Legal · v1.0
Terms of Engagement
By initiating any scan through the PentrAX AI Platform, you ("the Authorising Party") affirm under penalty of perjury that you are duly authorised to authorise security testing of the targets you submit.
1. Scope of Authorisation
Testing is limited to the assets you have explicitly listed within the engagement scope. Testing of out-of-scope assets, third-party services, or shared infrastructure not under your control is strictly prohibited.
2. Prohibited Activities
- Denial-of-service or resource exhaustion attacks
- Destructive exploitation of vulnerabilities
- Exfiltration of personal or regulated data beyond evidence sampling
- Pivoting into adjacent networks or systems
3. Legal Compliance
Unauthorised testing constitutes a criminal offence under the Computer Fraud and Abuse Act (USA), the Computer Misuse Act 1990 (UK), the EU NIS2 Directive, and equivalent legislation in other jurisdictions.
4. Data Handling
Evidence is retained for 12 months, encrypted at rest with AES-256-GCM, and accessible only via your DRM-protected viewer.
5. Liability
PentrAX AI's aggregate liability is limited to fees paid in the preceding 12 months. Indirect, consequential and punitive damages are excluded to the maximum extent permitted by law.
6. Digital Signature
Your acceptance is cryptographically timestamped using an Ed25519 keypair generated at account creation and stored immutably in our audit ledger.