Acceptable Use Policy & Rules of Engagement

Version 2026-10-06, effective 2026-10-06

This policy explains what you may and may not do with PentestHub AI. It is part of the Terms of Service. If anything here is unclear, ask before you test.

1. Authorization comes first

Test only assets you own, or for which you hold explicit, written and current authorization from the owner (contract, signed ROE, or a bug bounty program's published scope and safe harbor). Record the basis of your authorization for every target in the Service and keep it up to date.

2. Rules of Engagement

  • Stay inside the authorized assets, time window and methods.
  • Stop and ask the owner if you are unsure whether something is in scope.
  • Use the minimum intensity needed; avoid degrading the target's availability.
  • Collect only the proof of concept needed to demonstrate an issue.
  • Report findings only to the owner or through the program's official channel.

3. Prohibited activities

  • Accessing systems or data without authorization.
  • Denial-of-service, load or stress testing without explicit written permission.
  • Exfiltrating, changing or deleting data beyond a minimal proof of concept.
  • Social engineering or phishing of people who have not agreed to it.
  • Targeting critical infrastructure, government or military systems without written authorization from the responsible authority.
  • Testing third-party services that a target merely uses (payment, email, cloud or SaaS providers) without their own authorization.
  • Using the Service for extortion, ransomware, malware, spam, or to attack the Service itself.
  • Sharing your account or reselling access to the Service.

4. Built-in safeguards

Active scans require a valid, unexpired authorization on the target. The hosted Service does not actively scan private or internal network ranges, localhost or cloud metadata addresses, and by default refuses certain government and military domains. Owners who need such an asset tested can contact us. These safeguards reduce mistakes; they do not replace your own authorization.

5. If something goes wrong

If you accidentally access personal or sensitive data, stop, do not keep a copy and inform the owner. If you cause an outage, stop testing and contact the owner immediately.

6. Enforcement

Breaches may lead to blocked scans, suspension or termination of your account, and, where required or appropriate, reporting to the competent authorities. We keep audit records to investigate abuse.

7. Reporting abuse

To report abuse of the Service, email support@pentesthubai.com.