Back

Legal

Terms of Service

The rules for using GhostRecon. The short version: it runs on your machine, you bring your own model key, and you only ever point it at systems you are allowed to test.

Effective September 1, 2026 · Last updated September 1, 2026

01

The agreement

These Terms of Service (the Terms) are a contract between you and GhostRecon (we, us) covering the GhostRecon application, the ghostrecon.tech website, and everything we offer through them (together, the Service).

By joining the waitlist, installing the application, or using the Service in any way, you accept these Terms. If you are using the Service for an organisation, you confirm you are authorised to bind that organisation, and you means both you and it. If you do not accept these Terms, do not use the Service.

02

What GhostRecon is

GhostRecon is a desktop application that drives an AI agent and a set of open-source security tools against a target you choose, so you can find security weaknesses in software you own or are engaged to assess.

  • It runs on your machine. Scans, browser sessions, captured traffic, and findings stay on your computer unless you choose to share them.
  • You bring your own model key. The agent reasons using an AI provider you connect. We do not resell inference and we do not sit between you and your provider.
  • It is a tool, not a guarantee. It assists a person doing security work. It does not replace professional judgement and it does not certify anything as secure.
03

Authorised testing only

This is the most important term in this document, and the one we will enforce without discussion.

Read this one

You may only point GhostRecon at systems you own, or that you have explicit, written permission from the owner to test: a signed engagement letter, a scope document, a bug-bounty programme's published rules, or a lab or CTF environment built for the purpose. You are responsible for confirming that permission before you start and for staying inside the scope you were given.

Testing systems without authorisation is a criminal offence in most jurisdictions, including under the Computer Fraud and Abuse Act in the United States and the Computer Misuse Act in the United Kingdom. We provide the tool; the authorisation is yours to hold, and the liability for testing without it is yours alone.

04

What you may not do

You agree not to use the Service to:

  • Access, test, disrupt, or damage any system without authorisation from its owner.
  • Exfiltrate, retain, sell, or publish data belonging to anyone else, including data surfaced during an authorised engagement beyond what the engagement permits.
  • Deploy ransomware, backdoors, botnets, or any persistent access; deliberately degrade or deny service; or destroy or alter data on a target.
  • Harass, stalk, deanonymise, or target a private individual.
  • Break any applicable law or regulation, or breach a contract you have with a third party, including a hosting provider's or model provider's acceptable-use policy.
  • Resell, rent, or offer the Service as your own product, or share paid access across people or organisations it wasn't licensed to.
  • Reverse engineer, decompile, or circumvent the licensing and entitlement checks, or work around limits on a plan you have not paid for, except where that restriction is void under applicable law.
  • Extract, republish, or resell our prompts, agent methodology, templates, or reports as a product or dataset, including to train a competing model or service.

We may suspend or terminate access immediately, without refund, if we reasonably believe you have broken these rules.

05

Eligibility and your account

You must be at least 18 years old and legally able to enter a contract. You are responsible for keeping your account credentials safe and for everything done under your account. Tell us at legal@ghostrecon.tech as soon as you believe your account has been used without your permission.

Waitlist signups are an expression of interest. They do not guarantee access, a launch date, or any particular price.

06

Your model provider keys

GhostRecon runs on a model API key you supply. Your key stays on your machine and the application talks to your provider directly.

  • You are responsible for all usage charges your provider bills you, including usage driven by the agent.
  • Your use of that provider is governed by its own terms and privacy policy. What you send through the agent is sent to that provider, and how they handle it is between you and them.
  • Keep your key confidential. We cannot recover, rotate, or reimburse a key that leaks from your machine.
07

Plans, billing, and cancellation

GhostRecon has a free tier and a paid Pro subscription. Current features and prices are shown on ghostrecon.tech at the time you subscribe, and the price you see at checkout is the price you pay for that billing period.

  • Renewal. Paid plans renew automatically at the end of each billing period until you cancel.
  • Cancelling. You can cancel at any time. Cancellation stops the next renewal; your Pro features run to the end of the period you have already paid for.
  • Refunds. Payments are non-refundable except where the law requires otherwise or where we say so in writing. If something went genuinely wrong, write to us and we will look at it.
  • Price changes. We may change prices with at least 30 days' notice before your next renewal. Your remedy if you disagree is to cancel before then.
  • Taxes. Prices exclude taxes unless stated. You are responsible for any tax due on your purchase other than tax on our income.
08

Your licence to use the software

Subject to these Terms and your plan, we grant you a personal, non-exclusive, non-transferable, revocable licence to install and use GhostRecon for your own security testing or for engagements you are contracted to perform.

We keep all rights we do not expressly grant. The application, its interface, our agent prompts and methodology, our report templates, and our branding remain ours.

09

Third-party and open-source tools

GhostRecon orchestrates independent open-source security tools and third-party services. Each of those is distributed by its own authors under its own licence, and we make no warranty about any of them.

  • Some are capable of causing damage or downtime if misused. You are responsible for the effect they have on a target you point them at.
  • Their licences continue to apply to your use of them, and where a licence conflicts with these Terms in respect of that tool, that licence governs.
  • We may add, replace, or remove tools as the ecosystem changes, or where continuing to ship one creates legal or safety risk.
10

Your targets, data, and findings

You keep everything you own. Your code, your targets, the traffic you capture, and the findings and reports the agent produces for you are yours. We claim no ownership of them and no licence to use them.

Because engagements run locally, we do not receive that material in the ordinary course of using the Service. If you deliberately send us something such as a bug report, a log, or a support attachment, you give us permission to use it for the limited purpose of helping you and fixing the problem. What we do collect is set out in the Privacy Policy.

11

Availability and changes

We are building this in the open and the Service will change. We may add, alter, or remove features, and we may suspend parts of the Service for maintenance or for security. We aim to give reasonable notice of changes that materially reduce what you have paid for.

The Service depends on things outside our control: your machine, your network, your model provider, and the third-party tools above. We do not promise uninterrupted availability.

12

No warranty

The Service is provided “as is” and “as available”. To the fullest extent the law allows, we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement.

In particular, and to be direct about it:

  • Security testing is never complete. A clean run does not mean your application is secure, and no finding list should be read as an exhaustive one.
  • AI output can be wrong. Findings may be false positives, missed entirely, or described inaccurately. Verify anything you intend to act on or hand to a client.
  • The Service is not a certification, an audit, or a compliance attestation, and it is not legal advice.
  • Active testing can disrupt a live system. Test in an environment you can afford to break, and take backups first.
13

Limitation of liability

To the fullest extent permitted by law, neither we nor our suppliers are liable for any indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost revenue, lost data, business interruption, or damage to systems, however caused and on any theory of liability.

Our total liability for all claims relating to the Service is limited to the greater of the amount you paid us in the twelve months before the event giving rise to the claim, or one hundred US dollars (US$100).

Nothing here excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence. Some jurisdictions do not allow some of these exclusions, in which case they apply to you only as far as the law permits.

14

Indemnification

You will defend, indemnify, and hold us harmless from any claim, loss, liability, or expense (including reasonable legal fees) arising out of your use of the Service, your breach of these Terms, your infringement of anyone's rights, or any testing you carried out without the authorisation described in section 3.

15

Termination

You may stop using the Service and cancel your plan at any time. We may suspend or terminate your access if you breach these Terms, if we are required to by law, or if continuing to serve you creates material legal or security risk.

Sections covering prohibited use, third-party tools, warranty disclaimers, liability, indemnity, and governing law survive termination.

16

Governing law and disputes

These Terms are governed by the laws of the State of Delaware, United States, without regard to conflict of law rules. You and we submit to the exclusive jurisdiction of the state and federal courts located in Delaware, except that either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property.

If you have a mandatory consumer right to bring proceedings in your own country of residence, this section does not take it away.

Before filing anything, please write to legal@ghostrecon.tech. Most disputes are faster to fix by email.

17

General terms

  • Whole agreement. These Terms and the Privacy Policy are the entire agreement between us about the Service.
  • Severability. If a provision is unenforceable, the rest stays in force.
  • No waiver. Not enforcing a term once does not waive it.
  • Assignment. You may not assign these Terms without our written consent. We may assign them as part of a merger, acquisition, or sale of assets.
  • Notices. We may reach you at the email address on your account or by a notice in the application.
18

Changes to these Terms

We may update these Terms as the product and the law change. If a change is material we will give notice on ghostrecon.techor by email before it takes effect, and we will move the “last updated” date at the top of this page. Continuing to use the Service after a change takes effect means you accept the updated Terms.

19

Contact

Questions about these Terms: legal@ghostrecon.tech.

Questions about data and privacy: privacy@ghostrecon.tech, or read the Privacy Policy.