← Back to home

Terms of Service

Last updated: August 27, 2026

These Terms have not been reviewed or approved by legal counsel. Public paid plans and live charging are not available. Contact dsovan2004@gmail.com with questions.

1. Acceptance and Account Authority

By creating an account or using DefendML's services (the “Service”), you agree to these Terms. DefendML is operated by Sareth Dustin Sovan trading as DefendML (“DefendML,” “we,” or “us”).

You represent that you have authority to accept these Terms for yourself and, when you use the Service for an organization, for that organization. You are responsible for securing account credentials, limiting account access to authorized users, and notifying us if you believe an account has been compromised. DefendML is a business service and is not directed to children.

2. Access Model

Free account creation and Free onboarding are self-service. Creating a Free account does not grant reviewed Production or Custom organization access. Production and Custom access, additional limits, support, exports, or other entitlements may require separate review and written approval. Access remains organization-scoped and may be limited by the organization's entitlements.

Public paid pricing and live charging are not available. DefendML will not automatically convert or charge a Free organization.

3. Authorized Security Testing

The Service performs authorized pre-deployment offensive AI testing against Targets that you configure. Before an assessment runs, the product requires a Review & Run authorization confirmation. That confirmation records your representation; it does not mean DefendML independently established your legal authority.

You must own or have sufficient authorization to test every Target and related system you submit. You are responsible for defining an appropriate scope and ensuring that your use and submitted data are lawful.

4. Prohibited Use

  • Do not test a system without sufficient authorization.
  • Do not use the Service for unlawful, abusive, destructive, or malicious activity.
  • Do not bypass tenant boundaries, access another customer's data, or interfere with the Service.
  • Do not submit malware, unlawful content, or personal data unnecessary for an authorized assessment.
  • Do not copy or use DefendML's proprietary attack library to create a competing testing service.

These restrictions do not prohibit legitimate, authorized red-team testing within the agreed scope.

5. Customer Data and Target Configuration

You retain your rights in Target configuration, assessment inputs, Target responses, findings, evidence, and other content you submit or generate (“Customer Data”). You grant DefendML the limited right to process Customer Data as needed to operate, secure, support, and improve the Service as described in the Privacy Policy.

Provide only data needed for the assessment and do not submit personal or confidential data unless authorized. Target credentials and custom headers may be stored for use in authorized assessments; customer-facing responses expose configuration status, not stored values.

6. DefendML Intellectual Property

DefendML retains its rights in the Service, software, testing methods, attack library, report formats, branding, and related materials. Subject to these Terms and access limits, you may use your Reports and exports for internal security, remediation, procurement, and audit-support purposes and share them with professional advisers, auditors, and regulators.

7. Findings, Evidence, and Fix Plan Guidance

Findings, evidence, Reports, Fix Plan guidance, and retest outcomes describe retained evidence and test scope available at the assessment time. They do not guarantee complete discovery, continued security, successful remediation, certification, or satisfaction of a legal or regulatory requirement.

Remediation guidance is advisory. DefendML does not automatically modify customer code, deploy fixes, or assume implementation responsibility. A closed remediation case does not prove resolution; verified resolution requires qualifying retained retest evidence.

8. Availability and Delivery Targets

The Service is provided on an “as available” basis. Any stated evidence-delivery time is an operational target, not a guaranteed service level. A binding support, availability, delivery, or service-level commitment must appear in a separate written agreement signed by DefendML.

9. Fees and Future Paid Services

Current self-service Free access is non-billable. Stripe test-mode infrastructure may be used for internal validation, but DefendML does not currently enable live public checkout or automatic charging. Any future paid service requires your explicit selection and applicable commercial terms. Renewal, cancellation, refund, tax, and payment terms will be presented before a paid commitment.

10. Suspension and Termination

You may stop using the Service at any time. DefendML may suspend or terminate access when reasonably necessary to address prohibited use, security risk, legal obligations, future agreed nonpayment, or material breach. Data handling after termination is described in the Privacy Policy and remains subject to technical, security, backup, legal, and audit requirements.

11. Disclaimers and Liability

To the extent permitted by applicable law, the Service is provided “as is” and without warranties that every vulnerability will be identified or that use will make a Target secure. Nothing excludes or limits liability that cannot lawfully be excluded or limited.

No governing-law, venue, arbitration, class-action waiver, indemnity, or negotiated liability-cap provision is established by this version. Those provisions require owner and licensed-counsel review before paid contracting.

12. Changes

We may update these Terms by posting the revised version and effective date here. If applicable law or an executed agreement requires additional notice or consent, we will follow that requirement. Continued use does not waive a consent right required by law.

13. Contact

Questions: dsovan2004@gmail.com