Acceptable Use & Authorization Policy
Effective date: August 8, 2026
Product: ParityPT (by MayorSec Security)
Contact: legal@paritypt.com / joe@paritypt.com
This Acceptable Use & Authorization Policy (“Policy”) is part of the Terms of Service. It sets mandatory rules for anyone who creates assessments, downloads agents, shares magic links, or otherwise uses ParityPT to run security simulations.
1. Purpose
ParityPT executes real, attack-shaped probes (for example process execution, persistence techniques, credential-access probes, defense-evasion checks, and related ATT&CK-mapped techniques). These actions can trigger alerts, quarantine binaries, create artifacts, or stress controls. The Service is only for authorized defensive testing.
2. Required authorization
Before you run any assessment or deploy any agent, you must have current, documented authorization covering:
- Every host, identity, cloud tenant, and network segment in scope
- The testing window (start/end) and any blackout constraints
- Approval from the asset owner and, where applicable, the customer’s security/SOC leadership
- Any third-party provider terms (IaaS, SaaS, MSSP) that restrict security testing
“I have VPN access” or “I am a local admin” is not sufficient authorization by itself.
If authorization expires or is revoked, you must stop testing immediately and revoke outstanding agent tokens / magic links.
3. Permitted use
You may use the Service to:
- Validate detection and prevention controls on systems in your authorized scope
- Train defenders using controlled purple-team exercises
- Measure progress over time with retests on authorized targets
- Generate evidence and guidance for remediation within your organization
4. Prohibited use
You may not:
- Target systems without written authorization
- Use the Service to gain unauthorized access, maintain illicit persistence, exfiltrate data for non-testing purposes, or disrupt production outside an approved test plan
- Target critical safety systems, emergency services, or systems where testing is unlawful or contractually forbidden
- Share agent packages, tokens, or magic links with unauthorized parties
- Bypass ParityPT plan limits, access controls, or audit mechanisms
- Attempt to attack, scan, or overload the ParityPT infrastructure itself except via coordinated disclosure to us
- Upload malware unrelated to the platform’s intended checks, or use the platform to distribute malware to third parties
- Misrepresent simulated activity as a real intrusion to third parties for fraudulent purposes
- Violate export controls, sanctions, privacy laws, or computer-crime laws
5. Scope discipline
You agree to:
- Keep assessments scoped to named hosts / environments
- Prefer dedicated lab or explicitly approved production change windows for higher-impact techniques
- Coordinate with monitoring teams so alerts from ParityPT activity are expected
- Remove Defender/EDR exclusions and temporary allowlists when the engagement ends
- Delete or secure leftover agent binaries and
config.jsonfiles on endpoints after use
6. Customer warranties
You represent and warrant that:
- You have authority to authorize the testing described above (or you have obtained it from someone who does)
- Running ParityPT checks will not knowingly violate criminal law in the applicable jurisdictions
- You will not instruct ParityPT to process data you are not permitted to collect or transmit (including into AI features)
7. Monitoring and enforcement
We may investigate suspected abuse, suspend tenants or users, revoke tokens, and preserve logs needed for security and legal compliance. We may report unlawful activity to authorities when appropriate.
8. Your liability for unauthorized testing
Unauthorized testing can create civil and criminal exposure for you and your organization. You accept full responsibility for authorization gaps, out-of-scope targeting, and misuse by your users or anyone you provide agent packages or links to.
9. Reporting issues
If you believe a ParityPT assessment was run against you without authorization, contact legal@paritypt.com and joe@paritypt.com immediately with timestamps, hostnames, and any magic-link or agent indicators.
For product security issues in ParityPT itself, contact the same addresses with details sufficient to reproduce (no production exploitation required).
10. Changes
We may update this Policy as described in the Terms. Continued use of the Service after the effective date constitutes acceptance.
Related: Terms of Service · Privacy Policy