Legal

Terms of Service

These Terms of Service, together with the Acceptable Use Policy, Privacy Policy, and SLA, govern your use of the Stressthem platform. Please read them carefully before registering an account. By using the service you confirm that you have read, understood and agree to be bound by all of the terms below.

Short version. Stressthem is provided exclusively for stress testing infrastructure that you own or have explicit written authorization to test. Using the service against targets you do not own or do not have permission to test is a breach of these Terms and may be a criminal offense in your jurisdiction. We cooperate fully with law enforcement and will terminate accounts that violate this rule.

1. Definitions

"Stressthem", "we", "us" and "the Service" refer to the Stressthem stress testing platform, its operators and its infrastructure. "You", "the Customer" and "the User" refer to the individual or organization that registers an account and uses the Service. "Target" refers to any IP address, hostname, port or application endpoint against which a stress job is launched. "Verified Target" refers to a Target that has completed one of the verification methods documented in the documentation page and whose verification is currently valid (within the 30-day re-verification window).

"Stress Test" refers to the controlled generation of network or application traffic against a Target for the purpose of evaluating the Target's capacity, resilience or behavior under load. "Attack", "DDoS" and similar terms are used in this document only to describe the patterns of traffic that the Service simulates; the Service itself is not intended for use as an attack tool.

2. Eligibility & Account

You must be at least 18 years old and able to form a legally binding contract to use the Service. You represent that the information you provide during registration is accurate and complete, and that you will keep it up to date. You are responsible for safeguarding your account credentials, including API keys, and for all activity that occurs under your account. You agree to notify us immediately of any unauthorized use of your account or any other security breach. We are not liable for any loss or damage arising from your failure to comply with these obligations.

Accounts are personal to the registering individual or organization. You may not share account credentials between users; instead, invite team members through the dashboard so that each user has their own credentials and their own audit trail. Each team member inherits the plan limits of the parent account but has an independent API key.

3. Acceptable Use Policy

This Acceptable Use Policy (AUP) sets out the rules that govern how you may use the Service. The policy is designed to ensure that the Service is used lawfully, ethically and in a manner that does not cause harm to third parties. By using the Service you agree to comply with this AUP. We may update this AUP from time to time; continued use of the Service after any update constitutes acceptance of the revised policy.

You agree that you will only use the Service to stress test:

  • Infrastructure that you own, operate or control directly.
  • Infrastructure that you have explicit written authorization to test, including a signed statement from the owner or a contract clause granting permission.
  • Infrastructure hosted on networks or cloud accounts that are registered in your name or your organization's name.
  • Targets for which you have completed one of the verification methods documented at /docs.html#verify.

You agree that you will not use the Service to:

  • Launch traffic against any Target you do not own or do not have written permission to test.
  • Launch traffic against public infrastructure, government services, critical infrastructure or any Target protected by laws that prohibit stress testing.
  • Use the Service to extort, threaten, harass or retaliate against any person or organization.
  • Use the Service in violation of any applicable local, national or international law, including the Computer Fraud and Abuse Act (US), the Computer Misuse Act (UK), the Council of Europe Convention on Cybercrime, and equivalent laws in your jurisdiction.
  • Attempt to circumvent the target verification system, including by spoofing verification records or by relaying traffic through third parties.
  • Resell or sublicense access to the Service to third parties without explicit written permission.
  • Use the Service to test the Service itself, or to test infrastructure belonging to Stressthem or its infrastructure providers.

4. Target Verification

Every Target must be Verified before any traffic can be sent. Verification is enforced at the API gateway and cannot be bypassed by the Customer. The verification methods available are documented at /docs.html#verify. Targets must be re-verified every 30 days; the dashboard displays the re-verification deadline and the API exposes the verification status for programmatic monitoring.

If you believe a Target should be exempt from the standard verification methods (for example, a target that does not have a DNS zone), contact support to arrange an alternative out-of-band verification. Out-of-band verification may require additional documentation, including a signed authorization letter from the Target owner.

5. Audit Trail

The Service records every API call, every target verification, every job launch and every job outcome to an immutable audit log retained for 18 months. The audit log is available to the account owner for export as JSONL or CSV. The audit log is also available to law enforcement upon presentation of a valid court order or subpoena in the operator's jurisdiction. Audit logs are hashed and chained to detect tampering.

For Enterprise customers, audit logs can be streamed in real time to a customer-owned SIEM (Splunk, Elastic, Datadog, Sumo Logic) via a dedicated webhook sink. This enables customers to retain audit data indefinitely in their own infrastructure and to correlate stress testing activity with their broader security operations.

6. Privacy Policy

We collect the minimum personal information necessary to operate the Service: your email address, your account preferences, your billing information (processed by Stripe and not stored on our servers), and your API activity logs. We do not sell, rent or share your personal information with third parties for marketing purposes. We share personal information only in the limited circumstances described below.

Specifically, we collect and process:

  • Account email, organization name, and team member emails you invite to your account.
  • Target hostnames and IPs that you add to your account for stress testing.
  • API request metadata (timestamp, source IP, endpoint, parameters, response code) for the audit log.
  • Billing address and payment method token (the full card number is handled by Stripe and never touches our infrastructure).
  • Aggregate usage metrics (jobs per month, Gbps consumed) used for plan enforcement and capacity planning.

We retain API request metadata for 18 months for audit and abuse-prevention purposes. We retain billing records for 7 years as required by tax law in our operating jurisdictions. You may request export or deletion of your personal data at any time by contacting [email protected]; deletion requests are processed within 30 days, except where retention is required by law.

7. Data Security

We implement industry-standard technical and organizational measures to protect your data, including TLS 1.3 in transit, AES-256 at rest, strict role-based access controls on internal systems, mandatory two-factor authentication for all staff, and an annual third-party penetration test. API keys are hashed with bcrypt before storage; we cannot retrieve the original key after generation. If a key is lost, you must rotate it.

In the event of a confirmed security breach affecting your personal data, we will notify you within 72 hours of confirmation, in accordance with GDPR Article 34. Notifications will include the nature of the breach, the categories of data affected, the likely consequences, and the mitigation steps we are taking. Breach notifications will be sent to the email address on file for your account and, for material breaches, also published on the Service's status page.

8. Abuse Policy

We investigate every report of abuse within 24 hours. If we determine that an account has been used in violation of this AUP, we will take one or more of the following actions: (a) suspend the offending job immediately; (b) suspend the account pending investigation; (c) terminate the account and revoke all API keys; (d) report the activity to law enforcement; (e) cooperate fully with any criminal investigation, including providing audit logs, billing records and account information.

To report abuse, email [email protected] with the affected Target, the approximate time of the activity, and any supporting evidence (packet captures, logs, screenshots). Reports may be submitted anonymously; however, anonymous reports that cannot be verified may receive lower priority. We acknowledge all abuse reports within 24 hours and provide a substantive response within 72 hours.

9. Service Level Agreement (SLA)

We commit to a monthly uptime of 99.9% for the API and dashboard, excluding scheduled maintenance windows announced at least 72 hours in advance. Uptime is measured from the API health check endpoint using an external monitor. If we fail to meet the SLA in a calendar month, affected customers receive a service credit equal to 5% of the monthly subscription for each 0.5% below the SLA, up to a maximum credit of 50% of the monthly subscription. Credits are applied automatically to the next invoice.

The SLA does not apply to outages caused by: (a) customer-side issues, including misconfigured targets or expired API keys; (b) issues with third-party networks or cloud providers that we do not control; (c) force majeure events, including natural disasters, war or government action; (d) scheduled maintenance windows; (e) outages caused by customer violations of the AUP that result in account suspension.

10. Fees & Billing

Plan fees are billed in advance on a monthly or annual basis, depending on your selected billing cycle. Annual plans receive a 20% discount versus monthly billing. We accept Visa, Mastercard, American Express and PayPal via Stripe; bank transfers for annual Enterprise contracts; and selected cryptocurrencies (BTC, ETH, USDT, LTC, XMR) for researchers who require additional privacy. All fees are non-refundable except where required by law.

You may upgrade or downgrade your plan at any time. Upgrades take effect immediately and you are charged a prorated amount for the remainder of the billing period. Downgrades take effect at the start of the next billing period; the current plan remains active until then. You may cancel your subscription at any time; cancellation takes effect at the end of the current billing period and you retain access to the Service until then.

11. Termination

You may terminate your account at any time from the dashboard or by emailing [email protected]. Upon termination, all running jobs are immediately stopped, all API keys are revoked, and your personal data is scheduled for deletion in accordance with the Privacy Policy. Audit logs are retained for 18 months after termination as required for compliance and abuse-prevention purposes.

We may terminate or suspend your account immediately, without prior notice, if: (a) you violate the AUP; (b) we receive a credible report of abuse that, if true, would constitute a violation; (c) we are required to do so by law or by order of a court or government authority; (d) your account becomes more than 30 days overdue on payment. We may also terminate your account for any other reason with 30 days' notice.

12. Disclaimer

The Service is provided "as is" and "as available", without warranties of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or that it will meet your specific requirements. You use the Service at your own risk. The Service is provided for authorized testing purposes only; any use of the Service for unauthorized or illegal purposes is at your own risk and may subject you to criminal and civil liability.

13. Limitation of Liability

To the maximum extent permitted by law, in no event shall Stressthem be liable for any indirect, incidental, special, consequential or punitive damages, or any loss of profits or revenues, whether incurred directly or indirectly, or any loss of data, use, goodwill, or other intangible losses, resulting from (a) your use of or inability to use the Service; (b) any unauthorized access to or use of our servers and/or any personal information stored therein; (c) any interruption or cessation of transmission to or from the Service; (d) any bugs, viruses, trojan horses, or the like that may be transmitted to or through the Service by any third party; (e) any errors or omissions in any content or for any loss or damage incurred as a result of your use of any content.

Our total aggregate liability for any claim arising out of or relating to these Terms or the Service, regardless of the form of the action, shall be limited to the amount you paid to us in the 12 months preceding the claim. This limitation applies even if we have been advised of the possibility of such damages.

14. Governing Law

These Terms shall be governed by and construed in accordance with the laws of the jurisdiction in which the Service operator is incorporated, without regard to its conflict of law provisions. You agree to submit to the personal jurisdiction of the courts of that jurisdiction for any disputes arising out of or relating to these Terms or the Service. If any provision of these Terms is found to be unenforceable, the remaining provisions shall remain in full force and effect.

15. Changes to These Terms

We may revise these Terms from time to time. The most current version will always be available at this URL. We will notify you of material changes by email to the address on file for your account at least 30 days before the changes take effect. Your continued use of the Service after the effective date of any revision constitutes acceptance of the revised Terms. If you do not agree to the revised Terms, you must stop using the Service and terminate your account.

16. Contact

Questions about these Terms, the AUP, the Privacy Policy or the SLA may be directed to [email protected]. General support questions may be directed to [email protected]. Abuse reports must be directed to [email protected] as described in Section 8. We aim to respond to all inquiries within 24 hours during business days.