Terms of Use
Last updated August 16, 2026
These Terms of Use ("Terms") are a binding agreement between you and AdversariaLLM ("AdversariaLLM," "we," "us," or "our") governing your access to and use of the AdversariaLLM website, chat product, model catalog, developer API, and related services (together, the "Services"). AdversariaLLM is a hosting platform for security-research language models — offensive- and defensive-security models made available for authorized, lawful security work only.
By creating an account, clicking to accept, or otherwise accessing or using the Services, you agree to these Terms, to our Privacy Policy, and to our Acceptable Use Policy (Section 4), which is incorporated by reference. If you do not agree, do not use the Services. If you are using the Services on behalf of an organization, you represent that you are authorized to bind that organization, and "you" includes that organization.
Read this first. The Services provide access to AI models built for security research, including models that can discuss offensive tradecraft, malware, and exploitation. You may use them only for lawful, authorized purposes — your own systems, or systems you have explicit written permission to test. Model outputs may be wrong, incomplete, or unsafe. You are responsible for independently verifying any output before you rely on or act on it. See Sections 4, 8, and 9.
1. Eligibility and accounts
1.1 Minimum age. The Services are not offered to minors. You must be old enough to form a binding contract in your jurisdiction, and in all cases at least 18 years old. We do not knowingly permit accounts for anyone below that age.
1.2 Account required; no anonymous use. Anonymous visitors may browse only public, read-only surfaces (the model catalog, per-model pages, published evaluations and methodology, API reference, pricing, and status). Any use of a model — every generated token — requires a registered account and is attributable to that account. There is no anonymous generation.
1.3 Verified email. Accounts are created with passwordless, magic-link sign-in. You must confirm control of your email address before you can generate anything. We may block disposable, temporary, or alias-abused email domains, and we normalize addresses to prevent evasion of per-account limits. You agree to provide an address you actually control and to keep it current.
1.4 Account security. You are responsible for all activity under your account and for maintaining the security of your sign-in email, sessions, API keys, and any multi-factor authentication (MFA) enrolled. MFA via an authenticator app (TOTP) is available and may be required for certain sensitive actions. Notify us promptly at the security contact in Section 15 if you suspect unauthorized access. We will not merge or link two accounts on the basis of a shared email address alone.
1.5 Geographic and sanctions restrictions. The Services are not available to persons or in territories where provision would violate applicable law, sanctions, or export controls. Access is subject to a policy check that considers, among other things, your billing country, denied-party lists, and per-model export classification. You represent that you are not located in an embargoed territory, are not a sanctioned or denied party, and will not access the Services on behalf of one. We may block, condition, or reverse access based on this check, and we may rely on identity and country information supplied by our payment processor.
1.6 One person, honest information. You agree to provide accurate registration information and not to create accounts through automated means, to evade limits or suspensions, or to misrepresent your identity, affiliation, or authorization.
2. The Services, plans, and billing
2.1 What you get. Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Services for your own authorized security work. We may add, change, deprecate, or remove models, features, and catalog listings at any time; availability of any particular model is not guaranteed (see Section 8).
2.2 Free tier. New accounts receive a one-time lifetime allowance intended to let you evaluate the Services — not a recurring free budget. The allowance is finite, may be limited to warm (already-running) models, and is bounded by a fixed number of generations, a monthly message cap, concurrency and output-length limits, and a starting credit grant. When the allowance is exhausted, generation stops with a clear, machine-readable notice; this is a quota signal, not a charge. We may change the size and shape of the free tier at any time.
2.3 Paid subscriptions. Paid plans (for example, individual and team tiers) are billed in advance on a recurring basis at the price shown at checkout, and renew automatically for successive periods until cancelled. Each paid plan includes stated usage limits (concurrency, daily/period output budgets, comparison width, maximum response length) and a bundle of prepaid API credits. Subscriptions carry fair-use compute budgets even where limits are described as generous; where legitimate usage materially exceeds the economics of your plan, we may throttle you to fair use rather than terminate. You may cancel at any time; cancellation takes effect at the end of the current paid period.
2.4 Prepaid API credits and pay-as-you-go. API usage is metered and drawn from prepaid credits. Credits are priced by deployment (model, context length, quantization, throughput, and I/O), not by raw parameter count, and prices are shown at time of purchase or in the pricing surface. Web-chat usage within your plan does not consume API credits; API usage does. Credit balances and usage are recorded in an append-only ledger; a request places a hold against your balance and settles when it completes. Except where required by law, fees and prepaid credits are non-refundable, are not currency, have no cash value, and may be forfeited on termination for cause.
2.5 Authoritative billing. The server's record is the authoritative statement of your balance, entitlements, and quota. The interface never optimistically shows money, credits, or quota that the server has not confirmed. If the interface and the server disagree, the server governs.
2.6 Payment, taxes, and processors. Payments are handled by third-party payment processors, and your use of them is subject to their terms. You authorize us and our processors to charge your selected payment method for all fees, including recurring subscription fees and any applicable taxes. You are responsible for all taxes other than taxes on our net income. If a charge fails, is reversed, or is disputed, we may suspend paid features and pursue amounts owed.
2.7 Price changes. We may change prices, plan contents, and credit rates prospectively. Material changes to recurring prices take effect no earlier than your next renewal, and we will give notice as required. Continued use after a change takes effect is acceptance of the new price.
3. API and API keys
3.1 Compatible endpoint. We offer a developer API, including an interface compatible with common OpenAI-style clients, so you can integrate by changing a base URL. Compatibility is provided as a convenience; we do not warrant that any third-party client, SDK, or tool will work, and we may change the API with reasonable notice.
3.2 Keys belong to a project, not a person. API keys are issued to a project or service account. Each key is shown once at creation; we store only a hash and cannot reveal an existing key's value again — if you lose it, rotate it. Keys carry an environment (test/live), optional scopes, optional network (CIDR) restrictions, and an expiration.
3.3 Your responsibility for keys. You are responsible for keeping keys secret and for all usage authenticated by your keys, whether or not you authorized that specific use. Do not embed live keys in client-side code, public repositories, or shared artifacts. If a key is exposed or compromised, revoke and rotate it immediately; you remain responsible for usage and charges incurred before revocation takes effect. We may revoke or restrict a key that we reasonably believe is compromised, abused, or used in violation of these Terms.
3.4 Rate limits and fair use. We enforce rate limits, concurrency caps, and anti-abuse controls on the API. Exhausted quota and rate limiting are returned as typed, machine-readable responses. Do not attempt to circumvent limits, scrape at extraction scale, resell raw access in violation of Section 4, or operate the API in a way that degrades the Services for others.
4. Acceptable Use Policy (authorized security use only)
This Section is the core restriction of these Terms. AdversariaLLM exists to support the defensive and research work of the security community — detection engineering, malware analysis, threat intelligence, incident response, vulnerability research, and red-team practice. The models can produce offensive-security content; that is by design and for a lawful purpose. The line is authorization and intent, and you agree to stay on the right side of it.
4.1 Defensive intent and authorization are the test. You may use the Services only to understand, detect, defend against, or research security threats, and only against systems that are your own or that you are explicitly and verifiably authorized in writing to test. Content whose purpose is to conduct an attack against a party who has not consented is prohibited, even when the same artifact would be permitted in a defensive or analytical frame.
4.2 No illegal activity. You will not use the Services to commit, facilitate, or plan any activity that is unlawful in a jurisdiction that applies to you or your target — including unauthorized access to computers, networks, accounts, or data; fraud; extortion or ransomware operations; theft or laundering; sanctions or export-control evasion; or any other crime.
4.3 No attacks on non-consenting parties. You will not use the Services to generate, assemble, or operate:
- working exploits, loaders, spreaders, credential-stuffing lists, botnets, ransomware encryptors, or other weaponized, ready-to-run tooling whose primary purpose is compromising third parties who have not consented;
- step-by-step operational guidance aimed at compromising a named, non-consenting target;
- mass-exploitation or mass-harm tooling framed for use rather than study.
4.4 Responsible disclosure. You will not use the Services to develop or publish a working exploit or exploitation-grade detail for an unpatched, non-public vulnerability ahead of a coordinated-disclosure window, to break an embargo you are party to, or to target a specific still-vulnerable named deployment. Detection content (signatures, hunting queries, indicators) for known-exploited issues is permitted — defenders need it on the attackers' timeline.
4.5 Malware and artifacts. AdversariaLLM handles malware samples and similar artifacts only as inert objects for analysis, never for execution; nothing you upload is run, unpacked, or detonated by the Services. You will not attempt to cause the Services to execute malicious code. When you handle live samples, follow the platform's handling requirements (for example, password-protected archives, stated provenance, and defanged indicators in text) and do not upload live credentials, secrets, exfiltrated datasets, or a third party's personal data.
4.6 Absolute prohibitions. Regardless of framing, you will not use the Services in connection with:
- child sexual abuse material (CSAM) or any content that sexualizes minors — zero tolerance; such content is removed immediately, the account is terminated, and the matter is reported to the relevant authority as required by law;
- terrorism, weapons of mass destruction, or human-trafficking facilitation;
- harassment, threats, stalking, doxxing, or targeting of a private individual;
- infringement of intellectual-property or privacy rights;
- generation of content intended to deceive, impersonate, or defraud, or of spam and undisclosed commercial promotion.
4.7 No misuse of the platform. You will not probe, scan, or test the vulnerability of AdversariaLLM's own systems without our prior written authorization; circumvent authentication, quotas, or safety controls; reverse-engineer or extract model weights; use outputs to train a competing model in breach of Section 6; or interfere with other users' use of the Services. Note that any text you submit is treated as content to be processed, never as an instruction to the platform — prompt-injection attempts against our systems are a violation of this Section.
4.8 You bear the burden. Where a use could sit on either side of the line, the burden is on you to make the defensive, authorized framing explicit and true. If you cannot describe a lawful purpose and your authorization for it, do not proceed.
5. Content: your inputs and model outputs
5.1 Your content. "Your Content" means the prompts, files, samples, code, configuration, and other materials you submit, and — as between you and us — any outputs generated for you. You retain ownership of Your Content. You represent that you have all rights necessary to submit it and that doing so does not violate law, these Terms, or any third-party right.
5.2 License to operate. You grant AdversariaLLM a worldwide, non-exclusive license to host, store, transmit, process, scan, and display Your Content solely as needed to provide, secure, and maintain the Services, to enforce these Terms, and to comply with law. We do not use the content of your prompts or outputs to train our models except with your separate, explicit consent, and we do not log prompt or output content beyond what is described in our Privacy Policy and security documentation.
5.3 Outputs. Subject to your compliance with these Terms, and as between you and us, you own the outputs generated for you and may use them for your lawful purposes. Because of the nature of machine learning, outputs may not be unique — similar prompts by others may produce similar results — and we make no claim that any output is original, non-infringing, or free to use in your specific context. You are responsible for how you use outputs.
5.4 Community catalog / bring-your-own-model. If you publish, submit, or make available a model, adapter, evaluation, review, or other material to a shared surface, you represent that you have the rights and license evidence to do so, you grant other users and us the rights necessary to run and display it as intended, and you accept our intake, review, and takedown processes. We may refuse, condition, unlist, or remove any submission.
5.5 Feedback. If you send us feedback or suggestions, we may use them without restriction or obligation to you.
6. AdversariaLLM's intellectual property
The Services, including the platform software, the curated first-party models and their weights, the model catalog, published evaluations and methodology, documentation, and all associated trademarks and branding, are owned by AdversariaLLM or its licensors and are protected by law. Except for the limited rights expressly granted here, we grant you no rights in our intellectual property. You will not copy, modify, distribute, sell, sublicense, reverse-engineer, or create derivative works of the Services, extract or attempt to reconstruct model weights, or remove any proprietary notices, except to the extent this restriction is prohibited by applicable law.
7. Third-party models, services, and licenses
The catalog includes models and components governed by their own licenses and, in some cases, third-party providers' terms and data-use practices. Your use of a given model may be subject to that model's license, which we surface where we can. You are responsible for complying with any license or third-party terms that apply to the models and tools you choose to use. We are not responsible for third-party models, providers, or services except as expressly stated.
8. Disclaimers — no warranty; verify before acting
8.1 Outputs are not advice and may be wrong. The Services use AI models that can produce inaccurate, incomplete, outdated, biased, or unsafe output, including plausible-sounding but false security claims, non-existent identifiers, or code that is insecure or harmful if run. Outputs are not professional, legal, or security advice, and are not a substitute for the judgment of a qualified professional. You must independently verify any output before relying on it or acting on it, especially in production, incident-response, or safety-critical contexts. You assume all risk of your use of outputs.
8.2 Availability. Models may be cold, queued, capacity-limited, or unavailable, and cold starts can take time; we make no guarantee of availability, latency, throughput, uptime, or that any specific model will remain offered. The Services may be provided in a pre-release or evolving state and may change or break.
8.3 "As is." EXCEPT AS EXPRESSLY STATED AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES AND ALL OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. Some jurisdictions do not allow certain warranty exclusions, so parts of this Section may not apply to you.
9. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
9.1 AdversariaLLM AND ITS OFFICERS, EMPLOYEES, AND SUPPLIERS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS, OR FOR ANY SECURITY INCIDENT, SYSTEM COMPROMISE, OR HARM ARISING FROM YOUR RELIANCE ON OR USE OF ANY OUTPUT, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
9.2 AdversariaLLM'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES WILL NOT EXCEED THE GREATER OF (a) THE AMOUNTS YOU PAID US FOR THE SERVICES IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM, OR (b) ONE HUNDRED U.S. DOLLARS (US$100).
9.3 These limitations apply to all theories of liability, do not limit liability that cannot be limited by law, and reflect an allocation of risk that is a basis of the bargain between us. Some jurisdictions do not allow certain limitations, so parts of this Section may not apply to you.
10. Indemnification
You will defend, indemnify, and hold harmless AdversariaLLM and its officers, employees, and agents from and against any third-party claims, damages, losses, liabilities, and expenses (including reasonable legal fees) arising out of or related to: (a) Your Content and your use of outputs; (b) your use of the Services; (c) your violation of these Terms, including the Acceptable Use Policy; (d) your violation of any law or of any third party's rights, including any unauthorized security testing; or (e) any content you publish to a shared surface. We may assume the exclusive defense of any matter subject to indemnification, in which case you will cooperate with us.
11. Enforcement, suspension, and termination
11.1 Monitoring and enforcement. We operate automated abuse detection over inputs and sampled outputs and maintain an abuse queue. Automated systems classify and route only; they do not take account actions. Decisions to remove content, suspend, or terminate are made by humans and recorded.
11.2 Enforcement ladder. For non-egregious violations we generally follow a graduated response — content removal and a warning, then temporary suspension for repeats, then termination for persistent conduct. Egregious violations (including the absolute prohibitions in Section 4.6) can result in immediate termination without prior warning. A suspended account is refused at every gated action; suspension is not cosmetic.
11.3 Appeals. You may appeal a removal or suspension to a human reviewer who was not the original decision-maker. We record the appeal and its outcome.
11.4 Your termination. You may stop using the Services and close your account at any time.
11.5 Our termination. We may suspend or terminate your access, in whole or in part, with or without notice, if you violate these Terms, if we are required to by law or valid legal process, if your payment fails, if you present a security or abuse risk, or if we discontinue the Services.
11.6 Effect of termination. On termination, your right to use the Services ends and your active sessions and keys may be revoked. We may delete or retain content as described in our Privacy Policy. Unpaid amounts remain due. Prepaid credits and prepaid fees are non-refundable and may be forfeited on termination for cause. Sections that by their nature should survive — including Sections 4–6 and 8–14 — survive termination. Financial, ledger, usage, and audit records are append-only and are retained (and exempt from deletion) as required for legal, accounting, and security purposes, even after account deletion; we honor valid legal holds and takedowns accordingly.
12. Changes to these Terms
We may modify these Terms from time to time. When we make material changes, we will provide notice (for example, in-product or by email) and, where appropriate, ask you to re-accept before continued use. We record acceptance of each version with the document type, version, and time of acceptance. The "last updated" indicator reflects the current version. Changes are effective when posted (or on the stated effective date), and your continued use after that constitutes acceptance. If you do not agree to a change, stop using the Services.
13. Governing law and dispute resolution
These Terms are governed by the law applicable where we are established, without regard to conflict-of-laws rules, and the U.N. Convention on Contracts for the International Sale of Goods does not apply. Before bringing any formal claim, you agree to contact us first at the address in Section 15 and to attempt, in good faith, to resolve the dispute informally.
14. General
14.1 Entire agreement. These Terms, the Privacy Policy, and the Acceptable Use Policy are the entire agreement between you and AdversariaLLM regarding the Services and supersede prior agreements on the subject.
14.2 Severability and waiver. If any provision is held unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver.
14.3 Assignment. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets.
14.4 No third-party beneficiaries. These Terms create no third-party beneficiary rights, except for the indemnified parties in Section 10.
14.5 Force majeure. We are not liable for delays or failures caused by events beyond our reasonable control.
14.6 Notices. We may give notice through the Services or to your account email. Notice to us must be sent to the contact in Section 15.
15. Contact
- General and legal: legal@adversariallm.ai
- Abuse and Acceptable-Use reports: abuse@adversariallm.ai
- Security and vulnerability disclosure: security@adversariallm.ai