Acceptable Use Policy
Pentest Today points automated tooling and an AI agent at systems you name. This policy sets out the one rule that matters most, which is that you must be authorized to test what you submit, and what happens when someone is not.
Permitted use
- Testing systems your organization owns or operates.
- Testing a client's systems where you hold written authorization from that client covering the targets and the testing window.
- Generating security documentation about your own organization, or a client's, for your own use or to share with reviewers.
Prohibited use
You may not use the service to do any of the following.
- Test, scan, probe, or otherwise assess a system you do not own and are not authorized to test.
- Disrupt, degrade, or deny service to any system, whether or not you are authorized to test it.
- Access, copy, or retain data belonging to a third party that testing happens to expose.
- Circumvent the scope controls, rate limits, or safety restrictions built into the service.
- Present generated output as an independent third-party audit, assessment, or certification. It is not one.
- Resell, sublicense, or provide the service to others except as agreed with us in writing.
- Break the law, infringe someone's rights, or use the service to help anyone else do either.
Your warranty to us
For every target you submit, you warrant that you own it or hold current, documented authorization to test it, that the testing you request falls within that authorization, and that you will stop testing a target as soon as that authorization ends.
You indemnify us against any claim arising from testing you were not authorized to perform, as set out in the Terms of Service.
Enforcement
Where we believe this policy has been broken we may suspend or terminate the account, with no refund, and we may do so without notice where the risk to a third party warrants it. We will cooperate with lawful requests from law enforcement and will preserve and disclose records where we are legally required to.
If we determine that a target was tested without authorization, we will quarantine the output of that run and remove it from your account. You get no rights in material captured from a system you had no permission to touch, and we may disclose the run record to the target owner or to law enforcement.
We keep the records that identify who tested what, and when, for 24 months after an account closes, so that an abuse report can still be answered. The Privacy Policy explains how this sits alongside your deletion rights.
Reporting abuse
If you believe someone has used Pentest Today to test your systems without authorization, email scott@manager.ai with the target, the dates, and any evidence you have, such as source addresses or log entries. We acknowledge within two business days, investigate against our own run records, and tell you the outcome.
How to reach us
Questions about this policy go to scott@manager.ai, addressed to Crucible Fund LLC.