Legal Policies

Last updated: 14-September-2026


Terms of Service

Effective Date: 14-September-2026

These Terms of Service ("Terms") govern your access to and use of Vuln-X, an automated OWASP Top 10-based web vulnerability assessment platform (the "Service"). By creating an account or using the Service, you agree to be bound by these Terms. If you do not agree, do not use the Service.

1. Eligibility

You must be at least 18 years old, or the age of legal majority in your jurisdiction, to create an account. By registering, you confirm that the information you provide is accurate and that you meet this requirement.

2. The Service

Vuln-X performs automated security testing across the OWASP Top 10 (2017) categories — Injection, Broken Authentication, Sensitive Data Exposure, XML External Entities, Broken Access Control, Security Misconfiguration, Cross-Site Scripting, Insecure Deserialization, Vulnerable Components, and Insufficient Logging & Monitoring — and produces a scan report. The Service is an automated tool, not a substitute for manual penetration testing or professional security audit, and does not guarantee detection of all vulnerabilities.

3. Account Responsibilities
  • You are responsible for maintaining the confidentiality of your login credentials and for all activity under your account.
  • You must notify us promptly of any unauthorized use of your account.
  • You may not share account credentials or resell access to the Service without our written consent.
4. Authorized Use Only

You may only run a scan against a target — a website, domain, IP address, or system — that you own, or for which you have obtained clear, explicit, written authorization to test. Scanning any target without authorization is strictly prohibited, may violate computer-misuse and cybercrime laws in your jurisdiction, and will result in immediate suspension of your account. See our Ethical Use Policy for full detail.

5. Intellectual Property

The Service, including its scanning engine, dashboard, report templates, and branding, is the property of its operator and is protected by applicable intellectual property laws. Scan results and reports generated from your own scans belong to you; you are granted no other rights in the Service beyond what is needed to use it as intended.

6. Prohibited Conduct

In addition to unauthorized scanning, you agree not to:

  • Use the Service to launch denial-of-service, destructive, or data-modifying attacks against any target
  • Attempt to disrupt, reverse-engineer, or gain unauthorized access to the Service's own infrastructure
  • Use the Service to violate any applicable law or the rights of any third party
  • Misrepresent scan reports as an official, certified, or comprehensive security audit
7. Service Availability

The Service is provided on a best-effort basis. As an actively developed platform, features, scan modules, and availability may change, and scheduled or unscheduled downtime may occur without prior notice. We do not guarantee uninterrupted or error-free operation.

8. Suspension and Termination

We may suspend or terminate your account, without prior notice, for unauthorized scanning, abuse of the Service, non-payment, or any breach of these Terms. You may stop using the Service and request account closure at any time by contacting us (see Privacy Policy for account-deletion status).

9. Changes to These Terms

We may update these Terms from time to time. Material changes will be reflected by an updated "Effective Date" above. Continued use of the Service after changes take effect constitutes acceptance of the revised Terms.

10. Governing Law

These Terms are governed by the laws of the Islamic Republic of Pakistan, without regard to conflict-of-law principles, except where local law requires otherwise.

11. Contact

Questions about these Terms can be sent to: support@vuln-x.com


Privacy Policy

Effective Date: 14-September-2026

This Privacy Policy describes how Vuln-X collects, uses, stores, and discloses information in connection with your access to and use of the Service.

1. Information We Collect

We collect and process the following categories of data:

  • Account Information: Name, email address, and hashed login credentials. We never store your password in plain text.
  • Technical Data: IP address, browser type, device information, and access/session logs, collected for security and session-management purposes.
  • Scan Data: The target URL you submit, the resolved IP address, your chosen scan type, and the full findings/report produced by the scan. This data is tied to your account and visible in your Scan History.
  • Payment Verification Data: For paid plans, the transaction ID and payment-proof screenshot you submit for manual verification (see Payment Terms). We do not collect or store card numbers, mobile-wallet PINs, or other payment credentials — verification is manual, based on the proof you provide.
2. How Scan Data Is Used

When you run a scan, the Service sends requests to the target you specify in order to test it and to build your report. In the course of testing, the Component Vulnerability module may query the public NVD (National Vulnerability Database) CVE API using a generic technology/version string it detected (for example, "Apache 2.4.7") to check for known CVEs — this lookup never includes your target's URL, IP address, or any of your account information.

3. Purpose of Data Processing
  • To provide and operate the scanning Service and generate your reports
  • To maintain your account, authenticate you, and secure your session
  • To verify manually-submitted subscription payments
  • To detect, prevent, and respond to abuse or unauthorized scanning
  • To comply with legal obligations where applicable
4. Data Retention

Account information and scan history are retained for as long as your account remains active, so that your Scan History and reports stay accessible to you. If you request account deletion (see Section 8 below), we will delete or anonymize your account and scan data within a reasonable period, except where retention is required by law.

5. Data Security

Passwords are stored hashed, not in plain text. We use reasonable technical safeguards to protect stored data. No online system can guarantee absolute security, and you should never reuse your Vuln-X password on other services.

6. Data Sharing and Disclosure

We do not sell or rent your personal data. Information may be shared only:

  • With infrastructure providers strictly necessary to run the Service (e.g. hosting, database)
  • As a generic, non-identifying version string sent to the public NVD API, as described in Section 2 above
  • Where required to comply with a legal obligation or valid legal process
7. Cookies and Sessions

We use session cookies to keep you logged in and to protect your account (e.g. CSRF protection). We do not use third-party advertising or tracking cookies.

8. Your Rights and Account Deletion

You can export a full copy of your account, scan history, payment history, and session data at any time from Settings → Data & Privacy. You can also permanently delete your account and all associated data yourself from that same page — this requires your current password and cannot be undone. If you'd rather we handle either request manually, email us instead.

9. Children's Privacy

The Service is not directed at, and we do not knowingly collect data from, individuals under the age of 18.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Effective Date" above.

11. Contact

For privacy-related inquiries, contact: support@vuln-x.com


Ethical Use Policy

Effective Date: 14-September-2026

Vuln-X is built for lawful, authorized security testing and education. This policy explains exactly what "authorized" means and what we expect from every user.

1. What You May Scan
  • Systems, domains, or applications that you personally own
  • Systems your employer or client has given you explicit written permission to test (e.g. a signed pentest engagement letter or a documented bug-bounty scope)
  • Intentionally vulnerable training targets designed for security practice (for example, publicly offered "vulnerable by design" test applications), used in line with that target's own terms
2. What You May Not Scan

You may not scan any third-party production system — including but not limited to government, educational, corporate, or public websites — without that owner's explicit written authorization, even if the scan is "just informational" or non-destructive by design. Lacking authorization is a violation of these policies regardless of your intent.

3. Non-Destructive by Design, Not by Guarantee

Vuln-X's modules are designed to be non-destructive (e.g. read-only probes, time-based checks) rather than to exploit or modify data. However, no automated scanner can guarantee zero impact on every possible target configuration. You remain fully responsible for any impact your scan has on a target, authorized or not.

4. Enforcement

We may investigate reported or detected misuse. Confirmed unauthorized scanning will result in immediate account suspension or termination, and may be reported to the affected party and relevant authorities where appropriate.

5. Reporting Misuse

If you believe your system was scanned by a Vuln-X user without your authorization, contact us at security@vuln-x.com with the target, approximate time, and any evidence (e.g. server logs) — we will investigate.


Responsible Disclosure Policy

Effective Date: 14-September-2026

If you discover a security vulnerability in the Vuln-X platform itself (not in a target scanned by Vuln-X, but in Vuln-X's own website, API, or infrastructure), we ask that you disclose it to us responsibly.

1. How to Report

Email security@vuln-x.com with a clear description of the issue, the steps to reproduce it, and its potential impact. Please include proof-of-concept detail rather than a mass automated scan of our own infrastructure.

2. What We Ask
  • Give us a reasonable opportunity to investigate and remediate before any public disclosure
  • Do not access, modify, or delete data belonging to other users while investigating an issue
  • Do not run denial-of-service testing or automated brute-force testing against our infrastructure
  • Report in good faith — this policy does not protect testing carried out against other users' scan targets or accounts
3. What You Can Expect

As a small, actively developed project, response times are best-effort rather than SLA-backed. We aim to acknowledge reports promptly and will keep you informed as we investigate and remediate valid findings.


Data Handling Policy

Effective Date: 14-September-2026

This policy summarizes, in plain terms, exactly where your data lives and how it flows through the Service — a more technical companion to the Privacy Policy above.

1. Where Your Data Is Stored

Account records, scan configurations, and scan results are stored in our database. Passwords are stored as salted hashes, never in plain text.

2. What Leaves Our Infrastructure, and Where
  • To your scan target: HTTP(S) requests and, where applicable, Nmap network probes are sent directly to the target URL/IP you provide, in order to test it.
  • To the public NVD CVE API: a generic detected technology/version string only (e.g. "nginx 1.18") — never your target's URL, IP address, or your account data — used to cross-reference known CVEs for the Vulnerable Components (A9) check.
  • Nowhere else. We do not share scan data or account data with advertising networks, analytics trackers, or data brokers.
3. Payment Proof Handling

Payment-proof screenshots and transaction IDs you submit are stored solely to verify your subscription payment and are reviewed manually. They are not used for any purpose beyond payment verification.

4. Data You Can Request

Export and account deletion are self-service from Settings → Data & Privacy (see Privacy Policy, Section 8). You can also email support@vuln-x.com to request either be handled manually instead.


Disclaimer

Effective Date: 14-September-2026

The Service is provided strictly for lawful cybersecurity testing, educational use, and authorized vulnerability assessment.

1. No Warranty

The Service is provided "as is" and "as available" without warranties of any kind, whether express or implied, including but not limited to accuracy, reliability, or completeness of scan results. Automated scanning cannot detect every vulnerability, and the absence of a finding is not proof that a target is secure.

2. Limitation of Liability

To the maximum extent permitted by law, we shall not be liable for:

  • Any direct, indirect, incidental, or consequential damages arising from use of the Service
  • Data loss, system damage, or business interruption on any target you scan
  • Inaccurate, incomplete, or false-positive/false-negative vulnerability findings
  • Any consequence of scanning a target without proper authorization
3. User Responsibility

Users are solely responsible for ensuring:

  • They have explicit authorization to scan the target they submit
  • Compliance with all applicable laws and regulations in their jurisdiction and the target's
  • Proper, confidential handling of scan results and findings, since a report may itself describe an exploitable weakness
4. No Guarantee of Security

Use of this Service, or a "clean" scan report, does not guarantee that a system is secure or free from vulnerabilities. Manual, expert penetration testing is recommended for any system of genuine importance.

5. Third-Party Tools and Data

The Service relies on third-party components (including Nmap and the public NVD CVE database) to produce parts of its findings. We are not responsible for the accuracy, availability, or output of these third-party tools and data sources.

6. Indemnification

Users agree to indemnify and hold harmless the Service and its operator from any claims, damages, or liabilities arising from the user's misuse of the Service, including unauthorized scanning of a target.

By using the Service, you acknowledge and accept this disclaimer in full.


Refund Policy

Effective Date: 14-September-2026

This Refund Policy governs all paid-plan purchases made through the Service.

1. General Policy

All payments are final and non-refundable except as expressly stated below.

2. Eligible Refund Cases

Refunds may be granted at our sole discretion if:

  • The Service was unavailable due to a verified technical failure on our side for a significant portion of your billing period
  • You paid for a plan but it was never manually activated on your account despite valid payment proof
  • A genuine billing/amount error occurred
3. Non-Refundable Cases

Refunds will not be issued for:

  • Partial or unused scans within an active billing period
  • Forgetting to submit renewal payment before your plan expired (see Payment Terms — plans do not auto-renew)
  • User error or a misunderstanding of what a plan includes
  • Violations of the Terms of Service or Ethical Use Policy, including unauthorized scanning
4. Request Procedure

Refund requests must be submitted within 7 days of the transaction to support@vuln-x.com and include:

  • Your account email
  • The original transaction ID / payment proof
  • A description of the issue
5. Processing Time

Approved refunds are processed manually within 7–14 business days, via the same payment method (Easypaisa, JazzCash, Nayapay, or Sadapay) used for the original transaction.

6. Subscription Cancellation

Because subscriptions are manually activated and do not auto-renew, "cancellation" simply means not submitting a renewal payment — there is no recurring charge to stop. Your access remains active until the end of the period your last approved payment covers.

7. Chargebacks

Since payments are verified manually against proof you submit (not processed through a card gateway we control), a false or fraudulent chargeback claim may result in account suspension pending review.


Payment Terms

Effective Date: 14-September-2026

These Payment Terms govern all financial transactions conducted through the Service. Read this section carefully — Vuln-X uses manual, proof-of-payment billing, not automatic card or wallet charging.

1. Pricing and Plans

Current plans and pricing are shown on our Pricing page and may be updated periodically. A price change will not affect a period you have already paid for.

2. How Billing Actually Works

Vuln-X does not store your card, mobile-wallet, or bank details, and does not automatically charge you. Instead:

  • You send payment directly via Easypaisa, JazzCash, Nayapay, or Sadapay to the account details shown on the Subscription page
  • You submit the transaction ID and a screenshot of the payment as proof
  • Your submission is recorded as pending and reviewed manually
  • Once verified, your plan is manually activated on your account, typically within 24 hours
3. Subscription Renewal — No Auto-Renewal

Subscriptions do not renew automatically, because there is no stored payment method to charge. To keep a paid plan active, you must submit a new payment and proof before your current period ends. If you take no action, your account simply reverts to the Free plan at the end of the period — you will not be charged unexpectedly.

4. Taxes

Displayed prices are in PKR and are not itemized for tax. You are responsible for any taxes applicable to you under local law.

5. Payment Methods

We accept manual transfers via Easypaisa, JazzCash, Nayapay, and Sadapay, verified against the transaction ID and proof you submit.

6. Service Suspension

We reserve the right to suspend or downgrade access for:

  • An expired paid period with no renewal submitted
  • Fraudulent or falsified payment proof
  • Violation of the Terms of Service or Ethical Use Policy
7. Currency

All prices and transactions are in PKR (Pakistani Rupees) unless otherwise stated.

8. Disputes

Report any billing discrepancy within 7 days of your transaction to support@vuln-x.com, including your transaction ID.

9. Modifications

We reserve the right to modify pricing, plans, or the payment-verification process, with the current terms always reflected on this page and the Subscription page.

By submitting a payment, you agree to these Payment Terms.