Terms of Use
Last updated:
1. Purpose
These Terms of Use (hereinafter "Terms") set out the terms of access to and use of the products and services offered by own2pwn (hereinafter "the Services").
The Services include in particular:
- EASM, a SaaS platform for external attack surface mapping and monitoring
- AI-Native AppSec, a unified SAST / autonomous pentest / reporting platform
- Blackbox / Whitebox Web Pentest, audit engagements carried out by own2pwn consultants
- NIS2 Audit — technical scope: assessment of the effectiveness of technical measures within the meaning of article 21.2(f) of Directive (EU) 2022/2555, inventory of exposed assets, coverage matrix and remediation plan. This engagement excludes any governance component (risk analysis, ISSP, BCP/DRP, crisis management) and gives rise to no NIS2 certification or attestation of conformity — see article 1 bis of the Terms of Sale.
2. Acceptance of the Terms of Use
Use of the Services implies full and unreserved acceptance of these Terms of Use. If you do not accept these terms, please do not use the Services.
own2pwn reserves the right to modify the Terms of Use at any time. Users will be informed of any substantial modification. Continued use of the Services after a modification constitutes acceptance of the new terms.
3. Registration and user account
3.1 Account creation
Use of the SaaS platforms (EASM, AI-Native AppSec) requires creating an account. You must provide accurate, complete and up-to-date information when registering.
3.2 Account security
You are responsible for the confidentiality of your credentials. Any activity performed from your account is presumed to have been performed by you. Enabling two-factor authentication (2FA) is strongly recommended.
If you suspect unauthorised use, contact us immediately at: security@own2pwn.fr.
3.3 Eligibility conditions
The Services are reserved for professionals: legal entities (companies, administrations, associations) and individuals acting for the purposes of their professional activity. They are not offered to consumers.
By registering or subscribing, you declare that you are acting for the purposes of your professional activity, that you have the legal capacity to contract, and that you have the authority to bind the entity you declare. Online subscription requires entering the company name and SIRET number, as well as expressly accepting this declaration, which is timestamped and retained.
4. Rules of use and authorisation to scan
4.1 Authorised scope
Very important: the user warrants that they hold the written and explicit authorisation of the owner of each asset (domain, application, infrastructure) before submitting it for analysis via the Services.
You undertake to submit only scopes over which you have legal control or for which you hold a duly issued penetration-testing mandate.
4.2 Prohibited uses
The following are in particular prohibited:
- Scanning or testing assets you do not own and for which you have no explicit mandate
- Using the Services for unlawful, fraudulent or malicious purposes (hacking, denial of service, extortion)
- Attempting unauthorised access to the systems, data or accounts of third parties, including own2pwn's
- Circumventing the technical limitations, quotas or security mechanisms of the Services
- Using automated means (bots, scrapers) not provided for by the official API
- Reselling, redistributing or hosting the Services without written authorisation
- Extracting or reusing the databases (CVE signatures, detection rules) outside of normal use of the Services
4.3 User responsibility
Important: the results produced by own2pwn's automated tools are an aid to analysis. They do not replace a human review by a qualified professional before any remediation decision or communication.
You remain solely responsible for:
- The lawfulness of the scope submitted to the Services
- Verifying and prioritising findings
- Remediation decisions and their implementation
- Communicating results to third parties (clients, auditors, regulators)
5. Service availability
own2pwn implements reasonable means to ensure the availability of the SaaS platforms 24/7, subject to interruptions for planned maintenance or force majeure. No availability is guaranteed outside of a service level agreement (SLA) formalised in a dedicated Enterprise contract.
6. Prices and payment
6.1 Pricing plans
The applicable prices are those displayed on the product pages or, for Enterprise offers, defined in a signed quote. They are expressed in euros and net of VAT: THE HIVE falls under the French small-business VAT exemption (art. 293 B of the CGI) and charges no VAT — the displayed amount is the amount due. Existing clients benefit from 30 days' notice before any price increase. Details of the VAT regime appear in article 3 of the Terms of Sale.
6.2 Billing
Subscriptions are billed monthly or annually depending on the chosen plan. Payments are made by credit card (via Stripe) or by bank transfer for Enterprise offers.
6.3 Termination and refunds
You may terminate your subscription at any time from your account. Termination takes effect at the end of the current period. No pro-rata refund is provided, except where otherwise required by law.
7. Intellectual property
7.1 own2pwn's rights
All elements of the Services (software, interfaces, AI models, algorithms, signature databases, content) are the exclusive property of own2pwn or its licensors.
7.2 Licence to use
own2pwn grants you a non-exclusive, non-transferable and revocable licence to use the Services in accordance with these Terms, for the duration of your subscription.
7.3 User content
You retain all rights over the assets submitted (source code, configurations, scan scopes) and the generated reports. You grant own2pwn a limited licence to process this content solely for the purpose of providing the Service.
Important: we never resell your data and never use it to train our AI models without your explicit and formalised consent.
8. Protection of personal data
Data processing is carried out in accordance with the GDPR and our Privacy Policy.
9. Limitation of liability
Within the limits permitted by law:
- own2pwn does not warrant the exhaustiveness of detection. No tool, human or automated, can guarantee the discovery of all vulnerabilities in a system.
- own2pwn cannot be held liable for the consequences of decisions taken on the basis of the reports or alerts generated.
- own2pwn cannot be held liable for service interruptions, data loss, or indirect damage.
In any event, own2pwn's liability is limited to the amount paid by the client during the 12 months preceding the event giving rise to liability.
10. Suspension and termination for breach
own2pwn reserves the right to suspend or terminate access to the Services in the event of:
- Breach of these Terms, in particular section 4 (prohibited uses, authorised scope)
- Fraudulent or abusive use
- Non-payment of sums due
- Conduct harmful to the interests of own2pwn, its users or third parties
In the event of termination for breach, no refund will be provided.
11. Force majeure
own2pwn cannot be held liable for any failure to perform its obligations due to an event of force majeure within the meaning of French case law (large-scale externally-originated cyberattack, failure of a critical supplier, natural disaster, etc.).
12. Governing law and dispute resolution
These Terms of Use are governed by French law. Any dispute relating to their interpretation or performance will be submitted to the competent courts of Cannes, unless a mandatory provision provides otherwise.
13. Miscellaneous provisions
If any provision of these Terms of Use is deemed invalid or unenforceable, the remaining provisions shall remain in force. own2pwn's failure to exercise a right provided for in these Terms does not constitute a waiver of that right.
14. Contact
- Email: contact@own2pwn.fr
- Contact form: /en/contact