Terms of Service

Please read these terms carefully before using XHack services

Effective Date: February 1, 2025

Last Updated: August 9, 2026

Website: https://xhack.io

Contact: support@xhack.io


1. Acceptance of Terms

By accessing or using the XHack website (xhack.io), the XHack AI agent application, the XHack AI web interface, the XHackplatform, our APIs, or any of our professional cybersecurity services (collectively, the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, you must not access or use the Service.

If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms, and "you" refers to both you and that organization. If you do not have that authority, you must not accept these Terms or use the Service.

These Terms apply in addition to any Statement of Work, Master Services Agreement, Rules of Engagement, order form, or enterprise agreement executed between you and XHack. Where a signed agreement conflicts with these Terms, the signed agreement controls for the subject matter it covers.


2. Definitions

  • "Agent" means the XHack AI agent application, a graphical desktop application that runs on hardware you control.
  • "Platform" means the XHack hosted services, including the web interface, dashboard, account systems, and APIs.
  • "Verified User" means an individual who has completed and passed the verification process in Section 4 and whose access has not been suspended or revoked.
  • "Tenant" means an organization that holds a company or enterprise subscription, together with the individual seats it administers.
  • "Authorization Evidence" means written permission from the owner of a target system, such as a signed engagement letter, statement of work, rules of engagement, or a published bug bounty programme scope, that covers the activity you perform.
  • "In Scope" means activity that falls inside the boundaries of your Authorization Evidence, both as to targets and as to permitted techniques.
  • "Session Content" means the prompts, responses, tool invocations, tool outputs, findings, and files produced during your use of the Agent.
  • "Incident Record"means the record described in Section 9.4, created only when the Service's runtime guardrails trigger an enforcement action.

User Verification & Safe Harbour

XHack operates on a strict verification model. Every user is verified before being granted access to the Platform, the Agent, or professional services. We screen individuals and organizations to confirm they are legitimate security professionals, authorized personnel, or vetted researchers with lawful intent. There is no self-serve access to unrestricted capability.

Open capability comes with responsibility. Our model has three layers: access control decides who gets in; runtime monitoring watches what happens once they are in and can end a session mid-use; and an Incident Record makes an enforcement event reviewable afterwards. None of the three is infallible on its own, which is exactly why there are three.

For legitimate users, this creates a safe harbour. You operate in a controlled, accountable environment where every participant has been verified, every engagement is scoped, and every action is the responsibility of the Verified User who performs it. This protects you, your clients, and the integrity of the security industry.

By using XHack, you acknowledge that you have been verified, that you accept full and sole responsibility for your actions on the Service, and that you will use our tools and services only for authorized, in-scope, ethical, and lawful purposes.


3. Description of Service

XHack is a cybersecurity firm that provides AI-powered security tooling and professional security services. The Service includes:

  • The XHack AI agent, a graphical desktop application for authorized penetration testing, vulnerability assessment, exploit development, malware analysis, reverse engineering, red team planning, and defensive operations, including autonomous multi-step operation and browser-driven application testing
  • The XHack AI web interface and dashboard for account management, subscription management, and chat-based assistance
  • Professional cybersecurity services including Vulnerability Assessment and Penetration Testing (VAPT), Red Team Operations, Security Operations Center (SOC) monitoring, Threat Intelligence, Incident Response, Cloud Security Assessment, Defensive Coding consulting, and Cybersecurity Training
  • API access for programmatic security automation and CI/CD integration
  • Expert support from our security team

The XHack AI command-line interface (CLI) has been discontinued and is no longer offered, supported, or licensed. Any previously distributed CLI build is unsupported and its use is not covered by these Terms. The Agent is now delivered exclusively as a graphical application.

We may add, modify, deprecate, or withdraw features at any time. Where a change is material and adverse to a paid feature you actively use, we will provide reasonable advance notice.


4. Eligibility, Verification, and Onboarding

4.1 Eligibility

You must be at least 18 years of age and have the legal capacity to enter into a binding agreement. The Service is offered only to cybersecurity professionals and organizations acting in a professional security capacity, including penetration testers, red team operators, security researchers, SOC analysts, incident responders, bug bounty hunters, CTF competitors, and security consultants. Signup at: https://app.xhack.io. Registering does not by itself grant access, access is granted only after verification under Sections 4.2 to 4.5 is complete.

4.2 Verification of Individuals

Before access is granted to an individual account, we verify:

  • Identity: a valid government-issued identification document, cross-checked against the details on your account
  • Professional standing: your cybersecurity certifications and professional context, for example OSCP, OSCE, OSWE, CREST, CEH or equivalent credentials, your role at a security organization, your bug bounty history, or comparable evidence that you work in a legitimate security function

4.3 Verification of Companies and Tenants

Before access is granted to a company or tenant account, we verify:

  • Identity of the authorized representative: a valid government-issued identification document for the individual who signs up for and administers the account
  • Business documentation: evidence that the organization exists and is legitimate, which may include certificate of incorporation or registration, trade licence, tax or VAT registration, proof of registered address, and evidence that the representative is authorized to act for the organization

The Tenant is responsible for the individuals it invites onto its seats. Each individual seat holder is separately subject to Section 4.2 before that seat is activated, and the Tenant is jointly responsible with the seat holder for that person's compliance with these Terms.

4.4 Verification Interview

Verification may include a live video interview to confirm identity and intent. Where an interview is recorded, your consent is requested before the recording begins, and the recording is handled in accordance with our Privacy Policy. Declining consent to a required verification step means access cannot be granted.

4.5 Accuracy and Integrity of Verification

You represent and warrant that:

  • All documents and information you supply for verification are authentic, current, and your own
  • You are not submitting verification materials on behalf of an undisclosed third party who will use the account
  • You will notify us promptly if your professional status, employer, authorization basis, or eligibility materially changes

Submitting forged, altered, borrowed, or misrepresented verification materials is a material breach of these Terms. It will result in immediate and permanent termination without refund, and may be reported to the relevant authorities.

4.6 Re-verification and Continued Eligibility

Verification is a continuing condition of access, not a one-time gate. We may require re-verification at any time, including after a period of inactivity, after a change to your account or organization, after a suspected credential compromise, or following an enforcement event. We may suspend access while re-verification is pending. Access remains at our discretion, and we may decline or withdraw access without being obliged to state a reason beyond what applicable law requires.


5. Account Security and Non-Transferability

You are responsible for:

  • Providing accurate and complete information during registration and verification
  • Maintaining the confidentiality of your account credentials and API keys
  • All activity that occurs under your account, whether or not authorized by you
  • Notifying us immediately at support@xhack.io if you suspect unauthorized access to your account or a compromise of your credentials or API keys

Accounts are personal to the Verified User and are not transferable. You must not share, sell, lend, resell, or otherwise provide access to your account, credentials, API keys, session, or the Agent to any person who is not a Verified User, including colleagues, clients, contractors, or members of your own organization. Sharing access defeats the entire verification model and is treated as a material breach resulting in immediate termination without refund.

You must not operate the Agent as a proxy, relay, or service bureau for third parties, or expose its capability through any interface that allows an unverified person to direct it.


6. Authorized Use Only

By using the Service, you represent and warrant on a continuing basis that:

  • You hold written Authorization Evidence from the owner of every system, network, or application before conducting any security testing, scanning, exploitation, or assessment using the Service
  • Your authorization is current at the time of the activity, has not expired or been withdrawn, and covers both the targets and the techniques you employ
  • You will operate within the defined scope of that authorization at all times and will not exceed the boundaries of the agreed Rules of Engagement
  • You will retain your Authorization Evidence and will produce it to us promptly on request, including during the review of an enforcement event
  • You understand that unauthorized access to computer systems may violate the Computer Fraud and Abuse Act (CFAA), the Computer Misuse Act, the Budapest Convention as implemented locally, and equivalent legislation in other jurisdictions, and that such violations may carry civil and criminal liability

You are the operator. XHack supplies tooling; it is not a party to your engagement, does not verify your Authorization Evidence for any individual action in advance, and does not authorize, approve, endorse, or supervise any specific test you run. The decision to direct the Agent at a target, and the consequences of doing so, are yours alone.


7. Acceptable Use Policy

The Service is designed for offensive security work that is authorized and in scope. The capability is open for that work; the permitted uses are not open-ended. You must not use the Service, its outputs, or anything derived from them to:

  • Attack, access, disrupt, degrade, or damage any system for which you do not hold current, documented authorization
  • Continue activity against a target after authorization has expired, been withdrawn, or been exceeded
  • Conduct denial-of-service or distributed denial-of-service attacks, spam distribution, or unsolicited phishing outside an authorized and scoped social engineering engagement
  • Develop, deploy, distribute, or operate ransomware, wipers, botnets, cryptojacking payloads, stalkerware, or surveillance tooling directed at individuals without their informed consent
  • Exfiltrate, sell, publish, or trade data obtained from any system, including systems you were authorized to test, except as expressly permitted by your engagement terms
  • Target critical infrastructure, medical devices, safety systems, or life-supporting systems outside a formally scoped engagement with the operator's written consent
  • Facilitate fraud, extortion, harassment, stalking, doxxing, human trafficking, child sexual abuse material, terrorism, or violence
  • Suppress, surveil, or target journalists, activists, dissidents, or civil society organizations
  • Attempt to gain unauthorized access to XHacksystems, other users' accounts, other tenants' data, or infrastructure outside your authorized scope
  • Circumvent, disable, probe, degrade, or attempt to defeat the verification process, the runtime guardrails, usage metering, rate limits, or any other technical control of the Service, or assist any other person in doing so
  • Reverse engineer, decompile, or disassemble the Service or any component of it, except to the extent that restriction is unenforceable under applicable law
  • Resell, sublicense, rent, or redistribute access to the Service, or use it to build or train a competing product, without our written authorization
  • Violate any applicable local, national, or international law or regulation, or infringe the intellectual property, privacy, or other legal rights of any third party

This list is illustrative, not exhaustive. Conduct that is plainly inconsistent with authorized, in-scope, professional security work is prohibited whether or not it appears above. Violation may result in immediate suspension or termination, at our sole discretion, without refund, and may be reported to law enforcement.


8. Local Agent, Session Content, and Retention

The Agent runs on hardware you control. We do not store the chats or Session Content of your local XHack AI agent sessions. Prompts, responses, tool invocations, tool outputs, scan results, findings, and files produced by the Agent remain on your machine unless you deliberately transmit them to us or to a third party.

Because we do not hold your Session Content, we cannot recover, restore, export, or reproduce it for you if it is lost, corrupted, or deleted on your side. You are solely responsible for the security, backup, encryption, retention, and lawful handling of everything the Agent produces locally, including any client data, credentials, or personal data it touches during an engagement.

The single exception is described in Section 9.4: where the runtime guardrails trigger an enforcement action, we create and retain an Incident Record. Separately, we process the limited operational metadata described in our Privacy Policy, such as authentication events, usage counts, and billing metering, which is necessary to operate and bill for the Service.


9. Runtime Guardrails, Smart Detection, and Enforcement

9.1 What the guardrails do

XHack AI watches for context, not content. If a session that started as an authorized, in-scope engagement starts drifting toward something outside that scope, activity that looks like it is targeting a system with no authorization on file, or a request pattern that reads as harmful rather than defensive, the platform can detect that pivot in real time.

This is not a keyword filter. The Service does not refuse a request merely because it mentions an exploit, a payload, or any other term of art in offensive security, that kind of filtering is what makes general-purpose AI useless for real security work. What the guardrails look for is the shape of misuse: a Verified User whose actions stop matching the authorized, in-scope work they were vetted for.

9.2 Enforcement

When the guardrails detect that pivot, they act. A session that drifts from authorized, in-scope testing into unauthorized or harmful territory is not quietly noted. Depending on severity, we may:

  • Terminate the session immediately, mid-use, without warning
  • Lock the account and revoke active sessions, tokens, and API keys
  • Suspend or permanently terminate access, including all seats under a Tenant
  • Require re-verification before any restoration of access
  • Report the matter to law enforcement, a regulator, an affected system owner, or the relevant bug bounty platform where we consider it necessary or are legally required to do so

You are not entitled to advance notice, to a warning, or to an opportunity to complete work in progress before an enforcement action takes effect. Enforcement for cause does not entitle you to a refund of any prepaid fees.

9.3 Automated decision-making

Enforcement may be triggered automatically. Where a lockout materially affects you, you may request human review by writing to support@xhack.io, and we will review the Incident Record and any Authorization Evidence you provide. We aim to respond within a reasonable period. Restoration of access is at our discretion and is not guaranteed.

9.4 Incident Records

We do not keep a running log of your Agent activity. When the guardrails trigger an enforcement action, we create an Incident Record capturing what is necessary to justify and review that action, typically the account identifier, timestamps, session identifier, the signals that triggered the action, and the action taken. Incident Records are retained for the periods set out in our Privacy Policy, and are used to review the decision, to prevent repeat abuse, to establish or defend legal claims, and to comply with legal obligations.

9.5 Honest limits of these controls

We do not claim these controls are infallible, and you must not rely on them as if they were. Detection is probabilistic. It may produce false positives that interrupt legitimate work, and it may fail to detect genuine misuse. Access control can be defeated: credentials can be stolen, insiders can abuse trust, and verification processes can be socially engineered. Nothing in this Section creates a duty of care to you or to any third party to detect, prevent, or interrupt misuse, and no failure of these controls transfers any part of your responsibility for your own conduct to XHack. The guardrails raise the cost of abuse and create evidence when it happens. That is defense in depth, not a guarantee.


10. XHack AI Platform Terms

10.1 AI-generated output

The Agent operates on the instructions you provide. You are responsible for those instructions and for ensuring every AI-directed operation stays in scope. AI output may be incomplete, inaccurate, outdated, or wrong, may report false positives, and may miss real vulnerabilities. Output must be reviewed and validated by a qualified security professional before it is relied upon, acted upon, delivered to a client, or used to support a compliance position. XHack does not warrant the accuracy, completeness, safety, legality, or fitness of any AI-generated output.

10.2 Autonomous and auto-approve operation

The Agent can plan and execute multi-step operations autonomously, orchestrate security tooling, and drive a real browser. Where you enable auto-approve, unattended execution, or programmatic mode, tool executions proceed without per-step human confirmation. You accept the risk of unattended execution in full, including unintended actions against in-scope or out-of-scope systems, service disruption, data modification, cost overruns, and third-party impact. You are responsible for configuring cost limits, turn limits, and scope constraints appropriately, and for supervising operations to the degree your engagement requires.

10.3 Third-party models, BYOK, and local models

When you use local models or Bring Your Own Key (BYOK) configurations, you are responsible for complying with the terms of the third-party providers whose models or APIs you use, and for any charges they levy. XHack is not responsible for the behaviour, availability, output, pricing, or data handling practices of third-party AI providers, and does not intercept or store data exchanged directly between your machine and such a provider.

10.4 API usage

API access is subject to the limits of your subscription. You must not use automated systems to exceed rate limits, abuse endpoints, or interfere with service availability. API keys are confidential and must not be shared, published, committed to code repositories, or exposed in client-side code.


11. Professional Service Engagements

11.1 Scope and Rules of Engagement

All professional service engagements (VAPT, Red Teaming, SOC, and similar) are governed by a separate Statement of Work (SOW) defining scope, objectives, methodology, timeline, Rules of Engagement, escalation procedures, and deliverables. The SOW is agreed and signed by both parties before work begins. XHack will not exceed the agreed scope without written authorization from the client.

11.2 Client authorization

You warrant that you own the systems in scope or hold documented authority from their owner to commission testing against them, including where systems are hosted by a third party whose own terms require notice or consent. You are responsible for obtaining any such third-party consent before testing begins.

11.3 Strict scoping

Every engagement is strictly scoped. Target systems, IP ranges, domains, applications, and methodologies are defined precisely in the SOW. Testing is performed only against systems explicitly listed. If our team discovers a vulnerability or system outside the agreed scope that poses immediate risk, we will notify you through the established escalation channel before taking any action.

11.4 Confidentiality

Information obtained during professional engagements is treated as strictly confidential. Engagement data, findings, reports, and communications are not shared with third parties without your explicit written consent. Team members assigned to your engagement are bound by non-disclosure agreements. Engagement data is securely destroyed after the agreed retention period.

11.5 Reporting and deliverables

Reports and deliverables are provided in the formats specified in the SOW, with severity ratings, evidence, and remediation guidance, transmitted through secure channels. You retain ownership of the deliverables produced for you. Security testing is a point-in-time assessment: it does not certify that a system is secure, and it does not guarantee that every vulnerability has been found.


12. Payment Terms

12.1 Subscription plans

Subscription fees are billed in advance monthly or annually as specified in your plan. Fees are quoted in USD unless stated otherwise and are exclusive of taxes, which you are responsible for. You authorize us to charge your payment method for recurring fees until you cancel.

12.2 Professional service fees

Fees for professional engagements are defined in the SOW and due per the schedule specified there. They are separate from subscription fees.

12.3 Refunds

We do not offer a free trial. Subscriptions paid by credit or debit card are refundable on a pro-rata basis for the unused portion of the current billing period, calculated and administered in accordance with our Refund Policy, which governs all refund questions. If you cancel without requesting a refund, you retain access until the end of the current billing period. No refund is due for a billing period that has already ended, or where access is terminated for cause under Sections 4.5, 5, 7, or 9. Your non-waivable statutory rights are unaffected.

12.4 Non-payment and price changes

We may suspend access for non-payment after reasonable notice. We may change pricing with 30 days' advance notice; changes do not affect the current billing cycle. Continued use after a change takes effect constitutes acceptance.


13. Intellectual Property

The Service, including its software, models, design, branding, documentation, and proprietary methodologies, is owned by XHack and protected by copyright, trademark, and other intellectual property laws. Your subscription grants a limited, non-exclusive, non-transferable, revocable licence to use the Service for its intended purpose during your subscription term. All rights not expressly granted are reserved.

You retain ownership of the data you provide and, as between you and XHack, of the output the Agent generates for you, subject to any third-party model provider terms that apply to that output. XHack does not claim ownership over your Session Content, scan results, or engagement reports, and does not use them to train models.

Output is generated by statistical models and may not be unique to you. Similar or identical output may be generated for other users. We make no representation that output is original, non-infringing, or free of third-party rights, and you are responsible for verifying this before using it. If you send us feedback or suggestions, you grant us a perpetual, royalty-free licence to use them without obligation to you.


14. Data and Privacy

Your use of the Service is governed by our Privacy Policy, incorporated into these Terms by reference. In summary: we do not sell, share, or monetize your data; we do not store the chats or Session Content of your local XHack AI agent sessions; we do not use your data to train AI models; and the only record we create of Agent activity is the Incident Record described in Section 9.4, generated when the runtime guardrails trigger an enforcement action.

Where you process personal data belonging to your clients or third parties through the Service, you are the controller of that data and are responsible for having a lawful basis to process it, for any required notices or consents, and for compliance with applicable data protection law.


15. Export Control, Sanctions, and Trade Compliance

Offensive security tooling is subject to export control and sanctions regimes in several jurisdictions. You represent and warrant that you are not located in, ordinarily resident in, or organized under the laws of a jurisdiction subject to comprehensive trade sanctions; that you are not a person or entity designated on any applicable restricted-party, denied-persons, or sanctions list, nor owned or controlled by such a person; and that you will not export, re-export, transfer, or make the Service or its output available to any such jurisdiction, person, or entity, or for any prohibited end-use. You are responsible for compliance with the export control and dual-use regulations applicable to you.


16. Disclaimer of Warranties

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, COMPLETELY SECURE, OR FREE OF HARMFUL COMPONENTS. SECURITY TESTING TOOLS AND AI-GENERATED OUTPUTS MAY CONTAIN INACCURACIES, PRODUCE FALSE POSITIVES, OR MISS VULNERABILITIES.

WITHOUT LIMITING THE FOREGOING, WE DO NOT WARRANT THAT THE VERIFICATION PROCESS WILL IDENTIFY EVERY BAD ACTOR, THAT THE RUNTIME GUARDRAILS WILL DETECT OR PREVENT ANY PARTICULAR MISUSE, THAT AN ENFORCEMENT ACTION WILL OCCUR IN TIME TO PREVENT HARM, OR THAT THE ABSENCE OF AN ENFORCEMENT ACTION INDICATES THAT YOUR ACTIVITY IS AUTHORIZED, IN SCOPE, OR LAWFUL. USE OF THE SERVICE DOES NOT CONSTITUTE LEGAL ADVICE, AND NO OUTPUT OR CONTROL OF THE SERVICE CERTIFIES COMPLIANCE WITH ANY LAW, STANDARD, OR FRAMEWORK.


17. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, XHack, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AND AFFILIATES SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR IN CONNECTION WITH THE SERVICE. THIS INCLUDES, WITHOUT LIMITATION, DAMAGES ARISING FROM UNAUTHORIZED OR OUT-OF-SCOPE TESTING, AUTONOMOUS OR AUTO-APPROVED AGENT ACTIONS, SYSTEM DOWNTIME CAUSED BY SECURITY TESTING, DATA LOSS OR CORRUPTION DURING ASSESSMENTS, LOSS OF LOCAL SESSION CONTENT, RELIANCE ON AI-GENERATED OUTPUT, SUSPENSION OR TERMINATION OF YOUR ACCOUNT UNDER SECTION 9 (INCLUDING WORK INTERRUPTED MID-SESSION AND ANY RESULTING MISSED DEADLINE OR CLIENT CLAIM), OR THE ACTS OF ANY THIRD PARTY.

OUR TOTAL CUMULATIVE LIABILITY FOR ALL CLAIMS ARISING UNDER THESE TERMS SHALL NOT EXCEED THE AMOUNT PAID BY YOU TO XHack IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THESE LIMITATIONS APPLY REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. NOTHING IN THESE TERMS EXCLUDES OR LIMITS LIABILITY THAT CANNOT LAWFULLY BE EXCLUDED OR LIMITED, INCLUDING LIABILITY FOR DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE, OR FOR FRAUD.


18. Indemnification

You agree to indemnify, defend, and hold harmless XHack, its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, fines, penalties, costs, and expenses (including reasonable legal fees) arising out of or related to:

  • Your use of the Service, including anything the Agent does at your direction
  • Your breach of these Terms or of any representation or warranty in them
  • Any testing, scanning, exploitation, or security operation you conduct that is unauthorized, out of scope, or exceeds your Authorization Evidence
  • Any claim by a client, employer, or third party arising from your engagements
  • Any inaccurate, forged, or misrepresented verification material you supply, or any sharing of your access with a person who is not a Verified User
  • Your violation of any applicable law, regulation, or third party's rights

19. Term and Termination

19.1 Term

These Terms remain in effect for as long as you use the Service or maintain an account.

19.2 Termination by you

You may close your account at any time by contacting support@xhack.io. Your subscription will not renew and access continues until the end of the current billing period.

19.3 Suspension and termination by us

We may suspend or terminate your account immediately and without prior notice if you breach these Terms, if the runtime guardrails trigger an enforcement action, if verification fails or lapses, if we reasonably suspect unauthorized testing, credential sharing, or unlawful use, or if required by law. Termination for cause ends your right to use the Service immediately and without refund.

19.4 Effect of termination

On termination you must cease all use of the Service, uninstall the Agent, and destroy any API keys associated with your account. We will delete or de-identify your account data in accordance with our Privacy Policy, except where retention is required for legal compliance, billing records, or the establishment or defence of legal claims, which includes Incident Records. Sections 2, 6, 7, 8, 9.5, 13, 14, 15, 16, 17, 18, 19.4, 20, and 21 survive termination.


20. Modifications to Service and Terms

We may modify, update, or discontinue any part of the Service at any time, and may update these Terms from time to time. When we make material changes, we will notify you by email or a prominent notice on the Platform, and the "Last Updated" date above will change. Continued use after changes take effect constitutes acceptance. If you do not agree, you must stop using the Service and close your account.


21. Governing Law and Dispute Resolution

These Terms are governed by and construed in accordance with the laws applicable in the jurisdiction where XHack is registered, without regard to conflict of law principles. Any dispute shall first be addressed through good-faith negotiation; you agree to notify us in writing and allow 30 days to resolve the matter before commencing formal proceedings. If negotiation fails, disputes shall be resolved by binding arbitration under the applicable arbitration rules, on an individual basis. To the extent permitted by law, you and XHack waive any right to participate in a class, collective, or representative action. Nothing in this Section prevents either party from seeking injunctive relief in a court of competent jurisdiction to protect intellectual property or confidential information, and nothing in it removes any non-waivable right you have as a consumer under the law of your place of residence.


22. General Provisions

  • Entire Agreement: These Terms, together with the Privacy Policy, the Refund Policy, and any applicable SOW or enterprise agreement, constitute the entire agreement between you and XHack regarding the Service.
  • Severability: If any provision is found unenforceable, it shall be limited or severed to the minimum extent necessary and the remaining provisions remain in full force.
  • Waiver: Our failure to enforce any right or provision is not a waiver of it.
  • Assignment: You may not assign or transfer your rights without our prior written consent. We may assign our rights and obligations, including in connection with a merger or acquisition.
  • No third-party beneficiaries: These Terms do not create rights for any person who is not a party to them.
  • Force Majeure: Neither party is liable for delays or failures resulting from events beyond reasonable control, including natural disasters, acts of government, network outages, or third-party provider failures.
  • Notices: We may give notice by email to the address on your account or by posting on the Platform. Notices to us must be sent to support@xhack.io.

23. Contact Information

If you have questions about these Terms of Service, contact us: