Terms of Service
These Terms of Service are a binding agreement between you (the 'Customer', 'you') and CyberOrbit AI Pty Ltd (ACN 700 012 157, ABN 75 700 012 157) ('CyberOrbit', 'we', 'us', 'our'), governing your access to and use of our AI-powered penetration testing platform and services (the 'Services'). By accessing the Services, placing an order, or clicking 'I accept', you confirm you have authority to bind the Customer and you accept these Terms. If you do not agree, do not use the Services.
1. Definitions
In these Terms, the following capitalised words have the meanings set out below. Other capitalised terms are defined where they first appear.
- Acceptable Use Policy or AUP means our Acceptable Use Policy, as updated from time to time, which is incorporated into these Terms.
- Authorisation means a completed and signed Penetration Testing Authorisation for a specified target, in which an authorised representative of the Customer authorises CyberOrbit to test that target and defines the Scope and Test Window.
- Customer, you means the entity that accepts these Terms or places an Order Form, on whose behalf the Services are used.
- DPA means our Data Processing Agreement, which governs our processing of personal data and is incorporated into these Terms.
- Order Form means an ordering document, online subscription selection, or statement of work that references these Terms and sets out the plan, fees, term, and any agreed commercial parameters.
- Platform means the CyberOrbit AI software, AI models, dashboard, APIs, and supporting infrastructure through which the Services are delivered.
- Scope means the targets, IP ranges, URLs, test types, and constraints set out in an Authorisation.
- Services means the AI-powered penetration testing and vulnerability assessment services described below, including access to the Platform.
- SLA means the service levels set out in an Order Form (where applicable), as described in the SLA and Support section.
- Test Window means the period, set out in an Authorisation, during which CyberOrbit is authorised to test a target.
2. What the Services are
CyberOrbit provides AI-driven penetration testing and vulnerability assessment with certified human review of the reports you take to certification. An autonomous AI agent performs the active testing: it makes real, active connections to the systems you authorise and actively probes and attempts to exploit security weaknesses. The assessment reports you rely on for audit or certification are reviewed and signed by a certified security professional before they are finalised. The Services are offensive security testing, not passive or 'detection-only' scanning. Testing output generated between certified reports (for example, continuous-monitoring output) is produced by the AI without individual human sign-off; the certified-professional signature attaches to the reports selected or submitted for certification.
Against authorised targets, the Services include:
- Active vulnerability exploitation — sending crafted requests and payloads that attempt to trigger, confirm and demonstrate exploitable weaknesses
- Adaptive sandbox-based probing — an autonomous AI agent, running in an isolated E2B sandbox, that adaptively selects, chains and escalates techniques in real time based on system responses
- Server-Side Request Forgery (SSRF) testing
- Injection testing (SQL, command, template and similar)
- Port and service scanning
- Security misconfiguration, header and TLS/SSL testing
- AI analysis and human validation of findings by OSCP-certified engineers (including engineers in India), with report generation
You acknowledge that this is active, intrusive testing that carries an inherent risk of disruption to the tested systems.
3. Authorisation is mandatory
The Services may not be used to test any system without a completed and signed Penetration Testing Authorisation in place for that system.
Active penetration testing of a system without authorisation is a criminal offence — for example, the Criminal Code Act 1995 (Cth) s.477 in Australia, the Computer Misuse Act 1990 in the UK, and the Computer Fraud and Abuse Act, 18 U.S.C. § 1030 in the US. No scan will begin until an authorised representative has signed the Authorisation defining scope, targets, the test window, and the authorised test types. This requirement cannot be waived, including during trials and beta evaluations.
You represent and warrant that you own, or hold valid written authority over, every target you submit for testing, and you accept the authority warranties and indemnity in the Authorisation.
4. Your obligations
You will:
- Maintain a valid, current, signed Authorisation for every target before any scan begins
- Define and configure the Scope accurately, keep it current, and not submit targets outside the Scope
- Provide and keep up to date accurate emergency and technical contacts so we can reach you about active testing
- Comply with the Acceptable Use Policy at all times
- Keep your account credentials and API keys secure, restrict access to authorised personnel, and not share or expose them
- Obtain and maintain any third-party consents your testing requires (for example, from hosting providers, cloud platforms, or ISPs whose terms require notice of penetration testing)
- Promptly report any suspected unauthorised use of your account, any out-of-scope testing, or any security incident affecting the Services
- Comply with all applicable laws, including computer-misuse, privacy, and export-control laws
5. Licence and restrictions
Subject to these Terms and payment of fees, we grant you a non-exclusive, non-transferable, non-sublicensable licence to access and use the Platform during your subscription, solely for your internal security testing of authorised targets.
You must not:
- Test systems you are not authorised to test
- Use the Services to attack third parties
- Reverse engineer the Platform or extract its scanning methodology
- Use the Services to build a competing product
- Share credentials
- Circumvent security or rate-limit controls
6. Fees and payment
Fees, billing model and term are set out in your Order Form or subscription plan. Unless stated otherwise, invoices are payable within the period stated, and fees are exclusive of GST and other taxes. We may change pricing for future terms on 30 days' notice; existing committed terms are honoured.
7. Intellectual property
All intellectual property in the Platform (software, AI models, scanning logic, methodologies, documentation) remains exclusively with CyberOrbit.
On full payment, you own the assessment report specific to your targets and receive a licence to the findings outputs for your internal use. We retain report templates, methodologies, and the right to use de-identified, aggregated data to improve the Services. Your data remains yours; you grant us a limited licence to process it to provide the Services, as set out in the Data Processing Agreement. Feedback you provide may be used by us without obligation.
8. Confidentiality and data protection
Each party will protect the other's Confidential Information and use it only to perform these Terms. Our processing of personal data is governed by the Data Processing Agreement and our Privacy Policy, which are incorporated by reference. We process personal data in accordance with applicable data protection law.
Our standard Data Processing Agreement, including the Sub-Processor List, is made available to customers on request and is executed at, or referenced from, signup. You can request a copy of, or execute, the Data Processing Agreement through the contact form.
9. Third-party and open-source components
The Platform incorporates third-party and open-source software components. Those components remain the property of their respective owners and may be subject to their own licence terms. Where a third-party or open-source licence requires it, those terms apply to your use of the relevant component and, to the extent of any conflict with these Terms in respect of that component, prevail.
The Services rely on third-party sub-processors (for example, infrastructure, AI analysis, sandbox execution, and payment processing providers) to operate. These sub-processors are identified in our Sub-Processor List, which forms part of the Data Processing Agreement, and we remain responsible for their performance of the data protection obligations we flow down to them.
We do not provide any warranty in respect of third-party or open-source components beyond the warranties below, and your remedies in respect of those components are as set out in these Terms.
10. Warranties and disclaimer
We warrant that the Services will be performed with reasonable skill and care by competent professionals. We do not warrant that all vulnerabilities will be found (testing is inherently limited), that systems will be secure after testing, that testing will not cause disruption, or that results meet any specific compliance requirement.
Except as expressly stated and except for rights that cannot be excluded by law (including under the Australian Consumer Law), the Services are provided 'as is' and we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. Nothing in these Terms excludes, restricts or modifies any consumer guarantee or right that cannot lawfully be excluded.
11. Liability
- Subject to the exclusions below, our total aggregate liability arising out of or in connection with these Terms is limited to the total fees paid by you in the 12 months before the event giving rise to the claim.
- Subject to the exclusions below, neither party is liable for indirect or consequential loss, or for loss of profits, revenue, business, goodwill or data. This exclusion is mutual.
- The cap and consequential-loss exclusion do not apply to your obligation to pay fees; your indemnity for unauthorised testing; either party's breach of confidentiality or the other's IP; or liability that cannot be limited by law (including non-excludable consumer guarantees, where our liability is limited, at our option, to resupplying the Services or paying the cost of resupply, to the extent permitted).
- Where we test within the authorised scope and test window with reasonable skill and care, we are not liable for in-scope disruption or for pre-existing vulnerabilities. We remain responsible for testing conducted outside the authorised scope, subject to the cap and consequential-loss exclusion above.
12. Indemnity
You indemnify us against claims, losses and costs arising from: testing of systems you were not authorised to test; your breach of the Authorisation's authority warranties; or your use of the Services in breach of law or the Acceptable Use Policy.
13. Trial and beta terms
We may make the Services, or specific features, available to you on a trial, evaluation, or beta basis (a 'Trial'). Where you have signed a separate Trial / Evaluation Agreement, that agreement governs the Trial and prevails over these Terms to the extent of any inconsistency during the trial period.
Trials and beta features are provided strictly 'as is' and 'as available', with no warranties of any kind to the maximum extent permitted by law and except for rights that cannot be excluded under the Australian Consumer Law. No SLA applies to a Trial or beta feature. Trial and beta features may be changed, limited, or withdrawn at any time, and may not function as a generally available feature would. We may end a Trial at any time on notice.
The mandatory Authorisation requirement applies in full to every Trial and beta evaluation. A Trial does not waive the criminal-law requirement for a signed Authorisation before any scan begins.
14. Modifications to the Services
We continuously develop the Services and may add, change, or remove features, and update the Platform, from time to time. We will not make a change that materially degrades the core functionality of the Services during a committed term without giving you reasonable notice.
Where we discontinue a material feature you rely on during a committed term, and there is no substantially equivalent replacement, you may terminate the affected Services and receive a pro-rata refund of pre-paid fees for the discontinued feature. We may make changes required for security, legal compliance, or to address a material risk to any system or person without prior notice, and will notify you as soon as practicable afterwards.
15. SLA and support
Support. We provide support for the Services. You can raise support requests through the contact form and, for existing customers, from within the dashboard. Security issues should be reported via the security disclosure form.
Service levels. Where an Order Form sets out service levels (an SLA), those service levels form part of the agreement and set out our platform availability commitment, support response targets by severity, any assessment turnaround targets, and service credits as the sole remedy for availability misses. Service levels apply only where, and to the extent, they are set out in an Order Form.
The SLA does not apply to Trials, beta features, or free-tier use.
16. Term, suspension and termination
These Terms apply while you use the Services. Subscription terms are set out in your Order Form. We may suspend or terminate immediately for: a breach of the authorisation requirement or the Acceptable Use Policy; non-payment; or a material breach not cured within 30 days. Either party may terminate for the other's insolvency.
On termination, your access ends, outstanding fees fall due, and data is returned or deleted per the Data Processing Agreement. The clauses on definitions, authorisation, intellectual property, confidentiality and data protection, the disclaimer, liability, indemnity, and the general clauses survive termination.
17. Fair terms (Australian Consumer Law)
We have reviewed these Terms against the unfair contract terms regime applicable to small business contracts. In particular:
- Our indemnity is limited to losses arising from your unauthorised testing or unlawful use, matching the genuine criminal-law risk the Services create — it is reasonably necessary to protect our legitimate interests.
- We will not vary these Terms or pricing during a committed term to your detriment without notice; changes apply prospectively on at least 30 days' notice, and you may decline by not renewing.
- Any auto-renewal is disclosed in the Order Form, with notice before renewal and a right to cancel before the renewal date.
18. General
- Governing law. These Terms are governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of the courts of New South Wales.
- Dispute resolution. Good-faith negotiation first; failing resolution within 30 days, binding arbitration under the ACICA Arbitration Rules, seated in Sydney, in English.
- Assignment. You may not assign without our consent; we may assign to an affiliate or in a corporate transaction.
- Force majeure. Neither party is liable for any delay in or failure to perform its obligations (other than an obligation to pay money) to the extent caused by an event beyond its reasonable control, including natural disaster, fire, flood, war, terrorism, civil disturbance, epidemic or pandemic, industrial action, failure of utilities or telecommunications, and acts of government. The affected party will notify the other as soon as practicable and use reasonable efforts to mitigate and resume performance. If a force majeure event continues for more than 30 days, either party may terminate the affected Services on notice.
- Waiver. A failure or delay by a party to exercise a right under these Terms is not a waiver of that right, and a single or partial exercise of a right does not prevent its further exercise. A waiver is effective only if it is in writing and signed by the party giving it, and applies only to the specific instance for which it is given.
- Severability. If any provision of these Terms is or becomes invalid, illegal, or unenforceable, it is to be read down to the minimum extent necessary to make it valid and enforceable, or, if it cannot be read down, severed, without affecting the validity or enforceability of the remaining provisions.
- Entire agreement. These Terms, together with the Order Form, the Authorisation, the Data Processing Agreement, the SLA (where referenced), and the Acceptable Use Policy, form the entire agreement between the parties about their subject matter and supersede all prior representations, understandings, and agreements. Each party acknowledges it has not relied on any representation not set out in these documents. Nothing in this clause limits liability for fraud or excludes a non-excludable right under the Australian Consumer Law.
- Notices. Notices under these Terms must be in writing. We may give you notice through the contact form acknowledgement, by in-dashboard notice, or to the contact details associated with your account. You may give us notice through the contact form. A notice is taken to be received when delivered, or, if sent electronically, when sent, unless the sender receives an automated failure message.
- No third-party beneficiaries. These Terms are for the benefit of the parties only and do not confer any right or benefit on any third party, except that an affiliate to whom we assign may enforce these Terms.
- Relationship of the parties. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between them.
- Publicity. We may identify you as a customer (name and logo) unless you object in writing.
19. Changes to these terms
We may update these Terms of Service from time to time. When we do, we will update the 'Last updated' date at the top of this page. Continued use of our website or services after changes are posted constitutes your acceptance of the updated terms. We recommend reviewing this page periodically.
20. Contact us
CyberOrbit AI Pty Ltd (ACN 700 012 157, ABN 75 700 012 157). For any questions about these terms or to submit a legal inquiry, use the legal inquiry form at the bottom of this page. For commercial or support questions, contact us here; to report a security issue, use our security disclosure form.
Legal inquiries
For privacy requests, data access or deletion requests, or any other legal matter — use this form. We respond within 2 business days.
CyberOrbit AI · Australia