02Prohibited activity
You must not use the Service to:
- Scan, probe, enumerate, or test any system without authorization from its owner.
- Attempt to access, exfiltrate, alter, or destroy data you are not entitled to.
- Conduct denial-of-service, volumetric load, or resource-exhaustion attacks, or use the Service as a proxy to attack a third party.
- Circumvent authentication, authorization, rate limits, quotas, or plan entitlements, including by creating multiple accounts to obtain additional free usage.
- Reverse engineer, decompile, or extract the Service's source, models, prompts, or detection logic, except to the extent applicable law expressly permits.
- Resell, sublicense, or provide the Service to third parties as your own scanning product without a written agreement with us.
- Upload malware, or use the Service to develop, host, or distribute tooling whose primary purpose is unauthorized intrusion.
- Route special-category, health, payment card, or government-identifier data through the Service where you have no lawful basis to do so.
- Interfere with the integrity, availability, or isolation of our infrastructure, or attempt to break out of a scanner or runner container.
- Use the Service in violation of export control, sanctions, or any other applicable law.
03Automation and agent actions
Sentrail can draft migrations, pull requests, and configuration changes. You remain the operator of your systems and are responsible for every change you approve. You must not configure or attempt to configure the agent to bypass the approval gate for production-changing actions, and you must not use agent credentials to perform actions outside the connected project's scope.
Automated access through our API, MCP server, or tokens must stay within documented rate limits and your plan's entitlements. Tokens are personal to your organisation and must not be shared.
04Handling findings responsibly
Findings can describe exploitable weaknesses. Treat them as confidential to the organisation that owns the system. If a check reveals a vulnerability in third-party software, disclose it through that vendor's own disclosure process rather than publishing it, and never use a finding to gain unauthorized access.
05Reporting abuse
If you believe Sentrail is being used against a system you own, or otherwise in breach of this policy, email abuse@sentrail.dev with the target, timestamps, and any observed source addresses. To report a vulnerability in Sentrail itself, use our responsible disclosure policy.
06Enforcement
ZerwOne Network LLC may investigate suspected violations and may suspend or terminate access, revoke tokens, or disconnect an integration — without notice where there is a risk of harm to a third party, to our infrastructure, or of legal exposure. Where the situation allows, we will contact you first and give you an opportunity to remediate. We cooperate with lawful requests from authorities. Suspension for a breach of this policy does not entitle you to a refund.
Modelled on the acceptable-use and authorized-testing terms published by established security-testing and cloud vendors, and on the authorization requirement common to computer-misuse statutes including the U.S. Computer Fraud and Abuse Act. Provided for information; it is not legal advice.