Agent Terms
Version 2026-07-06 · Agent Software License & Offensive Security Testing Terms
Pending final legal review. These Agent Terms are prepared and not yet in force. The entity, governing law, arbitration, and data-processing sections marked below are being finalized with counsel. The middleBrick Agent's offensive modes (the Red-Team SKU) are not enabled for any customer until these Terms are finalized, published, and accepted.
These Agent Terms govern the download, installation, and use of the middleBrick Agent (the "Agent"), the locally-run security-testing software distributed by Zevlat Intelligence ("Company", "we", "us"). They supplement the middleBrick Terms of Service (the "General Terms"). Where the two conflict as to the Agent, these Agent Terms control.
By installing, running, or configuring the Agent, or by clicking "I Agree," you ("Customer", "you") accept these Agent Terms on behalf of the business you represent, and you warrant you are authorized to bind it.
1. Parties, Eligibility, and B2B-Only Scope
1.1 Business use only. The Agent is licensed exclusively to businesses and professionals acting in a commercial or professional capacity. You represent that you are not a consumer and are not installing or using the Agent for personal, family, or household purposes. The Agent is not offered to consumers.
1.2 Entity. The Company is Zevlat Intelligence, operating from México. (Final legal form and domicile to be confirmed with counsel.) Nothing in these Agent Terms creates any personal liability for any member, officer, or contractor of the Company.
1.3 Capacity. You must have authority to accept these Agent Terms and to make the authorization representations in §4.
2. What the Agent Is — Full Disclosure of Capabilities
You acknowledge that the Agent is a dual-use security-testing tool. It is designed to find security defects by exercising target systems, and depending on configuration and your subscription it can send requests that a target may treat as an attack. Specifically, the Agent can:
- Passive scanning — read-only
GET/HEADrequests, analyzing responses. Default, all plans. - Active probes —
POST/PUT/DELETE/PATCHrequests carrying test payloads (including LLM prompt-injection/jailbreak inputs and GraphQL mutation inputs) to elicit vulnerable behavior. Red-Team SKU + authorization gates (§4). - Attack chains — multi-step request sequences that extract artifacts from one response and use them in later requests, including authorization-boundary testing. Red-Team SKU + authorization gates.
- Race-condition probes — multiple concurrent requests to detect timing/TOCTOU and double-submission defects. Red-Team SKU + authorization gates.
- Reactive mutations — when a signal is detected, follow-up payloads (generated by the Company cloud) constrained to the same target host. Red-Team SKU + authorization gates.
- Proof-of-concept output — reproduction material for confirmed findings, subject to redaction and category scoping.
You acknowledge these capabilities exist in the Agent software whether or not you enable them, and that enabling offensive modes is your deliberate act.
3. License Grant
3.1 Subject to these Agent Terms and payment of applicable fees, the Company grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to install and run the Agent solely for lawful security testing of systems, applications, and APIs that you own or are expressly authorized in writing to test.
3.2 The Agent's source code is additionally provided under the Apache License 2.0. The Apache 2.0 license governs your rights in the code; these Agent Terms govern your rights and obligations in your use of the Agent against live targets. To the extent of any conflict as to use against targets, these Agent Terms control.
3.3 You will not use the Agent, or permit it to be used, outside the scope of §3.1.
4. Authorization to Test — Your Core Obligation
4.1 Authorization warranty. You represent, warrant, and covenant that, for every target host, endpoint, domain, or IP address you direct the Agent against, and before any scanning, probing, injection, chaining, race testing, exploitation, or proof-of-concept activity, you have obtained all authorization, consent, and legal right necessary from (a) the owner and operator of the target; and (b) any third party whose systems, data, hosting, or cloud infrastructure may be affected (including cloud providers such as AWS, Azure, or Google Cloud, whose own policies may require separate authorization).
4.2 Sole responsibility. You are solely responsible for determining that you hold the authorization required by §4.1 and that your use is lawful in every applicable jurisdiction. The Company does not and cannot grant you authorization over any system you do not own or control (§10).
4.3 How the Agent's authorization gates work — and their limits. For offensive modes, the Agent requires all of the following to align before any state-changing request is sent: (i) a local sandbox configuration you set; (ii) a dashboard-side configuration pushed from your Company account; and (iii) a signed authorization token that the target operator publishes at /.well-known/middlebrick-sandbox, cryptographically signed with the target operator's own key, scoping the permitted methods, paths, exploit categories, and agent identities, and time-bounded. These gates are a safety and evidence mechanism, not a substitute for your authorization warranty. They do not verify that you personally are lawfully entitled to test the target, and they do not transfer any of your obligations under §4.1 to the Company.
4.4 Per-run attestation. Before initiating any offensive operation, the Agent may require you to affirmatively attest that you are authorized to test the specified target. Each such attestation is a representation you make under these Agent Terms. You consent to the Company logging the attestation (target identifier, timestamp, your account and agent identity, and the terms version accepted) as a record of that representation.
5. Prohibited Use
5.1 You shall not use, configure, or permit any person to use the Agent for any unlawful, unauthorized, or irresponsible purpose, including directing the Agent — in any mode — at any system you do not own or lack written authorization to test.
5.2 You acknowledge that using the Agent against systems for which you lack authorization may violate criminal and civil law, including the U.S. Computer Fraud and Abuse Act (18 U.S.C. §1030), the UK Computer Misuse Act 1990, EU Directive 2013/40/EU and national implementing laws (including Germany's §§202a–202c StGB), and the Código Penal Federal (México), arts. 211 bis 1–7.
5.3 You shall not: (a) remove, disable, or circumvent any authorization gate, safety check, rate limit, kill-switch, or audit mechanism in the Agent; (b) use the Agent to cause a denial of service except where authorized and intended as part of a test you are permitted to perform; (c) use the Agent to access, exfiltrate, or retain data you are not authorized to access; or (d) misrepresent your authorization in any attestation under §4.4.
6. Assumption of Risk and Due Care
6.1 The Agent can cause damage. In its offensive modes, the Agent can disrupt, degrade, corrupt, or destroy target systems and data, trigger security controls, and generate load. You assume all risk arising from your use of the Agent.
6.2 You shall exercise due care, review the Agent documentation and configuration before each engagement, and not run offensive modes against production systems, or against any system for which you do not accept the risk of damage. Where practical, test against staging or dedicated sandbox environments.
6.3 You are responsible for configuring scope, rate, concurrency, and target allowlists appropriately for your authorized engagement.
7. Data Handling and Your Data Responsibilities
7.1 The Company does not receive your request or response content. The Agent processes request and response content only locally, on the machine you run it on, and transmits to the Company cloud only PII-free metadata, findings descriptors, and scores — never raw request or response bodies. This local-only content handling is the Agent's single operating mode; it is not a user-configurable option and cannot be turned off. Request bodies appear in audit records only as a cryptographic hash and size, never as raw content. Proof-of-concept output is generated and held locally, subject to redaction and category scoping.
7.2 You are responsible for anything the Agent does touch locally. Because content is processed on your own machine, you — not the Company — control and are responsible for any personal data the Agent encounters. You represent and warrant that you have and will maintain all rights, consents, and lawful bases required under applicable data-protection law (including the GDPR/UK GDPR, México's LFPDPPP, and the CCPA/CPRA) for the Agent to process, on your machine and on your instruction, any data belonging to you or to any target you are authorized to test.
7.3 No processing relationship over content. Because the Company does not receive raw request or response content (§7.1), the Company is not a processor of, and assumes no controller or processor obligations over, that content. For the limited PII-free metadata the Agent does transmit, the Data Processing Addendum governs to the extent any of it constitutes personal data.
7.4 Local artifacts. The Agent may write audit and telemetry records to the machine on which it runs. Those artifacts, and any content they reference, remain under your control. You are solely responsible for their security, retention, and disposal.
8. Disclaimer of Warranties
THE AGENT AND ALL OUTPUTS ARE PROVIDED "AS IS" AND "WITH ALL FAULTS," WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. THE COMPANY DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. THE COMPANY SPECIFICALLY DISCLAIMS ANY WARRANTY THAT SECURITY SCORES, FINDINGS, OR OUTPUTS WILL BE ACCURATE, COMPLETE, OR ERROR-FREE, OR THAT THE AGENT WILL NOT CAUSE DAMAGE TO ANY TARGET SYSTEM.
9. Limitation of Liability
9.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, OR FOR DAMAGE TO ANY THIRD-PARTY SYSTEM, ARISING OUT OF OR RELATING TO THE AGENT.
9.2 EACH PARTY'S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED THE GREATER OF (a) THE FEES YOU PAID FOR THE AGENT IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (b) US $100.
9.3 Sole and exclusive remedy. To the maximum extent permitted by law, your sole and exclusive remedy for any claim arising out of or relating to the Agent is (a) to stop using it, and (b) to recover the amount §9.2 permits — that is, a refund of the fees you paid.
9.4 Mandatory-liability carve-out. Nothing in these Agent Terms excludes or limits liability for fraud or fraudulent misrepresentation, willful misconduct, gross negligence, death or personal injury caused by negligence, or any liability that cannot be excluded or limited under applicable law. This §9.4 controls over §§8, 9.1–9.3 to the extent required by law.
10. No Authorization Over Third-Party Systems
Nothing in these Agent Terms, and nothing the Company provides, authorizes you to test any system you do not own or control. The Company cannot and does not grant authorization over third-party systems; only the owner or operator of a target can authorize testing of it. Any authorization gate the Agent enforces reflects a target operator's own signed grant and is not the Company's grant.
11. Indemnification
11.1 You will defend, indemnify, and hold harmless the Company and its affiliates, members, officers, employees, and contractors from and against any and all third-party or governmental claims, and all resulting damages, settlements, fines, penalties, and reasonable attorneys' fees and costs, arising out of or relating to: (a) your use or configuration of the Agent; (b) any target you direct the Agent against, including any claim by the owner or operator of a target; (c) your testing of any system you were not authorized to test; (d) your breach of these Agent Terms or any representation herein (including the §4 authorization warranty and the §7.2 data-rights warranty); or (e) your violation of any applicable law.
11.2 The user runs the defense; the Company steps aside. On any covered claim, the Company may tender the claim to you, whereupon you must assume and control the defense and settlement at your expense. You may not settle in a way that admits fault by, or imposes any non-monetary obligation on, the Company without its prior written consent. The Company is not obligated to litigate or defend on your behalf and may withdraw and leave the matter to you.
11.3 Evidence disclosure. You agree that the Company may disclose the attestation and audit records it holds (target identifier, timestamps, your account and agent identity, the authorization scope in effect, and the terms version you accepted) to any claimant, affected party, court, regulator, or law-enforcement authority, to establish who authorized and performed the activity. You waive any objection to the Company producing them for that purpose.
11.4 Neutral tool provider. The Agent is a tool you operate. The Company does not select your targets, does not authorize your targets (§10), does not receive your content (§7.1), and does not participate in your engagements. Responsibility for every use of the Agent rests solely with you.
11.5 This §11 is not subject to the limitation of liability or the sole-remedy provision in §§9.2–9.3.
12. Compliance and Export
You shall comply with all applicable laws in your use of the Agent, including computer-misuse, data-protection, sanctions, and export-control laws, and shall not use the Agent where prohibited or in any embargoed jurisdiction or by any sanctioned party.
13. Suspension, Revocation, and Termination
13.1 The Company may suspend, revoke, or terminate your license and disable the Agent's authorization immediately and without liability if it reasonably believes you are using the Agent unlawfully, without authorization, or in breach of these Agent Terms, or if required by law.
13.2 You acknowledge the Agent is designed to honor near-real-time revocation and quarantine commands from the Company cloud, and that upon revocation the Agent will cease authorized operation.
13.3 Upon termination your license ends immediately; you must stop using the Agent; and the surviving sections continue in effect.
14. Governing Law, Dispute Resolution, and Consumer Carve-Out
To be finalized by counsel. Governing law, venue, and arbitration depend on the final entity structure (§1.2) and are being finalized. Until then, these provisions are not in force. The recommended pattern is: governing law and exclusive venue in the Company's litigation base; binding individual arbitration with a class-action waiver for U.S. business users; and a mandatory consumer carve-out preserving non-waivable protections for any EU/UK/other consumer notwithstanding §1.1.
15. Survival, Severability, Entire Agreement
15.1 Survival. §§2, 4, 5, 6, 7.2–7.4, 8, 9, 10, 11, 12, 14, and 15 survive termination.
15.2 Severability. If any provision is held invalid or unenforceable, the remainder continues in full force, and the invalid provision is limited or reformed to the minimum extent necessary.
15.3 Relationship to General Terms. These Agent Terms supplement the General Terms, the Privacy Policy, and the DPA. Together they are the entire agreement between the parties as to the Agent.
Acceptance
Acceptance of these Agent Terms is required before the Red-Team SKU is enabled for your organization. Acceptance is recorded as version, timestamp, and account id — there is no pre-checked box, and each new version requires a fresh acceptance. Until an acceptance for the current version is on record, the Agent's offensive modes remain disabled regardless of subscription.