These Terms of Service ("Terms") govern your access to and use of the Coastline autonomous penetration testing platform, the portal at portal.coastlinecyber.com, and any reports or deliverables produced by it (together, the "Service"), operated by Coastline Cyber Security ("Coastline", "we", "us"). By creating an account, submitting a scan, or accepting these Terms in the application, you agree to be bound by them. If you accept on behalf of an organization, you represent that you have authority to bind that organization, and "you" means that organization.
Coastline performs black-box external security testing driven by a scope you describe. A scan may include subdomain enumeration, attack-surface mapping, and active exploitation attempts across a range of vulnerability classes. Findings that pass a proof-of-exploitation check are delivered as a written report.
Security testing is inherently incomplete. Coastline does not warrant that the Service will identify every vulnerability present in a target, that reported findings represent the full extent of your risk, or that a target is secure because a scan reported nothing. Each report includes a coverage appendix stating what was tested and what was only enumerated; you should read it as part of the deliverable. The Service is one input to your security program, not a substitute for it.
The Service is autonomous and uses machine learning models to plan and interpret testing. Its behavior is probabilistic: two scans of the same target may differ. Findings may include false positives, and severity ratings are estimates. You are responsible for validating findings before acting on them.
This section is the condition on which the Service is provided.
For every scan you submit, you represent and warrant that, as to each in-scope domain, host, IP address, network range, application, and account:
Many assets are hosted by third parties. Authorization from an application owner does not necessarily extend to the hosting provider, CDN, or upstream network. You are responsible for obtaining any additional consent those providers require.
Coastline applies technical scope controls — in-scope and out-of-scope fences, rate limiting, and exclusions for assets that resolve to private address space or appear to belong to third parties. These are engineering safeguards, not legal verification. We do not and cannot confirm that you are authorized to test what you submit, and no scope control should be relied on as evidence of authorization.
You will not use the Service to test any system you are not authorized to test; to attack, disrupt, or degrade any system; to access, exfiltrate, or retain data you are not entitled to; to violate any applicable law, including the U.S. Computer Fraud and Abuse Act, the Massachusetts Computer Crime statutes, or comparable law in your jurisdiction; or to evade any provider's security controls other than as part of authorized testing. You will not resell or provide the Service to a third party as a testing service without our written agreement.
Your scan prompt and any rules of engagement you supply — including declared rate limits, excluded assets, and prohibited techniques — are instructions to the Service and part of these Terms. Supplying inaccurate or incomplete rules is a breach of Section 3.1.
We may suspend or terminate a scan or an account immediately, without refund of credits consumed, if we reasonably believe it is being used outside the authorization you warranted, if testing is causing harm to a target or to third parties, or if we receive a credible complaint from an asset owner. Where practical we will tell you why.
The Service is sold in credits. Credits are consumed as a scan runs; unused credits from an allocation return to your balance when the scan completes. Credits have no cash value, are not transferable, and expire as stated at purchase. Subscription plans renew until cancelled. Where a scan fails for reasons attributable to the Service, we will restore the credits consumed. We do not refund credits spent on a scan that ran as specified, including one that produced no findings — a clean result is a result.
Scan results describe security weaknesses in your systems. We treat your scopes, findings, reports, and supplied credentials as your confidential information, and will not disclose them except to our sub-processors as needed to run the Service, or where compelled by law. Our handling of personal data is described in the Privacy Policy. You retain all rights in your data and in the reports produced for you.
If you provide test credentials, you warrant they belong to accounts created for testing and that their use is authorized. Do not supply production administrator credentials or credentials belonging to real users.
Coastline retains all rights in the Service, its engine, methodology, and report templates. Nothing here transfers those rights. You may use reports produced for you without restriction for your own security, compliance, and disclosure purposes, including submission to a bug bounty program.
Except as expressly stated, the Service is provided "as is" and "as available". To the fullest extent permitted by law, Coastline disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or that it will not cause an unintended effect on a target system. Active security testing carries inherent risk of service disruption, and you accept that risk for the assets you submit.
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data, arising from these Terms. Coastline's total aggregate liability arising out of or relating to the Service will not exceed the amounts you paid to Coastline in the twelve months preceding the event giving rise to the claim.
Nothing in these Terms limits liability that cannot lawfully be limited, including liability for fraud, willful misconduct, or, where applicable, claims under Massachusetts General Laws Chapter 93A.
You will defend, indemnify, and hold harmless Coastline and its personnel from any claim, demand, loss, liability, damages, fine, or expense (including reasonable attorneys' fees) arising out of or relating to: (a) your breach of the authorization warranty in Section 3; (b) testing conducted against any asset you were not authorized to test; (c) your violation of any law or third-party right in connection with your use of the Service; or (d) any claim brought by an asset owner, hosting provider, or network operator concerning testing you initiated.
This obligation survives termination and is a material part of the consideration for providing the Service.
These Terms are governed by the laws of the Commonwealth of Massachusetts, without regard to its conflict-of-laws rules. The exclusive venue for any dispute is the state or federal courts located in the Commonwealth of Massachusetts, and each party consents to personal jurisdiction there. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
We may update these Terms. Material changes will be posted here with a revised date and, where we have your email, notified to you. Continued use after a change takes effect is acceptance. The Terms in force when a scan is submitted govern that scan.
If a provision is held unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger or sale of assets. These Terms, with the Privacy Policy and any order form, are the entire agreement between us concerning the Service.
Coastline Cyber Security, Massachusetts, United States.
Questions about these Terms: coastlinecyber.com/contact-us