Muster.

legal

AI Penetration Testing Addendum

Draft. This document is pending legal review and may change before it takes effect. Questions? Contact us.

Addendum to the Muster Master Subscription Agreement

Effective Date: [DATE] · Version: 1.0 (draft)


This AI Penetration Testing Addendum (the "Addendum") is incorporated into and subject to the Master Subscription Agreement (the "MSA") between [MUSTER LEGAL ENTITY NAME] ("Muster") and the Customer. It sets out additional terms governing the Customer's use of Muster's agentic, AI-driven penetration testing service ("AI Pentest"). By requesting or initiating an AI Pentest (for example, via click-through acceptance on the Muster platform), Customer acknowledges and agrees to be bound by this Addendum. Capitalized terms not defined here have the meanings given in the MSA.

1. Authorized Scope of Testing

Permitted Targets. An AI Pentest may only be run against target systems that are explicitly designated by Customer and that Customer owns or is lawfully authorized to test. Customer must not include any system in the testing scope unless it is a non-production, staging, or testing environment whose use will not risk impact to live business operations and will not involve live user data, unless otherwise expressly agreed in writing by both Parties.

Customer Authorization. Customer represents and warrants that it holds all necessary rights, titles, and permissions to conduct security testing on the designated target systems. Where a target is owned or managed by a third party (for example, a cloud provider or partner), Customer has obtained that third party's explicit permission to perform the AI Pentest on those systems. Customer further agrees to provide, on request, a written Authorization to Test statement explicitly granting Muster (and its subcontractors, if any) permission to conduct the AI Pentest within the specified scope.

Third-Party Notifications. Muster is not responsible for any alerts, suspensions, or interference by internet service providers, cloud platforms, or other third parties that may occur as a result of authorized testing activity.

2. Customer Responsibilities and Preparation

Accurate Configuration. Customer is solely responsible for configuring the AI Pentest parameters via the Muster platform, including defining the target domains, IP addresses, or network ranges to be tested and providing any necessary context and access credentials (such as test user accounts). Muster will rely on the scope information provided by Customer and will not independently verify ownership or permission; Customer must therefore ensure that every configured target meets the Authorized Scope requirements in Section 1.

Pre-Test Safeguards. Customer is strongly advised to back up all data and systems within the target environment before initiating an AI Pentest, to ensure appropriate restore mechanisms and contingency plans are in place for the target systems, and to remove or mask any sensitive data where feasible. Customer will inform Muster of any particularly fragile systems or components that require cautious handling.

During and After Testing. Customer will monitor its systems during the test window (as feasible) and promptly notify Muster if any critical issue is observed. Customer is responsible for analyzing the AI Pentest results provided by Muster and for remediating any identified vulnerabilities at its own discretion and cost.

3. Testing Methodology and Limitations

Automated Testing Process. Customer understands that the AI Pentest is performed by autonomous software agents operating under Muster's direction. These agents conduct multi-phase activities — reconnaissance, vulnerability scanning, and exploitation attempts — against the in-scope targets. Testing may involve concurrent or rapid sequences of requests and attacks, which can stress the target systems. Muster will use commercially reasonable efforts to keep the testing within the agreed scope and to avoid intentional interaction with out-of-scope systems or data.

Potential Impact and Suspension. Customer acknowledges that penetration testing performed by autonomous AI agents carries inherent risks, including unpredictable non-deterministic behavior, performance degradation, service interruptions, or alterations of data on the target systems. If Muster becomes aware of a serious incident during testing, Muster will make commercially reasonable efforts to pause, adjust, or rate-limit the test and to inform Customer's point of contact. Customer should define any specific stop conditions or critical thresholds prior to the test.

Findings and Data Handling. All test activities and findings will be logged. Muster will treat any sensitive data obtained during testing as Confidential Information under the MSA and the Data Processing Agreement (DPA). Test data will be used solely for delivering pentest results and improving the service. Muster retains raw test data for a limited period to support follow-up questions or defend claims, after which it will be securely deleted. The final report or results will be made available to Customer, and Muster may retain an archival copy in accordance with its standard retention policy.

No Guarantee of Findings. Customer acknowledges that cybersecurity testing is a point-in-time assessment. Muster does not guarantee that the AI Pentest will find every vulnerability or security flaw in the target systems, or that the results will be free of false positives, errors, or omissions. Any remediation advice is for Customer's consideration and is not a warranty or certification of security. Results may include AI-generated observations that are not reproducible or fully explainable.

4. Assumption of Risk; Liability Limitations

Customer's Assumed Risk. By using the AI Pentest service, Customer knowingly assumes all risks of conducting penetration testing on its systems. Customer agrees that it will not hold Muster or its affiliates, employees, or agents liable for any indirect, special, incidental, or consequential damages arising out of the pentesting activities, including any loss of business, revenue, profits, data, goodwill, or use of systems, even if Muster was advised of the possibility of such damages. Customer waives any right to claim against Muster for downtime, degradation of performance, lost or corrupted data, inaccurate outputs, or work delays resulting from the AI Pentest, to the maximum extent permitted by law.

Limitation of Liability. Any direct damages or losses that may arise notwithstanding the above disclaimer are subject to the limitations of liability (including the liability cap) set forth in the MSA. For the avoidance of doubt, the AI Pentest is not a "Professional Service" as defined in the MSA and carries no warranty of performance or conformance. Nothing in this Addendum limits liability for gross negligence, willful misconduct, or other liability that cannot be limited by law.

Customer Indemnity. In addition to the indemnities in the MSA, Customer shall fully indemnify and hold harmless Muster from and against any third-party claims, fines, or regulatory actions arising from or related to Customer's configuration, authorization, or use of the AI Pentest.

No Warranties. The AI Pentest service is provided "as is" and, except to the extent (if any) expressly provided in the MSA, Muster disclaims all warranties and conditions, express or implied. Muster does not warrant that the AI Pentest will detect all vulnerabilities, or that running the test will not result in any system disruption. Customer is solely responsible for the consequences of running the test and for any necessary remediation or restoration activities thereafter.

5. General Provisions and Acceptance

Incorporation into the MSA. This Addendum is an integral part of the MSA. All terms and provisions of the MSA (including confidentiality, governing law, dispute resolution, indemnification, and data protection) apply to the AI Pentest service and this Addendum, except as specifically modified here. In the event of a conflict between this Addendum and the MSA, this Addendum controls with respect to the AI Pentest service.

Governing Law and Jurisdiction. The governing law and venue for any disputes under this Addendum are the same as those specified in the MSA.

Acceptance (Click-Through Agreement). Customer's authorized user indicates assent to this Addendum by electronic acceptance (for example, clicking "I Agree" or similar when enabling the AI Pentest feature). Such acceptance has the same force and effect as a signed agreement. By providing electronic acceptance, or by using the AI Pentest service, Customer confirms that it has read and agrees to this Addendum.