The binding Master Subscription Agreement is with counsel and is available on request — [email protected] . What follows describes how the service actually operates.
This is the one rule that matters most. Umbra sends real traffic to real systems. You must own the target, or hold documented permission from whoever does. Umbra verifies domain ownership before it will actively scan, and IP ranges require explicit authorisation — but that check protects us both, it does not transfer responsibility. Scanning a system you are not entitled to test may be a criminal offence in your jurisdiction.
A subscription grants a monthly allowance of Audits (one complete AI penetration test of one application, including up to ten related backends) and Checks (one AI verification — proving a service is exploitable, or that a reported CVE is real), plus continuous monitoring of up to your plan's asset limit.
Allowances reset each billing month and do not roll over. Re-testing a finding Umbra already reported to you is always free and never counted. If an Audit fails before producing anything, it is returned to you automatically.
Paid through Paddle, our Merchant of Record. Monthly or annual, cancel at any time; cancellation takes effect at the end of the paid period. Annual is billed as ten months for twelve. Enterprise is contracted directly and invoiced.
Umbra finds and proves what it can reach and test. No security tool finds every vulnerability, and a clean result is not a guarantee that a system is secure. Findings are evidence for your judgement, not a certification. You remain responsible for your own systems and for acting on what we report.
Do not use Umbra to attack systems you are not authorised to test, to resell scanning capacity without an agreement, or to attempt to circumvent the scope and authorisation controls in the product. Accounts doing any of these are suspended.
Last reviewed: 4 September 2026.