1. Acceptance & Contractual Scope
By creating an account, clicking "Accept", accessing our cloud dashboards, initiating an automated scan, or downloading security reports, you represent and warrant that you are at least 18 years of age, possess full legal capacity to enter into binding agreements, and accept these Terms of Service without reservation.
If you are accessing or using Pentoolkiton behalf of a corporate body, company, or governmental entity ("Organization"), you represent and warrant that you have explicit authority to bind that Organization to these Terms. If you do not agree to these terms, you must immediately cease all access to the platform.
3. Prohibited & Unlawful Conduct
You agree not to misuse Pentoolkit or assist any third party in doing so. Specifically, you shall not:
- Deploy denial-of-service (DoS/DDoS) payloads designed to render target applications unavailable or degrade service performance.
- Exploit discovered vulnerabilities to exfiltrate private consumer data, corrupt remote databases, or install persistent backdoors.
- Attempt to reverse-engineer, decompile, or compromise the integrity of Pentoolkit's Celery distributed execution workers or internal Docker sandboxes.
- Resell, sublicense, or share authentication credentials beyond your purchased seat entitlements.
4. Cloud Scanners & Service Availability
Pentoolkit provides 20+ automated security engines (including Port Scanner, Vulnerability Scanner, Web Scanner, Subdomain Scanner, and passive OSINT threat feeds). We make commercially reasonable efforts to maintain high availability across our cloud infrastructure. However, you acknowledge that scheduled maintenance, zero-day threat updates, and third-party upstream API rate-limits may occasionally affect scan execution times.
5. Subscriptions, Invoicing & Taxes
Paid tiers (Professional, Business, Enterprise) are billed on a recurring monthly or annual basis via our authorized payment gateways (including Razorpay). All fees are quoted exclusive of applicable statutory taxes (such as Indian GST, VAT, or local sales taxes), which shall be added to your invoice as required by prevailing law.
Subscriptions automatically renew unless cancelled through your dashboard prior to the billing cycle renewal date. Refunds are governed by our refund schedule and are granted in cases of verified billing errors.
6. Intellectual Property & Deliverables
Platform IP: All proprietary scanner orchestration algorithms, CVSS v3.1 correlation models, AI prompt architectures, and UI code remain the exclusive intellectual property of Rivedix Technology Solutions Pvt. Ltd..
Your Deliverables: All security assessment reports, PDF deliverable exports, vulnerability findings, and threat graphs generated for your authorized targets belong entirely to you. You are granted an irrevocable, perpetual, royalty-free license to use, white-label, and share generated reports with your auditors, clients, and engineering teams.
7. Data Protection & DPDP Act 2023 Compliance
We process your personal and organizational data in full compliance with the Digital Personal Data Protection Act, 2023 (India) and the General Data Protection Regulation (GDPR). Detailed information on data fiduciary obligations, retention schedules, and self-service privacy rights is set forth in our Privacy Policy and Privacy Center.
8. Disclaimers & Warranties
THE PLATFORM, SCANNERS, AND REPORT FINDINGS ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, Rivedix Technology Solutions Pvt. Ltd. EXPRESSLY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE.
Automated security scanning tools are designed to identify known vulnerability patterns and misconfigurations. No automated scanning tool can guarantee that an application or perimeter is 100% immune from compromise or that all possible security vulnerabilities have been detected.
9. Limitation of Liability & Indemnity
IN NO EVENT SHALL Rivedix Technology Solutions Pvt. Ltd., ITS DIRECTORS, EMPLOYEES, OR ADVISORS BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS, DATA LOSS, OR SYSTEM INTERRUPTION) ARISING OUT OF YOUR SCANNING ACTIVITIES.
You agree to defend, indemnify, and hold harmless Rivedix Technology Solutions Pvt. Ltd. from and against any third-party claims, liabilities, damages, and legal costs arising from your failure to obtain proper authorization for scanned targets or your violation of applicable cyber laws.
10. Suspension & Termination
We reserve the right to immediately suspend or terminate your account without notice if we detect scanning against unauthorized targets, abuse of Celery task queues, violation of third-party IP rights, or upon request by law enforcement authorities.
11. Governing Law & Dispute Jurisdiction
These Terms of Service, and any disputes arising out of or related thereto, shall be governed by and construed in accordance with the substantive laws of India, without regard to its conflict of law principles.
The courts and tribunals located in Pune, Maharashtra, India shall have exclusive territorial and subject-matter jurisdiction to hear and determine any action, suit, or proceeding arising under or in connection with these Terms.
12. Grievance Redressal & Official Contact
In compliance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the contact details of our designated Grievance Officer are set forth below: