SecurityBoat

Legal

Usage Agreement

This page will set the rules for customers and researchers actually operating inside the TriNetra platform — what a client organization may scope for testing, what a researcher may and may not do against a client's assets, and how authorization, scope boundaries, and rules-of-engagement work across PTaaS, Bug Bounty, Agentic Pentest, and ASM's scan-request flows. It governs product usage; the Terms of Use govern the marketing website itself.

⚠︎ Full legal text pending counsel review.

Nothing below is drafted policy language — it is a structural outline of the sections the final page will contain. Do not publish, link from a binding flow, or represent this page as final until legal counsel has reviewed and approved the language.

Planned coverage

What this usage agreement will cover

  • Authorized scopetesting (pentest, agentic pentest, bug bounty, or scan) is only ever authorized against assets a client has explicitly added and approved through the platform's own request flows (e.g. ASM's Add Target / Cloud Target wizard, PTaaS's engagement request) — never blanket or assumed scope.

  • Researcher conductrules of engagement for anyone testing under a Bug Bounty program or PTaaS engagement: no testing outside declared scope, no data exfiltration beyond proof-of-concept, responsible disclosure timelines, and consequences for violations.

  • Client responsibilitiesaccurate asset ownership representations, timely response to scoping and retest requests, and cooperation with the review process each request flow already describes.

  • Payouts and rewardsresearcher payout terms referencing the platform's real reward tiers (P1–P5) and payout mechanics, without restating exact figures here.

  • Findings ownership and confidentialitywho owns a finding's data, how long it's retained, and confidentiality obligations for both client and researcher.

  • Suspension and terminationgrounds for suspending a researcher's or client's platform access.

  • Liability for authorized testing activityclarifying that testing conducted within approved scope under this agreement is authorized activity, not unauthorized access.

  • Contact for usage disputesa named channel, once assigned ⚠︎.

Placeholder metadata

Not yet finalized

Effective date:
⚠︎ to be set on publish
Governing entity:
SecurityBoat ⚠︎ confirm exact legal entity name with counsel
Contact:
⚠︎ usage/compliance contact address pending

Questions about scope or rules of engagement before this agreement is finalized? Reach us directly.