GomuGuard Pentest · Legal
Terms of Service
Effective September 27, 2026
These Terms of Service ("Terms") are a binding agreement between you, the organization you represent, and each individual user of your account (collectively, "you," "your," or "Customer"), and Xhorizyn ("Xhorizyn," "we," "us," or "our"), the operator of GomuGuard Pentest, an AI-assisted, autonomous penetration-testing and vulnerability-assessment platform (the "Service").
Please read Sections 4, 5, 12, 13, and 14 carefully. They describe who is responsible for authorizing security testing, who bears the risk of the damage that active testing can cause, and how liability is limited and shifted between you and us. By creating an account, accepting an invitation to a workspace, or using the Service in any way, you agree to these Terms on behalf of yourself and, if applicable, the organization you represent.
1Acceptance of These Terms
By registering for, accessing, or using the Service, you represent that you have the legal authority to bind the organization on whose behalf you are acting (if any) to these Terms, and that you are at least 18 years old. If you do not agree to these Terms, you must not use the Service.
These Terms incorporate our Privacy Policy by reference, along with any order form, subscription confirmation, or other document that references these Terms.
2The Service
GomuGuard Pentest lets you configure and run automated and AI-assisted security assessments ("Assessments"), conversational engagements with an AI copilot ("Engagements"), and threat/attack simulations ("Simulations") against systems, applications, networks, and infrastructure that you designate ("Targets"). The Service captures findings, evidence, and generates reports based on the results of that activity.
The Service is a tool. It does not perform testing on its own initiative, and it does not verify, and cannot verify, that you or your organization actually own or are authorized to test any Target you configure. That verification is entirely your responsibility, as described in Section 4.
3Accounts, Workspaces & the Account Admin Role
The Service is organized around a tenant workspace created at registration. The person or entity that registers the workspace, and any user subsequently granted the Adminrole within it, is the "Account Admin." The Account Admin can invite additional users ("Members"), assign roles, configure billing, and manage the workspace's Targets, Assessments, and Engagements.
You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account, whether authorized by you or not. You must notify us promptly at [email protected] of any suspected unauthorized use.
The Account Admin is responsible for every Member's use of the workspace, including ensuring that every Member who configures a Target or launches an Assessment, Engagement, or Simulation has the authorization described in Section 4, and for enforcing that requirement within their own organization. Adding a Member to a workspace does not transfer or dilute the Account Admin's responsibility under these Terms — it is held jointly by the Account Admin and each acting Member.
5Assumption of Risk
Active security testing — including the automated exploitation, credential testing, fuzzing, and load generation the Service can perform — is inherently capable of causing service disruption, degraded performance, altered or corrupted data, triggered account lockouts, security-team alerts, temporary or extended downtime, or other operational impact on a Target and on systems connected to it. This is a characteristic of active testing itself, not a defect in the Service.
You acknowledge and accept this risk in full before running any Assessment, Engagement, or Simulation. You are responsible for deciding whether, when, and against which environments (for example, staging versus production) to run testing, for coordinating with your own operations and security teams beforehand, and for having appropriate backups, monitoring, and incident-response plans in place for any Target you test.
6Your Responsibilities
- Provide accurate registration, billing, and profile information, and keep it current.
- Ensure every Target, scope host, credential, and piece of context you submit to the Service is accurate and that you are authorized to submit it.
- Never submit a Target that is jointly operated or shared infrastructure (e.g. a multi-tenant SaaS platform, a shared cloud account, or a third party's network segment) unless your authorization from Section 4 extends to that shared environment specifically.
- Use credentials, session tokens, or other authentication material you provide to the Service (for example, through the credential-drop flow) only for Targets you are authorized to access with them.
- Review AI-generated findings, narratives, and proposed remediation before relying on them or acting on them against a live environment (see Section 8).
- Comply with all applicable laws, including computer-crime, data-protection, and export-control laws, in every jurisdiction from which you access the Service or in which a Target is located.
- Not use the Service to test, attack, or gather information about any system belonging to Xhorizyn or another customer's workspace.
7Prohibited Uses
In addition to Sections 4 and 6, you must not use the Service to:
- conduct testing against any Target without the authorization required by Section 4;
- test critical infrastructure, medical devices, safety systems, or any environment where disruption could endanger life or physical safety;
- violate the rights of any third party, including privacy, intellectual property, or contractual rights;
- attempt to circumvent usage limits, rate limits, or plan entitlements, or to reverse-engineer, resell, or white-label the Service without our written consent;
- upload malware, exploit code, or content intended to harm the Service itself or other customers; or
- use the Service in violation of any export-control or sanctions law (see Section 18).
We may suspend or terminate access for any violation of this Section, as described in Section 15.
8AI-Assisted Features & Automated Findings
The Service uses AI models — including a self-hosted language model that Xhorizyn operates on its own infrastructure — to assist with reconnaissance, conversational guidance in Engagements, payload suggestions, and narrative summaries. AI-generated output is probabilistic, not deterministic.
The Service does not guarantee that its findings are complete, accurate, or exhaustive. Automated tooling and AI models can produce false positives (reporting a vulnerability that does not exist) and false negatives (missing a real vulnerability). Findings, severity ratings, remediation guidance, and generated reports are provided to assist your own security judgment, not as a substitute for it, and must be independently verified before you rely on them for compliance attestations, remediation decisions, or any action against a production environment.
9Fees, Billing & Plans
Paid plans are billed in advance on a recurring basis (monthly, quarterly, or annual, as selected) through our payment processor. By subscribing, you authorize us and our payment processor to charge your designated payment method for all fees due.
Except where required by law or expressly stated otherwise, fees are non-refundable. We may change our pricing or plan entitlements prospectively, with notice, effective at your next renewal. If a payment fails, we may suspend access to paid features until the balance is resolved.
10Confidentiality
Each party may have access to the other's non-public information (including, for your workspace, Target details, findings, and evidence, and for us, non-public features of the Service). Each party agrees to use the other's confidential information only to perform its obligations under these Terms and to protect it with at least the same degree of care it uses for its own confidential information, and no less than reasonable care.
11Intellectual Property
Xhorizyn retains all right, title, and interest in and to the Service, including its underlying software, models, detection logic, and branding. You retain all right, title, and interest in your own data — including Target configurations, engagement transcripts, uploaded artifacts, and the findings and reports generated from your use of the Service ("Customer Data"). You grant us a limited license to process Customer Data solely to provide, secure, and improve the Service, as described in our Privacy Policy.
12Disclaimer of Warranties
Without limiting the foregoing, Xhorizyn does not warrant that the Service will be uninterrupted, timely, secure, or error-free; that it will identify every vulnerability present in a Target, or that every finding it reports reflects an actual, exploitable vulnerability; or that testing performed through the Service will not cause disruption, data alteration, or other impact to a Target, as described in Section 5.
13Limitation of Liability
This limitation applies in particular to, and Xhorizyn is not liable for, any damage, downtime, data loss, data corruption, business interruption, third-party claim, or other harm caused to a Target, to your systems, or to any third party's systems, arising from testing activity you initiated or configured through the Service, regardless of whether that activity was authorized by the Target's owner. That risk is allocated to you under Sections 4, 5, and 14.
Some jurisdictions do not allow the exclusion of certain warranties or the limitation of certain damages. In those jurisdictions, the exclusions and limitations in Sections 12 and 13 apply only to the maximum extent permitted by applicable law, and our liability is limited to the smallest amount permitted.
14Indemnification
You (and, where you act on behalf of an organization, that organization and its Account Admin, jointly and severally) agree to defend, indemnify, and hold harmless Xhorizyn, its officers, employees, and agents from and against any and all claims, demands, damages, liabilities, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:
- any Assessment, Engagement, or Simulation run against a Target you were not authorized to test, or that exceeded the scope of your authorization;
- any damage, disruption, data loss, or other harm caused to a Target or to any third party as a result of testing activity initiated through your account;
- your breach of these Terms, including the representations in Section 4;
- your violation of any applicable law or third party's rights; or
- content or credentials you submit to the Service.
We will provide you with prompt notice of any such claim and reasonable cooperation, at your expense, in its defense; you may not settle any claim in a manner that admits fault by Xhorizyn or imposes obligations on Xhorizyn without our prior written consent.
15Suspension & Termination
We may suspend or terminate your access to the Service, immediately and without notice, if we reasonably believe you have violated Section 4, 6, or 7, if required to do so by law, or to prevent harm to the Service, other customers, or a Target. You may cancel your subscription at any time; cancellation takes effect at the end of the current billing period unless stated otherwise.
Sections 4, 5, 10 through 14, and 19 through 22 survive termination of your account or these Terms.
16Data, Evidence & Retention
The Service automatically detects and redacts likely secrets and credentials (such as API keys, tokens, and session cookies) before they are persisted to an engagement transcript or sent to any AI model, both on the client side and, authoritatively, on our servers. This reduces, but does not eliminate, the risk that sensitive material is captured — you should still avoid pasting production secrets into the Service where avoidable.
Evidence, findings, and captured artifacts generated by an Assessment or Engagement belong to you as Customer Data (Section 11) and are retained as described in our Privacy Policy. You may delete captured evidence, findings, or an entire Engagement at any time through the Service; deletion is not necessarily instantaneous across backups.
17Third-Party Services
We use a small number of third-party services to operate the Service — for example, a payment processor to handle billing. Except for such narrowly-scoped processors disclosed in our Privacy Policy, AI processing within the Service runs on infrastructure we operate ourselves, not on a third-party AI vendor's platform. We are not responsible for the acts or omissions of third-party services outside our control.
18Export Control & Sanctions Compliance
The Service includes offensive security tooling that may be subject to export-control and economic-sanctions laws. You represent that you are not located in, and will not use the Service from or on behalf of, any country or region subject to comprehensive sanctions, and that you are not a person or entity restricted from receiving US-origin, or otherwise export-controlled, software or technology.
19Governing Law & Dispute Resolution
These Terms are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to these Terms or the Service will be brought exclusively in the state or federal courts located in Delaware, and you consent to the personal jurisdiction of those courts.
20Changes to These Terms
We may update these Terms from time to time. If we make a material change, we will provide notice (for example, by email or an in-product notice) before the change takes effect. Continued use of the Service after a change becomes effective constitutes acceptance of the updated Terms.
21General Provisions
Entire Agreement
These Terms, together with the Privacy Policy and any order form, constitute the entire agreement between you and Xhorizyn regarding the Service and supersede any prior agreements on the subject.
Severability
If any provision of these Terms is held unenforceable, the remaining provisions remain in full effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable.
No Waiver
Our failure to enforce any provision of these Terms is not a waiver of our right to do so later.
Assignment
You may not assign these Terms without our written consent. We may assign these Terms in connection with a merger, acquisition, or sale of assets.
Force Majeure
Neither party is liable for a failure to perform caused by events beyond its reasonable control.
22Contact Us
Questions about these Terms can be sent to [email protected].