Agreement & parties
These Terms of Service (the "Terms") are entered into between the operator of ddos-simulation.com (the "Provider", "we",
"us") and the organization on whose behalf an account is created or the Service is used (the "Customer", "you").
By creating an account, configuring a test, or otherwise using the Service, you accept these Terms, our Acceptable Use Policy, our
Privacy Policy, and, where personal data is processed on your behalf, our Data Processing Addendum, each of which is incorporated by reference. If you do not agree, do not use
the Service.
Definitions
- Service
- The ddos-simulation.com platform for planning, scheduling and running authorized, bounded traffic-resilience tests, together with the customer portal, health monitoring, and related tooling and documentation.
- Target
- A domain, host, or system that a test is directed at.
- Authorized Target
- A Target that you own or that you are lawfully and demonstrably authorized in writing to test, and for which all required consents from relevant infrastructure providers have been obtained.
- Verified Domain
- A domain for which ownership has been confirmed through the Service's HTTPS verification process.
- Test
- A configured plan of one or more bounded commands (each a "Command") executed against a single Verified Domain at a scheduled time.
- Workspace
- The tenant account under which your users, domains, tests, and billing are grouped.
- Workers
- The short-lived virtual machines the Service provisions to execute a Test.
Eligibility (business use only)
The Service is offered strictly to businesses and other organizations acting in
the course of their trade, business, or profession. It is not offered to consumers. By using the Service you represent that you are acting on behalf of an organization, that you are at least 18 years old, and that you have authority
to bind that organization to these Terms.
Because you contract as a business, statutory consumer-protection rights — including any right of withdrawal — do not apply.
Accounts & security
- You must provide accurate registration details and confirm your email address before your Workspace becomes usable.
- You are responsible for all activity under your Workspace and for keeping credentials, including any two-factor authentication device, secure.
- You must promptly notify us of any suspected unauthorized access at [email protected].
- Workspace administrators are responsible for the users they invite and the roles they assign.
The Service
The Service lets you design a timeline of bounded Commands, verify ownership of a Target domain, authorize a scheduled Test, and observe service-health signals while the Test runs. Commands are executed by short-lived Workers subject
to hard technical ceilings described in Section 9 and in the
Acceptable Use Policy.
The Service is a tool for measuring resilience. It is not a guarantee of security, availability, or compliance, and it is not a substitute for your own engineering, monitoring, and incident-response practices.
Authorization & your warranties
Core condition of useYou may only direct a Test at an Authorized Target. Running traffic against systems you do not own or are not clearly authorized to test may be a criminal offence under Dutch law (including Articles 138ab and
161sexies of the Dutch Criminal Code) and comparable laws elsewhere.
For every Test, you represent, warrant, and undertake on a continuing basis that:
- you own the Target or hold current, documented authorization from the owner and every operator of the Target to conduct the Test;
- you have obtained any consent required from hosting, cloud, CDN, DDoS-mitigation, or other infrastructure providers whose systems may be affected (see Section 10);
- the Test will not target shared infrastructure, third parties, or systems in a way that would disrupt anyone other than you;
- you will comply with all applicable laws, regulations, and third-party terms; and
- you will retain evidence of the authorization above and provide it to us promptly on request.
These warranties are fundamental to the agreement. We may require additional written authorization for larger or higher-impact engagements, and we may decline or stop any Test at our discretion.
Domain verification
Before a Test can be scheduled, you must verify control of the Target domain through the Service's HTTPS verification process. Verification is a technical control that helps prevent obvious misuse; it does not establish that you are authorized to test the systems behind that domain, and it does not reduce your obligations under Section 6. A verified Target may be tested at the regular validation
level; higher rate, concurrency, and worker limits, and certain higher-impact Commands, require extended validation, which we review and may grant, decline, or revoke at our discretion.
Acceptable use
Your use of the Service is governed by our Acceptable Use
Policy, which forms part of these Terms. Breach of that policy is a material breach of these Terms and may result in immediate suspension or termination.
Test execution & assumption of risk
Tests run only against a Verified Domain that you have proven you control, within the validation level granted for that domain. Each Verified Domain has its own limits on rate, concurrency, and worker count, and the most aggressive
network-layer Commands are available only with extended validation. Each Worker additionally enforces technical limits on task duration, concurrency, start rate, and total operations, and will accept work only for the single
Verified Domain assigned to it, resolved to a pinned public address with private and loopback destinations blocked. We set and enforce these controls and may adjust them to protect the Service and third parties.
Resilience testing can nonetheless degrade, slow, or interrupt the Target and dependent systems. You accept this risk for your own systems. You are responsible for scheduling Tests appropriately, maintaining backups,
informing your own stakeholders and on-call teams, and stopping a Test if you observe unacceptable impact. We do not warrant that a Test will be free of adverse effects.
Third-party infrastructure
If your Target is hosted, fronted, or protected by a third party (for example a cloud provider, CDN, load balancer, or DDoS-mitigation service), that provider's acceptable-use and penetration-testing policies may require prior
notice or authorization for the kinds of traffic the Service generates. You are solely responsible for reviewing and complying with those policies and for obtaining any required permissions before scheduling a Test. We are
not a party to, and accept no responsibility under, your agreements with such providers.
Fees, billing & taxes
- Quote and pricing. Each Test is priced individually. You build a Test plan (or ask us to design one) and request a quote; we set a one-off price for that specific engagement — the recorded plan revision, its
target, timeline, Commands, rates, concurrency, Workers, and health safeguards. There is no subscription and no prepaid balance. The quoted price is shown before you sign and is binding once you accept it.
- Authorization before scheduling. Before a Test is scheduled or run, we must accept and price the plan, and an authorized representative must electronically sign the applicable
Rules of Engagement and agreed quote. The quote and signature apply only to the recorded plan revision. Editing its target, timeline, Commands, rates, concurrency, Workers, health safeguards, or other scope invalidates the quote and signature
and requires a new quote and signature. Signing does not waive domain validation, safety limits, provider authorization requirements, or our right to decline a plan.
- Scheduling and start. When you build a plan you may name an approximate preferred window (a date and an hour). After the Test is accepted and signed, we confirm the exact time and schedule and start
the Test. Domain ownership must be verified before the Test runs.
- Invoicing and payment terms. Invoices are issued upon completion of the engagement or as agreed in writing. Payment terms are net 14 days from invoice date unless otherwise specified. We accept payment via bank transfer or supported payment methods.
- Taxes. Prices are exclusive of VAT and other applicable taxes, which are added where required. You are responsible for providing valid tax details (including a VAT identification number where applicable).
- Invoices & records. Invoices and the status of each engagement are made available in the portal.
Cancellations & service remedies
Agreed fees for an engagement become payable in accordance with the agreed terms once the engagement is authorized and executed. Cancelling or stopping a Test after execution begins does not waive accrued fees. We may suspend a Workspace to resolve overdue balances or payment disputes.
If we do not schedule and run an authorized Test, or a Test fails to run materially as configured due to a fault attributable to the Provider, we will, at our election, re-run the Test or credit/waive the affected engagement fee. Nothing
in this section limits rights that cannot be excluded under mandatory Dutch law.
Suspension & termination
We may suspend or terminate your access, cancel a scheduled or running Test, or remove content immediately and without prior notice where we reasonably believe that: a Test is directed at a Target that is not an
Authorized Target; there is a breach of these Terms or the Acceptable Use Policy; there is a risk to the Service, to us, or to any third party; or we are required to do so by law or by an infrastructure provider.
Either party may terminate the agreement on notice where the Service is not in active use. You may stop using the Service at any time. Sections that by their nature should survive termination (including Sections 6, 11–20 and
23) survive.
Intellectual property
The Service, including its software, design, and documentation, is and remains our property and that of our licensors. We grant you a limited, non-exclusive, non-transferable, revocable right to use the Service during the term,
solely for your internal business purposes and in accordance with these Terms. You may not copy, resell, sublicense, reverse engineer (except as permitted by mandatory law), or attempt to circumvent the technical limits of
the Service.
Your data & results
As between the parties, you retain all rights in the data you submit (such as domains, test plans, and configuration) and in the results and health data generated for your Tests ("Customer Data"). You grant us
a worldwide, royalty-free licence to host, process, and transmit Customer Data to the extent necessary to provide, secure, and improve the Service and to comply with law. We may use aggregated and anonymized data that does
not identify you or any person for operating and improving the Service.
Confidentiality
Each party may receive confidential information of the other. The receiving party will use it only to perform under these Terms, protect it with reasonable care, and not disclose it except to personnel and contractors bound by
equivalent obligations, or where required by law. Test results and security findings are your confidential information.
Data protection
Our processing of personal data is described in our Privacy
Policy. Where we process personal data on your behalf as a processor, the
Data Processing Addendum applies and forms part of these Terms. You are responsible for ensuring you have a lawful basis for any personal data you place into, or cause to be processed through, the Service.
Disclaimers
To the fullest extent permitted by law, the Service is provided "as is" and "as
available", without warranties of any kind, whether express or implied, including any implied warranties of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that the Service will be uninterrupted
or error-free, that a Test will detect all vulnerabilities or weaknesses, or that testing will not cause disruption to the Target or dependent systems.
Limitation of liability
To the fullest extent permitted by law:
- neither party is liable for indirect, incidental, special, or consequential loss, or for loss of profit, revenue, data, goodwill, or business, however arising;
- our total aggregate liability arising out of or relating to the Service and these Terms is limited to the total fees you paid to us for the Test(s) giving rise to the claim in the three (3) months before the event giving rise
to liability.
Nothing in these Terms excludes or limits liability that cannot be excluded or limited under mandatory Dutch law, including liability for damage caused by intent (
opzet) or deliberate recklessness (bewuste roekeloosheid) of the Provider's management, or for death or personal injury caused by negligence.
Indemnification
You will defend, indemnify, and hold harmless the Provider and its officers, employees, and contractors from and against all claims, liabilities, damages, penalties, and costs (including reasonable legal fees) arising out of or
related to: (a) your breach of
Section 6 (Authorization) or the
Acceptable Use Policy; (b) any Test directed at a Target that is not an Authorized Target; (c) your breach of applicable law or third-party terms; or (d) your Customer Data. This obligation
survives termination.
Force majeure
We are not liable for any failure or delay caused by events beyond our reasonable control, including failures of upstream infrastructure or connectivity, acts of government, or actual denial-of-service attacks against our own systems.
Changes
We may update these Terms, the Acceptable Use Policy, and pricing from time to time. Material changes will be notified through the portal or by email before they take effect. Continued use of the Service after changes take effect
constitutes acceptance. We may also modify or discontinue features of the Service.
General
- Assignment. You may not assign these Terms without our consent; we may assign them to an affiliate or successor.
- Subcontractors. We may use subcontractors (such as hosting and payment providers) to deliver the Service.
- Notices. Legal notices to us must be sent to [email protected]. We may give notice through the portal or to your account email.
- Entire agreement. These Terms and the documents incorporated by reference are the entire agreement and supersede prior discussions.
- Order of precedence. In case of conflict: the Data Processing Addendum (for personal-data processing), then these Terms, then the Acceptable Use Policy, then the Privacy Policy.
- Severability & waiver. If any provision is unenforceable, the rest remains in effect; failure to enforce is not a waiver.
Governing law & jurisdiction
These Terms and any non-contractual obligations arising out of them are governed by the laws of the Netherlands. The competent court in Amsterdam, the Netherlands, has exclusive jurisdiction over any dispute, without prejudice
to any mandatory statutory jurisdiction.
← Back to ddos-simulation.com