Acceptable Use Policy
What Pental may and may not be used for. Written for a customer base that breaks into systems lawfully for a living, so the line matters more here than it does for most software.
This policy forms part of the Terms of Service. It applies to you, everyone using the Platform under your account, and anyone you grant portal access to. Breaching it is a material breach of the Terms.
Pental is a record-keeping and reporting platform for authorised security testing. It does not scan, exploit or attack anything. The lawfulness of the work you record on it is your responsibility, and holding valid written authorisation is the line we care about most.
Authorisation is your obligation
- You must hold valid, current, written authorisation from the system owner for every engagement whose data you store on the Platform.
- That authorisation must cover the scope you actually tested, for the dates on which you tested it.
- You must not use the Platform to record, organise or report on testing you were not authorised to perform.
- Where an engagement covers systems your client does not own, you must hold the third party's permission as well.
We do not verify authorisation and are not in a position to. Storing evidence of unauthorised access on the Platform does not make it lawful, and we will cooperate with law enforcement where required.
Prohibited uses
You must not use the Platform, or permit anyone to use it, to:
- Store, organise or distribute material obtained through unauthorised access to any system.
- Coordinate, plan or document any attack you are not contractually authorised to perform.
- Store malware, ransomware or exploit code for any purpose other than legitimate evidence within an authorised engagement.
- Host, distribute or trade stolen credentials, personal data or intellectual property.
- Impersonate another organisation, or brand the portal in a way designed to deceive its users about who operates it.
- Send unsolicited bulk email through the mail configuration, or use it for phishing outside an authorised social engineering engagement.
- Circumvent plan limits, licensing controls, rate limits or access controls, or share one subscription across separate legal entities.
- Interfere with the Platform's operation for other customers, including through denial of service or resource exhaustion.
- Test the Platform itself without our prior written permission. See responsible disclosure below.
Evidence and client data
You are handling other organisations' most sensitive material. The Platform gives you the controls; using them is on you.
- Capture the minimum evidence that proves a finding, and redact before it is stored rather than afterwards.
- Grant portal access to the people your client nominates, and keep that list current as their staff change. Client access is meant to persist between engagements: that is what the portal is for.
- Set a retention period for evidence and hold to it, separately from how long the reports themselves remain available to the client.
- Where a client gives you credentials to their systems for testing, collect only what the engagement requires and have those revoked on the end date. That is separate from their portal account, which stays.
AI use
- You are responsible for what you send to any AI provider you configure, and for compliance with that provider's terms and with your own client agreements.
- Where a client contract prohibits their data reaching a third-party model, either use a locally hosted model or leave AI switched off.
- Generated text is a draft. Publishing an unreviewed draft to a client is your risk, not a defect in the Platform.
Responsible disclosure
Given who our customers are, we assume the Platform will be looked at closely, and we would rather hear from you than not.
- Report anything you find to hello@pental.io. It reaches the people who wrote the code.
- Test only against your own instance and your own data. Do not touch another customer's portal or database.
- No denial of service, no social engineering of our staff or suppliers, no automated scanning that degrades the service.
- Give us reasonable time to fix an issue before disclosing it publicly.
- Act in good faith within these bounds and we will not pursue you.
Enforcement
Where we believe this policy has been breached we may suspend access, terminate the Subscription, or, where there is a risk of serious harm or a legal obligation, report the matter to the appropriate authority. We will give notice and an opportunity to remedy where the circumstances reasonably allow it.
Your database is in your own hosting account. Suspending access to the Platform does not delete, disable or reach into it.
Reporting abuse
If you believe a Pental customer is using the Platform in breach of this policy, email hello@pental.io with as much detail as you can share. Reports are treated confidentially.
Pental Limited, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. Registered in England and Wales, company number 17172077.
Questions about this document go to hello@pental.io. We answer them ourselves.