CANIMA, INC.

ACCEPTABLE USE POLICY

Effective Date: 03/12/2026 | Last Updated: 07/27/2026

This Acceptable Use Policy ("AUP") governs the use of Canima, Inc.’s ("Canima," "we," "us," or "our") AI-powered penetration testing platform and related services (the "Service"). This AUP is incorporated into and forms part of the Master Subscription Agreement ("MSA") between Canima and Customer. Capitalized terms not defined herein have the meanings set forth in the MSA.

By using the Service, Customer agrees to comply with this AUP. Violation of this AUP may result in suspension or termination of Customer’s access to the Service.

1. AUTHORIZED TESTING ONLY

1.1 Ownership and Authorization. Customer shall only use the Service to test systems, networks, applications, and assets that Customer owns or for which Customer has obtained explicit, documented written authorization from the asset owner to conduct penetration testing. Customer is solely responsible for ensuring that all testing activities are authorized.

1.2 Testing Scope. Customer shall accurately define the Testing Scope within the Platform before initiating any testing engagement. The Testing Scope must reflect only those assets for which Customer has proper authorization. Customer must review and approve the Testing Scope prior to each engagement.

1.3 Asset Validation. Customer is responsible for validating that all IP addresses, domains, subdomains, URLs, and applications entered into the Platform belong to Customer or are authorized for testing. Company may require Customer to confirm asset ownership before testing begins.

2. PROHIBITED USES

Customer shall not use the Service to:

(a) Test, scan, probe, or attack any system, network, or application not within the authorized Testing Scope;

(b) Conduct denial-of-service attacks or any activity intended to disrupt the availability of any system;

(c) Access, exfiltrate, or steal data from systems beyond what is necessary to demonstrate a vulnerability;

(d) Modify, delete, or destroy data on target systems beyond what is necessary for safe exploitation and proof-of-concept;

(e) Install persistent backdoors, rootkits, or other malicious software on target systems;

(f) Use discovered vulnerabilities or credentials to access systems or data outside the authorized Testing Scope;

(g) Violate any applicable law, regulation, or industry standard, including but not limited to the Computer Fraud and Abuse Act (CFAA), data protection laws, and export control regulations;

(h) Conduct testing that may affect third-party systems or services without prior written authorization from such third parties;

(i) Resell, sublicense, or provide access to the Service to any unauthorized third party;

(j) Use the Service to develop, train, or improve competing products or services;

(k) Circumvent, disable, or interfere with any security-related features of the Service;

(l) Use the Service for social engineering, phishing, or any form of human manipulation, unless explicitly authorized in the Testing Scope; or

(m) Share, publish, or disclose Findings or vulnerability information to any third party without Company’s prior written consent, except: (i) to Customer’s own authorized personnel for remediation purposes; (ii) to Customer’s auditors, assessors, regulators, insurers, and professional advisers, in each case under obligations of confidentiality no less protective than those in the MSA and solely for the purpose of Customer’s own compliance, audit, underwriting, or legal requirements; and (iii) where a partner is providing the Service as a managed service, to the applicable managed client and that managed client’s advisers on the same basis. Nothing in this clause permits publication of Findings to the general public, to any competitor of Company, or for benchmarking or comparative marketing purposes.

3. PRODUCTION ENVIRONMENT TESTING

Customer acknowledges that penetration testing inherently carries risks, including the possibility of system disruption, data corruption, or service degradation. While Canima’s AI agents employ safe exploitation techniques designed for production environments, Customer is responsible for: (i) ensuring appropriate backups are in place before testing; (ii) configuring risk tolerance levels appropriately within the Platform; (iii) notifying relevant stakeholders within Customer’s organization about planned testing activities; and (iv) having an incident response plan in place in case testing causes unintended effects.

4. CLOUD AND THIRD-PARTY SERVICES

If Customer’s Testing Scope includes assets hosted on cloud platforms (such as AWS, Azure, or GCP) or involves third-party services, Customer is responsible for complying with such cloud provider’s or third party’s acceptable use policies, terms of service, and any penetration testing notification or approval requirements. Company is not responsible for any violations of third-party terms arising from Customer’s failure to obtain required approvals.

5. CREDENTIAL AND DATA HANDLING

If the Service discovers credentials, personal data, or other sensitive information during testing, Customer shall: (i) treat such information as Confidential Information under the MSA; (ii) use such information solely for the purpose of validating and remediating the vulnerability; (iii) not retain, distribute, or exploit such information for any other purpose; and (iv) promptly notify affected parties and take appropriate remediation steps as required by applicable law.

6. COMPLIANCE AND REPORTING

Customer shall promptly report to Company any suspected violations of this AUP by Customer’s Authorized Users, as well as any unauthorized access to or use of the Service. Customer shall cooperate with Company in investigating any AUP violations.

7. ENFORCEMENT

Company reserves the right, in its sole discretion, to: (i) investigate any suspected violation of this AUP; (ii) suspend or terminate Customer’s access to the Service for any violation; (iii) report any activity that Company believes violates applicable law to appropriate law enforcement authorities; and (iv) cooperate with law enforcement authorities in investigating and prosecuting such violations.

8. MODIFICATIONS

Company reserves the right to modify this AUP at any time. Material changes will be communicated to Customer via email or through the Platform. Continued use of the Service after changes take effect constitutes acceptance of the modified AUP.

9. CONTACT

Questions about this AUP should be directed to: [email protected]