Terms of Service
Last updated August 21, 2026
On this page+
- 01Acceptance of Terms
- 02Description of Service
- 03Authorised Use Only
- 04Account Registration
- 05Subscription and Payment
- 06Acceptable Use
- 07Intellectual Property
- 08Your Data
- 09Service Availability
- 10Disclaimer of Warranties
- 11Limitation of Liability
- 12Indemnification
- 13Suspension and Termination
- 14Changes to These Terms
- 15Governing Law
- 16Contact
- 17Version History
In short: AIPTx is a security testing platform. You may only test systems you own or have written authorisation to test. Our liability is capped, with exceptions the law does not permit us to exclude. These Terms are governed by the laws of England and Wales. This summary is not part of the agreement.
1. Acceptance of Terms
1.1 These Terms of Service ("Terms") form a binding agreement between AIPTx, a company registered in England and Wales, whose registered office is at 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF, United Kingdom ("AIPTx", "we", "us"), and the individual or entity accessing the Services ("you", "Customer").
1.2 By creating an account, accessing or using the Services, you accept these Terms. If you do not accept them, do not use the Services.
1.3 If you accept these Terms on behalf of an organisation, you confirm you have authority to bind that organisation.
1.4 These Terms incorporate the Acceptable Use provisions in clause 6, the Data Processing Agreement and the Privacy Policy. Where the Data Processing Agreement conflicts with these Terms in relation to the processing of personal data, the Data Processing Agreement prevails.
2. Description of Service
2.1 AIPTx provides a cloud-based security testing platform including automated penetration testing, vulnerability assessment, exploit validation, reporting and related functionality (the "Services").
2.2 The Services are provided on a subscription basis in accordance with the plan you select.
2.3 We may modify, add to or discontinue features. Where a change materially reduces core functionality, we will give at least 30 days' notice.
3. Authorised Use Only
This is the most important clause in these Terms. Please read it.
3.1 You may use the Services only to test systems, networks, applications and infrastructure that you own, or for which you hold explicit written authorisation from the owner.
3.2 You are solely responsible for obtaining, retaining and being able to produce evidence of that authorisation. We may require you to confirm control of a target before testing proceeds.
3.3 Using security testing tools against systems without authorisation is a criminal offence in most jurisdictions. Without limitation, this includes:
- (a) in the United Kingdom, the Computer Misuse Act 1990, under which unauthorised access to computer material, unauthorised access with intent to commit further offences, and unauthorised acts impairing the operation of a computer are criminal offences;
- (b) in the European Union, national laws implementing Directive 2013/40/EU on attacks against information systems;
- (c) in the United States, the Computer Fraud and Abuse Act, 18 U.S.C. § 1030; and
- (d) equivalent legislation in other jurisdictions.
3.4 You must comply with all laws applicable to your use of the Services, in every jurisdiction where you, your targets or your data are located.
3.5 You must comply with the terms of any third party whose infrastructure hosts a target, including the security testing policies of cloud providers where applicable.
3.6 We may suspend or terminate access immediately, without notice, where we reasonably believe testing is being conducted without authorisation. We may also be required to cooperate with law enforcement.
3.7 You indemnify us in respect of any claim arising from testing conducted without authorisation, in accordance with clause 12.
4. Account Registration
4.1 You must provide accurate and current registration information and keep it updated.
4.2 You are responsible for the security of your credentials and for all activity under your account.
4.3 You must be at least 18 years old.
4.4 You must notify us at [email protected] without undue delay if you become aware of unauthorised access to your account.
4.5 Credentials must not be shared. Each user requires their own account.
5. Subscription, Fees and Payment
5.1 Billing. Fees are payable in advance, monthly or annually according to your plan. All fees are stated exclusive of VAT and other applicable taxes, which are payable in addition at the prevailing rate.
5.2 Price changes. We will give at least 30 days' notice of a change to subscription pricing. Changes take effect at your next renewal.
5.3 Refunds. Fees are non-refundable except where a refund is required by law, or as expressly provided in these Terms or in our Refund Policy.
5.4 Free trial. Where offered, the free trial provides access to the Services without payment details. The trial expires automatically and does not convert to a paid subscription unless you choose to subscribe. The functionality included in the trial, and how long it runs, are shown at sign-up.
5.5 Cancellation. You may cancel at any time. Access continues to the end of the paid period. Data is deleted in accordance with clause 13 and the Data Processing Agreement.
5.6 Late payment. We may suspend access where fees remain unpaid after the due date, following written notice. We reserve our rights under the Late Payment of Commercial Debts (Interest) Act 1998 in respect of business customers.
6. Acceptable Use
6.1 You must not:
- (a) test any system without authorisation, as set out in clause 3;
- (b) conduct denial-of-service or resource-exhaustion attacks, whether against a target or against the Services;
- (c) attempt to disrupt, degrade or gain unauthorised access to the Services or to another customer's data;
- (d) share, resell or provide access to the Services to any third party except as expressly permitted;
- (e) reverse engineer, decompile or disassemble the Services, except to the extent this restriction cannot lawfully be imposed;
- (f) use the Services to develop a competing product;
- (g) use the Services to develop, distribute or deploy malware other than as necessary for authorised testing within scope;
- (h) circumvent usage limits, rate limits or scope restrictions; or
- (i) use the Services unlawfully or in breach of a third party's rights.
6.2 We may investigate suspected breaches and may suspend access during an investigation.
6.3 This clause is the Acceptable Use Policy referred to elsewhere in these Terms and forms part of them.
7. Intellectual Property
7.1 We and our licensors own the Services, including all software, documentation, methodologies and content, and all associated intellectual property rights. Nothing transfers ownership to you.
7.2 You retain all rights in your targets, your data and your authorisation documentation.
7.3 We grant you a non-exclusive, non-transferable, revocable licence to use the Services and the outputs they generate, for your own internal business purposes and for the purposes of your own compliance and assurance obligations, for the term of your subscription.
7.4 You may share assessment reports with your auditors, regulators, customers and professional advisers. You may not resell or publicly redistribute them as a commercial product without our written permission.
7.5 Where you provide feedback, you grant us a perpetual, royalty-free licence to use it, without obligation.
8. Your Data
8.1 Our processing of personal data is governed by the Privacy Policy and, where we act as processor, the Data Processing Agreement.
8.2 You are responsible for ensuring you have the rights and lawful basis necessary for the data you submit and the testing you instruct.
8.3 We do not claim ownership of your data.
8.4 We may use aggregated and anonymised data to operate and improve the Services, provided it does not identify you, your systems or any individual and cannot reasonably be used to do so.
8.5 We do not use customer data to train machine learning models, whether our own or those of a third party.
8.6 Enterprise customers may request dedicated infrastructure arrangements.
9. Service Availability
9.1 We operate the web application to an availability target, measured monthly, excluding scheduled maintenance and events outside our reasonable control. No availability figure is stated here as a contractual commitment. See clause 9.4.
9.2 Scheduled maintenance is notified in advance where practicable.
9.3 Support response targets apply according to your plan. No specific response target is stated as a contractual commitment in these Terms.
9.4 Availability under clause 9.1 is a target rather than a contractual commitment, and no service credit regime attaches to it, unless a service level agreement forming part of your order form states otherwise.
10. Disclaimer of Warranties
10.1 Subject to clause 11.1, the Services are provided "as is" and "as available", and we exclude all warranties, conditions and terms implied by statute or common law to the fullest extent permitted.
10.2 In particular, we do not warrant that:
- (a) the Services will be uninterrupted or error-free;
- (b) all vulnerabilities present in a target will be detected;
- (c) results will be complete or free from false positives or false negatives; or
- (d) the Services will meet your specific requirements.
10.3 Security testing does not guarantee security. An assessment that produces no findings means that no findings were produced within the scope, depth and time of that assessment. It is not a statement that a system is secure, and it must not be represented as one.
10.4 You remain responsible for your own security decisions, for remediation, and for compliance with your own legal and regulatory obligations.
11. Limitation of Liability
11.1 Nothing in these Terms excludes or limits our liability for:
- (a) death or personal injury caused by our negligence;
- (b) fraud or fraudulent misrepresentation;
- (c) breach of the terms implied by section 12 of the Sale of Goods Act 1979 or section 2 of the Supply of Goods and Services Act 1982, where applicable;
- (d) any other liability which cannot lawfully be excluded or limited, including under the Unfair Contract Terms Act 1977 and, where you contract as a consumer, the Consumer Rights Act 2015.
11.2 Subject to clause 11.1, we are not liable for:
- (a) indirect, special or consequential loss;
- (b) loss of profit, revenue, business, anticipated savings or goodwill;
- (c) loss or corruption of data, save to the extent caused by our breach of the security obligations in the Data Processing Agreement; or
- (d) loss arising from your failure to act on findings we provide.
11.3 Subject to clause 11.1, our total aggregate liability arising out of or in connection with these Terms, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the total fees paid by you under these Terms.
11.4 Each of the provisions in this clause operates separately. If any is held unreasonable or unenforceable, the remainder continue to apply.
11.5 You acknowledge that the allocation of risk in this clause is reflected in the fees.
12. Indemnification
12.1 You will indemnify us, our officers, employees and agents against all claims, liabilities, damages, losses and reasonable costs arising from:
- (a) testing conducted without proper authorisation;
- (b) your breach of these Terms or the acceptable use provisions in clause 6;
- (c) your infringement of a third party's rights; or
- (d) your unlawful use of the Services.
12.2 We will notify you promptly of any claim, allow you to control the defence with counsel reasonably acceptable to us, and provide reasonable cooperation at your expense. You may not settle a claim in a way that imposes an obligation or admission on us without our written consent.
13. Suspension and Termination
13.1 We may suspend or terminate your access, with notice where practicable and immediately where necessary, if:
- (a) you breach clause 3 or clause 6;
- (b) fees remain unpaid following notice;
- (c) your use presents a risk to the Services or to other customers; or
- (d) we are required to do so by law.
13.2 You may terminate at any time in accordance with clause 5.5.
13.3 On termination, your right to use the Services ends immediately. Personal Data will be deleted or returned in accordance with the Data Processing Agreement. You may elect deletion or return by notifying us in writing within 30 days of termination. We will complete the deletion or return within 30 days of that election, or, for complex cases requiring additional technical or operational steps, within 60 days, subject to applicable UK GDPR requirements and except where retention is required or permitted under clause 14.4 of the Data Processing Agreement or applicable law.
13.4 Clauses 7, 8, 10, 11, 12, 13.3, 15 and any other clause intended to survive, survive termination.
14. Changes to These Terms
14.1 We may amend these Terms. Material changes will be notified by email to your registered address and by notice within the Services, at least 30 days before they take effect.
14.2 Continued use after the effective date constitutes acceptance. If you do not accept a material change, you may terminate before it takes effect and receive a pro-rata refund of prepaid fees for the unused period.
14.3 Previous versions and their effective dates are recorded in clause 17.
15. Governing Law and Jurisdiction
15.1 These Terms and any dispute arising out of or in connection with them, including non-contractual disputes, are governed by the laws of England and Wales.
15.2 The courts of England and Wales have exclusive jurisdiction, save that we may bring proceedings for unpaid fees or to protect our intellectual property in any court of competent jurisdiction.
15.3 If you contract as a consumer, nothing in this clause deprives you of the protection of the mandatory provisions of the law of the country in which you are resident, and you may bring proceedings in the courts of that country.
15.4 The United Nations Convention on Contracts for the International Sale of Goods does not apply.
16. Contact
For questions about these Terms, please contact:
- Legal: [email protected]
- Security: [email protected]
- Data protection: [email protected]
- Support: [email protected]
Registered office
- 167-169 Great Portland Street
- Fifth Floor
- London, W1W 5PF
- United Kingdom
Registered in England and Wales.
17. Version History
| Version | Effective date | Summary |
|---|---|---|
| 2.0 | To be confirmed | Governing law moved to England and Wales; UCTA liability carve-outs added; Computer Misuse Act 1990 added to authorised use; UK registered office; VAT and late payment provisions; model-training representation harmonised with the Data Processing Agreement, Privacy Policy and Security Policy; deletion window and cross-reference aligned with the Data Processing Agreement |
| 1.0 | 29 December 2025 | Initial version |