← Back to sign in

Acceptable Use Policy

Partner Tests · Version 1.0 · Effective July 16, 2026

This Acceptable Use Policy (“AUP”) applies to the opSentry Partner Tests feature only. General use of opSentry is governed by the Terms of Service and Privacy Policy; this AUP supplements and is incorporated into those Terms. This version (1.0) is the exact text recorded with each Partner Tests authorization attestation.

1. Scope & Definitions

1.1 What this policy covers. This Acceptable Use Policy (“AUP” or “Policy”) governs your use of Partner Tests, a feature of the opSentry platform operated by Opsentry LLC (“opSentry,” “we,” “us,” or “our”). Partner Tests is a server-side API-testing tool: when you run a test, opSentry sends HTTP requests from opSentry’s own infrastructure (originating from opSentry’s IP addresses) to the endpoints you configure, on your behalf, and returns the results to you.

1.2 Definitions.

  • “You” / “Customer” — the workspace and the authenticated users acting within it.
  • “Target” / “Test Endpoint” — any URL, host, API, or service to which Partner Tests sends a request at your direction.
  • “Verified Domain” — a domain you have registered for Partner Tests and that opSentry has accepted under §3 (its registrable domain must match your business email domain, or it must have completed opSentry’s additional-domain verification).
  • “Attestation” — the per-domain authorization statement described in §4.
  • “Run” — a single execution of one or more tests against a Target.

1.3 Acceptance. By registering a Verified Domain, accepting the Attestation, or initiating a Run, you agree to this Policy for that domain and for all activity you conduct through Partner Tests. If you do not agree, do not use Partner Tests.

2. Authorized Use Only

2.1 Core rule. You may use Partner Tests only to send requests to endpoints that you own or are expressly authorized in writing to test. “Authorized in writing” means you hold a written agreement, statement of work, scope-of-work, penetration-testing authorization, or comparable documented permission from the party that owns or controls the Target.

2.2 Your representation and warranty. Each time you register a domain or initiate a Run, you represent and warrant that, for every Target involved:

  • (a) you own the Target, or you have current, valid, written authorization from its owner or controller to send the test traffic you are sending; and
  • (b) your use does not, and will not, violate any law, contract, terms of service, or third party’s rights; and
  • (c) you will cease testing any Target immediately upon withdrawal of that authorization.

2.3 Authorization is yours to hold and prove. opSentry provides the tooling; the legal authorization to test a given Target is yours to obtain, hold, and produce on request. opSentry does not verify that you in fact hold authorization for any individual Target and does not assume responsibility for confirming it.

2.4 No reliance on opSentry’s controls as authorization. opSentry’s domain-matching, verification, and safety controls (§§3, 7) are abuse-reduction measures for opSentry’s benefit. They are not a determination that you are authorized to test any Target, and passing them does not relieve you of the obligations in this §2.

3. Verified Domains

3.1 Domain registration required. Partner Tests will only send requests to a domain you have registered as a Verified Domain. Self-serve registration is limited to a domain whose registrable domain matches your business email domain (e.g., an acme.com account may register acme.com or api.acme.com).

3.2 Additional / non-matching domains. Testing a domain that is not your business email domain (for example, a subsidiary or a partner you are authorized to test) requires opSentry’s additional-domain process, which may include a support review and DNS-based proof of domain control before opSentry will enable that domain. opSentry may approve, decline, or revoke any domain request at its discretion.

3.3 Allowlist enforcement. Partner Tests enforces a per-workspace allowlist of Verified Domains. Requests to any host outside your allowlist are blocked. You may not attempt to defeat, spoof, or circumvent the allowlist (see §5).

4. Per-Domain Authorization Attestation

4.1 The Attestation. Each time you register, change, or re-register a Verified Domain, you must affirmatively accept the following statement:

“I own, or am expressly authorized to test, this domain and the endpoints under it, and I have the legal right to direct opSentry to send test traffic to it on my behalf.”

4.2 Recorded and versioned. Your acceptance is recorded for opSentry’s legal protection and for enforceability of this Policy. We record, at minimum: the acting user’s identity, the workspace, the action (add / change / remove), the domain(s) involved, the timestamp of acceptance, and the version of this AUP (and/or a hash of its exact text) presented to you at that moment. opSentry retains the exact text of each AUP version so the specific terms you accepted can be reproduced. (See the Privacy Policy for what is logged and why.)

4.3 Binding effect. The Attestation is a clickwrap acceptance and is intended to be legally binding on you and your workspace. You are responsible for ensuring that any user who accepts an Attestation on your workspace’s behalf is authorized to do so.

5. Prohibited Uses

You may not use Partner Tests to:

  • 5.1 access, probe, scan, fuzz, attack, or test any system, network, API, or endpoint that you do not own or are not expressly authorized in writing to test;
  • 5.2 conduct denial-of-service, flooding, load/stress, brute-force, credential-stuffing, or any activity intended or likely to degrade, overwhelm, disrupt, or deny service to any Target or any third party;
  • 5.3 circumvent, disable, spoof, or attempt to defeat the Verified-Domain allowlist, the SSRF/safety guard, rate limits, request ceilings, authentication, or any other opSentry safety or access control;
  • 5.4 direct requests at opSentry’s own infrastructure, internal networks, cloud-metadata endpoints (e.g., link-local/169.254.0.0/16 metadata services), or any non-routable, internal, or loopback address, or otherwise use Partner Tests to attack or probe opSentry or its providers;
  • 5.5 access, exfiltrate, alter, or destroy data you are not authorized to access, or use Partner Tests to gain unauthorized access to any account, system, or data;
  • 5.6 violate any applicable law or regulation, including computer-misuse, unauthorized-access, anti-hacking, wiretapping, export-control, and data-protection laws (for example, in the United States, the Computer Fraud and Abuse Act);
  • 5.7 infringe, misappropriate, or violate any third party’s intellectual-property, privacy, contractual, or other rights;
  • 5.8 transmit malware, exploits, or malicious payloads, or use Partner Tests to develop, stage, or deliver an attack against any party; or
  • 5.9 resell, sublicense, or provide Partner Tests as a testing service to third parties for use against targets they have not themselves authorized.

opSentry maintains the right, in its sole discretion, to determine whether a given use violates the letter or spirit of this Policy.

6. Your Responsibility

6.1 Sole responsibility. You are solely responsible for the Targets you test, the configuration of your tests, the authorization behind them, and all consequences of any Run you initiate or schedule (including auto-runs). opSentry acts only as the tool that transmits the requests you direct.

6.2 Workspace accountability. Workspace owners and administrators are responsible for the acts and omissions of the members they invite, including any Runs those members initiate and any Attestations they accept.

7. opSentry Safety Controls

Partner Tests runs server-side and is subject to controls that are part of the Service and may not be bypassed, including: an always-on request safety guard (SSRF protection) that blocks internal, loopback, and cloud-metadata targets; the per-workspace Verified-Domain allowlist; rate limits and per-run/burst request ceilings; and an append-only audit log of domain registrations, changes, removals, and the associated Attestations. These controls are abuse-reduction and safety measures maintained for opSentry’s benefit and do not constitute authorization to test any Target (see §2.4).

8. Enforcement, Suspension & Cooperation

8.1 Suspension and termination. opSentry may, with or without prior notice depending on the severity, suspend or terminate your access to Partner Tests and/or your opSentry account if we reasonably believe you have violated this Policy or applicable law, or to protect opSentry, its users, or third parties.

8.2 Monitoring and logging. opSentry logs Partner Tests activity (including domain changes, Runs, and Targets at the host level) for security, abuse prevention, and legal defensibility. opSentry is not obligated to monitor your use but may do so.

8.3 Cooperation with authorities. opSentry may preserve and disclose Partner Tests records, including audit logs and Attestation records, where it believes in good faith that disclosure is required by law, legal process, or to investigate suspected violations, fraud, or threats to safety, and may cooperate with law-enforcement or affected third parties.

9. Indemnification

To the maximum extent permitted by applicable law, you agree to defend, indemnify, and hold harmless Opsentry LLC and its officers, directors, employees, contractors, and agents from and against any and all claims, demands, suits, proceedings, liabilities, damages, losses, penalties, fines, and costs (including reasonable attorneys’ fees and expenses) arising out of or related to:

  • (a) your use or misuse of Partner Tests;
  • (b) any Run, Target, or test traffic you initiated, scheduled, or configured;
  • (c) your breach of this Policy or your representations in §2 (including any claim that you lacked authorization to test a Target);
  • (d) your violation of any law or any third party’s rights in connection with Partner Tests; or
  • (e) any claim brought by a third party whose systems you tested or affected through Partner Tests.

opSentry will provide reasonable notice of any claim subject to this section. The indemnifying party’s obligations are conditioned on prompt written notice, sole control of the defense and settlement (no settlement imposing non-indemnified liability or admitting fault without consent, not to be unreasonably withheld), and reasonable cooperation, consistent with the Terms of Service Section 9.

10. Disclaimer of Warranties

PARTNER TESTS IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. OPSENTRY DOES NOT WARRANT THAT PARTNER TESTS WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT TEST RESULTS WILL BE ACCURATE OR COMPLETE, OR THAT ITS SAFETY CONTROLS WILL PREVENT ALL UNAUTHORIZED, HARMFUL, OR UNINTENDED REQUESTS. OPSENTRY’S SAFETY CONTROLS DO NOT REPLACE YOUR OBLIGATION TO OBTAIN AND VERIFY AUTHORIZATION FOR EVERY TARGET.

11. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OPSENTRY WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, DATA, GOODWILL, OR BUSINESS, ARISING OUT OF OR RELATED TO PARTNER TESTS OR THIS POLICY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

OPSENTRY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO PARTNER TESTS WILL NOT EXCEED THE LIABILITY CAP SET OUT IN THE TERMS OF SERVICE §11. The cap is the greater of the fees you paid in the prior 12 months or US$100. Your indemnification obligations and any AUP breach are excluded from that cap (see Terms Section 11.3). Nothing in this section limits liability that cannot be limited by law.

12. Changes to This Policy

opSentry may revise this Policy from time to time. We will publish material changes as a new version with a new version string, and — consistent with the Terms of Service — provide notice of material changes before they take effect. Because acceptance of this Policy is version-tracked (§4.2), a new version may require you to re-accept the Attestation the next time you register or change a domain. Continued use of Partner Tests after a new version takes effect constitutes acceptance of the revised Policy.

13. Contact

Questions about this Policy or to report suspected misuse:
Opsentry LLC
support@opsentry.ai