complyeah
Legal

Terms of Use

Effective September 3, 2026

These Terms of Use ("Terms") govern your access to and use of the complyeah External Security and Agent Readiness service (the "Service"). By creating an account or using the Service, you agree to these Terms. If you are using the Service on behalf of an organization, you represent that you are authorized to bind it.

The Service

complyeah performs external security testing of internet-facing assets you control and read only AI Buyer Journeys on verified websites. It produces evidence, reports, fixes, private share links, and, only for qualifying security tests, certificates mapped to common compliance frameworks. Agent Readiness reports are not certifications.

Agent Readiness authorization and safe use

Agent Readiness requires its own current authorization in addition to domain ownership. The runner may read visible pages, follow safe navigation on the verified domain, scroll, open read only controls, and capture screenshots. It does not submit forms, log in, send email, purchase, reserve, upload, download, modify data, or conduct security exploitation. You must not design a journey intended to circumvent these controls or target a third party.

Accounts

You must provide an accurate email address and keep your account secure. Sign-in is passwordless via single-use magic links; you are responsible for activity conducted through your account.

Authorization to test - you may only scan what you control

This is the core rule of the Service. You represent and warrant that, for every domain or asset you submit, you are the owner or are expressly authorized by the owner to have it tested. You must:

  • complete our ownership verification (DNS or HTTP proof) before any scan runs;
  • record a scan authorization defining scope and rules of engagement; and
  • never use the Service against any system you do not own or are not authorized to test.

Unauthorized scanning of third-party systems is prohibited and may violate law (including computer-misuse and unauthorized-access statutes). You are solely responsible for ensuring you have authorization, and you agree to indemnify us against claims arising from assets you submit without proper authorization.

Acceptable use

  • Do not attempt to disrupt, overload, or circumvent the Service or its safeguards.
  • Do not use the Service to violate the rights of others or any applicable law.
  • Do not resell or misrepresent reports or certificates.

One-time purchases, subscriptions, and fees

A comprehensive penetration test is paid for with a pre-paid scan credit, purchased at the price shown before checkout. Payments are processed by our merchant of record, Creem, which handles billing and applicable taxes. Each credit entitles you to one comprehensive scan of one verified domain and is valid for 365 days (12 months) from purchase, after which it expires. Expiry dates are shown in your account, and we send reminder emails before a credit expires. A completed one-time pentest includes one full retest used within 60 days. Credits are one-time purchases, not a subscription. A scan that fails on our side does not consume a credit: we automatically restore it to your balance and email you. We may change our fees; any change applies only to future purchases, and we will give reasonable advance notice of a price increase. Credits you have already bought keep the terms in effect when you bought them.

Continuous is a recurring subscription for one verified domain, billed monthly or annually at the price shown before checkout. It currently includes three posture scans and five Agent Readiness runs in each monthly period, with up to ten workflow nodes per run, plus one comprehensive external pentest in each subscription quarter, available immediately, with at most four such pentests in a rolling year. Monthly allowances do not roll over and quarterly pentests do not stack. Each completed pentest includes one full retest within 60 days. One execution of a complete Agent Readiness workflow is one agent run.

Business is a recurring monthly subscription for up to three verified domains in one workspace. It includes per-domain posture and quarterly pentest allowances, one workspace pool of five Agent Readiness runs each month, workflows of up to thirty nodes, and focused monitoring of selected critical regression nodes. The purchased domain and up to two additional verified workspace domains are covered. New verified domains enter coverage when fewer than three eligible domains are present.

You may cancel Continuous or Business from the billing controls. Cancellation stops renewal and remains effective through the already-paid current period unless the checkout terms or applicable law require otherwise. Cancellation does not erase existing reports; they remain readable under the applicable retention policy. Provider failures that never start a browser session or produce a customer result do not consume Agent Readiness quota.

Right of withdrawal and refunds

You may withdraw from a purchase and receive a refund for any credit you have not used, within 14 days of purchase. Refunds are per-credit, at the price you actually paid, returned to your original payment method via Creem, and are self-serve from your billing page. Because a comprehensive scan is a digital service performed on request, starting a scan with a credit constitutes your express request to begin performance and your acknowledgement that you thereby lose the right of withdrawal for that credit. After 14 days, unused credits are non-refundable but remain valid until their 12-month expiry. A credit that has been spent on a scan, or that has expired, is not refundable, except for the automatic restoration of a credit when a scan fails on our side. Nothing in this policy limits rights you may have under applicable law.

Reports, sharing, and no guarantee

Reports reflect observations at a point in time. Security testing cannot identify every vulnerability, and Agent Readiness cannot predict every software agent or personalized experience. A report, outcome, or certificate is not a warranty that an asset is secure, compliant, or usable by every agent, and is not legal or audit advice. Private share links are published only when you explicitly create them; anyone with an active link may view its sanitized report until it expires or you revoke it.

Intellectual property

We retain all rights in the Service and its software. You retain rights in your data and the reports generated for your assets, and you may use and share them for your own compliance and security purposes.

Disclaimers and limitation of liability

The Service is provided "as is" without warranties of any kind, to the fullest extent permitted by law. To the maximum extent permitted by law, complyeah will not be liable for indirect, incidental, or consequential damages, and our total liability arising from the Service will not exceed the amount you paid us in the twelve months before the claim.

Termination

You may stop using the Service at any time. We may suspend or terminate access for breach of these Terms - in particular, for scanning assets you are not authorized to test.

Changes, governing law, and contact

These Terms are versioned by their effective date, shown at the top of this page. When you authorize a scan, we record your acceptance of the Terms in force at that time, together with the version and a timestamp. We may update these Terms; continued use after changes take effect constitutes acceptance. Questions: support@complyeah.com.