Pentest Today.
Legal

Acceptable Use Policy

Pentest Today points automated tooling and an AI agent at systems you name. This policy sets out the one rule that matters most, which is that you must be authorized to test what you submit, and what happens when someone is not.

Effective 2026-08-11·Version 1.1·Crucible Fund LLC

Authorization is your responsibility

Only test systems you own, or that you hold documented authorization to test. We do not verify authorization, and we cannot. Entering a target is your representation to us that you are authorized to test it.

Testing a computer system without the owner's permission is unlawful in most jurisdictions, including under the United States Computer Fraud and Abuse Act and comparable legislation elsewhere. Nothing in this service, and nothing it generates, constitutes permission from anyone.

Before an autonomous pentest can start, you tick a box certifying that you hold written authorization to test the targets in scope. That box is never pre-ticked, the engagement must be approved before a run is accepted, and we record the certification, the targets, and the timestamp against your account.

Keep your own authorization on file too. If a target owner or a regulator asks us about testing that originated from your account, that record is what we will produce, and it points to you.

Permitted use

  • Testing systems your organization owns or operates.
  • Testing a client's systems where you hold written authorization from that client covering the targets and the testing window.
  • Generating security documentation about your own organization, or a client's, for your own use or to share with reviewers.

Prohibited use

You may not use the service to do any of the following.

  • Test, scan, probe, or otherwise assess a system you do not own and are not authorized to test.
  • Disrupt, degrade, or deny service to any system, whether or not you are authorized to test it.
  • Access, copy, or retain data belonging to a third party that testing happens to expose.
  • Circumvent the scope controls, rate limits, or safety restrictions built into the service.
  • Present generated output as an independent third-party audit, assessment, or certification. It is not one.
  • Resell, sublicense, or provide the service to others except as agreed with us in writing.
  • Break the law, infringe someone's rights, or use the service to help anyone else do either.

Your warranty to us

For every target you submit, you warrant that you own it or hold current, documented authorization to test it, that the testing you request falls within that authorization, and that you will stop testing a target as soon as that authorization ends.

You indemnify us against any claim arising from testing you were not authorized to perform, as set out in the Terms of Service.

Enforcement

Where we believe this policy has been broken we may suspend or terminate the account, with no refund, and we may do so without notice where the risk to a third party warrants it. We will cooperate with lawful requests from law enforcement and will preserve and disclose records where we are legally required to.

If we determine that a target was tested without authorization, we will quarantine the output of that run and remove it from your account. You get no rights in material captured from a system you had no permission to touch, and we may disclose the run record to the target owner or to law enforcement.

We keep the records that identify who tested what, and when, for 24 months after an account closes, so that an abuse report can still be answered. The Privacy Policy explains how this sits alongside your deletion rights.

Reporting abuse

If you believe someone has used Pentest Today to test your systems without authorization, email scott@manager.ai with the target, the dates, and any evidence you have, such as source addresses or log entries. We acknowledge within two business days, investigate against our own run records, and tell you the outcome.

How to reach us

Questions about this policy go to scott@manager.ai, addressed to Crucible Fund LLC.