GomuGuard Pentest · Legal

Terms of Service

Effective September 27, 2026

These Terms of Service ("Terms") are a binding agreement between you, the organization you represent, and each individual user of your account (collectively, "you," "your," or "Customer"), and Xhorizyn ("Xhorizyn," "we," "us," or "our"), the operator of GomuGuard Pentest, an AI-assisted, autonomous penetration-testing and vulnerability-assessment platform (the "Service").

Please read Sections 4, 5, 12, 13, and 14 carefully. They describe who is responsible for authorizing security testing, who bears the risk of the damage that active testing can cause, and how liability is limited and shifted between you and us. By creating an account, accepting an invitation to a workspace, or using the Service in any way, you agree to these Terms on behalf of yourself and, if applicable, the organization you represent.

1Acceptance of These Terms

By registering for, accessing, or using the Service, you represent that you have the legal authority to bind the organization on whose behalf you are acting (if any) to these Terms, and that you are at least 18 years old. If you do not agree to these Terms, you must not use the Service.

These Terms incorporate our Privacy Policy by reference, along with any order form, subscription confirmation, or other document that references these Terms.

2The Service

GomuGuard Pentest lets you configure and run automated and AI-assisted security assessments ("Assessments"), conversational engagements with an AI copilot ("Engagements"), and threat/attack simulations ("Simulations") against systems, applications, networks, and infrastructure that you designate ("Targets"). The Service captures findings, evidence, and generates reports based on the results of that activity.

The Service is a tool. It does not perform testing on its own initiative, and it does not verify, and cannot verify, that you or your organization actually own or are authorized to test any Target you configure. That verification is entirely your responsibility, as described in Section 4.

3Accounts, Workspaces & the Account Admin Role

The Service is organized around a tenant workspace created at registration. The person or entity that registers the workspace, and any user subsequently granted the Adminrole within it, is the "Account Admin." The Account Admin can invite additional users ("Members"), assign roles, configure billing, and manage the workspace's Targets, Assessments, and Engagements.

You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account, whether authorized by you or not. You must notify us promptly at [email protected] of any suspected unauthorized use.

The Account Admin is responsible for every Member's use of the workspace, including ensuring that every Member who configures a Target or launches an Assessment, Engagement, or Simulation has the authorization described in Section 4, and for enforcing that requirement within their own organization. Adding a Member to a workspace does not transfer or dilute the Account Admin's responsibility under these Terms — it is held jointly by the Account Admin and each acting Member.

4Authorization to Test — Your Sole Responsibility

You, and not Xhorizyn, are solely responsible for confirming that every Target you configure in the Service is one you own, or one for which you hold current, explicit, written authorization to conduct security testing — including active exploitation, simulated attacks, and automated scanning that can generate significant load or trigger security controls.

Before initiating any Assessment, Engagement, or Simulation, you represent and warrant that:

  1. you either own the Target outright, or have obtained express written authorization from the legal owner or operator of the Target and, where applicable, from any third-party hosting provider, cloud provider, or upstream service whose infrastructure the Target runs on;
  2. your authorization covers the full scope of what you configure for testing — including every subdomain, API, integration, or related system the Service touches during the Assessment — not merely the primary hostname or IP you entered;
  3. you have reviewed and will comply with all applicable laws, regulations, and third-party agreements (including any acceptable-use policy of a hosting or cloud provider) governing security testing of the Target; and
  4. the authorization checkbox and any other attestation the Service presents before launching testing activity is true and accurate at the time you confirm it.

Unauthorized security testing is illegal in most jurisdictions and is strictly prohibited under these Terms, regardless of intent. Xhorizyn has no way to independently verify your authorization for a given Target, does not undertake to do so, and is not a party to the authorization relationship between you and the Target's owner.

5Assumption of Risk

Active security testing — including the automated exploitation, credential testing, fuzzing, and load generation the Service can perform — is inherently capable of causing service disruption, degraded performance, altered or corrupted data, triggered account lockouts, security-team alerts, temporary or extended downtime, or other operational impact on a Target and on systems connected to it. This is a characteristic of active testing itself, not a defect in the Service.

You acknowledge and accept this risk in full before running any Assessment, Engagement, or Simulation. You are responsible for deciding whether, when, and against which environments (for example, staging versus production) to run testing, for coordinating with your own operations and security teams beforehand, and for having appropriate backups, monitoring, and incident-response plans in place for any Target you test.

6Your Responsibilities

  • Provide accurate registration, billing, and profile information, and keep it current.
  • Ensure every Target, scope host, credential, and piece of context you submit to the Service is accurate and that you are authorized to submit it.
  • Never submit a Target that is jointly operated or shared infrastructure (e.g. a multi-tenant SaaS platform, a shared cloud account, or a third party's network segment) unless your authorization from Section 4 extends to that shared environment specifically.
  • Use credentials, session tokens, or other authentication material you provide to the Service (for example, through the credential-drop flow) only for Targets you are authorized to access with them.
  • Review AI-generated findings, narratives, and proposed remediation before relying on them or acting on them against a live environment (see Section 8).
  • Comply with all applicable laws, including computer-crime, data-protection, and export-control laws, in every jurisdiction from which you access the Service or in which a Target is located.
  • Not use the Service to test, attack, or gather information about any system belonging to Xhorizyn or another customer's workspace.

7Prohibited Uses

In addition to Sections 4 and 6, you must not use the Service to:

  • conduct testing against any Target without the authorization required by Section 4;
  • test critical infrastructure, medical devices, safety systems, or any environment where disruption could endanger life or physical safety;
  • violate the rights of any third party, including privacy, intellectual property, or contractual rights;
  • attempt to circumvent usage limits, rate limits, or plan entitlements, or to reverse-engineer, resell, or white-label the Service without our written consent;
  • upload malware, exploit code, or content intended to harm the Service itself or other customers; or
  • use the Service in violation of any export-control or sanctions law (see Section 18).

We may suspend or terminate access for any violation of this Section, as described in Section 15.

8AI-Assisted Features & Automated Findings

The Service uses AI models — including a self-hosted language model that Xhorizyn operates on its own infrastructure — to assist with reconnaissance, conversational guidance in Engagements, payload suggestions, and narrative summaries. AI-generated output is probabilistic, not deterministic.

The Service does not guarantee that its findings are complete, accurate, or exhaustive. Automated tooling and AI models can produce false positives (reporting a vulnerability that does not exist) and false negatives (missing a real vulnerability). Findings, severity ratings, remediation guidance, and generated reports are provided to assist your own security judgment, not as a substitute for it, and must be independently verified before you rely on them for compliance attestations, remediation decisions, or any action against a production environment.

9Fees, Billing & Plans

Paid plans are billed in advance on a recurring basis (monthly, quarterly, or annual, as selected) through our payment processor. By subscribing, you authorize us and our payment processor to charge your designated payment method for all fees due.

Except where required by law or expressly stated otherwise, fees are non-refundable. We may change our pricing or plan entitlements prospectively, with notice, effective at your next renewal. If a payment fails, we may suspend access to paid features until the balance is resolved.

10Confidentiality

Each party may have access to the other's non-public information (including, for your workspace, Target details, findings, and evidence, and for us, non-public features of the Service). Each party agrees to use the other's confidential information only to perform its obligations under these Terms and to protect it with at least the same degree of care it uses for its own confidential information, and no less than reasonable care.

11Intellectual Property

Xhorizyn retains all right, title, and interest in and to the Service, including its underlying software, models, detection logic, and branding. You retain all right, title, and interest in your own data — including Target configurations, engagement transcripts, uploaded artifacts, and the findings and reports generated from your use of the Service ("Customer Data"). You grant us a limited license to process Customer Data solely to provide, secure, and improve the Service, as described in our Privacy Policy.

12Disclaimer of Warranties

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. TO THE MAXIMUM EXTENT PERMITTED BY LAW, XHORIZYN DISCLAIMS ALL WARRANTIES, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

Without limiting the foregoing, Xhorizyn does not warrant that the Service will be uninterrupted, timely, secure, or error-free; that it will identify every vulnerability present in a Target, or that every finding it reports reflects an actual, exploitable vulnerability; or that testing performed through the Service will not cause disruption, data alteration, or other impact to a Target, as described in Section 5.

13Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) XHORIZYN WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; AND (B) XHORIZYN'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE FEES YOU ACTUALLY PAID TO XHORIZYN FOR THE SERVICE IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

This limitation applies in particular to, and Xhorizyn is not liable for, any damage, downtime, data loss, data corruption, business interruption, third-party claim, or other harm caused to a Target, to your systems, or to any third party's systems, arising from testing activity you initiated or configured through the Service, regardless of whether that activity was authorized by the Target's owner. That risk is allocated to you under Sections 4, 5, and 14.

Some jurisdictions do not allow the exclusion of certain warranties or the limitation of certain damages. In those jurisdictions, the exclusions and limitations in Sections 12 and 13 apply only to the maximum extent permitted by applicable law, and our liability is limited to the smallest amount permitted.

14Indemnification

You (and, where you act on behalf of an organization, that organization and its Account Admin, jointly and severally) agree to defend, indemnify, and hold harmless Xhorizyn, its officers, employees, and agents from and against any and all claims, demands, damages, liabilities, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:

  1. any Assessment, Engagement, or Simulation run against a Target you were not authorized to test, or that exceeded the scope of your authorization;
  2. any damage, disruption, data loss, or other harm caused to a Target or to any third party as a result of testing activity initiated through your account;
  3. your breach of these Terms, including the representations in Section 4;
  4. your violation of any applicable law or third party's rights; or
  5. content or credentials you submit to the Service.

We will provide you with prompt notice of any such claim and reasonable cooperation, at your expense, in its defense; you may not settle any claim in a manner that admits fault by Xhorizyn or imposes obligations on Xhorizyn without our prior written consent.

15Suspension & Termination

We may suspend or terminate your access to the Service, immediately and without notice, if we reasonably believe you have violated Section 4, 6, or 7, if required to do so by law, or to prevent harm to the Service, other customers, or a Target. You may cancel your subscription at any time; cancellation takes effect at the end of the current billing period unless stated otherwise.

Sections 4, 5, 10 through 14, and 19 through 22 survive termination of your account or these Terms.

16Data, Evidence & Retention

The Service automatically detects and redacts likely secrets and credentials (such as API keys, tokens, and session cookies) before they are persisted to an engagement transcript or sent to any AI model, both on the client side and, authoritatively, on our servers. This reduces, but does not eliminate, the risk that sensitive material is captured — you should still avoid pasting production secrets into the Service where avoidable.

Evidence, findings, and captured artifacts generated by an Assessment or Engagement belong to you as Customer Data (Section 11) and are retained as described in our Privacy Policy. You may delete captured evidence, findings, or an entire Engagement at any time through the Service; deletion is not necessarily instantaneous across backups.

17Third-Party Services

We use a small number of third-party services to operate the Service — for example, a payment processor to handle billing. Except for such narrowly-scoped processors disclosed in our Privacy Policy, AI processing within the Service runs on infrastructure we operate ourselves, not on a third-party AI vendor's platform. We are not responsible for the acts or omissions of third-party services outside our control.

18Export Control & Sanctions Compliance

The Service includes offensive security tooling that may be subject to export-control and economic-sanctions laws. You represent that you are not located in, and will not use the Service from or on behalf of, any country or region subject to comprehensive sanctions, and that you are not a person or entity restricted from receiving US-origin, or otherwise export-controlled, software or technology.

19Governing Law & Dispute Resolution

These Terms are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to these Terms or the Service will be brought exclusively in the state or federal courts located in Delaware, and you consent to the personal jurisdiction of those courts.

20Changes to These Terms

We may update these Terms from time to time. If we make a material change, we will provide notice (for example, by email or an in-product notice) before the change takes effect. Continued use of the Service after a change becomes effective constitutes acceptance of the updated Terms.

21General Provisions

Entire Agreement

These Terms, together with the Privacy Policy and any order form, constitute the entire agreement between you and Xhorizyn regarding the Service and supersede any prior agreements on the subject.

Severability

If any provision of these Terms is held unenforceable, the remaining provisions remain in full effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable.

No Waiver

Our failure to enforce any provision of these Terms is not a waiver of our right to do so later.

Assignment

You may not assign these Terms without our written consent. We may assign these Terms in connection with a merger, acquisition, or sale of assets.

Force Majeure

Neither party is liable for a failure to perform caused by events beyond its reasonable control.

22Contact Us

Questions about these Terms can be sent to [email protected].