Terms of Service

Effective Date: February 10, 2026

Last Updated: June 10, 2026

Welcome to Hound. These Terms of Service ("Terms") govern your access to and use of the Hound website, platform, services, reports, communications, and any other Hound offerings that link to or reference these Terms. These offerings are operated by Hound, a Fauna AI company ("we," "us," or "our"), and are collectively referred to as the "Service." By submitting a domain, verifying a domain, purchasing or approving paid services, or otherwise using the Service, you ("you" or "Client") agree to be bound by these Terms. If you do not agree, do not use the Service.

1. Service Description

Hound provides AI-assisted security review and penetration testing services for web applications and related services.

The Service may include: (a) a free preliminary assessment workflow ("Assessment") that evaluates a submitted target to understand visible application surface, authentication surface, security-relevant structure, and potential paid testing coverage; and (b) paid security testing, retests, and other paid or custom services ("Paid Services").

An Assessment is a preliminary review and scoping workflow. It may identify security-relevant observations, but it is not a full penetration test and does not include the deliverables of a paid engagement.

Hound has no obligation to launch, perform, or deliver Paid Services unless Hound accepts the engagement and payment has been received.

The Service does not include social engineering or physical security testing.

2. Eligibility & Authority

You must be at least 18 years of age (or the age of majority in your jurisdiction) to use the Service.

By using the Service, you represent and warrant that you have the legal authority to authorize security review and testing for any target you submit or approve. If you are acting on behalf of an organization, you represent that you have the authority to bind that organization to these Terms.

3. Acceptable Use

You agree to use the Service only for lawful purposes and in accordance with these Terms. You agree not to:

  • Test any domain or system you do not own or are not explicitly authorized to test
  • Misrepresent your authority over any submitted domain, system, account, environment, or testing scope
  • Attempt to circumvent, disable, or interfere with the domain verification process
  • Use the Service to attack, harm, or disrupt any systems or services outside the Authorized Scope
  • Use security findings for malicious purposes, extortion, or unauthorized disclosure
  • Resell, redistribute, or provide access to the Service to third parties without our written consent
  • Use the Service in any manner that could damage, disable, or impair the Service or interfere with other users

We reserve the right to suspend or terminate your access immediately if we believe you are violating these restrictions.

4. Domain Verification & Authorization

You may submit only domains, applications, accounts, environments, and systems that you own or are authorized to test. The authorized scope for the Service ("Authorized Scope") includes the submitted domain; customer-controlled subdomains and services under the same registrable domain; and related applications, APIs, accounts, workflows, environments, or systems that are reasonably discovered from, connected to, or necessary to assess or test the submitted domain, except where Hound determines they are unsupported, unsafe, third-party-controlled, insufficiently authorized, or outside the applicable order or written scope.

Hound treats the submitted domain as the scope identity for domain-based Service activity. The submitted domain may be a root domain, such as example.com, or a subdomain, such as app.example.com. Domain verification may require you to place a DNS TXT record we provide at the submitted domain or, where accepted by Hound, at the registrable root domain.

By submitting and verifying a domain, you authorize Hound to perform Assessment activity for that submitted domain and any applicable Authorized Scope. By purchasing or approving a Paid Service, you authorize Hound to perform the applicable paid security testing or retesting within the applicable Authorized Scope.

Hound may reject or decline to test domains or systems that Hound determines are unsupported, unsafe, or insufficiently authorized. Unsupported targets may include hosted platform domains under provider-controlled shared suffixes, domains that use CNAME or other indirection outside the verified root, targets offered for HTTP-file verification instead of DNS verification, and submitted domains that clearly redirect to a different root domain.

If your application is hosted on third-party infrastructure (e.g., cloud providers), you are solely responsible for ensuring that your use of the Service complies with your hosting provider's acceptable use policies and any applicable terms of service.

5. Testing Scope & Methodology

Hound uses automated systems, AI agents, and human-directed review to assess and test the Authorized Scope. Hound may evaluate connected surface discovered during the Service when that surface is within the Authorized Scope.

Assessments are intended to help Hound and the Client understand application surface, authentication requirements, likely testing coverage, and whether a Paid Service is appropriate.

Paid engagements may include the testing methods Hound determines appropriate for the Authorized Scope. Hound may adapt those methods as it discovers new surface, access requirements, or operational constraints during the Service.

Retests are limited to evaluating remediation of findings from the applicable prior paid engagement unless Hound agrees otherwise.

Hound controls the tools, timing, and operational approach used to provide the Service, subject to the Authorized Scope and these Terms.

Assessments and Paid Services may involve creating accounts, sessions, or credentials on target systems within the Authorized Scope. You authorize Hound to create them as needed for assessment or security testing. You are responsible for identifying and removing any accounts or credentials created by Hound during testing. Credentials and authentication materials are handled as described in our Privacy Policy and any applicable written agreement.

6. Risks & Disclaimer

Security review and testing, including Assessments, Paid Services, and retests, may involve interacting with systems in ways that cause unexpected behavior, performance degradation, or service disruption. While we employ safety controls to minimize impact, you acknowledge that:

  • Service activity may cause temporary disruption or degradation of your services.
  • Results are provided on an "as-is" basis and represent a point-in-time review. Hound does not guarantee that all vulnerabilities will be identified.
  • AI-driven testing may produce false positives or false negatives.
  • The absence of findings does not mean your application is free of vulnerabilities.

We recommend using staging or non-production environments where possible.

The Service is provided on an "as available" basis. We do not guarantee uninterrupted or error-free operation of the Service and may perform maintenance or updates that temporarily affect availability.

7. Pricing & Payment

Hound may offer Assessments at no charge at our discretion. Paid Services are subject to the prices and terms presented by Hound at the time of purchase or agreement.

The specific scope, deliverables, service level, included support, and schedule for any Paid Service are determined by the applicable order, proposal, checkout flow, written confirmation, or other agreement accepted by Hound.

Paid Services are purchased as one-off runs unless Hound agrees otherwise.

One scope-bounded retest is included with each paid engagement unless Hound agrees otherwise. Additional runs, broader scope, extra retests, or custom work require separate agreement or fees.

Hound has no obligation to schedule, launch, perform, or deliver any Paid Service unless payment has been received. If payment is not received, fails, is reversed, is charged back, is disputed, or is otherwise not completed, the applicable Paid Service is unpaid. Hound may decline, pause, cancel, or withhold the applicable Paid Service or report delivery and may seek recovery of unpaid amounts, dispute fees, collection costs, and other amounts permitted by law.

Satisfaction guarantee: if you are not satisfied with a paid run, notify Hound within ten (10) business days after report delivery. Hound will either make reasonable corrective efforts or refund the fee paid for that run. This guarantee does not apply to custom work unless Hound agrees otherwise in writing.

Except for this guarantee or as required by law, fees are non-refundable. Hound may issue other refunds or credits in its sole discretion. Any discretionary refund or credit does not create an obligation to provide the same or similar refund or credit in the future.

Hound may modify pricing at any time. Pricing changes do not affect Paid Services already purchased or agreed.

8. Data Handling & Privacy

In the course of providing the Service, our systems may encounter or process data associated with your Authorized Scope. We handle such data in accordance with our Privacy Policy.

Your data is not used to train or improve any AI models. Data storage, retention, and security practices are described in our Privacy Policy.

9. Third-Party Services

The Service utilizes third-party artificial intelligence providers to deliver security testing and analysis. Your use of the Service is subject to the terms and policies of these providers to the extent applicable. No client data is shared with third-party providers for the purpose of model training or improvement.

10. Confidentiality

We treat all test results, security reports, and data encountered during testing as confidential. We will not disclose your results to third parties except as required by law or with your written consent.

You agree not to reverse engineer, decompile, or attempt to derive the underlying methods, algorithms, prompts, safety mechanisms, or proprietary systems of the Service. The Service's testing methodology and safety architecture are proprietary and confidential.

Notwithstanding the above, we may derive and use anonymized, aggregate data from testing activity that cannot reasonably be used to identify any specific client, domain, system, or individual. This includes, but is not limited to, vulnerability type classifications, finding counts, detection speed metrics, and trend analyses. We may use such data to improve the Service and to describe and promote our platform's capabilities, including in marketing materials and industry research.

11. Intellectual Property

You retain all rights to your applications, systems, and data. Subject to payment in full for Paid Services, upon delivery you own customer-facing reports and deliverables generated specifically for you, excluding Hound's pre-existing materials, platform, software, methods, templates, prompts, systems, and know-how.

All rights to the Hound platform, including its software, testing methodology, AI systems, safety controls, branding, and documentation, remain the exclusive property of Hound.

12. Limitation of Liability

To the maximum extent permitted by applicable law, Hound will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, goodwill, data, business opportunity, or service availability, arising out of or related to the Service or these Terms.

For Paid Services, Hound's total aggregate liability for all claims arising out of or related to the Service or these Terms will not exceed the amounts you paid to Hound for the Service in the twelve (12) months before the event giving rise to the claim.

For any free Assessment or other Service provided without a paid entitlement, Hound's total aggregate liability is zero dollars ($0), to the maximum extent permitted by law.

Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law.

13. Indemnification

You agree to indemnify, defend, and hold harmless Hound, its officers, employees, and agents from and against any claims, damages, losses, liabilities, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your misrepresentation of ownership or authorization over a submitted or tested target; (b) your violation of any third-party rights or agreements, including hosting provider terms; or (c) your use of the Service in violation of these Terms or applicable law.

14. Termination

You may stop using the Service at any time. We may refuse, suspend, terminate, or discontinue access to the Service or related support, decline a submitted target, cancel an Assessment, engagement, retest, or other Service activity, or pause, narrow, or stop testing at any time, for any reason or no reason, at our sole discretion.

Termination does not relieve you of payment obligations already incurred. Upon termination, your right to use the Service ceases immediately. We will retain or delete your data in accordance with our Privacy Policy.

15. Governing Law & Disputes

These Terms shall be governed by and construed in accordance with the laws of the State of North Carolina, without regard to its conflict of laws principles. Any disputes arising out of or related to the Service or these Terms shall be resolved in the state or federal courts located in North Carolina, and you consent to the personal jurisdiction of such courts.

16. Changes to These Terms

We may update these Terms from time to time. If we make material changes, we will notify you by email or by posting a notice through the Service or website. Your continued use of the Service after such changes constitutes your acceptance of the revised Terms.

Contact

If you have questions about these Terms, please contact us at support@cyberhound.ai.