Legal

Terms of Use

Effective 2026-09-11 (subject to change on legal review) · Version terms-draft-2026-09-11

DRAFT - pending legal review. Not a binding agreement. The text below is the document prepared for legal review. It does not create, and must not be relied on as, a binding agreement. A reviewed version will supersede this draft under a new version id once review is complete. Breachr OÜ's registry code and registered address are placeholders (shown underlined) while company registration is with our lawyers. They are not the filed values.

These Terms of Use are a legal agreement between you and Breachr OÜ. By creating an account, accessing the platform, or running a security test through breachr, you accept these terms. If you are accepting on behalf of an organisation, you confirm you have authority to bind that organisation, and "you" means both you and that organisation.

Read these terms alongside our Privacy Policy, our Permission to Penetrate, our Data Processing Agreement (breachr.ai/dpa), and, where one applies, your order form or master services agreement. If there is a conflict, a signed order form or master services agreement prevails over these terms, and these terms prevail over any other document.

1. Definitions

breachr, we, us, our: Breachr OÜ, registry code 100010009prov., registered at 1b St Hammond Street, Estoniaprov., Estonia.

Platform: the breachr software, portal, APIs, agents and related services.

Customer Data: data you or your users put into the Platform, including target details, credentials, scan results, findings and reports.

Target: a system, application, API or asset you add to the Platform for security testing.

Security Test: any scan, probe, simulated attack or other testing activity the Platform performs against a Target.

Authorisation: your permission for us to test a Target, given through the portal and governed by the Permission to Penetrate.

2. Who may use breachr

You must be a business, and an individual acting for that business, and you must be at least 18. breachr is built for financial institutions, banks, payment firms and other regulated financial-sector organisations. You must give accurate registration information and keep it current.

3. The one rule that matters most: authorisation

This is a security-testing platform. It performs real attacks against the Targets you add. Everything else in these terms sits underneath this rule.

3.1 You may only add a Target that you own, or that you are authorised by its owner to have security tested, and for which you have the authority to give that authorisation.

3.2 Each time you add a Target, you give an Authorisation. The Authorisation is governed by our Permission to Penetrate, which is incorporated into these terms by reference. You must read it before you add a Target.

3.3 When you add a Target you warrant, for that Target, that:

  • (a) you own it, or you are authorised by its owner to have it security tested;
  • (b) you have the authority to give that permission and to bind the owner;

(c) the Authorisation does not breach any law, contract or third-party right; and

(d) you understand breachr will perform real attacks against it.

3.4 We record each Authorisation, including who gave it, which Target it covers, the version of the Permission to Penetrate accepted, and the time it was given. That record is evidence of your Authorisation.

3.5 If any warranty in clause 3.3 is untrue, you are responsible for the consequences, and clause 10 (your indemnity) applies.

4. Acceptable use

You must not:

  • add a Target you are not authorised to test, or use breachr to attack, disrupt or gain unauthorised access to any system;
  • use breachr against any system belonging to a third party without that party's authorisation;
  • use breachr to break any law, including computer-misuse, data-protection, sanctions or export-control law;
  • resell, sublicense or provide breachr to a third party except as we agree in writing;
  • reverse engineer, copy or create derivative works of the Platform, except where the law says you may;
  • probe, scan or attack breachr's own infrastructure other than through a channel we designate;
  • upload malware, or content that is unlawful, infringing or harmful; or
  • interfere with the integrity, security or performance of the Platform.

We may suspend or terminate your access immediately if we reasonably believe you have broken this section, and we may report unlawful activity to the authorities.

5. Your account and security

You are responsible for your account, your credentials and everything done under your account. Keep credentials confidential, use the security controls we provide, and tell us at once at legal@breachr.ai if you suspect any compromise. Any credentials you add for authenticated testing are Customer Data and are handled under our Privacy Policy and Data Processing Agreement.

6. The service, and what we do not promise

6.1 We provide the Platform as a hosted EU service and will use reasonable skill and care to deliver it. We aim for high availability but do not promise the Platform will be uninterrupted or error-free, unless a separate service level agreement says otherwise.

6.2 Security testing has limits, and we are honest about them. A Security Test reduces risk; it does not eliminate it. No test finds every vulnerability, a clean result is not a guarantee that a system is secure, and findings are point-in-time. AI-assisted analysis can produce false positives and false negatives. You remain responsible for your own security decisions. breachr is a tool that informs those decisions, not a warranty of security.

6.3 Testing can affect a Target. Real attacks can cause load, disruption or, in rare cases, downtime or data effects on the system under test. By giving an Authorisation you accept that risk for that Target, and you confirm you have taken your own precautions, including backups. Our responsibility for effects on a Target you authorised is limited by clause 9 and does not apply where you breached clause 3.

7. Fees

You pay the fees in your plan or order form. Unless stated otherwise, fees are exclusive of VAT and other taxes, are non-refundable, and are due in advance. We may change pricing on renewal with reasonable notice. Late payment may lead to suspension.

8. Intellectual property and data

8.1 Our IP. We own the Platform and everything in it except Customer Data. We grant you a non-exclusive, non-transferable right to use the Platform during your subscription. We reserve all rights not expressly granted.

8.2 Your data. You own your Customer Data. You grant us the rights needed to host and process it to deliver the service, as processor, under our Data Processing Agreement (breachr.ai/dpa), which is incorporated into these terms and governs how we process personal data on your behalf. Where this agreement and the Data Processing Agreement conflict on a data-protection matter, the Data Processing Agreement prevails.

8.3 Aggregated, anonymised insight. You grant us a perpetual, irrevocable right to create and use aggregated, anonymised and statistical datasets derived from platform activity, provided these can never identify you, your systems, your findings or your customers, and cannot be reversed to do so. We may use these datasets to improve breachr, to produce industry benchmarks, and to support regulators and industry bodies. This right does not extend to your raw Customer Data, your findings or your reports in any identifying form, which we never sell, share or use for any other purpose. This clause survives termination.

8.4 Feedback. If you give us feedback, we may use it freely, without obligation to you.

9. Our liability

9.1 Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud, or for anything that cannot be limited by law.

9.2 Subject to clause 9.1, we are not liable for loss of profit, revenue, business, goodwill, anticipated savings, or for indirect or consequential loss, however arising.

9.3 Subject to clause 9.1, our total liability arising out of or in connection with these terms, whether in contract, tort (including negligence) or otherwise, is limited in aggregate to the fees you paid us in the 12 months before the event giving rise to the claim.

9.4 We are not liable for any effect of a Security Test on a Target where you did not hold a valid Authorisation, or where any warranty in clause 3.3 was untrue. In that situation clause 10 applies.

10. Your indemnity

You will indemnify us against all losses, damages, costs and expenses (including reasonable legal fees) arising from:

  • (a) any breach of clause 3 (authorisation) or clause 4 (acceptable use);
  • (b) any claim that a Target you added was tested without proper authority;

(c) your Customer Data, including any claim that it infringes a third party's rights or breaks the law; or

(d) your breach of these terms.

This is the counterweight to a platform that runs real attacks on your instruction. It reflects that you, not we, know whether you are authorised to test a given system.

11. Confidentiality

Each of us will keep the other's confidential information confidential and use it only to perform these terms. Findings and reports about your systems are your confidential information. This clause survives termination.

12. Suspension and termination

We may suspend or terminate your access for material breach, non-payment, or where we reasonably believe continued use poses a legal or security risk. You may terminate as your plan allows. On termination your right to use the Platform ends, and we handle your data as set out in the Privacy Policy and Data Processing Agreement. Clauses that by their nature should survive (including 8, 9, 10, 11 and 14) survive.

13. Changes to these terms

We may update these terms. For material changes we will give reasonable notice and update the version and date. Continued use after a change means you accept the updated terms.

14. Governing law and disputes

14.1 These terms, and any dispute arising out of or in connection with them, are governed by the laws of Estonia.

14.2 The courts of Tallinn, Estonia have exclusive jurisdiction, except that we may bring proceedings to protect our intellectual property or to recover unpaid fees in any court of competent jurisdiction.

Note for Lex Law: the customer contracts can be moved to English law under Rome I if a major customer or lead investor requires it, without changing the entity's Estonian corporate seat. Default is Estonian law and Tallinn courts. Confirm final wording.

15. General

These terms, with the documents they reference, are the entire agreement between us. If a clause is unenforceable, the rest stands. A delay in enforcing a right is not a waiver of it. You may not assign these terms without our consent; we may assign them to an affiliate or on a sale of the business. Nothing here creates a partnership or agency. Notices to us go to legal@breachr.ai.

16. Contact

Breachr OÜ, 1b St Hammond Street, Estoniaprov., Estonia.

legal@breachr.ai

← Back to home