Permission to Penetrate
Effective 2026-09-11 (subject to change on legal review) · Version ptp-draft-2026-09-11
This Permission to Penetrate ("PTP") is the authorisation you give breachr before any scan begins. It exists so that a real attempt to exploit a system only ever happens against a host you own or are authorised to test, with a clear record of what you agreed to and when.
1. Purpose and scope of the authorisation
Draft placeholder text
This section will define exactly what the PTP authorises: the specific target host(s) you register on your account, for the scan tier and time window you select, and nothing beyond that. Draft text pending legal review.
2. What breachr does
Draft placeholder text
breachr performs active, real exploitation attempts against the authorised target host only, not a passive scan. This section will describe, at a placeholder level, the nature of that testing activity and why your explicit authorisation is required before it starts.
3. Your warranties
Draft placeholder text
By granting this authorisation you will be warranting, at minimum: that you own the target or hold written authority from its owner to have it tested; that you hold any third-party or SaaS provider consent a test of that host requires; and that you maintain your own current backups before testing begins. Draft text pending legal review.
4. Out of scope and prohibited
Draft placeholder text
Testing is confined strictly to the authorised host named at launch. Denial-of-service activity is prohibited under any circumstance. This section will set out the full list of out-of-scope activity and what happens if a boundary is reached during a scan. Draft text pending legal review.
5. Data handling and residency
Draft placeholder text
Data generated or observed during testing is handled under the terms of our Privacy Policy, which this section will reference directly rather than duplicate. Draft text pending legal review.
6. Liability, indemnity, suspension and our right to refuse
Draft placeholder text
This section will set out liability limits, indemnity obligations, the circumstances in which a scan may be suspended mid-run, and breachr's right to decline or halt testing against a given target. Draft text pending legal review.
7. Acceptance and record
Draft placeholder text
This section will describe how your acceptance of the PTP is captured at the point a scan is launched, and how that acceptance is tied to the specific document version shown above, so a later, superseding version never retroactively changes what you agreed to. Draft text pending legal review.
In summary: the PTP is what lets breachr actively test a host you have authorised, on the terms above. This is a draft pending legal review and is not yet a binding agreement. Register for an account to see how authorisation is captured against a specific target.
Register →