Skip to content
Back to home

Terms of Use

Last updated: July 21, 2026

These Terms govern your use of Vulnera. They explain what the platform does, what it does not do and, above all, the responsibility you take on when you point a security analysis tool at a system. Scanning touches real systems and the rights of others, so some rules here are non-negotiable, especially section 4. Read it carefully before you create your first scan.

1. Acceptance

By creating an account, purchasing a subscription, or using Vulnera in any way, you confirm that you have read and accept these Terms and our Privacy Policy. If you disagree with any part of them, do not use the platform.

If you use Vulnera on behalf of a company or organization, you represent that you have authority to bind it to these Terms, and "you" then also means that organization.

2. Description of the service

Vulnera:

  • Runs and coordinates automated security analyses on assets you register and authorize us to analyze.
  • Consolidates findings from different tools in one place, removing duplicates and correlating results.
  • Helps you understand and prioritize vulnerabilities in accessible language.
  • Generates remediation recommendations, including explanations produced by automated systems or AI.
  • Lets you send remediation context to your development tools and AI assistants, including through MCP integrations.
  • Revalidates findings after you apply a fix, to show whether the issue is gone.
  • Generates security reports that you can export as PDF whenever you need.

Vulnera is an initial and continuous layer of security: it reduces uncertainty and shows you where to act first. It does not guarantee complete detection of vulnerabilities or complete security of a system. See section 9.

3. Eligibility, accounts, and credentials

By maintaining an account, you agree to:

  • Provide accurate registration information and keep it up to date.
  • Keep your credentials and access tokens confidential, including integration and MCP tokens.
  • Be responsible for all activity carried out under your account, including scans it creates.
  • Report any unauthorized access or suspected compromise immediately.
  • Not share your account with anyone who is not authorized to use it.

If you administer an organization, you are responsible for who you invite, the level of access you grant, and removing access when someone leaves. Invited members act under that organization's responsibility, and the assets, scans, and findings belong to it, not to the personal account that created them.

You must be 18 or older to create an account and accept these Terms. Section 4 explains why: using Vulnera means taking on legal responsibility for the authorization to analyze an asset.

4. Authorization to analyze assets

This is the most important obligation in these Terms. Analyzing a system without the owner's authorization may constitute a civil wrong and a criminal offense, including under art. 154-A of the Brazilian Penal Code and equivalent legislation in other countries. Responsibility for that authorization is yours, not Vulnera's.

Before submitting any asset to Vulnera, you must:

  • Own the asset being analyzed, or hold express, documented authorization from whoever does.
  • Ensure that the scope, target, timing, and methods of the analysis are covered by that authorization.
  • Keep evidence of the authorization for the duration of the analysis and for as long as needed afterwards.
  • Respect restrictions imposed by hosting providers, cloud providers, customers, and third parties. Many of them limit security testing or require prior notice.
  • Stop an analysis if it causes instability, reaches data that is not yours, or affects third parties.
  • Be responsible for the assets, credentials, URLs, domains, APIs, IP addresses, repositories, containers, and cloud environments you submit.

To leave no room for doubt:

  • An asset being publicly accessible does not mean it is authorized for scanning. Accessibility is not permission.
  • Vulnera must not be used to analyze third-party systems without permission.
  • The ownership verification the platform performs, by DNS TXT record or by a file published on the asset, is a technical control of ours. It does not replace, nor transfer to us, your legal responsibility to obtain authorization. Confirming that you control a domain is not the same as proving you may test it.
  • We may require additional verification, or refuse an analysis, before allowing it to run.

When you register an asset, you expressly declare that you hold that authorization. We record that declaration.

5. Acceptable use

You may not use Vulnera to:

  • Violate applicable law or third-party rights.
  • Analyze systems without authorization, as described in section 4.
  • Conduct offensive security operations.
  • Attempt to gain unauthorized access to any system.
  • Exploit a vulnerability beyond what is strictly necessary to validate it.
  • Cause denial of service, excessive traffic, instability, or disruption to any system.
  • Carry out credential theft, credential stuffing, phishing, impersonation, or fraud.
  • Distribute malware or maintain unauthorized access to a system.
  • Collect or expose personal, confidential, or third-party data unrelated to the authorized analysis.
  • Circumvent rate limits, usage limits, billing controls, access controls, or asset verification.
  • Interfere with Vulnera, our providers, the scanners, or other customers.
  • Resell or sublicense the service without our authorization.
  • Use findings to harm, extort, threaten, or publicly expose a person or organization.
  • Publish security findings without authorization from the owner of the affected asset.

If you discover a vulnerability in a system that is not yours, even by accident, the expected conduct is described in section 13.

6. Scans and operational limits

To protect you, the targets, other customers, and our infrastructure, Vulnera may:

  • Apply rate limits.
  • Restrict how many scans run at the same time.
  • Limit the duration and intensity of a scan.
  • Pause or cancel scans in progress.
  • Block specific targets or network ranges.
  • Require manual verification before releasing a scan.
  • Temporarily restrict accounts when we detect abuse or risk.
  • Change scanner availability and the types of analysis supported.

An automated scan generates real traffic against the target and may affect its performance or behavior. Choosing the appropriate time, scope, and environment is your responsibility. Scan production systems only when you have explicit authorization to do so and when it is operationally appropriate, and prefer a window in which your team can watch the outcome.

7. Findings, evidence, and customer content

What is yours stays yours. You (or your organization) retain ownership of:

  • Your asset information.
  • Your scan configurations.
  • The security findings relating to your assets.
  • The content you upload to the platform.
  • Your remediation records.

You grant us a limited, non-exclusive, revocable license to process this information only as necessary to provide, protect, and improve the service, in accordance with the Privacy Policy. This license exists to operate the platform. It does not give us the right to use your findings for any other purpose.

Reports and findings describe real weaknesses in your systems. Treat them as sensitive information: whoever holds the report holds the map. See section 13.

8. Automated and AI-generated recommendations

About the results the platform delivers:

  • Findings may include false positives.
  • A scan may fail to identify vulnerabilities that exist.
  • Risk classification may change with your system's context. The suggested severity is a starting point, not a verdict.
  • AI-generated explanations and remediation suggestions may be inaccurate or incomplete.
  • You must review any recommendation before applying it.
  • To the extent permitted by law, Vulnera is not responsible for changes applied to your system without appropriate review, whether by you, your team, or an AI tool you use.

Vulnera explains and recommends; it does not apply fixes to your systems. When you send context to a development tool or AI assistant, you are the one who decides and executes the change, in your environment.

9. No security guarantee

A scan with no findings is not a certificate of security. Vulnera does not certify that an asset is secure, and no honest tool would.

Specifically:

  • Vulnera does not certify that an asset is secure.
  • A successful scan does not prove the absence of vulnerabilities.
  • Vulnera does not replace penetration tests, code reviews, audits, compliance assessments, certification, or security professionals.
  • Findings reflect the asset, configuration, scope, and detection capabilities available at the time of the analysis.
  • Any change to the asset may invalidate previous results, which is why revalidation and history exist.

What Vulnera delivers is valuable and concrete: a first layer of security that runs continuously, shows what is exposed, explains the risk in language you understand, and tells you where to start. That genuinely reduces uncertainty. Just don't mistake it for a guarantee.

10. Plans, free use, billing, and cancellation

Vulnera has a single plan with three billing periods. Each cycle is charged in full at its start. The prices below are the ones in effect today and already include applicable taxes. If they change, the change applies to future cycles, never to a cycle you have already paid for.

  • Plan and pricing: a single plan, charged according to the billing period you choose. R$189 per month on monthly; R$894 every 6 months on semiannual (the equivalent of R$149 per month); R$1,308 per year on annual (the equivalent of R$109 per month).
  • Free use: before subscribing, you can register 1 target and run 1 scan, with no card required. There is no time-boxed trial. Free use is measured by that scan, not by days. After it, you need to subscribe to continue.
  • Usage limits: on free use, 1 target and 1 scan. On the paid plan, 1 target and unlimited scans.
  • Automatic renewal: your subscription renews on its own at the end of each cycle, for the same billing period, until you cancel. Your next renewal date and the cancel option live in your account, and you can cancel any time before it.
  • Changing billing period: today, a change takes effect from your next cycle. You cancel the renewal of your current period, keep access until the end of the cycle you have already paid for, and subscribe to the new period from there. There is no pro-rata charge or credit for a cycle already under way.
  • Failed payment: if a charge does not go through, access is suspended. Once payment is settled, access returns, and your data stays where it was throughout the suspension.
  • Cancellation: cancel whenever you want, with no penalty and without having to talk to anyone. Cancellation takes effect at the end of the current cycle: the subscription stops renewing and your access continues until then. Because each cycle is charged in full at its start, cancelling triggers no new charge — and it does not refund the cycle you have already paid for, outside the refund case below. The 21% and 42% discounts against the monthly price are what you get for paying the whole period up front.
  • Refunds: the Brazilian Consumer Protection Code right of withdrawal applies, 7 calendar days from purchase, refunded in full. Outside that case, we do not refund a cycle already under way; you keep access until it ends.
  • What happens to your data when you cancel: your targets, findings, evidence, and reports are not deleted on cancellation. They are deleted after 1 year of account inactivity, as described in the Privacy Policy, so if you come back before then, your history is still there.

Payments are processed by Stripe. If you contract as a consumer, your rights under the Brazilian Consumer Protection Code remain fully intact, regardless of anything written above.

11. Third-party services and integrations

Vulnera depends on third-party services to work, including:

  • Cloud and infrastructure providers (AWS).
  • Payment processing (Stripe).
  • Authentication (Google, when you sign in with a Google account).
  • AI providers (OpenAI, when the feature is enabled).
  • Security scanners we run on our own infrastructure (OWASP ZAP and Vulnera's code analysis engine).
  • Development tools and MCP clients or integrations that you connect.

When you use these integrations, you may also be subject to those providers' terms and policies. This is especially true for what you connect yourself, such as your AI assistant or your development tool.

To the extent permitted by law, we are not responsible for outages, changes, limitations, or discontinuation of third-party services beyond our control. If an essential provider changes in a way that affects the service, we will let you know.

12. Intellectual property

Vulnera's software, brand, design, documentation, remediation knowledge base, the original explanations and content we produce, our APIs, and our integrations are ours or licensed to us, and are protected by intellectual property law.

Using the service grants you a license to use it for the duration of your subscription. It does not transfer ownership of any of the above, nor does it permit copying, redistributing, reverse engineering, or creating derivative works from the platform beyond what the law allows.

Nothing here gives us ownership of your assets, your code, or your organization's original data. What is yours stays yours. See section 7.

Third-party and open source components we use, such as OWASP ZAP, remain subject to their own licenses.

13. Confidentiality and responsible disclosure

Security findings are confidential by nature: they describe how a system can be compromised while it can still be compromised.

By using Vulnera, you agree to:

  • Restrict access to reports and findings to people authorized to see them.
  • Not publicly expose active vulnerabilities.
  • Follow coordinated and responsible disclosure practices.
  • Notify the affected owner through appropriate channels, allowing reasonable time to fix the issue.
  • Not use findings to pressure, embarrass, or harm third parties.

If you find a vulnerability in Vulnera itself, write to contato@vulnera.io before disclosing it, with a subject line starting with "Security". We will respond and treat the report as a priority. We do not run a formal vulnerability bounty program.

14. Availability and service changes

We use reasonable efforts to keep Vulnera available and working well, but we do not guarantee uninterrupted, error-free, or fault-free operation. We do not offer an SLA: there is no contractual commitment to minimum availability, and no credit for downtime.

We may perform maintenance, update scanners, and change, add, or remove features. When a change is material and adverse to you, we will give reasonable advance notice. If we discontinue the service, we will notify you in advance and give you the opportunity to export your data.

15. Suspension and termination

We may suspend or terminate access, in whole or in part, in cases of:

  • Unauthorized scanning.
  • Abuse of the platform or breach of acceptable use.
  • Security risk to you, to third parties, to other customers, or to our infrastructure.
  • Legal requirement or order from a competent authority.
  • Non-payment.
  • Breach of these Terms.

Whenever possible, we notify you first and give you a chance to put things right. But where it is necessary to prevent imminent harm to you, to third parties, or to infrastructure, particularly in the case of an unauthorized scan in progress, suspension may be immediate, with notice afterwards.

You may close your account at any time. After termination, your data is handled in accordance with the Privacy Policy, including the retention periods and the legal obligations that prevent us from deleting everything immediately.

16. Limitation of liability

This section does not exclude rights that the law grants on a mandatory basis. If you contract as a consumer, the Brazilian Consumer Protection Code prevails over any provision to the contrary, and nothing here limits liability for willful misconduct, gross negligence, or defects in the service as defined by law.

Subject to those limits, and to the maximum extent permitted by applicable law, Vulnera is not liable for:

  • Indirect damages.
  • Lost profits.
  • Business interruption.
  • Decisions made solely on the basis of automated findings, without review.
  • Changes applied to your systems without appropriate review.
  • Incidents arising from vulnerabilities the platform did not detect.
  • Misuse of the platform, unauthorized scans, or your breach of these Terms.

Also subject to those limits, our total aggregate liability for any claim relating to the service is capped at the amount you actually paid Vulnera in the 12 months preceding the event giving rise to the claim.

17. Indemnification

You agree to hold us harmless from claims, losses, damages, fines, and reasonable expenses, including legal fees, arising from:

  • Unauthorized scans carried out by you or under your account.
  • Lack of permission to test an asset.
  • Unlawful use of the platform.
  • Violation of third-party rights.
  • Content, assets, or credentials submitted by you without authorization.

This obligation does not apply to the extent the claim arises from our own acts. We will promptly notify you of any covered claim and will not settle it without your prior consent.

18. Changes to these Terms

We may change these Terms to reflect changes in the product, in our providers, in legislation, or in our commercial conditions. The last updated date is always at the top of this page.

When a change is material, we publish the new version here, with the date at the top updated, before it takes effect. Continuing to use Vulnera after that means you accept the revised Terms. If you disagree, you can close your account, as described in section 15. Wording corrections take effect on publication.

19. Governing law and jurisdiction

These Terms are governed by the laws of the Federative Republic of Brazil.

The competent venue for resolving disputes is the courts of São Paulo/SP, as elected by the parties. If you contract as a consumer, your right to bring proceedings in the courts of your own domicile is preserved under the Brazilian Consumer Protection Code, and nothing in this section removes that right or any other mandatory legal guarantee.

20. Contact

Get in touch at contato@vulnera.io. This is our single channel today: use it for support, for legal and contractual matters, for privacy, and to report a vulnerability found in Vulnera itself. Stating the subject on the first line helps us route your request.

  • Service provider: Osmir Custodio Mariano Tecnologia da Informação Ltda.
  • CNPJ: 53.636.099/0001-89
  • Address: Avenida Paulista 1106, sala 01, 16th floor, Bela Vista, São Paulo/SP, 01310-914, Brazil
  • Email: contato@vulnera.io