Trust & Compliance
Terms of Use (Public Template, Version 1.0)
These Terms of Use (the “Terms”) govern your access to and use of TurboPentest, an AI-powered penetration testing platform operated by IntegSec LLC, a Delaware limited liability company (“IntegSec,” “we,” “us”). These Terms are effective as of 2026-05-03.
By accessing or using the Service, you agree to be bound by these Terms. If you do not agree, do not use the Service.
1. Acceptance of Terms
By creating an account, clicking “I agree,” making payment, or otherwise accessing or using the Service, you accept these Terms and represent that you have authority to bind the organization on whose behalf you are acting (the “Customer”). If you are using the Service for personal use, “you” and “Customer” refer to you individually.
2. Definitions
- “Service” - the TurboPentest platform (websites, APIs, web application, agents, and any updates) made available by IntegSec.
- “User”- any natural person who accesses the Service under Customer's account.
- “Customer Data” - data Customer submits to the Service, including target metadata, source code, and pentest output generated for Customer.
- “Subscription” - a paid plan providing access to the Service, whether a one-time pentest or a recurring (monthly/annual) plan.
- “Documentation” - the user-facing documentation, security pages, and policies published at turbopentest.com.
- “DPA” - the Data Processing Agreement at /dpa.
3. The Service
TurboPentest is an AI-powered penetration testing platform. It combines a portfolio of 14 industry security testing tools with the Paladin AI orchestrator (15 platform components together) to plan, execute, and report on penetration tests against targets Customer authorizes.
The Service is self-service. Account creation requires a verified work email; running a pentest requires domain ownership verification for each in-scope target. We may modify, add, or remove features over time; material removals affecting Customer's active Subscription will be communicated in advance.
4. Account and registration
- Eligibility: you must be at least 18 years old, capable of forming a binding contract, and not barred from receiving the Service under U.S. or other applicable law. If you register on behalf of an organization, you represent you are authorized to bind that organization to these Terms.
- Account security: you are responsible for keeping account credentials confidential, for enabling reasonable account security controls (multi-factor authentication where offered), and for all activity occurring under your account.
- One account per organization: unless we authorize otherwise in writing, Customer maintains a single organizational account. Sharing of credentials across organizations is not permitted.
- Notifications: you agree to receive operational and transactional notices at the email address associated with your account.
5. Authorization to test (critical)
Penetration testing without authorization is illegal in most jurisdictions (including under the U.S. Computer Fraud and Abuse Act, the UK Computer Misuse Act, and equivalent laws elsewhere). The authorization warranty in this section is a material term of the Terms.
By submitting a target for testing, Customer represents and warrants that, for each in-scope target, Customer either (a) owns the target outright, or (b) has obtained explicit written authorization from the owner sufficient to permit the testing activities the Service will perform.
Domain verification is a procedural check that helps prevent accidental submission of third-party domains. It is nota substitute for actual authorization, and successful domain verification does not waive Customer's obligation to ensure authorization is in place. Customer alone is responsible for confirming the legal authority to test.
Indemnity for unauthorized testing:Customer will defend, indemnify, and hold harmless IntegSec from and against any claim, loss, damage, fine, or expense (including reasonable attorneys' fees) arising out of or related to Customer's submission of any target Customer was not authorized to test, or Customer's breach of the warranties in this section. This obligation survives termination.
Out-of-scope and denylisted targets.Some targets are not eligible for testing through the Service even with apparent authorization, including: government, military, and intelligence-community domains (e.g., .gov, .mil, .gc.ca, .gov.uk and equivalents); critical infrastructure systems where testing without provider coordination would breach abuse policies; cloud-provider shared services where the cloud provider's acceptable-use policy supersedes Customer authorization; and any target Customer has been notified is on a denylist. We reserve the right to refuse, halt, or revoke a pentest at any time if a target appears ineligible.
6. Acceptable use
Customer's use of the Service is governed by the Acceptable Use Policy (“ AUP”) referenced at /acceptable-use. Without limiting the AUP, Customer will not, and will not permit any User or third party to:
- Submit any target Customer is not authorized to test, including third-party assets and out-of-scope or denylisted assets;
- Use Service output (findings, payloads, reasoning logs) to launch, facilitate, or extend an unauthorized attack against any system;
- Use the Service to test or attack IntegSec's own infrastructure outside the Safe Harbor program (see section 16);
- Resell, sublicense, white-label, or otherwise commercially distribute the Service or its output without our prior written consent;
- Reverse-engineer, decompile, or attempt to derive the source code, model weights, or prompt structures of the Service, except to the extent permitted by mandatory law;
- Use the Service in violation of applicable law, including export-control, sanctions, data protection, anti-money-laundering, and computer-misuse laws;
- Interfere with or disrupt the integrity or performance of the Service, or attempt to gain unauthorized access to any non-public area of the Service;
- Use the Service to develop a product or service competitive with TurboPentest by copying its features, output structure, or methodology.
We may suspend or terminate the Service for Customers who breach this section.
7. Subscriptions and billing
- Pricing: we offer per-pentest pricing (one-time charges) and annual subscription tiers. Current pricing is published at /pricing and is the controlling reference at the time of purchase.
- Payment: payments are processed by Stripe, Inc. By providing payment information, you authorize us and Stripe to charge the applicable fees and any taxes.
- Auto-renewal: annual subscriptions automatically renew at the end of each term unless cancelled before the renewal date. Cancellation can be initiated from the billing settings of your account or by emailing [email protected].
- Refunds - undelivered results: if we fail to deliver pentest output for a paid one-time pentest within 30 days of purchase due to a defect or outage attributable to us, Customer may request a refund within 30 days of purchase. Refunds are not available for completed pentests where output was delivered.
- Volume discounts: volume-based discount tiers are published at /pricing and applied at checkout where applicable.
- Taxes:fees do not include taxes; Customer is responsible for applicable sales, use, value-added, and similar taxes (excluding taxes based on IntegSec's net income).
- Late payment: overdue amounts may accrue interest at the lesser of 1.5% per month or the maximum allowed by law. We may suspend the Service for accounts in material payment breach after reasonable notice.
8. Customer Data
Ownership. Customer owns Customer Data, including the content of pentest reports generated for Customer. Nothing in these Terms transfers ownership of Customer Data to IntegSec.
License to deliver the Service. Customer grants IntegSec a worldwide, non-exclusive, royalty-free license to host, copy, transmit, display, modify (e.g., reformatting), and Process Customer Data solely as necessary to provide, secure, and improve the Service for Customer, and to comply with law. We do not use Customer Data to train generally available AI models.
Processing terms.Where IntegSec Processes personal data on Customer's behalf, our DPA applies and is incorporated into these Terms by reference.
9. Intellectual property
TurboPentest IP. The Service (including software, models, methodology, scoring, prompts, agent design, documentation, and the TurboPentest and IntegSec brands) is owned by IntegSec or its licensors and is protected by intellectual property laws. We grant Customer a limited, non-exclusive, non-transferable, revocable license to access and use the Service during the Subscription term in accordance with these Terms.
Customer IP.Customer retains all rights in Customer Data and Customer's target environments, source code, and other Customer-provided materials. Nothing in these Terms transfers ownership of those materials to IntegSec.
Feedback. If Customer provides feedback, suggestions, or recommendations regarding the Service, Customer grants IntegSec a perpetual, irrevocable, worldwide, royalty-free license to use, modify, and incorporate that feedback into the Service without obligation or attribution.
Trademarks.“TurboPentest” and “IntegSec” are names used by IntegSec LLC. All other marks are the property of their respective owners.
10. Confidentiality
Each party may disclose “Confidential Information” - non-public information disclosed under these Terms that a reasonable person would understand to be confidential. Customer pentest reports, findings, scan output, and target metadata are Customer's Confidential Information. Information about the Service's architecture, prompts, agent design, and pricing not publicly disclosed is IntegSec's Confidential Information.
Each party will (a) use the other party's Confidential Information only as necessary to perform under these Terms, (b) protect it with the same degree of care used for its own confidential information of similar importance (and no less than a reasonable degree of care), and (c) not disclose it to any third party except to personnel and contractors with a need to know who are bound by confidentiality obligations at least as protective.
Exclusions.Confidential Information does not include information that (i) is or becomes generally available to the public without breach by the receiving party, (ii) was known to the receiving party prior to disclosure, (iii) was rightfully received from a third party without confidentiality obligations, or (iv) was independently developed without use of the disclosing party's Confidential Information. Disclosure required by law is permitted with prompt notice (where legally allowed) so the disclosing party can seek a protective order.
11. Warranties and disclaimers
Limited service warranty.IntegSec warrants that the Service will materially conform to its Documentation. As Customer's sole and exclusive remedy for a breach of this warranty, IntegSec will use commercially reasonable efforts to correct the non-conformity or, if it cannot do so within a reasonable period, refund the pro-rata fees paid by Customer for the affected portion of the Service.
Except for the warranty above, the Service is provided “as is” and “as available.” To the maximum extent permitted by law, IntegSec disclaims all other warranties, express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranties arising out of course of dealing or trade usage.
No guarantee of security.Penetration testing identifies a sample of vulnerabilities present at a point in time. The Service's output is not a guarantee that any tested target is secure, free from vulnerabilities, or compliant with any law, regulation, or framework. Customer remains responsible for its own security program, remediation, and compliance decisions.
12. Limitation of liability
To the maximum extent permitted by law, neither party will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, even if advised of the possibility.
Each party's aggregate liability arising out of or related to these Terms is capped at the greater of (a) the amount Customer paid IntegSec under these Terms in the 12 months preceding the event giving rise to the claim, or (b) USD $100.
Carve-outs.The above limitations do not apply to (i) Customer's payment obligations; (ii) Customer's indemnity for unauthorized testing under section 5; (iii) either party's indemnity obligations under section 13; (iv) breaches of confidentiality under section 10; or (v) liability that cannot be limited by law (e.g., gross negligence, willful misconduct, fraud, or personal injury).
13. Indemnity
By Customer.Customer will defend, indemnify, and hold harmless IntegSec from and against any third-party claim arising out of (a) Customer's breach of section 5 (Authorization to test) or section 6 (Acceptable use), (b) Customer Data or its use in violation of these Terms, or (c) Customer's violation of applicable law.
By IntegSec (IP infringement).IntegSec will defend Customer against any third-party claim alleging that the Service, when used as permitted by these Terms, infringes a third party's patent, copyright, trademark, or trade secret, and will pay damages and costs finally awarded against Customer (or agreed in settlement). If the Service is, or in our opinion may become, the subject of an infringement claim, we may at our option (i) procure the right to continue use, (ii) modify the Service to be non-infringing, or (iii) terminate the affected portion of the Service and refund pre-paid unused fees.
Exclusions. The IntegSec indemnity does not apply to claims arising from (i) modifications to the Service not made by IntegSec, (ii) use of the Service in combination with materials not provided or recommended by IntegSec where the claim would not have arisen but for the combination, (iii) use of the Service in violation of these Terms, or (iv) Customer Data.
Process.The indemnified party will (i) promptly notify the indemnifying party of the claim, (ii) give the indemnifying party sole control of the defense and settlement (provided settlement releases the indemnified party without admission of liability), and (iii) provide reasonable cooperation. This section states the parties' sole obligations and exclusive remedies for third-party IP infringement claims.
14. Term and termination
- Term. These Terms begin when Customer first accepts them and continue until terminated as permitted below or, for fixed-term Subscriptions, until the end of the then-current term (subject to auto-renewal).
- Termination for convenience by Customer. Customer may terminate at any time by closing the account; Customer remains liable for fees incurred through the termination date.
- Termination for material breach.Either party may terminate for material breach upon 30 days' written notice if the breach is not cured within that period (or immediately for breaches incapable of cure or for repeated breaches).
- Suspension.We may suspend access to the Service if (i) Customer's use poses a security or legal risk, (ii) Customer is in material payment breach, or (iii) suspension is required by law. We will restore access promptly once the cause is resolved.
- Effect of termination.Upon termination, Customer's right to use the Service ends. Customer Data is retained per the 90-day post-termination retention policy described in our Privacy Policy and DPA, then deleted (subject to legal retention obligations). Sections that by their nature should survive termination (including IP, confidentiality, indemnity, limitation of liability, governing law, and these survival provisions) survive.
15. Modifications
We may update these Terms from time to time. For material changes that negatively affect Customer, we will notify the administrator of record by email or in-app notice at least 14 days beforethey take effect. Continued use of the Service after the effective date constitutes acceptance. Non-material updates take effect when posted, with the “Last updated” date updated above.
16. Safe Harbor for security researchers
We welcome good-faith security research. Our published Safe Harbor at /security adopts language consistent with the HackerOne Gold Standard Safe Harbor: research conducted in good faith and in accordance with our published rules of engagement will not result in legal action from IntegSec, will be considered authorized, and will be treated as covered by the Computer Fraud and Abuse Act safe harbor where applicable.
Researchers are still expected to: avoid privacy violations, data destruction, and service disruption; only interact with accounts they own or are explicitly authorized to access; report findings promptly through the disclosure channel; and not publicly disclose vulnerabilities until coordinated remediation. Activity outside the Safe Harbor scope is not covered.
17. Governing law and dispute resolution
These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Any dispute arising out of or related to these Terms will be brought exclusively in the state or federal courts located in New Castle County, Delaware, and the parties consent to the personal jurisdiction of those courts. Each party waives the right to a jury trial to the maximum extent permitted by law.
Nothing in this section prevents either party from seeking injunctive or other equitable relief in any court of competent jurisdiction to protect its intellectual property or Confidential Information.
18. General provisions
- Entire agreement. These Terms, together with the Privacy Policy, the DPA, and the Acceptable Use Policy, constitute the entire agreement between the parties regarding the Service and supersede all prior or contemporaneous understandings.
- Severability. If any provision is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision is deemed modified to the minimum extent necessary to be enforceable.
- Assignment.Customer may not assign these Terms without IntegSec's prior written consent. IntegSec may assign these Terms in connection with a merger, acquisition, reorganization, or sale of substantially all of its assets. Any assignment in violation of this section is void.
- No waiver.A party's failure to enforce a provision is not a waiver of its right to enforce it later.
- Force majeure. Neither party is liable for delays or failures to perform (other than payment obligations) caused by events beyond reasonable control, including acts of God, natural disasters, war, terrorism, labor disputes, denial-of-service attacks, internet or cloud-provider outages, and government action.
- Notices. Notices to IntegSec must be sent to [email protected] with copy by mail to the postal address in section 19. Notices to Customer may be sent to the email address on file. Notices are effective upon delivery.
- Independent contractors. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.
- Government users.The Service is “commercial computer software” provided with limited rights consistent with FAR 12.211, FAR 12.212, DFARS 227.7202, and successor regulations.
- Export and sanctions. Customer represents it is not located in, and is not a national or resident of, a country subject to comprehensive U.S. sanctions, and is not on any U.S. government list of restricted parties.
19. Contact
- General legal: [email protected]
- Phone: +1 (207) 200-3288
- Postal: IntegSec LLC, 5305 Limestone Road, Suite 200, Wilmington, DE 19808
Status: Public template - Version 1.0 - 2026-05-03.
Counsel review:this template is substantively complete for self-serve onboarding. For a counter-signed bespoke version on Customer's paper, email [email protected].
Related trust documents
For IntegSec's broader terms (covering the full IntegSec security consultancy), see integsec.com/terms-and-conditions.