Terms of Service

Coastline Cyber Security · Last updated 4 August 2026
Read Section 3 before you run a scan. Coastline actively probes and attempts to exploit the systems you name in your scope. You are solely responsible for confirming that you are authorized to test every asset you submit. If you are not, do not use this service.

1. Agreement

These Terms of Service ("Terms") govern your access to and use of the Coastline autonomous penetration testing platform, the portal at portal.coastlinecyber.com, and any reports or deliverables produced by it (together, the "Service"), operated by Coastline Cyber Security ("Coastline", "we", "us"). By creating an account, submitting a scan, or accepting these Terms in the application, you agree to be bound by them. If you accept on behalf of an organization, you represent that you have authority to bind that organization, and "you" means that organization.

2. The Service

Coastline performs black-box external security testing driven by a scope you describe. A scan may include subdomain enumeration, attack-surface mapping, and active exploitation attempts across a range of vulnerability classes. Findings that pass a proof-of-exploitation check are delivered as a written report.

2.1 No guarantee of completeness

Security testing is inherently incomplete. Coastline does not warrant that the Service will identify every vulnerability present in a target, that reported findings represent the full extent of your risk, or that a target is secure because a scan reported nothing. Each report includes a coverage appendix stating what was tested and what was only enumerated; you should read it as part of the deliverable. The Service is one input to your security program, not a substitute for it.

2.2 Automated and AI-assisted operation

The Service is autonomous and uses machine learning models to plan and interpret testing. Its behavior is probabilistic: two scans of the same target may differ. Findings may include false positives, and severity ratings are estimates. You are responsible for validating findings before acting on them.

3. Authorization — your core obligation

This section is the condition on which the Service is provided.

3.1 Warranty of authorization

For every scan you submit, you represent and warrant that, as to each in-scope domain, host, IP address, network range, application, and account:

3.2 Shared infrastructure

Many assets are hosted by third parties. Authorization from an application owner does not necessarily extend to the hosting provider, CDN, or upstream network. You are responsible for obtaining any additional consent those providers require.

3.3 We do not verify your authorization

Coastline applies technical scope controls — in-scope and out-of-scope fences, rate limiting, and exclusions for assets that resolve to private address space or appear to belong to third parties. These are engineering safeguards, not legal verification. We do not and cannot confirm that you are authorized to test what you submit, and no scope control should be relied on as evidence of authorization.

3.4 Prohibited use

You will not use the Service to test any system you are not authorized to test; to attack, disrupt, or degrade any system; to access, exfiltrate, or retain data you are not entitled to; to violate any applicable law, including the U.S. Computer Fraud and Abuse Act, the Massachusetts Computer Crime statutes, or comparable law in your jurisdiction; or to evade any provider's security controls other than as part of authorized testing. You will not resell or provide the Service to a third party as a testing service without our written agreement.

3.5 Rules of engagement

Your scan prompt and any rules of engagement you supply — including declared rate limits, excluded assets, and prohibited techniques — are instructions to the Service and part of these Terms. Supplying inaccurate or incomplete rules is a breach of Section 3.1.

4. Suspension

We may suspend or terminate a scan or an account immediately, without refund of credits consumed, if we reasonably believe it is being used outside the authorization you warranted, if testing is causing harm to a target or to third parties, or if we receive a credible complaint from an asset owner. Where practical we will tell you why.

5. Credits, billing and refunds

The Service is sold in credits. Credits are consumed as a scan runs; unused credits from an allocation return to your balance when the scan completes. Credits have no cash value, are not transferable, and expire as stated at purchase. Subscription plans renew until cancelled. Where a scan fails for reasons attributable to the Service, we will restore the credits consumed. We do not refund credits spent on a scan that ran as specified, including one that produced no findings — a clean result is a result.

6. Your data and our confidentiality obligation

Scan results describe security weaknesses in your systems. We treat your scopes, findings, reports, and supplied credentials as your confidential information, and will not disclose them except to our sub-processors as needed to run the Service, or where compelled by law. Our handling of personal data is described in the Privacy Policy. You retain all rights in your data and in the reports produced for you.

6.1 Credentials you supply

If you provide test credentials, you warrant they belong to accounts created for testing and that their use is authorized. Do not supply production administrator credentials or credentials belonging to real users.

7. Our intellectual property

Coastline retains all rights in the Service, its engine, methodology, and report templates. Nothing here transfers those rights. You may use reports produced for you without restriction for your own security, compliance, and disclosure purposes, including submission to a bug bounty program.

8. Disclaimer of warranties

Except as expressly stated, the Service is provided "as is" and "as available". To the fullest extent permitted by law, Coastline disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or that it will not cause an unintended effect on a target system. Active security testing carries inherent risk of service disruption, and you accept that risk for the assets you submit.

9. Limitation of liability

To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data, arising from these Terms. Coastline's total aggregate liability arising out of or relating to the Service will not exceed the amounts you paid to Coastline in the twelve months preceding the event giving rise to the claim.

Nothing in these Terms limits liability that cannot lawfully be limited, including liability for fraud, willful misconduct, or, where applicable, claims under Massachusetts General Laws Chapter 93A.

10. Indemnification

You will defend, indemnify, and hold harmless Coastline and its personnel from any claim, demand, loss, liability, damages, fine, or expense (including reasonable attorneys' fees) arising out of or relating to: (a) your breach of the authorization warranty in Section 3; (b) testing conducted against any asset you were not authorized to test; (c) your violation of any law or third-party right in connection with your use of the Service; or (d) any claim brought by an asset owner, hosting provider, or network operator concerning testing you initiated.

This obligation survives termination and is a material part of the consideration for providing the Service.

11. Governing law and venue

These Terms are governed by the laws of the Commonwealth of Massachusetts, without regard to its conflict-of-laws rules. The exclusive venue for any dispute is the state or federal courts located in the Commonwealth of Massachusetts, and each party consents to personal jurisdiction there. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

12. Changes

We may update these Terms. Material changes will be posted here with a revised date and, where we have your email, notified to you. Continued use after a change takes effect is acceptance. The Terms in force when a scan is submitted govern that scan.

13. General

If a provision is held unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger or sale of assets. These Terms, with the Privacy Policy and any order form, are the entire agreement between us concerning the Service.

14. Contact

Coastline Cyber Security, Massachusetts, United States.
Questions about these Terms: coastlinecyber.com/contact-us