CTEMEGA

Terms of Service

Last updated: September 15, 2026

AGREEMENT

1. Acceptance of terms

By creating an account or otherwise accessing CTEMEGA (the “Service”), you agree to these Terms of Service. If you are using the Service on behalf of an organization, you represent that you have the authority to bind that organization to these terms. CTEMEGA is a Continuous Threat Exposure Management platform — discovery, attack surface analysis, attack graph correlation, AI-assisted triage, governed exploit validation, and automated response, offered as software. It is not a substitute for a manual penetration test, a security consulting engagement, or professional services tailored to your environment, and using it does not constitute a guarantee that your systems are secure or free of vulnerabilities.

2. Authorized use only

CTEMEGA performs active security scanning — including reconnaissance and, on paid plans, Deep Scan techniques — against targets you register. You must only register targets you own or have explicit, documented authorization to scan. You are solely responsible for ensuring your use of the Service complies with applicable law and the terms of service of any third party whose infrastructure your targets run on.

3. Exploit validation and Governed Exploit Validation

Where your plan includes it, Governed Exploit Validation reproduces a suspected exploit against a registered target to confirm whether it's actually exploitable. This capability is gated by the same authorization requirement as Section 2, plus its own explicit rules of engagement, technique scoping, and rate limits — and, outside a narrow, pre-approved, zero-payload technique tier, requires your approval before it runs. You are responsible for ensuring you have the authority to authorize exploit-validation activity against a given target, independent of whether you have authority to register it for scanning.

4. AI-assisted features

OMEGA Intelligence and its AI Agents produce assistive analysis — severity assessments, threat context, risk scoring, and recommendations. These outputs are decision support, not guaranteed-correct determinations, and you remain responsible for reviewing and acting on them appropriately.

5. Automated actions and approval

Consequential automated actions — such as applying a remediation or running a higher-risk validation technique — require your approval within the platform before they execute. A narrow set of lower-risk, pre-approved, zero-payload actions (for example, certain Safe Autonomy L5 validation techniques on Enterprise plans) may run without a per-run approval click; these remain scoped, rate-limited, and revocable, and are never used for destructive or higher-risk techniques.

6. Accounts and plans

Accounts start on the Free plan. Paid plans (Starter, Pro) are billed through Dodo Payments; Enterprise arrangements are agreed separately. Plan limits (scan targets, monitoring, AI usage, validation technique coverage, and other features) are enforced as described on our Pricing page and may change with notice.

7. Billing

Dodo Payments is our current payment processor for paid plans. Charges, invoices, and payment method management happen through Dodo Payments' own checkout and billing flows.

8. Customer responsibilities

You are responsible for:

  • Ensuring you have authorization to register, scan, and — where applicable — validate every target you add to the Service.
  • The legality of your use of the Service under applicable law and any third party's terms.
  • Any credentials, cloud accounts (e.g. AWS, Kubernetes), or integrations you connect, and their configuration.
  • Your organization's own environment, access controls, and who on your team can approve consequential actions.

9. Suspension and termination

You may stop using the Service and cancel a paid subscription at any time. We may suspend or terminate access for unauthorized target scanning or validation, abuse of the Service, violation of these terms, or other reasonable grounds related to protecting the Service or other customers.

10. Disclaimer and limitation of liability

The Service is provided “as is” and “as available.” We don't warrant that the Service will be uninterrupted or error-free, that it will detect every vulnerability, or that using it makes your systems secure — no security platform can promise that, and CTEMEGA doesn't either. To the maximum extent permitted by applicable law, CTEMEGA is not liable for indirect, incidental, or consequential damages arising from your use of the Service, and our total liability for any claim is limited to the amount you paid us for the Service in the twelve months preceding the claim. Nothing here limits liability that can't be limited under applicable law.

11. Changes

We may update these terms as the Service evolves. Material changes will be reflected here with an updated date.

12. Contact

Questions about these terms: customer.service@ctemega.com