Terms

Terms of service

Legal terms and conditions for using Nautillo Pro.

Version 1.5.1 | Last updated 2026-07-08 | Effective 2026-07-08

Agreement overview

These Terms of Service ("Terms") govern your use of Nautillo Pro's cybersecurity platform and services. By using our service, you enter into a legally binding agreement with NØRTH HŪMAN OÜ (Reg. No. 16865564).

Important: Our service is designed for authorized attack simulation only. Unauthorized use of offensive security tools may violate laws and regulations.

Acceptance and Account Registration

By accessing or using Nautillo Pro, you agree to be bound by these Terms of Service and our Privacy Policy.

Our Acceptable Use Policy is incorporated by reference and governs how you may use the platform.

You must be at least 18 years old and have the legal capacity to enter into this agreement.

You are responsible for maintaining the confidentiality of your account credentials and all activities under your account.

You must provide accurate, current, and complete information during registration and keep your account information updated.

Personal accounts are for use by a single individual only. Organizational accounts may add additional users exclusively through the platform's built-in team feature. Sharing credentials or granting access outside the team feature is prohibited.

Account owners must ensure anyone providing intrusive-test consent or managing credentials has authority to bind the organization and comply with applicable laws.

You may not create multiple accounts or use our service if we have previously terminated your account.

We reserve the right to refuse service, terminate accounts, or cancel orders at our sole discretion.

Permitted and Prohibited Use

Our service is designed for authorized attack simulation of websites and applications that you own or have explicit permission to evaluate.

You must comply with all rules in the Acceptable Use Policy, including authorization, simulation boundaries, and prohibited activities.

You must have written authorization from the website or application owner before conducting any attack simulations.

You may not use our service to test third-party websites without proper authorization.

Prohibited activities include: attacking systems you don't own, attempting to bypass our security measures, disabling platform safeguards (intrusive-test consent, audit logging, or rate limiting), or using our service for illegal purposes.

You may not attempt to reverse engineer, decompile, or disassemble our software or the platform.

Sharing, reselling, or sublicensing access to our service without written permission is strictly prohibited.

You must comply with all applicable laws and regulations when using our service.

Subscription and Billing

Subscription fees are billed in advance on a monthly basis.

You authorize us to charge your chosen payment method for all applicable fees and taxes.

Price changes will be communicated at least 30 days in advance and will apply to subsequent billing cycles.

Failed payments may result in service suspension. You are responsible for maintaining valid payment information.

Starter to paid upgrades apply immediately after checkout.

Switching between paid plans (Professional ↔ Business) is scheduled to take effect at the end of the current billing period.

You may cancel or downgrade to Starter at any time, but cancellation will take effect at the end of the current billing period.

If you are a team owner and you cancel your subscription, team members are removed immediately and switched to individual Starter accounts with no access to team data. If you downgrade between paid plans (e.g. Business to Professional), seat limit changes take effect at the end of the current billing period.

If the platform is unavailable for more than 48 consecutive hours during your paid term, you are entitled to a service credit for the affected period upon written request to support@nautillo.pro. Credits are applied to your next invoice and have no cash value.

Subscription fees are non-refundable. By completing your purchase you acknowledge that service starts immediately upon payment and you expressly request immediate access.

EU consumers — right of withdrawal: You have a statutory 14-day right of withdrawal under the Consumer Rights Directive 2011/83/EU. By completing your purchase and accessing the platform you expressly request that the service begins immediately and acknowledge that you thereby waive this right.

Intellectual Property Rights

Nautillo Pro and all related trademarks, logos, and brand names are our exclusive property.

Our software, algorithms, simulation methodology, and platform technology are protected by intellectual property laws.

You retain ownership of your data and simulation results, but grant us a license to process and analyze this data to provide our services.

You may not copy, modify, distribute, or create derivative works based on our platform or proprietary technology.

Any feedback, suggestions, or improvements you provide may be used by us without compensation or attribution.

We respect the intellectual property rights of others and expect our users to do the same.

If you believe your intellectual property rights have been violated, please contact us immediately.

Disclaimers and Limitations

To the fullest extent permitted by applicable law, our service is provided 'as is' without warranties of any kind, express or implied.

We do not guarantee that our attack simulations will identify all vulnerabilities or security issues.

Attack simulation results should be verified by qualified security professionals before taking action.

We are not liable for any damages, losses, or security breaches that may occur as a result of using our service.

Our liability is limited to the amount you paid for our service in the 12 months preceding any claim.

We do not warrant that our service will be uninterrupted, error-free, or completely secure.

You acknowledge that attack simulation may have inherent risks and use our service at your own risk.

Incident Response & Notification

In the event of a security incident, service disruption, or data breach, we will notify affected customers in accordance with applicable laws and regulations.

For GDPR-covered incidents, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay if there is a high risk to their rights and freedoms.

For other jurisdictions, we will comply with all applicable data breach notification laws including CCPA, PIPEDA, and local privacy regulations.

We maintain documented incident response procedures with severity-based escalation paths to ensure rapid response to critical incidents.

Security incidents are classified into four severity levels (P0–P3) with corresponding response times: P0 Critical (< 15 minutes business hours / < 4 hours out of hours), P1 High (< 1 hour), P2 Medium (< 4 hours), P3 Low (< 24 hours).

You can report security concerns or vulnerabilities to support@nautillo.pro. We maintain a responsible disclosure program and will respond within 24 hours.

In the event your simulation inadvertently causes service disruption or exposes sensitive data, you must immediately notify both the affected organization and support@nautillo.pro.

We reserve the right to suspend accounts and cooperate with law enforcement if we detect unauthorized use or violations of our Acceptable Use Policy.

Security, Compliance & Data Protection

We implement administrative, technical, and physical safeguards aligned with industry standards, including TLS encryption in transit, AES-256 encryption at rest, and role-based access controls.

Authentication credentials supplied for attack simulations (passwords, bearer tokens, cookies) are encrypted with AES-256-GCM, stored server-side for the duration of the scan only (maximum 24 hours), then automatically and permanently deleted. Credentials are never exposed to the client, never logged, and never included in reports.

Plan-based data retention applies: simulation evidence is purged within 7-60 days, simulation results within 30-730 days, and audit or consent logs are retained up to 36 months. Uploaded file artifacts are deleted immediately after analysis.

Personal data is stored and processed through Supabase (managed PostgreSQL, storage, authentication, edge functions) hosted in the EU (Frankfurt region), under a GDPR-compliant data processing agreement. Frontend hosting and delivery is handled by Cloudflare (Pages, Workers, CDN) under Standard Contractual Clauses.

AI-assisted analysis is optional for Business plans. When enabled, structured prompts and scan metadata are shared with OpenAI, Inc. (US) under Standard Contractual Clauses and strict confidentiality obligations. AI Code Analysis may include JavaScript bundle content from the target (up to 8,000 characters, truncated) to detect hardcoded secrets and vulnerabilities. Data submitted to OpenAI via our API is not used to train AI models; model training is disabled in our OpenAI account settings and is prohibited by OpenAI's API usage policy by default.

We will notify you of personal data breaches affecting your account in accordance with GDPR, CCPA/CPRA, and other applicable notification laws.

You remain the controller for any personal data processed through the platform and are responsible for obtaining necessary consents and honoring data subject rights requests from your end users.

If you are located in the European Economic Area, you have the right to access, rectify, erase, restrict, or port your personal data, and to object to its processing. To exercise any of these rights, contact support@nautillo.pro. We will respond within 30 days in accordance with GDPR Article 12.

EEA residents have the right to lodge a complaint with their national data protection authority (DPA). A list of EU supervisory authorities is available at edpb.europa.eu.

Compliance Testing Disclaimer

Our compliance features (including PCI DSS, HIPAA, and GDPR presets) provide compliance-aligned technique coverage, NOT compliance certification or attestation.

These features test technical security controls that align with selected regulatory frameworks. They do not validate policies, procedures, documentation, or administrative/physical controls.

Simulation results showing 'PASS' for a control indicate that the associated techniques were executed without confirmed findings — not that you are compliant with the framework.

Our reports may be used as supporting evidence for your compliance program but do not replace professional compliance audits, QSA reviews, or legal review.

We do not provide legal, regulatory, or compliance advice. Consult with qualified compliance professionals, legal counsel, and certified auditors for your specific compliance requirements.

Each regulatory framework (PCI DSS, HIPAA, GDPR, etc.) has extensive requirements beyond what automated tooling can validate, including organizational policies, employee training, physical security, and more.

You are solely responsible for achieving and maintaining compliance with applicable regulations. Our service can support evidence collection, but it is not a guarantee of compliance.

Compliance requirements change over time. While we strive to keep our coverage aligned with current frameworks, you are responsible for staying informed of regulatory updates.

Results should be reviewed by your security team and validated by professional auditors before relying on them for compliance purposes.

HIPAA: We are not a HIPAA-covered entity or business associate and do not execute Business Associate Agreements (BAAs). Organizations subject to HIPAA must not process Protected Health Information (PHI) through this platform. Our HIPAA preset tests technical security controls aligned with the HIPAA Security Rule — it does not create a covered-entity or business-associate relationship, nor does it constitute a HIPAA compliance assessment.

User Responsibility & Liability Limits

Users are solely responsible for ensuring they have appropriate authorization and insurance coverage for all simulation activity conducted through our platform.

As stated in our 'Disclaimers and Limitations' section, our liability is limited to the amount you paid for our service in the 12 months preceding any claim.

We strongly recommend that organizations conducting simulations maintain appropriate cyber liability insurance and professional indemnity coverage.

You are responsible for any damages, losses, or claims arising from unauthorized activity or activity conducted without proper authorization.

Our service is provided as a platform for authorized simulations. You accept all responsibility for how you use the platform and the results it generates.

You must immediately cease activity and notify the affected organization if you inadvertently cause service disruption or expose sensitive data.

If you have legal questions or concerns, contact support@nautillo.pro with full details.

Indemnification

You agree to indemnify, defend, and hold harmless NØRTH HŪMAN OÜ and its affiliates, officers, employees, and agents from any claims, damages, losses, and expenses (including reasonable attorneys' fees) arising out of or related to your use of the service.

This includes claims arising from unauthorized activity, violations of the Acceptable Use Policy, violations of law, or infringement of third-party rights.

This indemnification applies to users acting in a business or commercial capacity. It does not limit any mandatory rights you hold under the consumer protection laws of your country of residence.

Force Majeure

Neither party will be liable for any failure or delay in performance caused by circumstances beyond its reasonable control, including acts of God, natural disasters, war, terrorism, government actions, widespread internet outages, cyberattacks on third-party infrastructure, or failures of upstream service providers (including Supabase, Cloudflare, Stripe, or other sub-processors named in these Terms).

We will notify you promptly of any force majeure event materially affecting service delivery and will resume performance as soon as reasonably practicable.

If a force majeure event prevents service delivery for more than 30 consecutive days, either party may terminate the affected subscription with written notice. Any prepaid fees covering the remaining affected period will be issued as service credits.

Termination and Enforcement

We may terminate or suspend your account immediately if you violate these terms or engage in prohibited activities.

Upon termination, your right to use our service ceases immediately, and we may delete your account and data.

Sections of these terms that by their nature should survive termination will remain in effect.

These terms are governed by the laws of Estonia.

Any disputes will be resolved through binding arbitration seated in Tallinn, Estonia, under the UNCITRAL Arbitration Rules, in English, by a single arbitrator.

You and NØRTH HŪMAN OÜ agree to bring claims only in an individual capacity and not as a plaintiff or class member in any purported class or representative proceeding.

Nothing in this section limits any mandatory consumer protections or rights to bring claims in local courts where such rights apply.

Either party may seek injunctive or equitable relief in court for claims involving intellectual property, confidentiality, or unauthorized access.

If any provision of these terms is found unenforceable, the remaining provisions will continue in full force.

We may modify these terms at any time, with changes taking effect 30 days after notification.

Service Level Agreement (SLA)

Uptime Commitment

  • • Professional Plan: 99.5% uptime target
  • • Business Plan: 99.9% uptime target
  • • Scheduled maintenance windows excluded
  • • Service credits applied to future invoices for SLA violations (not monetary refunds)

Support Response Times

  • • Starter Plan: 48-72 hours (email only)
  • • Professional: 24 hours (email)
  • • Business: 4 hours (email)
  • • No phone support available

Legal and compliance

Governing Law

These Terms are governed by and construed in accordance with the laws of Estonia, without regard to conflict of law principles.

Dispute Resolution

Any disputes arising from these Terms will be resolved through binding arbitration seated in Tallinn, Estonia, under the UNCITRAL Arbitration Rules, in English, by a single arbitrator, except for claims involving intellectual property or injunctive relief.

Compliance Requirements

Users must comply with all applicable laws, including but not limited to the Computer Fraud and Abuse Act (CFAA), GDPR, Directive 2013/40/EU on attacks against information systems, and other applicable cybersecurity and data protection regulations in their jurisdiction. You are responsible for obtaining any required consents or disclosures before processing personal data through the platform and for honoring data subject rights requests.

We maintain GDPR-compliant data processing agreements with Supabase, Cloudflare, Stripe, and OpenAI. A Standard Contractual Clause-based Data Processing Addendum (DPA) is available on our DPA page — email support@nautillo.pro to request a countersigned copy. Optional AI-assisted features (Business plan) leverage OpenAI under Standard Contractual Clauses and contractual confidentiality safeguards.

Jurisdiction & Geographic Restrictions

Nautillo Pro stores and processes personal data through Supabase infrastructure hosted in the European Union (Frankfurt region). Frontend hosting and delivery is handled by Cloudflare (Cloudflare Pages, Workers, CDN). We permit customers based in the United States, European Union, Canada, Australia, New Zealand, and other jurisdictions that recognize authorized security work.

Nothing in these Terms limits any mandatory statutory rights you hold under the law of your country of residence. EU consumers may exercise mandatory rights under EU consumer protection law. These Terms do not affect those rights.

Due to export control, sanctions, and local cybercrime legislation, you may not use the service if you or your monitored assets are located in, controlled by, or acting on behalf of individuals or entities in embargoed or restricted regions including, but not limited to, Cuba, Iran, North Korea, Syria, Crimea, Donetsk, Luhansk, or any destination prohibited by OFAC, BIS, or relevant EU sanctions authorities. If you are unsure whether your jurisdiction allows authorized attack simulation, please contact support@nautillo.pro before scheduling a run.

Questions about these terms?

Legal & Compliance

Email: support@nautillo.pro

Business Hours: Monday – Friday, 9 AM – 6 PM EET/EEST

Mailing Address

NØRTH HŪMAN OÜ
Legal & Compliance
Harju maakond, Tallinn, Kesklinna linnaosa
Tornimäe tn 5, 10145
Estonia

Acknowledgment

By using Nautillo Pro, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service. If you do not agree to these terms, you may not use our service.