middleBrick

Vulnerabilities

  • Prompt Injection
  • BOLA / IDOR
  • Auth Bypass
  • JWT Misconfiguration
  • SSRF
  • Data Exposure
  • Rate Limiting
  • Mass Assignment
  • GraphQL Attacks
View all 60+

Frameworks

  • FastAPI
  • Express
  • Spring Boot
  • Django
  • NestJS
  • Rails
  • Laravel
  • Gin
  • ASP.NET
View all 30+

LLM Security

  • OpenAI
  • Anthropic
  • Google Gemini
  • Mistral
  • Meta Llama
  • LangChain
  • LlamaIndex
View all 15+

By Industry

  • Fintech
  • Healthcare
  • SaaS
  • IoT

By Protocol

  • REST
  • GraphQL
  • gRPC
  • WebSocket

CWE Database

  • CWE-89: SQL Injection
  • CWE-79: XSS
  • CWE-287: Auth Bypass
  • CWE-200: Data Exposure
  • CWE-918: SSRF
  • CWE-502: Deserialization
View all 200+

Attack Techniques

  • Credential Stuffing
  • JWT Cracking
  • Prompt Injection
  • SSRF Metadata
  • IDOR Enumeration
View all 40+
Scan Your API Now — Free

Standards

  • OWASP API Top 10
  • PCI-DSS
  • HIPAA
  • SOC 2
  • GDPR
  • ISO 27001
  • NIST
  • CIS

Popular Checks

  • OWASP: Auth Bypass
  • PCI-DSS: Data Exposure
  • HIPAA: PII Leakage
  • SOC 2: Encryption
  • GDPR: Data Protection

Regional Regulations

  • GDPR (EU)
  • CCPA (California)
  • LGPD (Brazil)
  • PSD2 (EU)
  • DORA (EU)
  • NIS2 (EU)
  • PIPL (China)
  • CMMC (US DoD)
  • FedRAMP (US)
View all 20+

Standards

  • OWASP API Top 10
  • PCI-DSS
  • HIPAA
  • SOC 2
  • GDPR
  • ISO 27001
  • NIST
  • CIS
Pricing Docs
EN ES PT DE FR
Get Started

Terms of Service

Last updated: March 28, 2026

Our Philosophy: These terms are designed to be fair, clear, and respectful of your rights. We believe in complete transparency about what you can expect from our services.

The following Terms of Service ("Terms") govern your access to and use of the products, services, and applications provided by Zevlat Intelligence and all its brands, including middleBrick ("we", "our" or "Zevlat Intelligence"). By using our services, you accept these Terms.

1. Acceptance of Terms

By accessing or using any of our services, you confirm that:

  • You have read and understood these Terms
  • You agree to comply with these Terms and all applicable laws
  • You have the legal capacity to enter into this agreement
  • If acting on behalf of an organization, you have authority to bind that organization

2. Description of Services

middleBrick provides API security scanning and risk scoring services. Specific services, features, and functionalities may vary depending on your subscription plan and are subject to change to improve your experience.

2.1 Service Modifications

We reserve the right to:

  • Modify, suspend, or discontinue any aspect of the service
  • Update functionalities to improve user experience
  • Perform scheduled or emergency maintenance

We will make reasonable efforts to notify you of significant changes that materially affect your use of the service.

3. Scanning Services

3.1 How Scanning Works

middleBrick scans APIs by sending lightweight, read-only HTTP requests (GET and HEAD only) to the endpoint you provide. The scanner analyzes the responses to identify security vulnerabilities. middleBrick does not sit inline with your API traffic, does not intercept or modify requests, and does not send destructive payloads.

3.2 Your Responsibility

You represent and warrant that:

  • You are authorized to scan the API endpoints you submit (you own them, or have explicit written permission from the owner)
  • You will not use middleBrick to scan APIs you do not have authorization to test
  • You understand that scanning sends HTTP requests to the target endpoint

3.3 AI/LLM Endpoint Probing

For endpoints detected as AI or LLM services, middleBrick may send adversarial text prompts (POST requests) to test for prompt injection, jailbreak, and data leakage vulnerabilities. These probes contain text only — no malware, exploit code, or destructive payloads. If you prefer to exclude AI probing, scan your staging environment instead of production.

3.4 Scan Data Ownership

All data generated from scanning your APIs — including endpoint URLs, scan results, findings, and risk scores — is your data. You retain full ownership. We process this data solely to provide the scanning service and do not use it for any other purpose.

No Data Sharing: We do not sell, share, or use your scan data to train machine learning models, benchmark against other customers, or for any purpose beyond providing the service you requested. Anonymized, aggregated metadata (such as technology signature frequencies) may be used to improve detection accuracy — no customer-identifiable data is included.

3.5 Data Deletion

You may delete individual scan results at any time through the dashboard or API. Upon account cancellation, all your scan data (results, findings, audit logs) will be permanently deleted within 30 days.

4. User Accounts

4.1 Registration and Security

If you create an account with us, you are responsible for:

  • Providing accurate and complete information
  • Maintaining the security of your account and password
  • Notifying us immediately of any unauthorized use
  • All activities that occur under your account

4.2 Age Requirements

You must be at least 13 years old to use our services. If you are between 13 and 18 years old, you must have the consent of a parent or legal guardian.

5. Acceptable Use

When using our services, you agree NOT to:

  • Violate any laws, regulations, or third-party rights
  • Use the service for illegal or unauthorized activities
  • Attempt to gain unauthorized access to our systems or other users' data
  • Distribute malware, viruses, or malicious code
  • Reverse engineer, decompile, or decrypt our software
  • Interfere with the normal operation of the service
  • Use the service for spam, phishing, or fraud
  • Impersonate other persons or organizations
  • Collect user information without their consent

6. Intellectual Property

6.1 Zevlat Intelligence Rights

All rights, titles, and interests in our services, including software, design, content, trademarks, and technology, are owned by Zevlat Intelligence. These Terms do not grant you any ownership rights over our services, only a limited right to use them according to these Terms.

6.2 Your Content

You retain all rights to content you create, upload, or provide through our services. You grant us a limited license to operate, improve, and provide our services.

Commitment to Your Intellectual Property: We respect your work and creativity. We do not claim ownership of your content nor use it for purposes other than providing the service you requested.

7. Privacy and Data Protection

Your privacy is fundamental to us. The use of our services is also governed by our Privacy Policy, which describes how we collect, use, and protect your information.

Key points of our privacy commitment:

  • We collect only the minimum necessary data
  • We never sell or monetize your personal information
  • We implement security measures to protect your data
  • You own your content and data

8. Payment and Billing

8.1 Pricing and Charges

Some of our services may require payment. By subscribing to a paid service:

  • You agree to pay all fees and charges according to current prices
  • You provide accurate and complete payment information
  • You authorize recurring charges according to your subscription plan
  • Prices may change with prior notice

8.2 Refunds

We currently do not offer refunds for our products and services. All sales are final.

9. Warranties and Limitation of Liability

9.1 "As Is" Services

Our services are provided "as is" and "as available". While we strive to offer high-quality services, we do not guarantee that:

  • The service will be error-free or uninterrupted
  • Results will meet your specific expectations
  • All errors will be corrected

9.2 Limitation of Liability

To the maximum extent permitted by law:

  • We will not be liable for indirect, incidental, special, or consequential damages
  • Our total liability is limited to amounts you have paid in the last 12 months
  • We are not liable for loss of data, profits, or business opportunities

Legal Transparency: These limitations are standard in the software industry and allow us to offer accessible services. However, nothing in these Terms limits your right to file valid complaints or seek appropriate legal remedies.

10. Indemnification

You agree to indemnify and hold harmless Zevlat Intelligence from any claim, damage, obligation, loss, liability, cost or debt, and expense arising from:

  • Your use or misuse of our services
  • Your violation of these Terms
  • Your violation of third-party rights
  • Any content you provide or publish

11. Termination

11.1 Termination by You

You may stop using our services at any time. For paid services, please review specific cancellation terms.

11.2 Termination by Us

We may suspend or terminate your access if:

  • You violate these Terms or our Acceptable Use Policy
  • Your use puts our systems or other users at risk
  • We are legally required to do so
  • We discontinue the service (with reasonable prior notice)

11.3 Effects of Termination

Upon terminating your account:

  • Your right to use the service ceases immediately
  • We may delete your content according to our data retention policy
  • Sections of these Terms that by their nature should survive will continue in effect

12. Dispute Resolution

12.1 Direct Contact

If you have a problem with our services, we encourage you to contact us first to resolve the matter informally.

12.2 Governing Law

These Terms will be governed by and construed in accordance with applicable laws, without giving effect to any principles of conflicts of law.

13. General Provisions

13.1 Severability

If any provision of these Terms is deemed invalid or unenforceable, the remaining provisions will continue in full force and effect.

13.2 Entire Agreement

These Terms, together with our Privacy Policy and any service-specific agreements, constitute the entire agreement between you and Zevlat Intelligence.

13.3 Waiver

No waiver of any provision of these Terms will be deemed a further or continuing waiver of such provision or any other provision.

13.4 Assignment

You may not assign these Terms without our prior written consent. We may assign these Terms at any time, including in the event of a merger or acquisition.

13.5 No Agency Relationship

These Terms do not create any partnership, joint venture, employment, or agency relationship between you and Zevlat Intelligence.

14. Changes to These Terms

We may update these Terms periodically to reflect:

  • Changes to our services
  • Legal or regulatory requirements
  • Industry best practices

Significant changes will be communicated through:

  • Notification on our website
  • Email to your registered address (when applicable)
  • In-service message

Your continued use of our services after changes take effect constitutes your acceptance of the new Terms.

Scope: These Terms of Service apply to all products, services, applications, and websites operated by Zevlat Intelligence and its associated brands, including middleBrick. Our commitment to fair and transparent practices extends throughout our entire ecosystem.

Final Note: We believe terms of service should not be documents designed to confuse or trap users. These terms are written to be as clear and fair as possible, protecting both your rights and ours.

middleBrick is a Zevlat Intelligence venture

Privacy Policy