Legal

Permission to Penetrate

Effective 2026-09-11 (subject to change on legal review) · Version ptp-draft-2026-09-11

DRAFT - pending legal review. Not a binding agreement. The text below is placeholder content prepared ahead of formal legal review. It does not create, and must not be relied on as, a binding agreement. A reviewed version will supersede this draft under a new version id once legal review is complete.

This Permission to Penetrate ("PTP") is the authorisation you give breachr before any scan begins. It exists so that a real attempt to exploit a system only ever happens against a host you own or are authorised to test, with a clear record of what you agreed to and when.

1. Purpose and scope of the authorisation

Draft placeholder text

This section will define exactly what the PTP authorises: the specific target host(s) you register on your account, for the scan tier and time window you select, and nothing beyond that. Draft text pending legal review.

2. What breachr does

Draft placeholder text

breachr performs active, real exploitation attempts against the authorised target host only, not a passive scan. This section will describe, at a placeholder level, the nature of that testing activity and why your explicit authorisation is required before it starts.

3. Your warranties

Draft placeholder text

By granting this authorisation you will be warranting, at minimum: that you own the target or hold written authority from its owner to have it tested; that you hold any third-party or SaaS provider consent a test of that host requires; and that you maintain your own current backups before testing begins. Draft text pending legal review.

4. Out of scope and prohibited

Draft placeholder text

Testing is confined strictly to the authorised host named at launch. Denial-of-service activity is prohibited under any circumstance. This section will set out the full list of out-of-scope activity and what happens if a boundary is reached during a scan. Draft text pending legal review.

5. Data handling and residency

Draft placeholder text

Data generated or observed during testing is handled under the terms of our Privacy Policy, which this section will reference directly rather than duplicate. Draft text pending legal review.

6. Liability, indemnity, suspension and our right to refuse

Draft placeholder text

This section will set out liability limits, indemnity obligations, the circumstances in which a scan may be suspended mid-run, and breachr's right to decline or halt testing against a given target. Draft text pending legal review.

7. Acceptance and record

Draft placeholder text

This section will describe how your acceptance of the PTP is captured at the point a scan is launched, and how that acceptance is tied to the specific document version shown above, so a later, superseding version never retroactively changes what you agreed to. Draft text pending legal review.

In summary: the PTP is what lets breachr actively test a host you have authorised, on the terms above. This is a draft pending legal review and is not yet a binding agreement. Register for an account to see how authorisation is captured against a specific target.

Register →
← Back to home