Skip to content
How it works Scope & safety Findings Review desk Blog Book a demo

Terms of Service

← Back to Zaaf
Last updated: August 12, 2026
By accessing or using Zaaf (the website, dashboard, scanning service and API at zaaf.ai), you agree to be bound by these Terms of Service, entered into with Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi (Tax ID 8800579984, Şarköy / Tekirdağ, Turkey).

1. Acceptance of Terms

By creating an account or commissioning an engagement, you agree to these Terms and to our Privacy Policy. If you do not agree, do not use the service. If you use Zaaf on behalf of an organization, you represent that you are authorized to bind that organization to these Terms.

2. Service Provider

Zaaf is operated by Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi, with registered address at İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey, contactable at support@zaaf.ai.

3. What Zaaf Is

Zaaf is an adversarial security testing service, delivered as scoped engagements. An automated agent tests the assets in scope the way an attacker would, it maps what is reachable, forms a hypothesis, chains requests to test it, and attempts exploitation in a safe, non-destructive way, and a security researcher reviews every finding before it is delivered to you. Depending on the engagement, the assets in scope may include web applications and their APIs, cloud and infrastructure configuration, smart contracts and the application layer around them, and connected devices including their firmware and the services they communicate with. Testing runs from our own infrastructure; Zaaf is not software you install on your own systems, except where a device engagement requires equipment you have provided or authorised us to use. The deliverable is an evidence-backed dossier, with reproduction steps for each finding, and where agreed a signed attestation you can share during a buyer’s security review.

4. Authorization to Test

You may only submit assets that you own or are explicitly authorized to test. Before any testing begins, each target domain must be verified, typically by placing a DNS TXT record we provide. Zaaf tests only assets that have passed this verification. Assets that cannot be verified this way: cloud accounts, smart contracts, source code, physical devices, are tested only when they are named in the written scope for the engagement and you have confirmed your authority over each of them there. You are solely responsible for ensuring you have the legal right to authorize testing of every asset you submit, including where an asset is operated on your behalf by a third party whose own consent may be required. You must tell us immediately if your authorization to test an asset ends. We may suspend testing of any asset if we reasonably believe authorization is absent.

5. Engagements and Fees

Zaaf is sold per engagement. Before any work begins we agree a written scope with you, which names the assets to be tested, what the engagement covers, what it deliberately does not, and the fee. The fee is fixed for that scope; if the scope changes, the fee is re-agreed in writing before the additional work starts. Fees are exclusive of taxes, which are handled by Paddle at checkout.

Retesting after you remediate is included as stated in your scope. An engagement recurs only where the scope says so; there is no automatic renewal otherwise.

Zaaf was previously offered as monthly subscription plans (Starter, Growth and Scale) and as a one-time Enterprise Review Pack. Those plans are no longer sold. If you purchased one while it was offered, it continues to be governed by the Terms and Refund Policy in force at the time of your purchase until it ends.

6. Acceptable Use

You agree not to use Zaaf to: violate any law; scan, probe or attack assets you do not own or are not authorized to test; attempt to gain unauthorized access to any system; circumvent our access or billing controls; resell, sublicense or redistribute the service or its findings data without authorization; or interfere with the operation of the service. Zaaf is a defensive security tool and must not be used to facilitate attacks against third parties.

7. Findings, Reports and Attestations

Findings, evidence packages, reports and attestations are produced by automated adversarial testing and reviewed by a security researcher before delivery. They reflect the state of your assets at the time of testing and are provided to help you assess and communicate your security posture. An engagement with Zaaf is not a certified or accredited penetration test, and our deliverables are not a formal certification, an audit opinion, or a warranty of security to any third party; where a buyer or regulator specifically requires a test from an accredited firm, this does not replace one. They are also not a guarantee that your assets are free of vulnerabilities. You are responsible for how you share and represent any deliverable to your buyers or auditors.

8. Intellectual Property

The Zaaf software, brand, website, scanning engine and vulnerability knowledge base (as compiled and curated by us) are the property of Türkol and its licensors. An engagement grants a non-exclusive, non-transferable right to use the service for the scope and duration agreed. Reports, dossiers and attestations produced for your authorised assets are yours to use and share.

9. Payment and Billing

Payments are processed through Paddle, our Merchant of Record. Payments are handled securely; we never store your full card details. Applicable taxes are collected and remitted by Paddle. An engagement is billed against the fee in its agreed scope, and nothing renews automatically unless that scope provides for recurring work, in which case it renews each term until you cancel.

10. Cancellation and Refunds

You may cancel an engagement before work begins for a full refund. Once testing has started, refunds are governed by our Refund Policy, which also covers recurring work and any subscription purchased while those plans were offered.

11. Limitation of Liability

Zaaf is provided "as is" and "as available" without warranties of any kind. While we work to identify known vulnerabilities and verify exploitability, no security tool can detect every vulnerability or guarantee that an asset cannot be compromised. To the maximum extent permitted by law, our total liability is limited to the amount you paid for the service in the 12 months preceding the claim.

12. Termination

We may suspend or terminate access for violation of these Terms or for unlawful use, including submitting assets you are not authorized to test. Upon termination, your right to use the service ends; data may be deleted after 30 days in accordance with our Privacy Policy.

13. Governing Law

These Terms are governed by the laws of the Republic of Turkey. Any disputes shall be resolved in the courts of Tekirdağ, Turkey.

14. Changes to Terms

We may update these Terms from time to time. The "Last updated" date reflects the latest version. Continued use after changes constitutes acceptance.

15. Contact

Questions about these Terms: support@zaaf.ai.

© 2026 Zaaf, a product of Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi.