Legal
End User License Agreement
And Terms of Service
Effective Date: May 1, 2026
This End User License Agreement (“Agreement”) is entered into by and between Blazing Tiger LLC, a limited liability company incorporated in Delaware and operating out of Illinois, USA (hereinafter referred to as “Service Provider,” “BlazingTiger,” “Blazing Tiger LLC,” “blazingtiger.ai,” “we,” “us”) and the customer identified in the applicable Sales Order Form or Statement of Work (hereinafter referred to as “Customer,” “you”). This Agreement governs Customer’s access to and use of Blazing Tiger’s offensive security testing services, platform, and related deliverables (collectively, the “Services”).
By signing an Order Form, executing a Statement of Work, or accessing the Services, Customer agrees to be bound by this Agreement.
1. Services
Blazing Tiger provides offensive security testing services, including penetration testing, vulnerability assessment, and related cybersecurity services, delivered through a combination of human researchers, proprietary tooling, automation, and AI-assisted analysis, as further described in the applicable Sales Order Form or Statement of Work (“Order”).
2. Permission to Test; Authorization
Customer permits Service Provider to access Customer’s Assets and Customer Data to enable the Services, which constitutes authorization under the Computer Fraud and Abuse Act, the Computer Misuse Act 1990, Directive 2013/40/EU, and similar laws and regulations as applicable to Customer based on its jurisdiction. Customer represents and warrants that it has the authority, and will maintain such authority at all times throughout the term of its contract with Service Provider, to grant such access and authorization with respect to all systems, applications, networks, and assets identified in the applicable Order (“Target Systems”).
This authorization is granted solely for the purpose of performing the Services and is limited to the scope, time window, and methods specified in the Order. Any testing of systems outside the agreed scope is not authorized under this Agreement.
Customer acknowledges that testing activities may include techniques that could trigger security alerts, monitoring systems, or automated defenses, and that this is an expected and authorized part of the Services. Service Provider will take reasonable precautions to minimize such disruptions.
3. No Guarantee of Complete Vulnerability Discovery
Customer acknowledges and agrees that penetration testing and vulnerability assessment services are inherently limited by scope, time, methodology, and the state of Target Systems at the time of testing. Service Provider does not represent, warrant, or guarantee that:
- All vulnerabilities, misconfigurations, or security weaknesses present in the Target Systems will be identified;
- The Target Systems are or will be free of security vulnerabilities, whether or not identified during testing; or
- Remediation of identified findings will eliminate all risk of compromise.
The Services reflect a point-in-time assessment only. Security posture may change at any time following delivery of Service Provider’s findings due to changes in Customer’s environment, newly disclosed vulnerabilities, or evolving threat techniques.
Remediation of identified findings is the sole responsibility of Customer. Service Provider may offer remediation guidance as part of the Services, but Service Provider assumes no responsibility for Customer’s implementation, timing, or effectiveness of any remediation.
Service Provider shall have no responsibility or liability for any security breach, data breach, unauthorized access, or other security incident affecting Customer or any third party, whether occurring before, during, or after the Services, including incidents involving vulnerabilities not identified during the engagement.
4. Insurance
Service Provider maintains commercial insurance coverage, including cyber liability insurance and professional/technology errors & omissions liability insurance. Certificates of insurance and specific coverage limits are available to Customer upon written request.
5. Data Security
Service Provider will implement reasonable administrative, technical, and physical safeguards designed to protect Customer information transmitted to or processed by Service Provider in connection with the Services.
Customer is solely responsible for the security of its own systems, networks, and data, including any personally identifiable information (“PII”) of Customer’s own customers, employees, or other third parties residing on or processed by the Target Systems. Service Provider’s Services do not relieve Customer of its obligations to secure such data under applicable law or contract, and Service Provider assumes no responsibility for Customer’s compliance with data protection or privacy obligations owed to Customer’s customers or end users.
Service Provider may utilize third-party AI providers and cloud infrastructure providers as part of service delivery, including but not limited to Anthropic, OpenAI, Google, and Microsoft. Customer acknowledges that data transmitted through these systems may be processed or stored outside of Service Provider’s direct control.
Customer agrees that data processed through such third-party providers is subject to those providers’ respective data security, privacy, and terms of service policies, and Service Provider is not responsible for the practices or policies of such third parties.
6. Platform Access
Where Services include access to a BlazingTiger software platform, dashboard, or portal, such access is provided solely for the duration of the active contract term. Upon expiration or termination of the contract term, Service Provider may revoke Customer’s platform access without further notice. Revocation of platform access does not affect Customer’s right to retain deliverables (such as written reports) provided prior to revocation.
7. Intellectual Property
All methodologies, workflows, templates, software, automation routines, prompts, agent designs, report formats, and other proprietary materials used by Service Provider in delivering the Services remain the exclusive property of Service Provider. All data, systems, documents, and materials owned or operated by Customer remain the exclusive property of Customer. Nothing in this Agreement transfers ownership of either party’s pre-existing intellectual property to the other party.
Upon delivery and full payment, Customer receives a non-exclusive, internal-use license to use the written reports and recommendations generated under the applicable Order.
8. Marketing and Use of Customer Name
Customer grants Service Provider permission to identify Customer by name and logo, and to reference the general nature of the engagement, in Service Provider’s marketing materials, website, case studies, and promotional content, except where the applicable Order designates the engagement as confidential. Customer may request removal of its name, logo, or reference from any such materials at any time by contacting Service Provider, and Service Provider will remove the requested material within a reasonable time.
9. Confidentiality
Each party shall treat as confidential all non-public information received from the other party in connection with the Services, and shall use such information solely for purposes of the engagement, except as required by law or with the disclosing party’s written consent. This section survives termination of this Agreement and is independent of the marketing rights granted in Section 8.
10. Disclaimer of Warranties
The Services and all deliverables are provided “as is” and “as available.” Service Provider disclaims all warranties, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, and non-infringement.
Without limiting the foregoing, Service Provider does not warrant that the Services will identify all vulnerabilities or security risks, or that Customer’s systems will be secure following delivery of the Services.
11. Limitation of Liability
To the maximum extent permitted by applicable law, neither party shall be liable for any indirect, consequential, special, incidental, or punitive damages, including lost profits, lost revenue, loss of data, or business interruption, even if advised of the possibility of such damages.
In no event shall Service Provider’s total aggregate liability arising out of or related to this Agreement or any Order exceed the total fees actually paid by Customer to Service Provider for the specific engagement giving rise to the claim. This limitation applies regardless of the form or theory of liability (contract, tort, negligence, or otherwise).
12. Indemnification
Customer agrees to indemnify, defend, and hold harmless Service Provider, its employees, contractors, researchers, officers, and agents from and against any claims, damages, costs, and expenses (including reasonable attorneys’ fees) arising out of: (a) Customer’s lack of authority to authorize testing of any Target System; (b) Customer’s breach of this Agreement; (c) Customer’s violation of applicable law; or (d) third-party claims related to assets included within scope by Customer.
Service Provider agrees to indemnify, defend, and hold harmless Customer, its employees, officers, and agents from and against claims, damages, and costs (including reasonable attorneys’ fees) arising out of Service Provider’s gross negligence or willful misconduct in performing the Services, subject to the limitation of liability in Section 11.
13. Term and Termination
This Agreement remains in effect for the duration of the applicable Order. Either party may terminate an Order for material breach upon written notice if such breach remains uncured for thirty (30) days. Sections 3, 5, 7, 9, 10, 11, and 12 survive termination or expiration of this Agreement.
14. Governing Law
This Agreement shall be governed by the laws of the State of Illinois, without regard to conflict-of-law principles. The parties consent to exclusive jurisdiction in Illinois courts for disputes arising from this Agreement.
15. Entire Agreement
This Agreement, together with any applicable Sales Order Form or Statement of Work, constitutes the entire agreement between the parties regarding the Services and supersedes all prior discussions and understandings. No modification shall be effective unless made in writing and signed by both parties.