Legal
Last updated: September 2026
By creating an account or using CarbonMantis (the "Service"), you agree to these Terms. If you use the Service on behalf of an organization, you represent that you're authorized to bind that organization.
CarbonMantis performs automated penetration testing of web applications and APIs and returns confidence-rated findings with reproducible evidence. It is a complement to, not a replacement for, expert-led security testing and a broader security program.
You may only scan targets you own or are explicitly authorized to test. Scanning is gated behind ownership verification, but you remain solely responsible for ensuring you have the necessary authorization for every target and scope you configure. Using the Service to test systems without authorization is strictly prohibited and may be unlawful. You agree to indemnify us against claims arising from targets you were not authorized to test.
You're responsible for safeguarding your credentials and API keys and for activity under your account. Notify us promptly of any unauthorized use.
You agree not to misuse the Service, including by attempting to disrupt it, circumvent isolation or rate limits, reverse engineer it, or use it to harm others or violate the law.
We may modify or discontinue features, and we perform maintenance from time to time. We aim to communicate material changes in advance.
The Service is provided "as is." Automated testing cannot find every vulnerability, and a clean scan is not a guarantee of security. You remain responsible for your own security posture and decisions.
To the maximum extent permitted by law, CarbonMantis is not liable for indirect, incidental, or consequential damages, and our aggregate liability is limited to the amounts you paid us in the 12 months preceding the claim.
These Terms are governed by the laws of [Jurisdiction — to be finalized].
We may update these Terms; material changes will be communicated through the Service.
Questions about these Terms? Email [email protected].