1. About These Terms
These Terms of Service (“Terms”) govern access to and use of the AegisBreach website, application, account area, domain-verification functionality, security-scanning services, reports, package access, support, and related services (collectively, the “Service”).
AegisBreach is a cybersecurity service being developed and operated under the AegisBreach brand by Mladen Stanković in Pirot, Serbia.
In these Terms, “AegisBreach”, “we”, “us”, and “our” refer to the operator of the Service.
For questions about these Terms, contact:
2. Acceptance of These Terms
By creating an account, accessing an authenticated area, submitting a domain, requesting a scan, purchasing package access, or otherwise using the Service, you agree to these Terms.
If you use the Service on behalf of a company, organization, client, school, project team, or another person, you confirm that you are authorized to act for that party and to bind that party to these Terms where legally permitted.
If you do not agree to these Terms, do not use the Service.
Mandatory rights that cannot legally be excluded or limited remain unaffected.
3. Who May Use the Service
The Service is intended for:
- businesses;
- entrepreneurs;
- developers;
- technical teams;
- freelancers;
- students;
- school-project creators;
- website and application owners; and
- other people or organizations with a legitimate and authorized cybersecurity-testing purpose.
AegisBreach does not impose a general product minimum age and is not specifically directed at children.
Younger users may use the Service for their own websites, school projects, development projects, or other authorized systems, subject to applicable law.
A person must have the legal capacity to accept these Terms or must use the Service with any permission, involvement, or authorization required under applicable law.
A person making a paid purchase must have the legal capacity or required authorization to complete that transaction.
AegisBreach does not currently use automatic age-verification technology.
4. Accounts and Organizations
Some Service features require an account.
You agree to:
- provide accurate and reasonably current account information;
- use an email address that you are authorized to use;
- protect your password and account access;
- not share credentials in an unsafe or unauthorized manner;
- promptly notify AegisBreach of suspected unauthorized access;
- keep organization membership and role assignments appropriate; and
- remain responsible for activity performed through your account, except where applicable law provides otherwise.
An organization account may include owners, members, or other roles with different permissions.
The organization owner or an authorized administrator is responsible for deciding who may access the organization and its domains, scans, reports, package entitlements, and related data.
AegisBreach may use technical controls to enforce organization and authorization boundaries, but each user remains responsible for using only the access granted to them.
5. Authorized Security Testing Only
You may submit or scan only a domain, website, application, or system that:
- you own;
- your organization owns;
- you administer with appropriate authority;
- a client has authorized you to test; or
- you otherwise have clear legal permission to assess.
By submitting a target, you represent that you have the necessary authorization.
Domain verification or another technical control may be required before certain scans or features are available. Passing a technical verification step does not replace your legal responsibility to obtain authorization.
You must not use the Service to scan, test, access, investigate, or collect information from systems without permission.
6. Prohibited Use
You must not use or attempt to use the Service to:
- gain unauthorized access to any account, system, network, or data;
- exploit, weaponize, or abuse a discovered weakness;
- steal, expose, alter, destroy, or unlawfully obtain data;
- deploy malware, ransomware, spyware, credential-stealing software, or other harmful code;
- perform denial-of-service activity or intentionally overload a system;
- evade authentication, authorization, rate limits, quotas, or security controls;
- scan targets for which you do not have authorization;
- impersonate another person or organization;
- submit false ownership or authorization information;
- interfere with the Service or another user’s access;
- resell, sublicense, copy, reverse engineer, or commercially exploit the Service except where a written agreement or applicable law permits it;
- use automated access in a way not supported or authorized by AegisBreach;
- violate intellectual-property, privacy, confidentiality, consumer-protection, computer-misuse, export-control, sanctions, or other applicable laws;
- use scan results to facilitate illegal activity; or
- encourage or assist another person to do any of the above.
AegisBreach may investigate suspected misuse and may preserve or disclose relevant information where required or permitted by law.
7. Nature of the Service
AegisBreach provides controlled cybersecurity scanning and informational risk assessment.
Depending on the selected feature or package, the Service may examine technical matters such as:
- configuration weaknesses;
- SSL or TLS configuration;
- security headers;
- exposed technical information;
- e-commerce-related security indicators;
- domain-verification status;
- other supported security checks; and
- related findings and recommendations.
The exact checks, features, limits, and report content may vary by package, target, technical conditions, and Service version.
AegisBreach may use automated systems, rules, and technical checks to produce findings.
8. No Guarantee of Complete Security
Scan results and reports are informational risk assessments, not guarantees of complete security.
AegisBreach does not guarantee that:
- every vulnerability, weakness, misconfiguration, or risk will be identified;
- every finding will be free from false positives or false negatives;
- a target is secure because no issue was reported;
- a target will remain secure after a scan;
- a recommended action will be suitable for every environment;
- a third party will not successfully attack a target; or
- the Service replaces a penetration test, code review, compliance audit, legal review, or assessment by a qualified cybersecurity professional.
Security conditions can change after a scan because of software updates, configuration changes, new vulnerabilities, third-party changes, user actions, or new attack methods.
You are responsible for evaluating findings, backing up systems, testing remediation safely, and deciding whether professional assistance is required.
9. User Responsibility for Findings and Remediation
You are responsible for:
- reviewing the accuracy and relevance of findings;
- deciding whether and how to remediate an issue;
- avoiding changes that could damage production systems;
- creating appropriate backups before making changes;
- testing changes in a safe environment where possible;
- obtaining professional advice for high-risk systems; and
- complying with legal, contractual, industry, and regulatory requirements applicable to your system.
AegisBreach does not perform remediation unless a separate written service expressly states otherwise.
10. Free and Paid Service Features
AegisBreach may provide free scans, free account functionality, paid packages, promotional access, trial functionality, or other feature levels.
Free features may have stricter limits and may be changed, restricted, or discontinued.
Paid package details may include:
- access period;
- included scan types;
- scan-credit allocation;
- domain quota;
- report functionality;
- package-specific features; and
- other limits displayed before purchase.
The package description shown before purchase forms part of the transaction information.
AegisBreach may correct an obvious pricing, configuration, or package-description error before completing a transaction, subject to applicable law.
11. One-Time 31-Day Package Model
The planned paid-package model is:
- one-time payment;
- 31 days of package access;
- no automatic renewal;
- no recurring charge; and
- a new purchase is required for a new access period.
The 31-day period begins when package access is successfully activated, unless the purchase page clearly states another legally valid start time.
Changing the price or features of a package does not retroactively change a package already purchased, except where a change is required by law, is necessary for security, or is expressly agreed with the user.
12. Scan Credits, Domain Quotas, and Expiry
A paid package may include a specified number of scan credits and a domain quota.
Unless the purchase page expressly states otherwise:
- scan credits may be used only during the active 31-day package period;
- unused scan credits expire at the end of that period;
- unused scan credits do not roll over automatically;
- domain capacity does not carry forward after package expiry;
- expired credits have no cash value; and
- buying a later package does not restore credits from an earlier expired package.
AegisBreach may restore credits where a confirmed technical failure incorrectly consumed them.
Any mandatory rights under applicable law remain unaffected.
13. Prices, Currency, and Charges
Before purchase, AegisBreach will display the selected package, price, currency, and any other information required by applicable law.
There are no automatic renewal charges under the planned package model.
AegisBreach will not add an optional paid item without the user’s express selection or consent.
Taxes, duties, conversion fees, bank fees, or similar charges will be handled or disclosed as required by applicable law and the payment arrangement.
A bank, card issuer, or payment provider may apply its own currency-conversion or transaction charges. Those third-party charges are outside AegisBreach’s control unless applicable law provides otherwise.
Price changes apply only to future purchases and do not create a recurring payment obligation.
14. Payment Processing
Live card checkout is not currently enabled.
When card payments are enabled, the intended model is a bank-hosted or bank-controlled payment environment.
The exact bank, gateway, acquiring arrangement, and payment disclosures remain pending contract and technical confirmation.
AegisBreach does not intend to store:
- the full payment-card number; or
- the CVV, CVC, or other card security code.
AegisBreach may receive and store limited transaction information needed to manage the order, such as:
- order identifier;
- selected package;
- amount;
- currency;
- transaction status;
- bank or provider reference;
- activation status;
- timestamps; and
- related entitlement information.
The payment provider’s own terms and privacy practices may also apply to the payment process.
15. Package Activation
A paid package will be activated only after AegisBreach receives and verifies a successful backend payment confirmation from the contracted bank or payment provider.
A browser redirect, success page, screenshot, email, or user-provided statement is not by itself sufficient proof of payment.
If payment status is delayed, pending, reversed, disputed, rejected, or cannot be verified, package activation may be delayed or withheld while the transaction is reviewed.
AegisBreach may correct an entitlement that was activated by mistake, but will not remove properly paid access without a valid reason permitted by these Terms and applicable law.
16. Withdrawal, Cancellation, and Consumer Rights
Consumers may have mandatory rights to withdraw from a distance contract, request conformity, receive a price reduction, terminate a contract, or obtain another remedy under applicable law.
Nothing in these Terms removes a right that cannot legally be waived.
Where immediate or early performance of a digital service is requested during a statutory withdrawal period, AegisBreach may request any express request, consent, confirmation, or acknowledgment required by applicable law.
The legal effect of starting or completing performance may depend on:
- whether the user is legally a consumer;
- the type of digital service or content;
- whether performance has started or been completed;
- whether legally required information was provided;
- whether legally required consent or acknowledgment was obtained; and
- the law applicable to the transaction.
The final checkout consent wording, withdrawal information, and any required consumer form remain pending payment-flow implementation and external legal review.
17. Refunds and Payment Corrections
Refunds and payment corrections are subject to applicable law and final legal review.
The intended operational approach is:
17.1 Duplicate or incorrect charge
If AegisBreach confirms a duplicate or incorrect charge, we will correct the charge or issue an appropriate refund.
17.2 Paid package not activated because of an AegisBreach failure
If payment is verified but package access is not activated because of an AegisBreach failure, we will restore the purchased access, correct the entitlement, or issue an appropriate refund.
17.3 Nonconforming or unavailable digital service
Where the Service is not delivered as agreed or does not conform to mandatory legal requirements, the user may be entitled to correction, restoration, a proportionate price reduction, termination, refund, or another remedy required by applicable law.
17.4 Voluntary change of mind after use has started
A request based only on a change of mind after activation or use will be reviewed individually.
A refund is not automatically guaranteed merely because the user chose not to use all available credits or no longer needs the package.
This does not limit mandatory withdrawal, conformity, cancellation, or refund rights.
17.5 Abuse or unauthorized use
A refund may be denied to the extent legally permitted where access is suspended or terminated because of confirmed fraud, payment abuse, unauthorized scanning, harmful conduct, or a serious violation of these Terms.
17.6 Refund method and processing time
Approved refunds will normally be returned through the original payment channel where practical and legally appropriate.
Bank, card-network, or payment-provider processing time may affect when refunded funds become visible to the payer.
18. Service Availability
AegisBreach aims to provide a secure and reliable Service but does not promise uninterrupted or error-free availability.
The Service may be unavailable or restricted because of:
- planned maintenance;
- emergency maintenance;
- security incidents;
- infrastructure or hosting failures;
- payment-provider or banking failures;
- internet or network failures;
- software defects;
- capacity limits;
- abusive activity;
- legal or regulatory requirements; or
- events outside reasonable control.
No service-level agreement or guaranteed uptime percentage applies unless AegisBreach enters into a separate written agreement that expressly provides one.
Where reasonably possible, AegisBreach may provide notice of material planned interruptions.
19. Changes to the Service
AegisBreach may improve, update, replace, restrict, or discontinue Service features.
Changes may be made to:
- improve security;
- fix defects;
- respond to abuse;
- maintain compatibility;
- comply with law;
- change infrastructure;
- improve performance;
- adjust free-service limits; or
- develop the product.
AegisBreach will not intentionally remove a material paid feature during an active package period without a reasonable operational, security, or legal reason.
Where mandatory law requires a remedy because a change materially and negatively affects a consumer’s access or use, the applicable remedy remains available.
20. Support
Support is currently provided through:
The initial support model does not include a guaranteed response time, service-level agreement, ticketing portal, or live chat.
Support may assist with:
- account and access issues;
- domain verification;
- scans and reports;
- package and payment questions;
- confirmed technical errors; and
- suspected account or security incidents.
AegisBreach may request reasonable information needed to investigate a request.
Do not send passwords, session tokens, full card numbers, CVV or CVC codes, private keys, secret API keys, or unnecessary sensitive information by email.
21. Suspension and Restriction
AegisBreach may restrict, suspend, or disable access where reasonably necessary because of:
- suspected unauthorized scanning;
- security threats;
- account compromise;
- fraud or payment abuse;
- attempts to bypass limits;
- harmful or illegal activity;
- a serious or repeated breach of these Terms;
- legal or regulatory requirements;
- risk to other users, systems, or AegisBreach infrastructure; or
- nonpayment or reversed payment for paid access.
Immediate action may be taken when reasonably necessary to protect users, systems, data, infrastructure, or legal interests.
For a less urgent issue, AegisBreach may provide a warning or an opportunity to correct the problem where reasonable.
AegisBreach may require additional verification before restoring access.
Any decision concerning unused paid access or refunds after suspension will be made under applicable law, the circumstances of the case, and Section 17.
22. Account Closure and Termination
A user may stop using the Service at any time.
A user may request account deletion through:
Account and personal-data deletion requests are currently reviewed and handled manually.
Deleting an account may remove access to:
- domains;
- scan history;
- findings;
- reports;
- package entitlements;
- unused credits; and
- organization features.
Certain records may be retained where required or permitted for legal, accounting, tax, payment, fraud-prevention, dispute, or security purposes, as explained in the Privacy Policy.
AegisBreach may terminate an account for a serious or repeated breach of these Terms, subject to applicable law.
23. Privacy
Personal-data processing is described in the AegisBreach Privacy Policy.
The Privacy Policy explains matters including:
- account and organization data;
- domain and verification data;
- scan and report data;
- technical and security data;
- payment-related records;
- essential cookies;
- data retention;
- user rights; and
- privacy-request procedures.
These Terms and the Privacy Policy should be read together.
24. Intellectual Property
AegisBreach and its licensors retain ownership of the Service and related intellectual property, including:
- platform code;
- software;
- user-interface design;
- original graphics;
- brand names;
- logos;
- documentation;
- report templates;
- original written content; and
- other protected materials.
These Terms grant only a limited, personal or internal-business, non-exclusive, non-transferable, and revocable right to use the Service in accordance with these Terms.
No ownership right in AegisBreach intellectual property is transferred to the user.
You must not remove copyright, trademark, attribution, or proprietary notices.
25. User Domains, Materials, and Results
You retain any rights you already have in:
- your domains;
- your website or application;
- materials you submit;
- information you provide; and
- your organization’s content.
You grant AegisBreach a limited right to process submitted domains, technical inputs, and related materials only as reasonably necessary to:
- provide the requested Service;
- verify authorization or domain control;
- perform scans;
- generate findings and reports;
- provide support;
- protect the Service; and
- comply with legal obligations.
AegisBreach does not acquire ownership of a user’s domain or website merely because it is submitted for scanning.
AegisBreach owns the Service software, report design, scanning methodology, and original explanatory content. The user may use a generated report for legitimate internal, client, remediation, or compliance-support purposes, subject to these Terms.
26. Confidential and Sensitive Information
The Service is not intended to receive unnecessary secrets or sensitive personal data.
You should not intentionally submit:
- passwords;
- private keys;
- authentication tokens;
- full payment-card details;
- medical records;
- government identification documents;
- highly sensitive personal data; or
- confidential material unrelated to the scan.
Scan findings may reveal sensitive technical information about a system. You are responsible for controlling who can access and share those findings.
AegisBreach does not provide a separate nondisclosure agreement unless expressly agreed in writing.
27. Third-Party Services
The Service may depend on or link to third-party services, including hosting, infrastructure, banking, payment, networking, email, domain, or other providers.
Third-party services may have their own terms, privacy policies, availability, and security practices.
AegisBreach is not responsible for an unrelated third party’s acts or omissions beyond the extent required by applicable law.
The final production providers and payment provider remain subject to review and contracting.
28. Feedback
If you voluntarily provide suggestions, ideas, or product feedback, AegisBreach may use that feedback to improve the Service without an obligation to pay compensation.
This does not transfer ownership of your confidential information, domain, code, or other submitted materials.
Do not submit feedback that you are not authorized to share.
29. Warranties and Disclaimers
AegisBreach will provide the Service with the level of care required by applicable law.
To the maximum extent permitted by law and subject to mandatory consumer rights:
- the Service may contain errors or temporary interruptions;
- scan results may include false positives or false negatives;
- findings are not professional, legal, compliance, or penetration-testing advice;
- compatibility with every technology or environment is not guaranteed;
- remediation outcomes are not guaranteed; and
- third-party systems and services remain outside AegisBreach’s control.
Nothing in these Terms excludes any statutory conformity, quality, security, information, or other right that applicable law makes mandatory.
30. Limitation of Liability
Nothing in these Terms excludes or limits liability where exclusion or limitation is prohibited by applicable law.
Subject to that rule and to the maximum extent permitted by law, AegisBreach is not responsible for indirect, incidental, special, or consequential losses arising only from:
- reliance on a scan as a guarantee of complete security;
- failure to maintain backups;
- unauthorized use of the Service;
- unsafe remediation performed by the user;
- user-provided inaccurate information;
- acts of unrelated third parties;
- internet, hosting, or provider failures outside reasonable control;
- use of the Service contrary to these Terms.
Mandatory consumer remedies and liability for matters that cannot legally be excluded remain unaffected.
An exact contractual liability cap has not yet been adopted and remains pending external legal review.
31. Responsibility for Unauthorized Use and Business-User Claims
You are responsible for losses, claims, or disputes caused by your intentional unauthorized scanning, illegal use, harmful activity, or material breach of these Terms.
Where the user acts as a business or professional user, and to the extent permitted by law, the user may be required to reimburse reasonable losses or costs arising directly from a third-party claim caused by that user’s confirmed unauthorized or illegal use.
This section does not impose an unlawful obligation on a consumer and does not apply where the loss was caused by AegisBreach’s own legally relevant conduct.
The final wording of any business-user indemnity remains subject to external legal review.
32. Force Majeure and Events Outside Reasonable Control
AegisBreach is not responsible for a delay or failure caused by an event outside reasonable control, to the extent permitted by law.
Such events may include:
- widespread internet or network failures;
- major infrastructure-provider failures;
- power outages;
- natural disasters;
- war, terrorism, civil unrest, or sanctions;
- government action;
- banking or payment-network disruption;
- widespread cyberattacks;
- labour disruption; or
- other comparable events.
AegisBreach will take reasonable steps to reduce the impact where practical.
33. Complaints and Dispute Resolution
Questions, complaints, and payment disputes should first be sent to:
The message should include enough information to identify the account, order, affected feature, and requested resolution, without including full card details or unnecessary secrets.
AegisBreach will review the complaint and respond in accordance with applicable law.
A consumer may also have access to:
- a competent consumer-protection authority;
- an authorized out-of-court consumer-dispute-resolution body;
- a data-protection authority for privacy matters; and
- a competent court.
Nothing in these Terms prevents a consumer from using a mandatory complaint, regulatory, out-of-court, or judicial remedy available under applicable law.
The exact commercial-launch complaint procedure and legally required notices remain pending registration and legal review.
34. Governing Law and Jurisdiction
These Terms are intended to be governed by the laws of the Republic of Serbia.
This choice does not remove mandatory consumer rights or protections that apply under the law of another country and cannot lawfully be excluded by contract.
Subject to mandatory consumer-jurisdiction rules, disputes may be brought before a court with jurisdiction under applicable law.
The final jurisdiction and dispute-resolution wording remains subject to external legal review.
35. Changes to These Terms
AegisBreach may update these Terms when:
- the Service changes;
- a payment provider is contracted;
- checkout is implemented;
- package features change;
- infrastructure changes;
- law or regulatory guidance changes;
- business registration is completed;
- security requirements change; or
- external legal review requires amendments.
The updated version will show a revised “Last updated” date.
Material changes affecting an active paid package or mandatory consumer rights will be handled as required by applicable law.
Continued use after a validly communicated change may constitute acceptance where legally permitted. Where fresh consent is legally required, AegisBreach will request it.
36. Electronic Communications
AegisBreach may use the account email address or the Service interface to send operational communications concerning:
- account security;
- domain verification;
- scans and reports;
- payment and package status;
- changes to the Service;
- changes to legal documents;
- support; and
- other necessary Service matters.
Operational messages are not the same as marketing messages.
AegisBreach does not currently plan automated marketing-email campaigns at initial launch.
37. Assignment
You may not transfer your account or rights under these Terms to another person without authorization where such transfer would create security, payment, or legal risk.
AegisBreach may transfer these Terms as part of a lawful business reorganization, sale, merger, or transfer, subject to applicable law and appropriate notice where required.
38. Severability
If a provision of these Terms is found invalid, unlawful, or unenforceable, that provision will be interpreted or limited as far as legally possible.
The remaining provisions will continue to apply unless the Terms cannot reasonably operate without the invalid provision.
39. No Waiver
A failure or delay by AegisBreach in enforcing a provision does not permanently waive the right to enforce that provision later.
A waiver is effective only to the extent clearly given and legally valid.
40. Entire Agreement and Order of Documents
These Terms, the Privacy Policy, the package information shown before purchase, and any other expressly incorporated terms form the agreement governing the Service.
A separately signed written agreement may override these Terms only to the extent that it expressly says so.
Mandatory law prevails over any conflicting contractual provision.
The final priority between checkout disclosures, package descriptions, these Terms, and any localized version remains subject to legal review.
41. Language
This draft is written in English.
A Serbian version or other localized version may be provided before commercial launch.
The controlling-language rule has not yet been finalized and will be confirmed during external legal review.
Nothing in this section limits a consumer’s right to receive information in a language required by applicable law.
42. Contact
For questions about these Terms, account issues, complaints, or payment questions:
For privacy requests, the same email address may be used, with a clear description that the message concerns personal data.
43. Pending Items Before Final Legal Approval
The following items must be completed or confirmed before these Terms are treated as final:
- exact registered business name;
- registered business address;
- registration number;
- tax identification number;
- final business activity information where legally required;
- final production hosting provider and region;
- final bank, payment gateway, and acquiring arrangement;
- final checkout flow;
- final pre-contract information shown before purchase;
- final consumer withdrawal notice and any required form;
- exact consent or acknowledgment flow for immediate digital-service performance;
- final complaint and reclamation procedure;
- final refund-processing procedure;
- treatment of unused access following suspension or termination;
- final package names, prices, currencies, quotas, and features;
- exact tax and invoice disclosures;
- final consumer-conformity wording;
- final wording concerning younger users and paid purchases;
- final business-user indemnity wording;
- final limitation-of-liability wording and any liability cap;
- final governing-law, jurisdiction, and out-of-court dispute-resolution wording;
- final language and controlling-version rule;
- consistency review against the Privacy Policy and checkout pages;
- review against the Serbian Consumer Protection Act adopted in 2026 and its application timeline;
- review against applicable electronic-commerce, payment, contract, cybersecurity, and data-protection law;
- external legal review; and
- owner approval following legal review.