Cobalt Crowdsourced Application PentestCobalt Crowdsourced Application PentestCobalt Crowdsourced Application Pentest

Terms of use

General


Last update on September 16th, 2015

Binding Agreement

Cobalt (hereafter referred to as "Cobalt", "we", "us", or "our") provides an online platform that connects Program Owners who have applications they want to have security tested with Security Researchers seeking applications to test (collectively we call this the "Services"). The Services are made accessible at websites e.g. at cobalt.io (collectively, we call these sites the "Site") By using the Site and Services, you agree to comply with and be legally bound by the terms and conditions of these Terms of Service ("Terms"), whether or not you become a registered user of the Services. These Terms govern your access to and use of the Site and Services and all Collective Content (defined below) and constitute a binding legal agreement between you and Cobalt. Please read carefully these Terms and our Privacy Policy, which may be found at cobalt.io/terms, and which is incorporated by reference into these Terms. If you do not agree to these Terms, you have no right to obtain information from or otherwise continue using the Site. Failure to use the Site in accordance with these Terms may subject you to civil and criminal penalties.

Disclaimer - Acceptance of these Terms

YOU ACKNOWLEDGE AND AGREE THAT, BY ACCESSING OR USING THE SITE OR SERVICES OR BY DOWNLOADING OR POSTING ANY CONTENT FROM OR ON THE SITE OR THROUGH THE SERVICES, YOU ARE INDICATING THAT YOU HAVE READ, AND THAT YOU UNDERSTAND AND AGREE TO BE BOUND BY THESE TERMS, WHETHER OR NOT YOU HAVE REGISTERED WITH THE SITE IF YOU DO NOT AGREE TO THESE TERMS, THEN YOU HAVE NO RIGHT TO ACCESS OR USE THE SITE, SERVICES, OR COLLECTIVE CONTENT.

If you accept or agree to these Terms on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that company or other legal entity to these Terms and, in such event, "you" and "your" will refer and apply to that company or other legal entity.

The Role of Cobalt

The site and services comprise an online platform through which Program Owners (defined below) may create Security Programs (defined below) for application testing (defined below) and Security Researchers (defined below) may learn about the Security Programs and initiate test on the applications based on this. You understand and agree that Cobalt is not a party to any agreements entered into between program owners and security researchers, nor is Cobalt a broker, agent or insurer.

COBALT HAS NO CONTROL OVER THE CONDUCT OF PROGRAM OWNERS, TESTERS AND OTHER USERS OF THE SITE AND SERVICES, AND DISCLAIMS ALL LIABILITY IN THIS REGARD.

Key Abbreviations

Abbreviation Description
Services An online platform that connects Program Owners who have applications they want to have security tested with Security Researchers seeking applications to test
Site The sites where the Services are made available
Terms The terms and conditions and Terms of Service you agree to comply with and be legally bound by if you use the Site and Services
Cobalt Content Means all Content that Cobalt makes available through the Site, or Services, including any Content licensed from a third party, but excluding Member Content.
Collective Content Member Content and Cobalt Content.
Content Text, graphics, images, music, software, audio, video, information or other materials.
Member A person who completes Cobalt account registration process, including, but not limited to Program Owners and Security Researchers, as described under "Account Registration" below.
Member Content All Content that a Member posts, uploads, publishes, submits or transmits to be made available through the Site or Services.
Security Researcher A Member who signs up as a security researcher on the Site in order to potentially engage in a test of an application set in scope of a Security Program and potentially submit a Vulnerability Report via the Site or Services.
Program Owner A Member who signs up as a Program Owner on the Site in order to potentially create a Security Program via the Site and Services.
Program Collaborator A Member who is invited by a Program Owner to help support the management of the Security Program via the Site and Services
Security Program A program that is listed by a Program Owner requesting and allowing security researchers to test what (typically web or mobile application(s)) have been listed in the Security Program as being in scope within a defined set of rules (the Program Rules).
Application(s) The application(s) (typically web or mobile applications) involved directly or indirectly (through a test system) in a Security Program.
Vulnerability Report A report of an issue found during the testing of the application(s) in scope for a given Security Program. Vulnerability Reports are submitted and listed by the security researcher.
Program Rules The rules and scope set by the Program Owner when creating the Security Program
Tax (or Taxes) Any sales taxes, value added taxes (VAT), goods and services taxes (GST) and other similar municipal, state and federal indirect or other withholding and personal or corporate income taxes.

Notice on Terms

Certain areas of the Site (and your access to or use of certain aspects of the Services or Collective Content) may have different terms and conditions posted or may require you to agree with and accept additional terms and conditions. If there is a conflict between these Terms and terms and conditions posted for a specific area of the Site, Services, or Collective Content, the latter terms and conditions will take precedence with respect to your use of or access to that area of the Site, Services, or Collective Content.

Terms for actively using the Services

Additional Terms are created for Running a Security Program and Engaging in a Test respectively. These you need to read carefully and agree with in order to do any of the two activities.

Modification

Cobalt reserves the right, at its sole discretion, to modify the Site or Services or to modify these Terms, including the Service Fees, at any time and without prior notice. If we modify these General terms, Terms for Running a Security Program and/or the Terms for Engaging in a test, we will post the modification on the Site or via the Application or provide you with notice of the modification. We will also update the "Last Updated Date" at the top of these Terms. By continuing to access or use the Site or Services after we have posted a modification on the Site or via the Application or have provided you with notice of a modification, you are indicating that you agree to be bound by the modified Terms. If the modified Terms are not acceptable to you, your only recourse is to cease using the Site and Services.

Eligibility

By accessing or using the Site or Services you represent and warrant that you are 18 or older. If you are under 18 and want to use the Site and Services please contact us on info@cobalt.io.

How the Site and Services Work

The Site and Services can be used to facilitate Security Programs. Such Security Programs are included on the Site and Services by Program Owners. You may view the Security Programs as an unregistered visitor to the Site and Services; however, if you wish to test the application(s) and content in scope for the Security Program and submit a Vulnerability Report or create your own Security Program, you must first register to create an Cobalt Account (defined below).

As stated above, Cobalt makes available a platform or marketplace with related technology for Program Owners to display their Security Programs to Security Researchers which then can do a test on the applications in scope and submit Vulnerability Reports to the Program Owners. Cobalt is not responsible or liable for the test service performed by the Security Researchers, including, but not limited to, any harm or disruption caused by the test service and Cobalt does not provide, manage and/or control the Security Researchers, Cobalt’s responsibilities are limited to: (i) facilitating the availability of the Site and Services and (ii) serving as the limited agent of each Program Owner for the purpose of handling payments to the Security Researchers.

PLEASE NOTE THAT, AS STATED ABOVE, THE SITE AND SERVICES ARE INTENDED TO BE USED TO FACILITATE SECURITY PROGRAMS. COBALT CANNOT AND DOES NOT CONTROL THE CONTENT CONTAINED IN ANY SECURITY PROGRAM AND THE CONDITION, LEGALITY OR SUITABILITY OF ANY APPLICATION(S) LISTED AS IN SCOPE FOR THE SECURITY PROGRAM. COBALT IS NOT RESPONSIBLE FOR AND DISCLAIMS ANY AND ALL LIABILITY RELATED TO ANY AND ALL SECURITY PROGRAMS AND VULNERABILITY REPORTS.

ACCORDINGLY, ANY PARTICIPATION ON THE SITE AND SERVICES WILL BE DONE AT THE MEMBERS OWN RISK.

Account Registration

In order to access certain features of the Site, and to create Security Programs and/or to test an application and submit Vulnerability Reports, you must register to create an account ("Cobalt Account") and become a Member. You may register to join the Services directly via the Site or as described in this section.

You can also register to join by logging into your account with certain third party social networking sites ("SNS") (including, but not limited to, GitHub, Google, LinkedIn); each such account, a "Third Party Account", via our Site, as described below. As part of the functionality of the Site and Services, you may link your Cobalt Account with Third Party Accounts, by either: (i) providing your Third Party Account login information to Cobalt through the Site or Services; or (ii) allowing Cobalt to access your Third Party Account, as is permitted under the applicable terms and conditions that govern your use of each Third Party Account. You represent that you are entitled to disclose your Third Party Account login information to Cobalt and/or grant Cobalt access to your Third Party Account (including, but not limited to, for use for the purposes described herein), without breach by you of any of the terms and conditions that govern your use of the applicable Third Party Account and without obligating Cobalt to pay any fees or making Cobalt subject to any usage limitations imposed by such third party service providers. By granting Cobalt access to any Third Party Accounts, you understand that Cobalt will access, make available and store (if applicable) any Content that you have provided to and stored in your Third Party Account ("SNS Content") so that it is available on and through the Site and Services via your Cobalt Account and Cobalt Account profile page. Unless otherwise specified in these Terms, all SNS Content, if any, will be considered to be Member Content for all purposes of these Terms. Depending on the Third Party Accounts you choose and subject to the privacy settings that you have set in such Third Party Accounts, personally identifiable information that you post to your Third Party Accounts will be available on and through your Cobalt Account on the Site and Services. Please note that if a Third Party Account or associated service becomes unavailable or Cobalt’s access to such Third Party Account is terminated by the third party service provider, then SNS Content will no longer be available on and through the Site and Services. You have the ability to disable the connection between your Cobalt Account and your Third Party Accounts, at any time, by accessing the "Settings" section of the Site.

PLEASE NOTE THAT YOUR RELATIONSHIP WITH THE THIRD PARTY SERVICE PROVIDERS ASSOCIATED WITH YOUR THIRD PARTY ACCOUNTS IS GOVERNED SOLELY BY YOUR AGREEMENT(S) WITH SUCH THIRD PARTY SERVICE PROVIDERS.

Cobalt makes no effort to review any SNS Content for any purpose, including but not limited to, for accuracy, legality or non-infringement and Cobalt is not responsible for any SNS Content.

Member Account Limitations

We will create your Cobalt Account and your Cobalt Account profile page for your use of the Site based upon the personal information you provide to us or that we obtain via an SNS as described above. You may not have more than one (1) active Cobalt Account. You agree to provide accurate, current and complete information during the registration process and to update such information to keep it accurate, current and complete. Cobalt reserves the right to suspend or terminate your Cobalt Account and your access to the Site and Services if you create more than one (1) Cobalt Account or if any information provided during the registration process or thereafter proves to be inaccurate, not current or incomplete. You are responsible for safeguarding your password. You agree that you will not disclose your password to any third party and that you will take sole responsibility for any activities or actions under your Cobalt Account, whether or not you have authorized such activities or actions. You will immediately notify Cobalt of any unauthorized use of your Cobalt Account.

No Endorsement

Cobalt does not endorse any Members, any Security Program and Vulnerability Reports. In addition, although these Terms require Members to provide accurate information. You are responsible for determining the identity and suitability of others who you contact via the Site and Services. Cobalt will not be responsible for any damage or harm resulting from your interactions with other Members.

By using the Site or Services, you agree that any legal remedy or liability that you seek to obtain for actions or omissions of other Members or other third parties will be limited to a claim against the particular Members or other third parties who caused you harm and you agree not to attempt to impose liability on, or seek any legal remedy from Cobalt with respect to such actions or omissions. Accordingly, we encourage you to communicate directly with other Members on the Site and Services regarding any Security Program(s) and/or Vulnerability Reports submitted by you.

User Conduct

You understand and agree that you are solely responsible for compliance with any and all laws, rules, regulations, and Tax obligations that may apply to your use of the Site, Services and Content. In connection with your use of our Site and Services, you may not and you agree that you will not:

  • violate any local, state, provincial, national, or other law or regulation, or any order of a court, including, without limitation, zoning restrictions and Tax regulations;
  • use manual or automated software, devices, scripts robots, other means or processes to access, "scrape," "crawl" or "spider" any web pages or other services contained in the Site, Services or Content; Unless requested in a Security Program.
  • use the Site or Services for any commercial or other purposes that are not expressly permitted by these Terms;
  • copy, store or otherwise access any information contained on the Site, Services or Content for purposes not expressly permitted by these Terms;
  • infringe the rights of any person or entity, including without limitation, their intellectual property, privacy, publicity or contractual rights;
  • interfere with or damage our Site or Services, including, without limitation, through the use of viruses, cancel bots, Trojan horses, harmful code, flood pings, denial-of-service attacks, packet or IP spoofing, forged routing or electronic mail address information or similar methods or technology; Unless requested in a Security Program;
  • use our Site or Services to transmit, distribute, post or submit any information concerning any other person or entity, including without limitation, photographs of others without their permission, personal contact information or credit, debit, calling card or account numbers;
  • use our Site or Services in connection with the distribution of unsolicited commercial email ("spam") or advertisements unrelated to Security Programs and Vulnerability Reports;
  • "stalk" or harass any other user of our Site, or Services or collect or store any personally identifiable information about any other user other than for purposes of transacting as an Security Researcher or Program Owner;
  • register for more than one Cobalt Account or register for an Cobalt Account on behalf of an individual other than yourself;
  • contact a Program owner for any purpose other than asking a question related to a Security Programs, such as the rules, rewards etc.
  • contact a Security Researcher for any purpose other than asking a question related to a Vulnerability Report or such Security Researchers use of the Site and Services;
  • when acting as a Security Researcher or otherwise, recruit or otherwise solicit any Program Owner or other Member to join third party services or websites that are competitive to Cobalt, without Cobalt’s prior written approval;
  • impersonate any person or entity, or falsify or otherwise misrepresent yourself or your affiliation with any person or entity;
  • or post, upload, publish, submit or transmit any Content that: (i) infringes, misappropriates or violates a third party’s patent, copyright, trademark, trade secret, moral rights or other intellectual property rights, or rights of publicity or privacy; (ii) violates, or encourages any conduct that would violate, any applicable law or regulation or would give rise to civil liability; (iii) is fraudulent, false, misleading or deceptive; (iv) is defamatory, obscene, pornographic, vulgar or offensive; (v) promotes discrimination, bigotry, racism, hatred, harassment or harm against any individual or group; (vi) is violent or threatening or promotes violence or actions that are threatening to any other person; or (vii) promotes illegal or harmful activities or substances;
  • systematically retrieve data or other content from our Site or Services to create or compile, directly or indirectly, in single or multiple downloads, a collection, compilation, database, directory or the like, whether by manual methods, through the use of bots, crawlers, or spiders, or otherwise; Unless requested in a Security Program;
  • use, display, mirror or frame the Site, or any individual element within the Site, Services, or Application, Cobalt’s name, logo or other proprietary information, or the layout and design of any page or form contained on a page, without Cobalt’s express written consent;
  • access, tamper with, or use non-public areas of the Site, Cobalt’s computer systems, or the technical delivery systems of Cobalt’s providers;
  • attempt to probe, scan, or test the vulnerability of any Cobalt system or network or breach any security or authentication measures; Unless requested in a Security Program;
  • avoid, bypass, remove, deactivate, impair, descramble, or otherwise circumvent any technological measure implemented by Cobalt or any of Cobalt’s providers or any other third party (including another user) to protect the Site, Services, Application or Collective Content; Unless Requested in a Security Program;
  • forge any TCP/IP packet header or any part of the header information in any email or newsgroup posting, or in any way use the Site, Services, Application or Collective Content to send altered, deceptive or false source-identifying information;
  • attempt to decipher, decompile, disassemble or reverse engineer any of the software used to provide the Site, Services, Application or Collective Content; or advocate, encourage, or assist any third party in doing any of the foregoing.

Cobalt will have the right to investigate and prosecute violations of any of the above to the fullest extent of the law. Cobalt may involve and cooperate with law enforcement authorities in prosecuting users who violate these Terms. You acknowledge that Cobalt has no obligation to monitor your access to or use of the Site, Services or Collective Content or to review or edit any Member Content, but has the right to do so for the purpose of operating the Site and Services, to ensure your compliance with these Terms, or to comply with applicable law or the order or requirement of a court, administrative agency or other governmental body. Cobalt reserves the right, at any time and without prior notice, to remove or disable access to any Collective Content that Cobalt, at its sole discretion, considers to be objectionable for any reason, in violation of these Terms or otherwise harmful to the Site or Services.

Privacy

See Cobalt’s Privacy Policy at https://cobalt.io/terms and for information and notices concerning Cobalt’s collection and use of your personal information.

Ownership

The Site, Services, and Collective Content are protected by copyright, trademark, and other laws of the United States of America and foreign countries. You acknowledge and agree that the Site, Services and Collective Content, including all associated intellectual property rights is the exclusive property of Cobalt and its licensors. You will not remove, alter or obscure any copyright, trademark, service mark or other proprietary rights notices incorporated in or accompanying the Site, Services, or Collective Content.

Cobalt Content and Member Content License

Subject to your compliance with the terms and conditions of these Terms, Cobalt grants you a limited, non-exclusive, non-transferable license, to (i) access and view any Cobalt Content solely for your internal use in connection with the Cobalt engagement and (ii) access and view any Member Content to which you are permitted access, solely for your internal use in connection with the Cobalt engagement. You have no right to sublicense the license rights granted in this section.

You will not use, copy, adapt, modify, prepare derivative works based upon, distribute, license, sell, transfer, publicly display, publicly perform, transmit, broadcast or otherwise exploit the Site, Services, or Collective Content, except as expressly permitted in these Terms. No licenses or rights are granted to you by implication or otherwise under any intellectual property rights owned or controlled by Cobalt or its licensors, except for the licenses and rights expressly granted in these Terms.

Member Content

We may, in our sole discretion, permit Members to post, upload, publish, submit or transmit Member Content. By making available any Member Content on or through the Site and Services, you hereby grant to Cobalt a worldwide, irrevocable, perpetual, non-exclusive, transferable, royalty-free license, with the right to sublicense, to use, view, copy, adapt, modify, distribute, license, sell, transfer, publicly display, publicly perform, transmit, stream, broadcast, access, view, and otherwise exploit such Member Content on, through, or by means of the Site and Services. Cobalt does not claim any ownership rights in any such Member Content and nothing in these Terms will be deemed to restrict any rights that you may have to use and exploit any such Member Content.

You acknowledge and agree that you are solely responsible for all Member Content that you make available through the Site and Services. Accordingly, you represent and warrant that: (i) you either are the sole and exclusive owner of all Member Content that you make available through the Site and Services or you have all rights, licenses, consents and releases that are necessary to grant to Cobalt the rights in such Member Content, as contemplated under these Terms; and (ii) neither the Member Content nor your posting, uploading, publication, submission or transmittal of the Member Content or Cobalt’s use of the Member Content (or any portion thereof) on, through or by means of the Site and the Services will infringe, misappropriate or violate a third party’s patent, copyright, trademark, trade secret, moral rights or other proprietary or intellectual property rights, or rights of publicity or privacy, or result in the violation of any applicable law or regulation.

Links

The Site and Services may contain links to third-party websites or resources. You acknowledge and agree that Cobalt is not responsible or liable for: (i) the availability or accuracy of such websites or resources; or (ii) the content, products, or services on or available from such websites or resources. Links to such websites or resources do not imply any endorsement by Cobalt of such websites or resources or the content, products, or services available from such websites or resources. You acknowledge sole responsibility for and assume all risk arising from your use of any such websites or resources or the Content, products or services on or available from such websites or resources.

Proprietary Rights Notice

All trademarks, service marks, logos, trade names and any other proprietary designations of Cobalt used herein are trademarks or registered trademarks of Cobalt. Any other trademarks, service marks, logos, trade names and any other proprietary designations are the trademarks or registered trademarks of their respective parties.

Feedback

We welcome and encourage you to provide feedback, comments and suggestions for improvements to the Site and Services ("Feedback"). You may submit Feedback by emailing us at info@cobalt.io or through the about section of the Site. You acknowledge and agree that all Feedback will be the sole and exclusive property of Cobalt and you hereby irrevocably assign to Cobalt and agree to irrevocably assign to Cobalt all of your right, title, and interest in and to all Feedback, including without limitation all worldwide patent, copyright, trade secret, moral and other proprietary or intellectual property rights therein. At Cobalt’s request and expense, you will execute documents and take such further acts as Cobalt may reasonably request to assist Cobalt to acquire, perfect, and maintain its intellectual property rights and other legal protections for the Feedback.

Termination and Cobalt Account Cancellation

We may, in our discretion and without liability to you, with or without cause, with or without prior notice and at any time: (a) terminate these Terms or your access to our Site and Services, and (b) deactivate or cancel your Cobalt Account. Upon termination we will promptly pay you any amounts we reasonably determine we owe you in our discretion, which we are legally obligated to pay you. In the event Cobalt terminates these Terms, or your access to our Site and Services or deactivates or cancels your Cobalt Account you will remain liable for all amounts due hereunder. You may cancel your Cobalt Account at any time via the "Cancel Account" feature of the Services or by sending an email to info@cobalt.io. Please note that if your Cobalt Account is cancelled, we do not have an obligation to delete or return to you any Content you have posted to the Site and Services, including, but not limited to, any reviews or Feedback.

DISCLAIMERS

IF YOU CHOOSE TO USE THE SITE AND SERVICES YOU DO SO AT YOUR SOLE RISK. YOU ACKNOWLEDGE AND AGREE THAT COBALT DOES NOT HAVE AN OBLIGATION TO CONDUCT BACKGROUND CHECKS ON ANY MEMBER, INCLUDING, BUT NOT LIMITED TO, TESTERS AND PROGRAM OWNERS, BUT MAY CONDUCT SUCH BACKGROUND CHECKS IN ITS SOLE DISCRETION. THE SITE, SERVICES AND COLLECTIVE CONTENT ARE PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED. WITHOUT LIMITING THE FOREGOING, COBALT EXPLICITLY DISCLAIMS ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT, AND ANY WARRANTIES ARISING OUT OF COURSE OF DEALING OR USAGE OF TRADE. COBALT MAKES NO WARRANTY THAT THE SITE, SERVICES, COLLECTIVE CONTENT, INCLUDING, BUT NOT LIMITED TO, THE SECURITY PROGRAMS OR ANY VULNERABILITY REPORTS WILL MEET YOUR REQUIREMENTS OR BE AVAILABLE ON AN UNINTERRUPTED, SECURE, OR ERROR-FREE BASIS. COBALT MAKES NO WARRANTY REGARDING THE QUALITY OF ANY SECURITY PROGRAMS AND VULNERABILITY REPORTS, THE SERVICES OR COLLECTIVE CONTENT OR THE ACCURACY, TIMELINESS, TRUTHFULNESS, COMPLETENESS OR RELIABILITY OF ANY COLLECTIVE CONTENT OBTAINED THROUGH THE SITE OR SERVICES.

NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED FROM COBALT OR THROUGH THE SITE, SERVICES OR COLLECTIVE CONTENT, WILL CREATE ANY WARRANTY NOT EXPRESSLY MADE HEREIN.

YOU ARE SOLELY RESPONSIBLE FOR ALL OF YOUR COMMUNICATIONS AND INTERACTIONS WITH OTHER USERS OF THE SITE OR SERVICES AND WITH OTHER PERSONS WITH WHOM YOU COMMUNICATE OR INTERACT AS A RESULT OF YOUR USE OF THE SITE OR SERVICES, INCLUDING, BUT NOT LIMITED TO, ANY TESTERS OR PROGRAM OWNERS. YOU UNDERSTAND THAT COBALT DOES NOT MAKE ANY ATTEMPT TO VERIFY THE STATEMENTS OF USERS OF THE SITE OR SERVICES OR TO REVIEW OR VISIT ANY SECURITY PROGRAMS OR VULNERABILITY REPORTS. COBALT MAKES NO REPRESENTATIONS OR WARRANTIES AS TO THE CONDUCT OF USERS OF THE SITE OR SERVICES OR THEIR COMPATIBILITY WITH ANY CURRENT OR FUTURE USERS OF THE SITE OR SERVICES. YOU AGREE TO TAKE REASONABLE PRECAUTIONS IN ALL COMMUNICATIONS AND INTERACTIONS WITH OTHER USERS OF THE SITE OR SERVICES AND WITH OTHER PERSONS WITH WHOM YOU COMMUNICATE OR INTERACT AS A RESULT OF YOUR USE OF THE SITE OR SERVICES, INCLUDING, BUT NOT LIMITED TO, TESTERS AND PROGRAM OWNERS. NOTWITHSTANDING COBALT’S APPOINTMENT AS THE LIMITED AGENT OF THE PROGRAM OWNERS FOR THE PURPOSE OF PERFORMING PAYMENTS TO TESTERS ON BEHALF OF THE PROGRAM OWNERS, COBALT EXPLICITLY DISCLAIMS ALL LIABILITY FOR ANY ACT OR OMISSION OF ANY TESTER OR OTHER THIRD PARTY.

LIMITATION OF LIABILITY

YOU ACKNOWLEDGE AND AGREE THAT, TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE ENTIRE RISK ARISING OUT OF YOUR ACCESS TO AND USE OF THE SITE, SERVICES AND COLLECTIVE CONTENT, YOUR SECURITY PROGRAM OR VULNERABILITY REPORT VIA THE SITE AND SERVICES AND ANY CONTACT YOU HAVE WITH OTHER USERS OF COBALT WHETHER IN PERSON OR ONLINE REMAINS WITH YOU. NEITHER COBALT NOR ANY OTHER PARTY INVOLVED IN CREATING, PRODUCING, OR DELIVERING THE SITE, SERVICES OR COLLECTIVE CONTENT WILL BE LIABLE FOR ANY INCIDENTAL, SPECIAL, EXEMPLARY OR CONSEQUENTIAL DAMAGES, INCLUDING LOST PROFITS, LOSS OF DATA OR LOSS OF GOODWILL, SERVICE INTERRUPTION, COMPUTER DAMAGE OR SYSTEM FAILURE OR THE COST OF SUBSTITUTE PRODUCTS OR SERVICES, OR FOR ANY DAMAGES FOR PERSONAL OR BODILY INJURY OR EMOTIONAL DISTRESS ARISING OUT OF OR IN CONNECTION WITH THESE TERMS, FROM THE USE OF OR INABILITY TO USE THE SITE, SERVICES OR COLLECTIVE CONTENT, FROM ANY COMMUNICATIONS, INTERACTIONS OR MEETINGS WITH OTHER USERS OF THE SITE, OR SERVICES OR OTHER PERSONS WITH WHOM YOU COMMUNICATE OR INTERACT AS A RESULT OF YOUR USE OF THE SITE, SERVICES, OR FROM YOUR LISTING OF A SECURITY PROGRAM OR VULNERABILITY REPORT VIA THE SITE AND SERVICES, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), PRODUCT LIABILITY OR ANY OTHER LEGAL THEORY, AND WHETHER OR NOT COBALT HAS BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGE, EVEN IF A LIMITED REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.

IN NO EVENT WILL COBALT’S AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THESE TERMS AND YOUR USE OF THE SITE AND SERVICES INCLUDING, BUT NOT LIMITED TO, FROM YOUR LISTING OF YOUR SECURITY PROGRAM OR VULNERABILITY REPORT VIA THE SITE AND SERVICES, OR FROM THE USE OF OR INABILITY TO USE THE SITE, SERVICES, OR COLLECTIVE CONTENT AND IN CONNECTION WITH ANY INTERACTIONS WITH ANY OTHER MEMBERS, EXCEED THE AMOUNTS YOU HAVE PAID OR OWE IN RELATION TO A SECURITY PROGRAM VIA THE SITE AND SERVICES AS A PROGRAM OWNER IN THE TWELVE (12) MONTH PERIOD PRIOR TO THE EVENT GIVING RISE TO THE LIABILITY, OR IF YOU ARE A TESTER, THE AMOUNTS PAID BY COBALT TO YOU IN THE TWELVE (12) MONTH PERIOD PRIOR TO THE EVENT GIVING RISE TO THE LIABILITY, OR ONE HUNDRED DOLLARS ($100), IF NO SUCH PAYMENTS HAVE BEEN MADE, AS APPLICABLE. THE LIMITATIONS OF DAMAGES SET FORTH ABOVE ARE FUNDAMENTAL ELEMENTS OF THE BASIS OF THE BARGAIN BETWEEN COBALT AND YOU. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, SO THE ABOVE LIMITATION MAY NOT APPLY TO YOU.

Indemnification

You agree to release, defend, indemnify, and hold Cobalt and its affiliates and subsidiaries, and their officers, directors, employees and agents, harmless from and against any claims, liabilities, damages, losses, and expenses, including, without limitation, reasonable legal and accounting fees, arising out of or in any way connected with (a) your access to or use of the Site, Services, or Collective Content or your violation of these Terms; (b) your Member Content; (c) your (i) interaction with any Member, (ii) Running a Security Program, (iii) creation of Security Program or (iv) the test of an application and its content by you, including, but not limited to any injuries, losses, or damages (compensatory, direct, incidental, consequential or otherwise) of any kind arising in connection with or as a result of a test and/or your participation in a Security Program.

Reporting Misconduct

If you interact with anyone who you feel is acting or has acted inappropriately, including but not limited to, anyone who (i) engages in offensive, violent or sexually inappropriate behavior, (ii) you suspect of stealing from you, or (iii) engages in any other disturbing conduct, you should immediately report such person to the appropriate authorities and then to Cobalt by contacting us with your police station and report number at info@cobalt.io; provided that your report will not obligate us to take any action beyond that required by law (if any) or cause us to incur any liability to you.

Assigning

You may not assign or transfer these Terms, by operation of law or otherwise, without Cobalt’s prior written consent. Any attempt by you to assign or transfer these Terms, without such consent, will be null and of no effect. Cobalt may assign or transfer these Terms, at its sole discretion, without restriction. Subject to the foregoing, these Terms will bind and inure to the benefit of the parties, their successors and permitted assigns.

Notices

Any notices or other communications permitted or required hereunder, including those regarding modifications to these Terms, will be in writing and given by Cobalt (i) via email (in each case to the address that you provide) or (ii) by posting to the Site. For notices made by e-mail, the date of receipt will be deemed the date on which such notice is transmitted.

Controlling Law and Jurisdiction

These Terms will be interpreted in accordance with the laws of the State of California and the United States of America, without regard to its conflict-of-law provisions. You and we agree to submit to the personal jurisdiction of a state court located in San Francisco County, San Francisco, California or a United States District Court, Northern District of California located in San Francisco, California for any actions for which the parties retain the right to seek injunctive or other equitable relief in a court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation or violation of a party’s copyrights, trademarks, trade secrets, patents, or other intellectual property rights, as set forth in the Dispute Resolution provision below.

Dispute Resolution

You and Cobalt agree that any dispute, claim or controversy arising out of or relating to these Terms or the breach, termination, enforcement, interpretation or validity thereof, or to the use of the Services or use of the Site or Application (collectively, "Disputes") will be settled by binding arbitration , except that each party retains the right to seek injunctive or other equitable relief in a court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation or violation of a party’s copyrights, trademarks, trade secrets, patents, or other intellectual property rights. You acknowledge and agree that you and Cobalt are each waiving the right to a trial by jury or to participate as a plaintiff or class member in any purported class action or representative proceeding. Further, unless both you and Cobalt otherwise agree in writing, the arbitrator may not consolidate more than one person's claims, and may not otherwise preside over any form of any class or representative proceeding. If this specific paragraph is held unenforceable, then the entirety of this "Dispute Resolution" section will be deemed void. Except as provided in the preceding sentence, this "Dispute Resolution" section will survive any termination of these Terms.

Arbitration Rules and Governing Law. The arbitration will be administered by the American Arbitration Association ("AAA") in accordance with the Commercial Arbitration Rules and the Supplementary Procedures for Consumer Related Disputes (the "AAA Rules") then in effect, except as modified by this "Dispute Resolution" section. (The AAA Rules are available at http://www.adr.org/arb_med or by calling the AAA at 1-800-778-7879.) The Federal Arbitration Act will govern the interpretation and enforcement of this section.

Arbitration Process. A party who desires to initiate arbitration must provide the other party with a written Demand for Arbitration as specified in the AAA Rules. (The AAA provides a form Demand for Arbitration at http://www.adr.org/aaa/ShowPDF?doc=ADRSTG_004175 and a separate form for California residents at http://adr.org/aaa/ShowPDF?doc=ADRSTG_004314.) The arbitrator will be either a retired judge or an attorney licensed to practice law in the state of California and will be selected by the parties from the AAA’s roster of consumer dispute arbitrators. If the parties are unable to agree upon an arbitrator within seven (7) days of delivery of the Demand for Arbitration, then the AAA will appoint the arbitrator in accordance with the AAA Rules.

Arbitration Location and Procedure. Unless you and Cobalt otherwise agree, the arbitration will be conducted in the county where you reside. If your claim does not exceed $10,000, then the arbitration will be conducted solely on the basis of documents you and Cobalt submit to the arbitrator, unless you request a hearing or the arbitrator determines that a hearing is necessary. If your claim exceeds $10,000, your right to a hearing will be determined by the AAA Rules. Subject to the AAA Rules, the arbitrator will have the discretion to direct a reasonable exchange of information by the parties, consistent with the expedited nature of the arbitration.

Arbitrator’s Decision. The arbitrator will render an award within the time frame specified in the AAA Rules. The arbitrator’s decision will include the essential findings and conclusions upon which the arbitrator based the award. Judgment on the arbitration award may be entered in any court having jurisdiction thereof. The arbitrator’s award damages must be consistent with the terms of the "Limitation of Liability" section above as to the types and the amounts of damages for which a party may be held liable. The arbitrator may award declaratory or injunctive relief only in favor of the claimant and only to the extent necessary to provide relief warranted by the claimant’s individual claim. If you prevail in arbitration you will be entitled to an award of attorneys’ fees and expenses, to the extent provided under applicable law. Cobalt will not seek, and hereby waives all rights it may have under applicable law to recover, attorneys’ fees and expenses if it prevails in arbitration.

Fees. Your responsibility to pay any AAA filing, administrative and arbitrator fees will be solely as set forth in the AAA Rules. However, if your claim for damages does not exceed $75,000, Cobalt will pay all such fees unless the arbitrator finds that either the substance of your claim or the relief sought in your Demand for Arbitration was frivolous or was brought for an improper purpose (as measured by the standards set forth in Federal Rule of Civil Procedure 11(b)).

Changes. Notwithstanding the provisions of the "Modification" section above, if Cobalt changes this "Dispute Resolution" section after the date you first accepted these Terms (or accepted any subsequent changes to these Terms), you may reject any such change by sending us written notice (including by email to info@cobalt.io) within 30 days of the date such change became effective, as indicated in the "Last Updated Date" above or in the date of Cobalt’s email to you notifying you of such change. By rejecting any change, you are agreeing that you will arbitrate any Dispute between you and Cobalt in accordance with the provisions of this "Dispute Resolution" section as of the date you first accepted these Terms (or accepted any subsequent changes to these Terms).

Final Comment

The failure of Cobalt to enforce any right or provision of these Terms will not constitute a waiver of future enforcement of that right or provision. The waiver of any such right or provision will be effective only if in writing and signed by a duly authorized representative of Cobalt. Except as expressly set forth in these Terms, the exercise by either party of any of its remedies under these Terms will be without prejudice to its other remedies under these Terms or otherwise. If for any reason an arbitrator or a court of competent jurisdiction finds any provision of these Terms invalid or unenforceable, that provision will be enforced to the maximum extent permissible and the other provisions of these Terms will remain in full force and effect.