Terms and Conditions
Last updated: September 3, 2026
These Terms and Conditions ("Terms") govern your access to and use of the BlackBrains security-scanning platform, available at blackbrains.tech.
1. Agreement
By creating an account or using BlackBrains, you agree to these Terms. If you are agreeing on behalf of a company, you confirm you are authorised to bind it. If you do not agree, do not use the service.
2. What the service does
BlackBrains runs automated security tools against websites you nominate and returns a report on the weaknesses found. The tools currently used include OWASP ZAP, Nmap, ffuf, sqlmap and WPScan. We also provide an optional AI layer that explains findings in plain language, a browser extension for single-page checks, and an optional Jira integration. Automated scanning is not a penetration test and is not a substitute for one.
3. Accounts
• You must be 18 or older. • You must give accurate registration details and keep your password confidential. • You are responsible for everything done through your account. • Login requires a code sent to your email address. • Tell us immediately at info@blackbrains.tech if you suspect unauthorised access. We may suspend or terminate an account that breaches these Terms, and we will do so immediately for a breach of section 4 (Authorisation to scan).
4. Authorisation to scan — the most important term
You may only scan systems you own, or that you have explicit written permission to test. Before starting any scan you represent and warrant that: 1. You own the target, or you hold documented authorisation from its owner to have it security-tested by a third party on your behalf; 2. That authorisation covers automated and intrusive testing, including request flooding, directory brute-forcing and SQL-injection probing; 3. You have the authority to grant us permission to test it; and 4. Your testing complies with the law everywhere you and the target are located. Why this matters. Scanning a system without authorisation is a criminal offence in most countries — for example under the UK Computer Misuse Act 1990, the US Computer Fraud and Abuse Act, and equivalent laws elsewhere. Running an unauthorised scan through our platform does not make it lawful, and does not shift responsibility to us. You accept that: • We do not and cannot verify that you are authorised. We rely entirely on your word. • We keep records (account, IP address, target, timestamp) and will disclose them to law enforcement on a valid legal request. • Any account used for unauthorised scanning will be terminated immediately and without refund. • You indemnify us in full for any claim arising from a scan you were not authorised to run. Scanning can disrupt the target. Active tools send large volumes of traffic and deliberately malformed input. This can slow a site, fill logs, trigger alerts and rate limits, create junk records through forms, or in some cases cause an outage. Scan systems you can afford to disrupt, scan outside peak hours, and take a backup first. You accept this risk. Use the excluded-paths setting to keep sensitive areas (checkout, admin, payment flows) out of scope.
5. Acceptable use
You must not: • Scan any system you are not authorised to scan; • Use the service to attack, disrupt, or gain unauthorised access to anything; • Use it against critical national infrastructure, medical or safety-critical systems; • Attempt to break out of, overload, reverse engineer or bypass the limits of our platform; • Resell or white-label the service without our written agreement; • Share your account, or automate access outside the documented API; • Upload malware, or use the platform to store or distribute unlawful content; • Enter credentials for any system you do not control.
6. Plans, credits and payment
Plans are sold as scan credit packs: Basic — Light Scan Pack: $15.00, 2 scan credits. Professional — Standard Scan Pack: $45.00, 5 scan credits. Advanced — Deep Audit Pack: $119.00, 10 scan credits. • Payment is handled by Stripe. By subscribing you also accept Stripe's terms. • A scan reserves credits when it starts; unused credits from a completed scan are returned. • Credits consumed by a scan that ran are not refundable, including where the scan finished early at its time limit or where a tool failed after starting. • Plans include limits on tools, scan depth and runtime. Exceeding them requires an upgrade. • We may change pricing with 30 days' notice to existing subscribers.
7. Scan results — what we promise and what we do not
We do not promise to find every vulnerability. Automated tools miss things. A clean report means the tools we ran did not detect a problem — it is not a certificate that your site is secure, and must not be presented as one. Reports may also contain false positives: findings that look like vulnerabilities but are not. Verify findings before acting on them, and before reporting them to anyone else. Results reflect a single point in time. Your site changes; so does its risk. You own your scan results. You may use, export and share them. We process them only to provide and improve the service, as described in the Privacy Policy. Partial results. If some tools fail while others succeed, we still give you the findings from the tools that worked, and we label the result as partial. Partial results cover less than a complete scan — treat them accordingly.
8. Availability
We aim for high availability but do not guarantee uninterrupted service. We may take the platform down for maintenance, and scans are queued and may wait during busy periods.
9. Our intellectual property, and yours
The platform, its code, interface and branding are ours or our licensors'. We grant you a limited, non-exclusive, non-transferable right to use it under these Terms. Your data, your targets and your scan results remain yours. The service incorporates third-party open-source tools, each under its own licence.
10. Liability
Nothing in these Terms limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited. Subject to that: • The service is provided "as is". We exclude all implied warranties to the extent the law allows. • We are not liable for indirect or consequential loss, loss of profit, loss of data, business interruption, or reputational damage. • We are not liable for damage to a target system caused by a scan you authorised, nor for loss arising from a vulnerability our tools did not find, nor for your reliance on a finding that turns out to be a false positive. • Our total liability in any 12-month period is limited to the amount you paid us in that period. You indemnify us against claims arising from your breach of these Terms, and in particular from any scan you ran without authorisation.
11. Ending the agreement
You may stop using the service and delete your account at any time from account settings. Deletion is immediate and irreversible, and permanently erases your account and scan data as described in the Privacy Policy. Deleting your account does not automatically refund an unused plan — request that separately before deleting. We may suspend or terminate your access if you breach these Terms, if payment fails, or if required by law. For a breach of section 4 (Authorisation to scan) we will act immediately and without notice. Sections 4, 7, 9, 10 and 12 survive termination.
12. General
• If a provision is unenforceable, the rest stands. • We may update these Terms; material changes will be emailed to registered users at least 14 days before they take effect. Continuing to use the service after that means you accept them. • These Terms, with the Privacy Policy, are the whole agreement between us. • You may not transfer your rights under these Terms without our consent.
13. Contact
Email: info@blackbrains.tech Support: support@blackbrains.tech
Questions about these Terms? Contact us at info@blackbrains.tech.