Platform
Explore Inspectiv’s AI-enabled platform that integrates Bug Bounty, Pentesting, Feature Testing, and VDP, designed to cut through noise and deliver signal-driven results.
Platform
Explore Inspectiv’s AI-enabled platform that integrates Bug Bounty, Pentesting, Feature Testing, and VDP, designed to cut through noise and deliver signal-driven results.
Bug Bounty
Continuously discover high-impact vulnerabilities, without the overhead of traditional bug bounty programs.
Penetration Testing
Stay audit-ready and reduce risk with expert-led testing and flexible retesting support.

See Inspectiv in Action!
Schedule a live demo to see how our platform helps you manage vulnerabilities, reduce noise, and stay compliant.

See Inspectiv in Action!
Schedule a live demo to see how our platform helps you manage vulnerabilities, reduce noise, and stay compliant.

Inspectiv Insights
July 7, 2026
Recent Inspectiv findings, and what do to about them.
Read the latest insights
Application Security
July 1, 2026
Moving Beyond Severity: The Risk-Based Security Imperative
Read the latest blogWe are Inspectiv, Inc., a Delaware corporation (“Inspectiv”). Our application security platform (the “Platform”), available at www.inspectiv.com and https://client.inspectiv.com/ (the “Website”), combines manual and automated application security testing solutions to scan for Vulnerabilities in Customer Products, prioritize and eliminate those Vulnerabilities, and help secure Customer Products at scale (collectively, the “Services”). In addition to manual and automated testing and scanning, Customer can publish Vulnerability Disclosure Policy (“VDP”) programs that provide guidelines for submitting information on security Vulnerabilities in Customer Products. Customer can further leverage the global, independent community of “ethical hacker” security researchers by deploying coordinated disclosure programs that offer monetary rewards to individual volunteers who submit actionable Vulnerability reports.
These Inspectiv Terms of Service, including any SOs and SOWs entered into hereunder, the Inspectiv Data Processing Addendum (“DPA”) and all other documents incorporated or referenced herein (collectively, the “Agreement”) govern all access to and use of the Services and other Inspectiv Technology by the customer identified in the applicable SO or SOW, or if there is no SO or SOW, the person or entity accessing or using the Services or other Inspectiv Technology (“Customer”, “you” or “your”). By accessing or using the Services or other Inspectiv Technology, you agree to abide by the terms and conditions of this Agreement. This Agreement is effective as of your initial access or use, or upon execution of an SO or SOW hereunder, whichever is earlier (the “Effective Date”). Inspectiv and you are each a “Party” and collectively, the “Parties.” In consideration of the mutual promises herein, the Parties agree as follows:
1. Definitions
a. "Affiliate" means an entity Controlled by, Controlling or under common Control with a Party. An entity has “Control” of another entity when it owns more than 50% of equity or voting interests or has primary operational or management responsibility.
b. "Change of Control" means one or more transactions whereby (i) Control of a Party is transferred, (ii) all or substantially all of the Party’s assets or securities are acquired or (iii) the Party is merged or consolidated with another entity; provided, that such Party's equity owners immediately before the transaction(s) will, immediately afterward, hold less than 50% voting power of the successor entity.
c. "Confidential Information" means non-public, proprietary or trade secret information in any format (written, oral, visual, etc.) (i) that the disclosing Party, its Affiliates or agents (each, a "Disclosing Party") provides to the receiving Party, its Affiliates or agents (each, a "Receiving Party"), (ii) that the Disclosing Party designates as confidential or that should reasonably be understood to be confidential under the circumstances of disclosure and (iii) that relate to Disclosing Party, its services, products, trade secrets, developments, know-how, personnel or a potential or actual Vulnerability in a Customer Product (except when included in aggregated data that does not identify Customer or a Customer Product).
d. "Customer Account" means the Inspectiv account used by Customer to access the Services.
e. "Customer Materials" means Customer Products, Testing Environments, Personal Data and other digital assets, materials and intellectual property provided or made available by Customer.
f. "Customer Product" means any software, technology or other product or service of Customer that Customer submits to Inspectiv pursuant to any SO, SOW and/or Rules of Engagement.
g. “Data Protection Laws” mean any privacy or data protection Laws applicable to Inspectiv’s Processing of Personal Data hereunder, including without limitation: (i) Title 1.81.5, California Consumer Privacy Act of 2018 (California Civil Code §§ 1798.100–1798.199), as amended by Proposition 24, the California Privacy Rights Act of 2020 (the “CCPA”); (ii) the EU General Data Protection Regulation 2016/679 (“GDPR”); (iii) the Privacy and Electronic Communications (EC Directive) Regulations 2003; (iv) the Swiss Federal Act on Data Protection; (v) the Data Protection Act 2018 and the United Kingdom’s version of the GDPR which is part of UK law by virtue of the European Union (Withdrawal) Act 2018 ("UK GDPR") and any legislation applicable in the UK in force from time to time relating to privacy or the Processing of Personal Data (the “UK Data Protection Laws”); and (vi) other applicable U.S. state Laws, in each case, as updated, amended or replaced from time to time.
h. “Documentation” means electronic or printed technical documentation regarding the Services that Inspectiv provides or makes available to Customer.
i. “Equipment” means any equipment and ancillary services necessary for Customer to access or use the Services or any Testing Environment, including without limitation hardware, servers, software and operating systems.
j. "Feedback" means comments, ideas, proposals, suggestions, recommendations, enhancement requests, data, statistics or other information provided by or on behalf of Customer regarding the Services. Feedback will not include Customer's Confidential Information.
k. “Independent Security Researcher” means and refers to an individual member of the global “ethical hacker” community who participates in a Program on a volunteer basis. To participate in a Program, Independent Security Researchers must abide by Inspectiv’s Researcher Terms and Conditions available at https://www.inspectiv.com/legal/researcher-terms-conditions, as well as any applicable Rules of Engagement. Customer acknowledges that Independent Security Researchers: (i) have the same opportunity to gain access to Customer Products as any other member of the online public (they are not granted internal security access or login credentials to Customer Products, unless expressly agreed by the Parties); (ii) are not Inspectiv employees, contractors, personnel or agents, do not undergo background screens, and are not managed or supervised by Inspectiv; and (iii) before receiving a fee for a Vulnerability submission, they are vetted for payment eligibility against, as applicable, the United States Department of Commerce’s Denied Persons or Entity List, the U.S. Department of Treasury’s Specially Designated Nationals or Blocked Persons Lists and/or the U.S. Department of State’s Debarred Parties List.
m. "Intellectual Property Rights" means all patents, copyrights, trade secrets, trademarks and service marks, trade dress, trade names, goodwill and marketing rights related thereto, works of authorship, inventions, discoveries, improvements, enhancements, methods, processes, formulas, designs, techniques, know how, derivative works, all other intellectual property or proprietary rights (whether or not registered) and equivalents or similar forms of protection existing worldwide, and all applications for and registrations in such rights.
l. "Inspectiv Technology" means and includes the proprietary technology owned or licensed by Inspectiv, including the Services, platform, tools, database, user interface and hardware designs, algorithms, architecture, software in source or object formats, class libraries, objects, Documentation, and any Intellectual Property Rights embodied therein or related to any of the foregoing, as well as any derivatives, improvements, enhancements or extensions thereof, whenever developed.
n. “Laws” means any applicable national, state, provincial and local laws, rules, regulations, directives, statutes, orders, judgments, decrees, rulings, and enforceable regulatory guidance.
o. “Personal Data” means data relating to an identified or identifiable natural person. An identifiable natural person is one who can be specifically identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data or online identifier, or by reference to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
p. “Process” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
q. “Program” means a coordinated disclosure program (i.e., “bug bounty”), an initiative sponsored by Customer that offers rewards to Independent Security Researchers for reporting security Vulnerabilities discovered in Customer Products. A Program enables Inspectiv and Customer to identify and remediate potential security issues, before they can be exploited by malicious actors. Independent Security Researchers may volunteer to participate in a “public” Program by responding to a publicized listing, or to participate in a “private” Program by answering a targeted invitation from Inspectiv. Inspectiv will not pursue legal action against good-faith security testing conducted under the agreed Rules of Engagement in connection with a Program.
r. "Rules of Engagement" means the Parties' mutually-agreed, additional terms and conditions for Independent Security Researchers, applicable to a specific Program.
s. “Security Incident” means a Personal Data breach or any unauthorized access or breach of security due to Inspectiv’s failure to comply with its data privacy and/or security obligations hereunder, leading to, or reasonably believed to have led to, the theft, accidental or unlawful destruction loss, alteration or unauthorized disclosure of, or access to, any Personal Data Processed by Inspectiv under or in connection with the Agreement.
t. “Service Order” (or “SO”) means a mutually executed Inspectiv order form specifying the Services purchased by Customer and any applicable fees, charges and other terms.
u. “Services” means and includes the Services as defined in the introductory paragraph of this Agreement, the Inspectiv Technology and any Professional Services.
v. "Statement of Work” (or “SOW") means a mutually executed Inspectiv order form specifying any non-standard, security-related Services ("Professional Services") purchased by Customer and any applicable fees, charges and other terms.
w. "Taxes" means any applicable taxes and like charges or surcharges, including excise, use, sales, value-added and other fees, surcharges and levies.
x. "Testing Environment" means a non-production Customer Product environment provided or made available to Inspectiv in order to perform the Services.
y. “Usage Metadata” means data generated, collected and processed by Inspectiv in connection with providing the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services and to investigate and prevent system abuse. Usage Metadata (i) does not comprise Customer data and (ii) is collected by Inspectiv solely on a pseudonymized and aggregated basis, such that it does not allow Inspectiv or any third party readily to determine that such data relates to or is derived from any specific customer or user. As between the Parties, Inspectiv owns the Usage Metadata.
z. "Vulnerability" means a weakness, susceptibility or flaw (i.e., “bug”) discovered in a Customer Product that (i) enables an attacker to access a network or system or otherwise reduce its information security and (ii) meets the terms of the applicable Rules of Engagement.
2. Licenses, Intellectual Property Rights
a. Inspectiv’s License to Customer
Services During the Term, Inspectiv hereby grants Customer a limited, non-exclusive, non-transferable, non-assignable and non-sublicensable license to access and use the Services, as specified in an applicable SO or SOW, solely for Customer’s internal business purposes. Customer will obtain and securely maintain any Equipment needed to access or use the Services at Customer’s own expense. Except as expressly agreed by the Parties, the identity of any Inspectiv personnel will not be disclosed or otherwise made available to Customer by Inspectiv or through the Services.
Monitoring. Inspectiv is not obligated to monitor use of Services, but it may do so for the purposes of operating the Services, ensuring compliance with this Agreement, protecting the rights and safety of Inspectiv’s personnel and third parties, and complying with legal requirements. To the extent that Customer uses the Services to message or communicate with Inspectiv, Inspectiv reserves the right to monitor, intercept, review, store and/or delete such messages or communications without further notice. Inspectiv reserves the right to investigate violations or other conduct that affects the Inspectiv Technology. Inspectiv may also consult and cooperate with law enforcement authorities to prosecute users who violate applicable Laws. Inspectiv may prohibit any use that it believes (or that is alleged) to be in violation of the Agreement or that otherwise adversely impacts Inspectiv Technology.
Automated Processing and Artificial Intelligence
Trial Services. From time to time, Inspectiv may offer certain Services on a limited basis without fee or charge, including for example, free accounts, trial use, and access to pre-release and beta services (collectively, “Trial Services”). Access to and use of Trial Services may be subject to additional terms, as specified by Inspectiv. Inspectiv’s aggregate liability (excluding indirect damages, for which Inspectiv expressly disclaims all liability) for any claim arising out of or related to Customer’s use of Trial Services will not exceed $500.00. Inspectiv may modify, discontinue or terminate access to or use of Trial Services at any time, in its sole discretion, and without liability.
Modifications. Inspectiv may update, modify or even discontinue all or any part of the Services or other Inspectiv Technology in Inspectiv’s sole discretion, with or without notice. If Inspectiv materially reduces the functionality of Services or discontinues Services that are not replaced by a substantially equivalent function or feature, Customer may terminate the affected Services upon 30 days’ notice; and in such event, Inspectiv will refund any prepaid, unused Fees in respect of the terminated Services.
Subcontractors. Inspectiv may, at any time and without notice, use subcontractors in connection with the Services; provided that, that with respect to subcontractors that would qualify as Sub-processors of Personal Data under applicable Data Protection Laws, Inspectiv will provide reasonable notice of any new or changed Sub-processors and a reasonable opportunity to object. Inspectiv will be liable for the performance of its subcontractors. For clarity, Customer acknowledges that Independent Security Researchers are independent third-party volunteers and are not Inspectiv subcontractors.
Third-Party Resources. The Services may allow access to or integrate with certain third-party products, services, websites or other resources (“Third-Party Resources”). Inspectiv provides access to any such Third-Party Resources solely as a convenience, without endorsement or liability. If Customer chooses to use Third-Party Resources in connection with the Services, Inspectiv may provide the relevant third-party provider with access or use of Customer’s information, to the extent expressly authorized by Customer. Access to and use of Third-Party Resources will be subject to any applicable agreement between Customer and the applicable third-party provider. Inspectiv expressly disclaims any liability for Third-Party Resources, including without limitation any content, products or services that they display, link to or make available, and for any acts and omissions of third-party providers.
b. Customer’s License to Inspectiv
Customer acknowledges that Inspectiv will require access to and use of certain Customer Materials to fulfill its obligations under this Agreement. During the Term, Customer grants to Inspectiv, its Affiliates and their respective agents, suppliers and subcontractors, a limited, non-exclusive, transferable, worldwide, royalty-free license, with the right to sublicense through multiple tiers to access and use the applicable Customer Materials and associated metadata solely to provide the Services. As between the Parties, Customer is solely liable for all Customer Materials as provided or made available to Inspectiv.
If Customer provides Inspectiv with access to any non-public website or Testing Environment, Customer will cooperate with Inspectiv in its efforts to make such website or Testing Environment available through the Services and allow Inspectiv to access such website or Testing Environment in order to provide the Services. If any integration, development or other Professional Services are necessary to make such website or Testing Environment available to Inspectiv through the Services, the Parties will enter into an applicable SOW, Customer will timely pay Inspectiv for the Professional Services on a time and materials basis at Inspectiv’s then-current rates, and Customer will reimburse Inspectiv for all Customer approved, out-of-pocket costs incurred in connection with the performance of such Professional Services.
c. Feedback
Inspectiv appreciates any Feedback that Customer or its personnel may provide regarding the Services. Customer agrees that Inspectiv owns all right, title and interest in such Feedback, including all associated Intellectual Property Rights.
d. Intellectual Property Rights.
Notwithstanding anything to the contrary, Inspectiv (or its licensors, as applicable) retains all worldwide rights, title and interest in and to the Services and other Inspectiv Technology, Usage Metadata, Feedback, and any Intellectual Property Rights embodied therein or related thereto. Notwithstanding anything to the contrary, Customer retains all rights, title and interest in and to the Customer Materials, Customer Products and any Intellectual Property Rights embodied therein or related thereto.
3. Use of the Services.
4. Payments, Taxes
5. Privacy, Security
a. Inspectiv will treat any Personal Data collected from Customer or its users in accordance with the Inspectiv Privacy Policy at https://www.inspectiv.com/legal/privacy-policy. Customer will not provide or make available to Inspectiv any personal health data, Personal Data of minors, PCI cardholder data or sensitive data unless agreed by the Parties in writing. To the extent Inspectiv Processes Personal Data on behalf of Customer in connection with the Services, the DPA is incorporated into and forms part of this Agreement.
b. Each Party will implement reasonable physical, technical and organizational safeguards designed to secure the Inspectiv Technology (with respect to Inspectiv) and the Customer Materials (with respect to Customer) from unauthorized access, disclosure, loss, modification or destruction. Further, in connection with any Processing hereunder of Personal Data, each Party will comply at all times with all applicable Data Protection Laws. If any act or omission by a Party results in any actual or reasonably suspected Security Incident, such Party will (i) notify the other Party within 24 hours (unless otherwise prohibited by Laws or otherwise instructed by a law enforcement or supervisory authority) and (ii) promptly take reasonable steps to investigate and mitigate the effects of the Security Incident.
6. Confidentiality
Receiving Party will not use, copy or disclose Disclosing Party’s Confidential Information except as expressly permitted herein. All copies of Confidential Information remain Disclosing Party’s sole property. Receiving Party will protect Disclosing Party’s Confidential Information using at least the same degree of care as it uses to protect its own Confidential Information, but with no less than reasonable care. Receiving Party may disclose Confidential Information to its employees, consultants and contractors who have a need to know in connection with this Agreement and who have executed a similarly stringent confidentiality agreement or are subject to a professional duty of confidentiality. Receiving Party also may disclose Confidential Information pursuant to applicable Laws, subpoena or other order of a court of competent jurisdiction (collectively, “Legal Requirement”) or to establish rights or obligations under this Agreement in any proceeding; provided, that: (i) reasonable prior notice, unless legally prohibited, is provided to Disclosing Party to permit it the opportunity to contest such disclosure; (ii) Receiving Party cooperates with Disclosing Party to comply with any applicable protective order; and (iii) Receiving Party discloses only to the extent necessary to comply with the Legal Requirement or to establish such rights or obligations. Receiving Party will notify Disclosing Party upon discovery of any unauthorized use or disclosure of Confidential Information and will cooperate to help prevent further unauthorized use or disclosure.
These confidentiality obligations do not apply to Confidential Information which: (i) was in the other's possession before receipt from Disclosing Party; (ii) was received in good faith from a third party not subject to a confidential obligation to the other Party; (iii) now is or later becomes publicly known, through no breach of confidential obligation by Receiving Party; (iv) was developed by Receiving Party without having access to the Confidential Information received from the other Party; or (v) is authorized in writing by Disclosing Party to be released or is designated in writing by Disclosing Party as no longer confidential.
Receiving Party acknowledges that Disclosing Party’s Confidential Information is valuable and unique and that unauthorized use or disclosure may result in irreparable injury to Disclosing Party, for which monetary damages may be inadequate. If Receiving Party violates or threatens to violate this Section 6, Disclosing Party may seek injunctive relief without posting bond, in addition to any other available remedies.
7. Representations and Warranties
8. Disclaimer
9. Term and Termination
10. Limitation of Liability
11. Indemnification
12. Insurance
13. Publicity
14. Copyright
15. General
If you have any questions about this Agreement or the Services, please contact us at:
Inspectiv, Inc.
10866 Washington Blvd., #1300
Culver City, CA 90232
Email: legal@inspectiv.com
Web: www.inspectiv.com
Inspectiv, Inc. (“Inspectiv”) provides the Inspectiv Services, including the hosted Platform (the “Platform”) available at www.inspectiv.com and https://client.inspectiv.com/ (the “Website”). This Service Level Agreement (“SLA”) sets forth the uptime and support service levels for the Platform and Inspectiv-controlled support processes, and does not apply to Independent Security Researchers, Program outcomes, the timing, volume, quality or content of Vulnerability submissions, Customer Products, Customer-controlled systems or third-party products or services. This SLA applies only to a registered customer of Inspectiv (“Customer”). Any capitalized terms in this SLA, if not defined below, are as defined in Inspectiv’s Terms of Service available at https://www.inspectiv.com/legal/customer-terms-conditions (“Agreement”).
|
Severity Level |
Definition |
Example |
|
1: Critical |
Business outage or significant Customer impact that threatens future productivity |
Many or all users are unable to access the Platform; Platform response time is severely degraded from standard |
|
2: Urgent |
High-impact problem where production is proceeding, but in a significantly impaired fashion; there is a time-sensitive issue important to long term productivity that is not causing an immediate work stoppage |
Certain users are unable to access the Platform; Platform performance is unstable |
|
3: Important |
Important issue that does not significantly impact current productivity |
User requires a patch for non-emergency break-fix situation |
|
4: Informational |
Request for information or enhancement, or minor technical issue with only a minor impact on Customer productivity |
User desires a new Platform feature or function |
|
Severity Level |
Receipt Acknowledged |
Restoration Target |
|
1: Critical |
4 Business Hours |
Within 8 Business Hours |
|
2: Urgent |
4 Business Hours |
Within 48 Business Hours |
|
3: Important |
1 Business Day |
To be determined with proposed course of action (e.g., next release) |
|
4: Informational |
1 Business Day |
To be determined with proposed course of action (e.g., next release) |