These Platform Terms govern access to and use of the Teisoft Exposure Platform™. If the customer has executed a Master Services Agreement or Order Form with Teisoft, that agreement controls in case of conflict.
1Customer authority
The individual accepting these Terms represents that they have authority to bind the customer organization.
The platform is intended for business use and not for personal, household, or consumer purposes.
2Subscription and access
Subject to payment and compliance with these Terms, Teisoft grants the customer a limited, nonexclusive, nontransferable right to use the platform during the subscription term.
Accounts may be used only by authorized users associated with the customer.
The customer is responsible for account administration, permissions, credentials, and user activity.
3Authorized targets
The customer may submit or authorize testing only for domains, applications, APIs, IP addresses, infrastructure, and other systems that the customer owns or has explicit legal authority to assess.
The customer represents and warrants that:
- It has authority to register every target.
- Testing does not violate third-party agreements.
- Required internal and third-party permissions have been obtained.
- Scope information is accurate.
- Teisoft is authorized to perform the selected activities.
Teisoft may request evidence of authorization and may reject, suspend, or remove a target when authorization is uncertain.
4Security testing restrictions
Unless expressly authorized in writing, the platform and services may not be used to:
- Scan or test third-party systems.
- Conduct denial-of-service testing.
- Disrupt production.
- Destroy, alter, or exfiltrate data.
- Deploy malware.
- Conduct phishing or social engineering.
- Attempt credential stuffing or password attacks.
- Bypass physical or organizational controls.
- Access data beyond what is necessary to demonstrate a finding.
- Test critical systems whose failure could create a safety risk.
- Conduct illegal surveillance or interception.
- Retaliate against attackers or conduct “hack back” activity.
5Customer data
The customer retains ownership of data submitted to the platform.
The customer grants Teisoft permission to host, process, reproduce, analyze, and transmit customer data only as necessary to:
- Provide the service.
- Secure the platform.
- Provide support.
- Prevent misuse.
- Comply with law.
- Perform obligations under the customer agreement.
The customer is responsible for the legality, accuracy, and quality of submitted data.
6Security findings
Security findings, reports, evidence, and remediation records produced for the customer are confidential customer information, subject to Teisoft’s underlying methodologies, templates, tools, and intellectual property.
The customer may use reports internally and share them with authorized auditors, insurers, customers, and advisors subject to confidentiality.
Reports may not be altered misleadingly or used to imply certification, endorsement, or guaranteed security.
7Aggregated data
Teisoft may create and use aggregated or de-identified information to:
- Operate and improve the service.
- Develop security intelligence.
- Measure trends.
- Produce benchmarking or research.
Such information must not reasonably identify the customer, its users, or an individual.
8Acceptable use
Customer use must comply with the Acceptable Use & Authorized Testing Policy.
Teisoft may investigate suspected misuse and suspend activity when reasonably necessary to protect systems, third parties, or the platform.
9Third-party services
Certain functionality may depend on third-party providers, integrations, intelligence sources, or security tools.
Third-party services may be governed by additional terms and may change or become unavailable.
Teisoft is not responsible for third-party services outside its reasonable control.
10No guarantee of complete detection
The platform may produce false positives, false negatives, incomplete attribution, or findings whose relevance changes over time.
Teisoft does not guarantee that:
- Every asset will be discovered.
- Every vulnerability will be detected.
- Every finding is exploitable.
- Every attack path will be identified.
- Every remediation will be effective.
- Use of the platform will prevent an incident.
- The customer will achieve compliance.
Customers must use professional judgment and maintain additional controls appropriate to their risk.
11Fees and renewal
Fees, billing cycles, subscription periods, usage limits, and renewal terms will be stated in the Order Form.
Unless the Order Form states otherwise:
- Fees are noncancelable and nonrefundable.
- Taxes are the customer’s responsibility.
- Late amounts may result in suspension.
- Changes in scope may require additional fees.
12Suspension
Teisoft may suspend access when:
- Payment is overdue.
- Use creates security or legal risk.
- Targets appear unauthorized.
- Customer use violates these Terms.
- Suspension is required by law.
- Continued operation may harm Teisoft, the customer, or a third party.
Where practicable, Teisoft will provide notice and an opportunity to cure.
13Termination and data return
Upon termination or expiration of the applicable subscription, the customer may request an export of available Customer Data for thirty (30) days after the effective date of termination or expiration.
Teisoft will use commercially reasonable efforts to provide the export in a commonly used electronic format within ten (10) business days after receiving a valid request.
Unless a different period is stated in the applicable Order Form, Teisoft may delete Customer Data from active systems ninety (90) days after termination or expiration.
Residual encrypted backup copies may remain until deleted or overwritten through Teisoft’s normal backup-rotation process, ordinarily within ninety (90) days after deletion from active systems. Backup data will remain protected and will not be processed except when reasonably necessary for disaster recovery, business continuity, security, or legal purposes.
After the thirty-day export window expires, Teisoft will have no obligation to provide or recover Customer Data, except as required by applicable law or expressly agreed in writing.
14Confidentiality
Each party will protect the other party’s nonpublic information using reasonable care and use it only for the contractual relationship.
Confidentiality exclusions cover information that is public, previously known, independently developed, or lawfully received from another source.
15Intellectual property
Teisoft owns the platform, software, methodologies, scanning techniques, interfaces, documentation, templates, improvements, and related intellectual property.
No ownership transfers to the customer.
The customer owns its data and customer-specific deliverables, subject to Teisoft’s pre-existing materials and intellectual property.
16Security and privacy
Teisoft will maintain appropriate administrative, technical, and organizational safeguards.
Processing of customer personal data will be governed by the applicable Data Processing Addendum.
No security measure eliminates all risk.
17Warranties
Teisoft warrants that it will provide paid services materially in accordance with the applicable documentation and agreement.
The customer’s exclusive remedy for a verified material breach of this warranty is re-performance or, if re-performance is not commercially reasonable, termination and refund of prepaid fees for the affected unused period.
All other warranties are disclaimed to the extent permitted by law.
18Indemnification
The final agreement includes:
- Teisoft defense of qualifying third-party intellectual-property claims arising from the platform.
- Customer defense of claims arising from unauthorized targets, unlawful instructions, customer data, or prohibited use.
- Notice, control-of-defense, and cooperation procedures.
- Appropriate exclusions and remedies.
19Limitation of liability
The customer agreement establishes:
- Exclusion of indirect and consequential damages.
- A general liability cap tied to fees paid during a defined prior period.
- A potentially higher “super-cap” for confidentiality, data protection, or security obligations.
- Exclusions that cannot legally be limited.
- Separate treatment of customer unauthorized-testing obligations.
20Governing law
Unless the applicable Order Form provides otherwise, Florida law and an agreed Broward County venue apply.
21Contact
Questions concerning platform use may be sent to [email protected].
© 2026 Teisoft LLC. All rights reserved.