full manual penetration test, legal review, compliance audit, source code audit, architecture review, or professional consulting engagement unless separately agreed in writing.

14. Payments

14.1. Paid Services may be available through subscriptions, one-time purchases, scan credit packages, AI resource packages, invoices, or other billing models.

14.2. Prices, currencies, plan limits, billing periods, and payment methods are displayed on the Platform or checkout page before payment confirmation.

14.3. Payments may be processed through third-party Payment Providers, including Stripe and Monobank acquiring / plata by mono.

14.4. For Stripe payments, payment processing is handled by Stripe according to Stripe's own terms, rules, and technical procedures.

14.5. For Monobank acquiring / plata by mono payments, payment processing is handled through Monobank acquiring / plata by mono and related payment infrastructure.

14.6. We do not store full payment card numbers, CVV codes, or complete card authentication data.

14.7. Payment Provider availability may depend on your location, currency, risk checks, payment method, and Platform configuration.

14.8. We may refuse, cancel, or suspend paid access if payment is declined, reversed, disputed, suspected to be fraudulent, or violates Payment Provider rules.

15. Subscriptions and Renewal

15.1. Subscription terms are displayed at checkout or inside the Platform.

15.2. Subscriptions may be monthly, annual, or another billing period displayed before payment.

15.3. If automatic renewal is enabled, you authorize recurring charges until you cancel the Subscription.

15.4. You are responsible for cancelling a Subscription before renewal if you do not want future charges.

15.5. Cancellation stops future billing but does not automatically refund the current billing period unless required by the Refund Policy or applicable law.

15.6. After cancellation, your Subscription generally remains active until the end of the paid billing period, unless access is suspended or terminated due to violation of these Terms.

15.7. We may change pricing or plan limits for future billing periods by providing notice where required by law or Payment Provider rules.

16. Refunds

16.1. Refunds are governed by the Refund Policy.

16.2. Refund eligibility may depend on payment date, plan type, scan usage, AI usage, generated reports, consumed credits, account status, abuse history, chargeback status, and applicable law.

16.3. By starting a Scan, generating a Report, using Deep Pentest AI, consuming Scan Credits, consuming AI Resources, or otherwise using paid digital functionality, you request immediate performance of the digital Services and acknowledge that refund eligibility may be reduced or lost for the consumed portion.

16.4. Approved refunds are returned to the original payment method where technically possible.

16.5. Refund timing depends on the Payment Provider, bank, card network, and payment method.

16.6. We do not control bank-side or card-network processing times after a refund has been initiated.

17. Chargebacks and Payment Disputes

17.1. If you believe a payment was made in error, contact us first at:

[email protected]

17.2. If you initiate a chargeback, payment dispute, or bank investigation, we may temporarily suspend access to the related Account or Services while the matter is reviewed.

17.3. We may provide payment records, account activity, usage logs, scan activity, generated report records, IP logs, subscription status, refund records, and support communications to Payment Providers, banks, card networks, dispute processors, legal advisors, or competent authorities where necessary.

17.4. Fraudulent payments, unauthorized payment methods, chargeback abuse, or false claims may result in Account termination and denial of refunds for consumed Services.

18. API Use

18.1. If API access is available, you must use the API only according to the documentation, plan limits, rate limits, and these Terms.

18.2. You are responsible for securing API keys and tokens.

18.3. You must not share API keys with unauthorized users or expose them in public repositories, client-side code, screenshots, logs, or third-party systems.

18.4. We may revoke, rotate, restrict, or disable API keys if we suspect compromise, abuse, excessive usage, unauthorized access, or violation of these Terms.

18.5. API availability, endpoints, limits, and functionality may change over time.

18.6. We may monitor API usage for billing, rate limiting, abuse prevention, diagnostics, security, and product improvement.

19. Beta Features

19.1. We may offer beta, experimental, preview, early access, or test features.

19.2. Beta features may be unstable, incomplete, inaccurate, unavailable, or changed without notice.

19.3. Beta features are provided “as is” and may be removed or modified at any time.

19.4. You should not rely on beta features for critical security, compliance, production, legal, or business decisions.

20. Third-Party Services

20.1. The Services may depend on third-party providers, including hosting providers, cloud providers, AI providers, payment providers, analytics providers, email providers, security providers, and infrastructure providers.

20.2. We are not responsible for third-party outages, data processing practices, terms, delays, errors, payment decisions, or service failures beyond our reasonable control.

20.3. Your use of third-party services may be subject to their own terms and privacy policies.

20.4. We may change third-party providers where necessary for operational, technical, legal, security, payment, or business reasons.

21. User Content and Submitted Data

21.1. You may submit assets, scan configurations, URLs, IP addresses, domains, API endpoints, credentials for authorized testing, support messages, files, screenshots, prompts, and other data.

21.2. You retain ownership of data you submit, subject to the rights granted to PentestForge in these Terms.

21.3. You grant PentestForge a limited right to process submitted data to provide, secure, maintain, improve, troubleshoot, and enforce the Services.

21.4. You represent and warrant that you have all rights, permissions, and legal bases required to submit and process such data through the Platform.

21.5. You must not submit unlawful, stolen, unauthorized, malicious, or unnecessary sensitive data.

21.6. We may remove or restrict access to submitted data if we believe it violates these Terms, applicable law, third-party rights, or creates risk.

22. Confidentiality

22.1. PentestForge will treat non-public Reports, scan data, and account information as confidential, subject to the Privacy Policy and these Terms.

22.2. We may access confidential data where necessary to provide support, operate the Platform, investigate abuse, resolve disputes, comply with law, prevent fraud, secure the Platform, or enforce these Terms.

22.3. You must keep your Account, API keys, Reports, and third-party confidential data secure.

22.4. You must not publicly disclose vulnerability details from third-party systems unless you have permission or a lawful basis to do so.

23. Privacy

23.1. Personal data is processed according to the Privacy Policy.

23.2. By using PentestForge, you acknowledge that your data may be processed as described in the Privacy Policy.

23.3. If you submit personal data or third-party data to the Platform, you are responsible for ensuring that you have a valid legal basis and all required permissions.

23.4. You must not submit unnecessary personal data, regulated data, secrets, passwords, or private keys unless strictly necessary and legally permitted.

24. Intellectual Property

24.1. PentestForge and its licensors own all rights, title, and interest in the Platform, Services, software, source code, object code, APIs, designs, interfaces, databases, models, workflows, trademarks, logos, documentation, and related intellectual property.

24.2. These Terms do not transfer ownership of PentestForge intellectual property to you.

24.3. Subject to compliance with these Terms and payment of applicable fees, PentestForge grants you a limited, non-exclusive, non-transferable, revocable right to access and use the Services during the active access period.

24.4. You must not copy, modify, adapt, translate, reverse engineer, decompile, disassemble, scrape, resell, sublicense, or create derivative works from the Platform except where expressly permitted by law or written agreement.

24.5. You may use Reports generated for your Authorized Assets for internal security, compliance, remediation, customer communication, and business purposes.

24.6. You must not remove proprietary notices, branding, legal notices, or attribution from the Platform unless expressly permitted.

25. Feedback

25.1. If you provide feedback, suggestions, ideas, bug reports, improvement requests, or recommendations, you grant PentestForge the right to use them without restriction or compensation.

25.2. Feedback does not create any confidentiality obligation unless separately agreed in writing.

26. Service Availability

26.1. We use commercially reasonable efforts to keep the Platform available.

26.2. We do not guarantee uninterrupted, error-free, or always-available operation.

26.3. The Platform may be unavailable due to:

26.4. We may modify, suspend, throttle, or disable parts of the Services for security, legal, operational, maintenance, or abuse prevention reasons.

27. Suspension and Termination

27.1. We may suspend, restrict, or terminate your access if:

27.2. Suspension may apply to your Account, Organization Account, specific Assets, scans, reports, API keys, billing access, or selected features.

27.3. We may terminate access immediately for serious violations, including unauthorized scanning, malicious activity, fraud, malware activity, phishing, illegal exploitation, or payment abuse.

27.4. Upon termination:

28. Disclaimers

28.1. The Services are provided on an “as is” and “as available” basis.

28.2. To the maximum extent permitted by law, PentestForge disclaims all warranties, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, availability, and security.

28.3. PentestForge does not warrant that:

28.4. You use the Services at your own risk and remain responsible for validating results and acting safely.

29. Limitation of Liability

29.1. To the maximum extent permitted by law, PentestForge is not liable for:

29.2. To the maximum extent permitted by law, PentestForge's total liability for all claims arising out of or related to the Services shall not exceed the amount actually paid by you to PentestForge for the Services during the 12 months preceding the event giving rise to the claim.

29.3. Nothing in these Terms excludes liability that cannot be excluded under applicable law.

30. Indemnification

30.1. You agree to indemnify, defend, and hold harmless PentestForge, its owners, employees, contractors, affiliates, service providers, and partners from and against any claims, damages, losses, liabilities, costs, expenses, penalties, and legal fees arising from or related to:

30.2. PentestForge may control the defense of any matter subject to indemnification, and you agree to cooperate with the defense.

31. Export Controls and Sanctions

31.1. You must comply with all applicable export control, sanctions, cybersecurity, anti-terrorism, and trade compliance laws.

31.2. You must not use the Services if you are located in, organized under the laws of, or ordinarily resident in a country or region subject to applicable sanctions that prohibit such use.

31.3. You must not use the Services for prohibited military, surveillance, weapons, cyber abuse, or other restricted purposes.

31.4. We may restrict or terminate access where required by sanctions, export controls, Payment Provider rules, or compliance obligations.

32. Changes to the Services

32.1. We may update, improve, modify, replace, limit, or discontinue features from time to time.

32.2. We may add or remove integrations, scan modules, AI features, report templates, API endpoints, payment methods, or plan features.

32.3. We will use reasonable efforts not to materially reduce core paid functionality during an active billing period without reason.

32.4. Some changes may be necessary for security, legal compliance, abuse prevention, technical reliability, or provider requirements and may be applied immediately.

33. Changes to These Terms

33.1. We may update these Terms from time to time.

33.2. The updated version will be posted on the Platform with a new “Last updated” date.

33.3. Material changes may be notified by email, in-account notice, website notice, or other reasonable means where required by law.

33.4. Continued use of the Services after the updated Terms become effective means that you accept the updated Terms.

33.5. If you do not agree with updated Terms, you must stop using the Services and may cancel your Subscription.

34. Governing Law

34.1. These Terms are governed by the laws of Ukraine, unless mandatory consumer protection laws of another jurisdiction apply.

34.2. If you use the Services as a consumer, you may have mandatory rights under the laws of your country of residence that cannot be limited by these Terms.

35. Dispute Resolution

35.1. Before filing a legal claim, the parties agree to attempt to resolve disputes through good-faith negotiation.

35.2. Written claims should be sent to:

[email protected]

or

[email protected]

35.3. We will review written claims within 10 business days unless more time is reasonably required due to complexity.

35.4. If the dispute cannot be resolved through negotiation, it shall be submitted to the competent court according to applicable procedural law, unless mandatory law provides otherwise.

35.5. If you qualify as a consumer under applicable law, you may have the right to contact a competent consumer protection authority.

36. Force Majeure

36.1. PentestForge is not liable for failure or delay caused by events beyond reasonable control, including:

36.2. We will use reasonable efforts to reduce the impact of such events where possible.

37. Assignment

37.1. You may not assign or transfer your rights or obligations under these Terms without our prior written consent.

37.2. We may assign or transfer these Terms in connection with a merger, acquisition, restructuring, financing, sale of assets, change of control, or transfer of business.

38. Severability

38.1. If any provision of these Terms is found invalid, unlawful, or unenforceable, the remaining provisions will remain in effect.

38.2. The invalid provision will be interpreted or replaced to achieve the original intent as closely as legally possible.

39. No Waiver

39.1. Failure to enforce any provision of these Terms does not constitute a waiver of that provision.

39.2. Any waiver must be in writing and signed by an authorized representative of PentestForge.

40. Entire Agreement

40.1. These Terms, together with the Public Offer Agreement, Privacy Policy, Refund Policy, Cookie Policy where published, and any plan-specific or checkout-specific terms, form the entire agreement between you and PentestForge regarding use of the Services.

40.2. These Terms replace any prior oral or written understanding regarding the same subject matter.

41. Contact

For questions about these Terms, contact us at:

Support: [email protected]

Legal: [email protected]

Privacy: [email protected]

Website: https://pentest-forge.com