Back to login

Terms of use

Welcome to IronBOT. These Terms of Use govern access to and use of the IronBOT automated penetration testing platform ("platform", "services"), including the web dashboard, the API, and the intrusion-testing agents executed on your behalf (built on the Kali Linux operating system and its tools). By creating an account or using the services, you agree to these terms. Read them carefully before requesting any pentest.

Use of the platform

You must follow all policies made available to you within the services. Do not misuse the platform — do not interfere with its operation or attempt to access it by any method other than the interfaces, APIs, and instructions we provide. You may use the services only as permitted by law, including applicable information-security, data-protection, and export-control laws. We may suspend or terminate your access if you fail to comply with these terms or if we are investigating suspected misconduct.

Using the platform does not grant you ownership of our services, trademarks, logos, or technology. Do not remove, obscure, or alter any legal notices displayed on the platform.

Target authorization and user liability

It is an essential, non-negotiable, and prior condition for running any pentest through IronBOT that the user is the legitimate owner of the target (domain, web application, code repository, or infrastructure) OR holds express, valid, current, and verifiable authorization from the legitimate owner to conduct intrusion testing against that specific target.

Depending on the verification method chosen, IronBOT requires submission of an authorization document, proof of domain ownership, or a verifiable link (e.g., OAuth with the source-control provider) before releasing any target for testing. Even so, IronBOT does not have, and cannot have, means to absolutely audit the authenticity, validity, or currency of documents, signatures, powers of attorney, or statements provided by the user.

By requesting a target or a pentest, the user declares, under applicable civil and criminal penalties, that they hold ownership of the target or express and valid authorization from whoever does, and that the information and documents provided to prove that authorization are true, complete, and have not been forged, altered, or fraudulently obtained.

Should it be found, at any time, that the authorization submitted is false, forged, altered, expired, or fraudulently obtained, the user responsible for the request assumes, fully and exclusively, all civil, administrative, and criminal liability arising from any damage, loss, unauthorized access, intrusion into a third party's system, or violation of law resulting from the execution of the pentest, expressly releasing Crinos Cybersecurity from any liability for such acts.

The user agrees to indemnify and hold harmless Crinos Cybersecurity, its partners, employees, and collaborators against any losses, damages, fines, indemnities, attorney's fees, or court costs arising from a third-party claim related to the lack of legitimate authorization for the requested test.

Crinos Cybersecurity reserves the right to immediately suspend the account, cancel any pentest in progress, retain evidence of the request, and, where applicable, notify the competent authorities, whenever there is reasonable indication that the authorization submitted is not legitimate.

Nature of penetration testing and disclaimer of liability for damages

Penetration tests (pentests), by their very technical nature, involve deliberately attempting to identify and, where applicable, exploit security vulnerabilities in real systems, applications, and infrastructure. The user acknowledges and accepts that this activity is inherently invasive and not risk-free, even when conducted with all reasonable technical care.

The user acknowledges and accepts that running a pentest may result in: (i) temporary unavailability, slowness, or instability of the tested target or of systems connected to it; (ii) crashes, restarts, or unexpected behavior of services; (iii) accidental exposure, alteration, or loss of data stored on the target; (iv) triggering alarms, automatic blocks, third-party notifications (including cloud providers, CDNs, and security services), or automated third-party containment measures.

Crinos Cybersecurity does not guarantee the absence of operational impact during or after a pentest and is not liable for direct, indirect, consequential, or incidental damages, lost profits, data loss, revenue loss, or any other harm arising from a test requested by the user themselves, within the scope defined and authorized by them.

It is the user's exclusive responsibility to: assess the risks involved before requesting the test; back up critical data on the target; notify interested parties in advance (technical team, infrastructure providers, affected third parties) where applicable; and define the test scope consciously and proportionately to the environment being tested, avoiding inclusion of critical production systems without proper precautions.

Nothing in this clause excludes any liability Crinos Cybersecurity may have for willful misconduct or proven gross negligence in the technical conduct of the test, when directly attributable to the platform's own conduct and not to the target, the scope defined by the user, the absence of legitimate authorization, or factors outside IronBOT's reasonable control.

Use of artificial intelligence in the services

IronBOT uses machine-learning artificial intelligence models (including various LLM providers) to assist with vulnerability analysis and pentest report generation. By using these features, you agree that:

Machine learning may produce unexpected, incomplete, or incorrect results in its analyses and reports; neither the IronBOT platform nor Crinos Cybersecurity is liable for decisions made solely on the basis of such results without proper human review — it is the user's responsibility to technically validate findings before acting on them (e.g., applying fixes in production).

Technical data collected during the pentest (network responses, source code where applicable, vulnerability metadata) may be processed by the AI provider configured on the platform solely for the purpose of generating the requested analysis and report, without use for training third-party models without additional consent.

User-submitted and generated content

You retain ownership of the authorization documents, scope data, and other content you submit to the platform. Reports, findings, and evidence generated from a pentest you requested belong to you, with Crinos Cybersecurity, through IronBOT, being responsible only for providing the technical service of generating these artifacts.

By submitting authorization documents, source code, or any other content to the platform, you grant Crinos Cybersecurity the license strictly necessary to store, process, and transmit that content for the purpose of executing the requested pentest and generating the corresponding report.

Use of third-party services

IronBOT relies on third-party providers to operate, including a payment processor (Stripe) for billing plans and tokens, an S3-compatible object storage provider for documents and reports, an email (SMTP) provider for notifications, and a cloud infrastructure provider for isolated execution of pentest agents.

Crinos Cybersecurity is not liable for outages, improper charges, or security failures caused solely by these third-party providers, without prejudice to Crinos Cybersecurity's duty to select reputable providers and reasonably mitigate the risks of using them.

Suspension and termination of accounts

Crinos Cybersecurity may suspend or terminate accounts, subject to due process where applicable, in cases of: use of the platform for unlawful purposes; attempting to test a target without legitimate authorization; forging authorization documents; attempting to circumvent the platform's technical or billing limits; or any other material breach of these terms.

Changes to these terms

We may update these Terms of Use periodically. Material changes will be communicated by email or notice on the platform before taking effect. Continued use of the services after an update constitutes acceptance of the new terms.

How to contact us

Questions about these terms can be sent to contato@ironbot.io.