Legal Document

Terms of Use

Last updated: August 16, 2026 · Version 2.1

These Terms of Use ("Terms") govern access to and use of the Coruzen Security platform (security.coruzen.com), owned by Coruzen ("we"). Please read them carefully before using the Service — they define, in particular, the boundaries of authorized use and Coruzen's disclaimers of liability.

1. Acceptance of these Terms

By creating an account, accessing or using Coruzen Security (the "Service") through any channel, you confirm that you have read, understood and fully accepted these Terms and our Privacy Policy, which is incorporated into this document by reference.

If you do not agree with any provision of these Terms, do not access or use the platform. An individual accepting these Terms on behalf of an organization represents that they have the authority to bind it contractually.

2. Definitions

  • Service or Platform: the Coruzen Security system, including the website, scan engine, reports, API and related functionality;
  • Coruzen: the company that develops and owns the Coruzen Security platform;
  • User: the individual or legal entity that creates an account, requests analyses or consumes the Service's reports;
  • Analyzed Domain: the website, application, SaaS or domain submitted for analysis by the User;
  • Report: the document generated by the Service containing a risk score, technical findings and remediation guidance;
  • Passive Check: an analysis technique that uses only standard HTTP/HTTPS requests and publicly accessible information, without exploiting flaws.

3. Service description

Coruzen Security is a security best-practices checker built for developers, product teams and organizations who want to assess the surface-level security posture of their own websites, SaaS products and applications — including applications built with the help of AI ("vibe coding").

The Service performs exclusively Passive Checks, organized into categories such as attack surface, HTTP headers, exposed secrets, cloud exposure, data leakage, sensitive files, outdated technologies and SaaS integration risks, producing a Report with a risk score and a remediation plan.

The Service is offered in Free, Professional and Enterprise tiers, whose checks, limits and deliverables are described on the platform at the time of purchase.

4. Eligibility and registration

Use is permitted to adults (18+) and to legal entities acting through authorized representatives. When registering, you agree to provide truthful, complete and up-to-date information, and you are responsible for safeguarding your access credentials and for all activity under your account.

You must notify Coruzen immediately of any unauthorized use of your account or suspected security breach, at security@coruzen.com.

5. Mandatory authorization and exclusive use on your own domains

Coruzen Security is intended exclusively for analyzing domains, websites and applications owned by the User, or domains for which the User holds express authorization from the rightful owner to run the analysis. By submitting an Analyzed Domain, you declare, under your sole and full responsibility, that you own it or hold such authorization.

It is strictly prohibited to use the Service to analyze third-party domains without authorization, to hunt for vulnerabilities in systems that are not yours, or to use the Report's results for intrusion, exploitation or any offensive purpose against third-party systems.

Such conduct may constitute a crime under the Computer Fraud and Abuse Act — CFAA (US), Law 12.737/2012 (Brazil) and equivalent legislation in other jurisdictions, exposing the offender to applicable civil and criminal sanctions.

Coruzen reserves the right to suspend accounts, block domains and IP addresses involved in misuse, retain evidence, and fully cooperate with law-enforcement and judicial authorities.

6. Nature of the Service: best-practices checking — not a pentest

Coruzen Security is a best-practices and security-hygiene assessment tool, not a penetration testing (pentest), red-team or offensive security auditing service.

Coruzen does not perform, and the User is not authorized to use the Service to perform: active exploitation of vulnerabilities, brute-force attacks against credentials, denial-of-service (DoS/DDoS) attacks, payload injection, lateral movement, privilege escalation, or any technique capable of causing unavailability, performance degradation or damage to systems — whether the User's own or a third party's.

The Service is limited to identifying improvement opportunities and deviations from best practices based on public, passive information — such as response headers, exposed configuration, public files and metadata — and does not replace a manual pentest, a formal audit, a bug-bounty program, or ongoing security assessment performed by qualified professionals.

7. Acceptable use and prohibited conduct

In addition to the restrictions in Clauses 5 and 6, the User may not, under any circumstances:

  • Use the Service for unlawful, fraudulent purposes or purposes that infringe third-party rights;
  • Attempt to access, without authorization, other users' areas, data or accounts on the platform;
  • Reverse-engineer, decompile or attempt to extract Coruzen's methodology or scan engine;
  • Use bots, scripts or automated methods to circumvent rate limits or issue abusive requests;
  • Resell, sublicense or make the Service or its Reports available to unauthorized third parties without Coruzen's prior written consent;
  • Deliberately overload the Service's infrastructure or interfere with its normal operation.

8. Plans and payment

Paid reports are charged per analysis (one-time payment) or by subscription, depending on the plan, with the price shown before confirmation. Payments are processed by PCI DSS-certified providers — Coruzen does not store card data.

For PIX payments, the CPF you provide is used exclusively to create the charge with our payment provider and is never stored on our servers. Non-payment may result in suspension of access to paid features, without prejudice to collection of amounts owed.

9. Refunds and right of withdrawal

As digital content with immediate execution, the Report is generated right after payment confirmation. Under art. 49 of the Brazilian Consumer Code, you may exercise your right of withdrawal within 7 (seven) days.

We guarantee a full refund whenever an analysis fails to complete due to a technical fault on our side. Other requests are reviewed case by case at security@coruzen.com.

10. Intellectual property

The platform, its source code, the Coruzen brand, visual identity and analysis methodology are the exclusive property of Coruzen or its licensors, protected under applicable intellectual property law. These Terms grant the User no ownership rights over the platform, only a personal, non-exclusive and non-transferable license to use it.

The delivered Report is licensed for your organization's internal use; resale or commercial publication without Coruzen's prior written authorization is prohibited.

11. Reports: limitations and informational nature

Reports are informational and reflect the state of the Analyzed Domain at the time the scan was run, based on publicly available information at that moment. Subsequent changes to the domain, newly disclosed vulnerabilities or configuration changes are not automatically reflected in previously issued reports.

Reports do not constitute legal advice, a compliance certification (e.g., PCI DSS, ISO 27001, SOC 2) or a guarantee of the absence of vulnerabilities. The decision to implement, prioritize or disregard any recommendation is the User's sole responsibility.

12. User's Sole Responsibility for Implementing Fixes

Coruzen does not perform, execute, or take responsibility for any modification, correction, adjustment, or change applied by the User — whether manually or automatically, including through AI agents or automation tools — to their sites, systems, applications, or infrastructure based on the information, findings, or recommendations contained in the Report.

The data and recommendations in the Report are for informational purposes only. It is the User's responsibility to critically review each finding, assess its applicability to the technical and business context of the Analyzed Domain, and decide, under their sole responsibility, what should or should not be implemented, corrected, or changed.

We strongly recommend that the implementation of any fix be carried out or supervised by a qualified information security professional, especially when it involves configuration changes, infrastructure, source code, or automated execution by AI agents.

Coruzen is not liable for any damage, downtime, data loss, functional regression, or harm — including irreversible damage — resulting from the application of fixes, adjustments, or changes made by the User, by third parties hired by the User, or by AI agents and automations operated by the User based on the Report.

Lack of adequate technical knowledge when applying the Report's recommendations is the User's sole responsibility. Coruzen recommends hiring a qualified information security professional to ensure fixes are implemented safely and without negative impact to the Analyzed Domain.

13. Third-party integrations and services

Coruzen Security relies on third-party services to operate, such as cloud hosting and infrastructure providers, payment processors (e.g., Stripe, Mercado Pago) and transactional email providers. The availability, performance and practices of these third parties are the exclusive responsibility of their respective operators, and Coruzen cannot be held liable for failures, outages or changes made by them.

14. Disclaimer of warranties

The Service is provided "as is" and "as available". To the maximum extent permitted by law, Coruzen does not warrant that the Service will be uninterrupted, error-free, or that it will identify every vulnerability or best-practice deviation that may exist on the Analyzed Domain.

15. Limitation of liability

To the maximum extent permitted by applicable law, Coruzen will not be liable for indirect, incidental, special, punitive or consequential damages, including lost profits, lost data or lost revenue, arising from use of, or inability to use, the Service.

Coruzen is not liable for any misuse of the platform by the User — including the analysis of third-party domains without authorization — nor for damage caused by the User to their own or third-party systems as a result of failing to comply with these Terms.

Coruzen is also not liable for technical, business or operational decisions made by the User based on information contained in a Report — including modifications, corrections or changes applied manually or by AI agents and automation tools — nor for vulnerabilities not identified by the Passive Check.

Coruzen's total aggregate liability to the User arising from these Terms or from use of the Service is limited to the amount actually paid by the User to Coruzen in the 12 (twelve) months immediately preceding the event giving rise to the claim.

16. Indemnification

The User agrees to indemnify and hold Coruzen harmless from any claims, losses, damages, liabilities and expenses (including reasonable attorneys' fees) arising from: (i) the User's breach of these Terms, including unauthorized analysis of third-party domains; (ii) misuse of the Service for pentesting, brute-force, denial-of-service or any offensive activity; or (iii) infringement of third-party rights resulting from the User's use of the Service.

17. Suspension and termination by Coruzen

Without prejudice to other remedies available, Coruzen may suspend or terminate, in whole or in part and at any time, a User's access to the Service, without prior notice, in the following situations:

  • Detection of a scan against a third-party domain without demonstrable authorization;
  • Use of the Service for pentesting, brute-force, denial-of-service or any offensive activity;
  • Abuse of resources, unauthorized automation, or any conduct that jeopardizes the security, stability or availability of the platform;
  • Chargebacks, payment disputes, or unresolved non-payment after notice;
  • Breach of any provision of these Terms or of the Privacy Policy;
  • A court order or applicable legal requirement.

Coruzen will not be liable for any losses or damages arising from suspension or termination of an account carried out in accordance with this clause.

18. Termination by the customer

The User may close their account and cancel their subscription at any time through the channels available on the platform or by contacting support. Cancellation does not entitle the User to a refund of amounts already paid, except as provided in Clause 9 or by law.

19. Legal compliance

The Service is provided in compliance with applicable Brazilian law, including the General Data Protection Law (Law 13.709/2018 — LGPD), the Brazilian Internet Civil Rights Framework (Law 12.965/2014) and the Cybercrimes Law (Law 12.737/2012). Coruzen may provide information to competent authorities when legally required to do so, pursuant to a court order or a request from an authority with legal power to make it.

20. Changes to these Terms

These Terms may be updated at any time to reflect Service improvements, legal changes or security adjustments. The current version will always be published on this page, with the date and version shown at the top. Continued use of the Service after changes take effect constitutes acceptance of the new conditions.

21. Governing law and venue

These Terms are governed by the laws of the Federative Republic of Brazil. For consumer relations, the courts of the consumer's domicile shall have jurisdiction; in all other cases, the courts of Coruzen's domicile shall have exclusive jurisdiction, with waiver of any other, however privileged.

22. General provisions

If any provision of these Terms is held invalid or unenforceable, the remaining provisions will remain in full force and effect. Failure to enforce any provision of these Terms will not constitute a waiver of the right to enforce it later. These Terms constitute the entire agreement between the parties regarding their subject matter, superseding any prior understandings on the same matter.

Questions about these Terms?

Our team replies within 2 business days.

security@coruzen.com