1. Definitions & Interpretation
In these Terms of Service (the "Terms"), the following terms have the meanings set out below:
- "CyberAgent.id", "we", or "us" refers to the provider of security audit and AI engineering services operating under the cyberagent.id domain.
- "Service" refers to the security audit work (testing of applications, APIs, source code, infrastructure and AI systems) and the AI engineering work we deliver under a written quote.
- "Engagement" refers to a single assignment agreed through a quote, covering scope, schedule and testing limits.
- "Client" refers to the individual or entity that accepts our quote.
- "Target" refers to any website, domain, or digital asset that you own or lawfully control and that is audited through the Service.
- "PoC" (Proof of Concept) refers to technical evidence demonstrating an exploit or vulnerability in a Target.
2. Acceptance of Terms
By accepting a quote, accessing our site, or using the Service in any form, you represent that you have read, understood, and agreed to all of these Terms and our Privacy Policy. If you do not agree with part or all of these Terms, we cannot take on the engagement.
Important: You are only permitted to audit Targets that you own yourself or for which you hold valid written authorization to audit. Auditing systems belonging to third parties without permission may violate applicable law.
3. Description of Service
CyberAgent.id provides security audit and AI engineering services, covering, but not limited to:
- Testing of web applications and APIs (OWASP Top 10, OWASP API Security Top 10, injection, XSS, IDOR, SSRF, and other attack vectors).
- Source-code review, external infrastructure review, and cloud configuration review.
- AI system testing, including resistance to prompt injection and data leakage through model answers.
- Findings reports with reproduction steps, CVSS 3.1 scores and remediation guidance, delivered by email.
We reserve the right to add, modify, or discontinue part or all of the Service features at any time with reasonable notice.
4. Engagement & Quotes
- Every assignment starts with a scoping call and a written quote setting out scope, schedule and testing limits.
- You warrant that you are authorised to approve testing of the assets listed in the quote.
- We may decline or stop an engagement where fraudulent activity, abuse, or a breach of these Terms is detected.
- Scope changes mid-engagement are recorded as an amendment to the quote before the work is carried out.
- Confidentiality of findings applies to both parties unless otherwise agreed in writing.
5. Permitted Use
You may only use the Service for lawful purposes, including:
- Security audits of Targets that you own or for which you hold written authorization to audit.
- Internal corporate security testing, due diligence, and security compliance.
- Official bug bounty activities in accordance with the applicable program scope.
6. Prohibited Use
You are prohibited from using the Service to:
- Audit, scan, or attack systems, networks, or websites belonging to third parties without written authorization.
- Violate any law, regulation, or policy applicable in your jurisdiction.
- Distribute malware, engage in extortion, steal data, or carry out any other criminal activity.
- Create fake or bulk accounts, or exploit system flaws to gain unauthorized access.
- Reverse engineer our platform, except where permitted by applicable law.
- Use bots, scrapers, or automation that exceeds the Service's fair use limits.
7. Fees, Quotes & Payment
- Fees are quoted per project after a scoping call, based on the agreed scope. We do not sell credits or subscription packages.
- A quote sets out scope, schedule and testing limits; work begins once the quote is accepted.
- Payment follows the schedule on the invoice, under the terms stated in the quote.
- Refunds are only processed in accordance with the applicable policy and prevailing laws and regulations.
8. Audit Results & PoC
- Audit results, findings, and PoCs produced by the Service are informational and intended to help you improve the security of your Target.
- You are responsible for verifying and re-testing all findings before taking action.
- We do not warrant that the audit will discover every vulnerability present in the Target.
9. Intellectual Property Rights
- All software, algorithms, AI models, designs, trademarks, and platform content are the property of CyberAgent.id or its licensors.
- Reports generated for you are licensed for your limited internal use, unless otherwise agreed.
- You may not copy, modify, or distribute any part of the material we hand over without written permission.
10. Confidentiality
We maintain the confidentiality of your audit data. Information about your Target, vulnerability findings, and technical details will not be shared with third parties without your consent, except where required by law.
11. Disclaimer & Disclaimers
The Service is provided "as is" and "as available" without warranties of any kind, whether express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement.
We do not warrant that: (a) the Service will operate uninterrupted or error-free; (b) all vulnerabilities will be detected; (c) audit results will be free of false positives or false negatives; or (d) the Service will be secure against external attack.
12. Limitation of Liability
To the maximum extent permitted by applicable law, in no event shall CyberAgent.id, its affiliates, directors, employees, or agents be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or reputational harm, arising out of or relating to the use of the Service, even if advised of the possibility of such damages. Our total liability for all claims shall not exceed the amount you paid to us in the last 6 (six) months.
13. Indemnification
You agree to release, indemnify, and hold CyberAgent.id harmless from any and all claims, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from: (a) your use of the Service; (b) your breach of these Terms; (c) infringement of third-party rights; or (d) your unlawful activities.
14. Term & Termination
These Terms apply for as long as you use the Service. We reserve the right to terminate or restrict your access to the Service, with or without notice, where: (a) you breach these Terms; (b) we suspect illegal activity or abuse; or (c) we discontinue the Service in its entirety.
Upon termination, provisions that by their nature must survive (including but not limited to: confidentiality, disclaimer, limitation of liability, indemnification, and governing law) shall remain in effect.
15. Freezing & Suspension
We may pause or terminate an engagement where suspicious activity, attempted unauthorized access, abnormal usage patterns, or indications of fraud are detected. During that period, work in progress may be paused until verification is complete.
16. Changes to the Terms
We may update these Terms at any time. Material changes will be notified by email or recorded on this page. Your use of the Service after the changes take effect constitutes acceptance of the updated Terms. The "Last updated" date at the top of this document will be updated accordingly.
17. Governing Law
These Terms are governed by and construed in accordance with the laws of the Republic of Indonesia, without regard to conflict of law provisions. Any dispute arising shall first be resolved through deliberation; if no agreement is reached, the dispute shall be resolved through the competent courts in Indonesia.
If you have any questions regarding these Terms, please contact us via: