Terms of Service
Last updated: 2026-09-21 · Effective: 2026-09-10
These Terms govern your access to and use of RealExploit (the "Service"), operated by KeyStone Labs (the "Operator", "we", "us", or "our"). Legal inquiries: legal@realexploit.io.
1. Acceptance of Terms
By creating an account, accessing the API, or otherwise using the Service, you represent that you are at least 18 years of age and agree to be bound by these Terms. If you are using the Service on behalf of an organization, you represent that you have authority to bind that organization, and "you" refers to that organization.
2. Description of Service
RealExploit aggregates publicly available threat-intelligence signals — including but not limited to the CISA Known Exploited Vulnerabilities (KEV) catalog, the NIST National Vulnerability Database (NVD), FIRST.org Exploit Prediction Scoring System (EPSS) scores, ExploitDB, the Metasploit Framework, ProjectDiscovery's Nuclei templates, and curated GitHub proof-of-concept indexes — and produces a single deterministic verdict per CVE for use in vulnerability prioritization workflows.
The Service is an informational data-aggregation product. It is not a security advisor, a penetration-testing tool, a vulnerability scanner, or a substitute for professional security consulting. Verdicts do not constitute investment, legal, or compliance advice.
3. Account Registration
You must provide accurate, current, and complete information during registration and keep it up to date. You are responsible for maintaining the confidentiality of your password, API keys, and session tokens, and for all activity that occurs under your account. Account credentials may not be shared with any third party. Notify us at security@realexploit.io immediately upon any suspected unauthorized access.
Telegram membership and activation codes are no longer required to use RealExploit.
4. Acceptable Use Policy
Your use of the Service must comply with this Acceptable Use Policy and with the Creem Buyer Terms, which apply to all transactions processed through Creem as Merchant of Record.
Permitted uses:
- Defensive vulnerability management and patch prioritization for systems you own or operate.
- Authorized security research and red-team assessments where you have explicit written authorization to test the target systems.
- Internal scanning, asset inventory, and risk reporting within your organization.
- Integration with SIEMs, ticketing systems, and SOAR platforms for legitimate security operations.
Prohibited uses. You must not, and must not permit any third party to:
- Resell, sublicense, or redistribute the Service's output, in whole or in part, without our prior written consent.
- Scrape, mirror, or otherwise systematically extract data from the Service beyond reasonable use of the documented API endpoints and within your tier's published quotas.
- Use the Service to weaponize CVE data against systems you do not own or do not have explicit written authorization to test.
- Reverse engineer, decompile, or attempt to derive the source code or scoring algorithm of the Service, except to the extent expressly permitted by applicable law notwithstanding this restriction.
- Use Service outputs to train, fine-tune, or otherwise build machine-learning models without an explicit written license from us.
- Engage in any activity that violates applicable law in any jurisdiction relevant to you, the target systems, or our infrastructure.
- Share, publish, or transfer API keys to any third party. API keys are personal to the issuing account.
- Interfere with or disrupt the integrity or performance of the Service, including by transmitting malware, conducting denial-of-service attacks, or attempting to bypass rate limits.
We may suspend or terminate accounts engaged in any prohibited activity, with or without prior notice, and may report illegal activity to competent authorities.
5. Subscription Tiers and Billing
The Service is offered on the following plans, with feature details on the Pricing page:
- 7-Day Pass — USD 4.99 once for 7 days of access and up to 20 distinct CVEs. Web only, 1 user, no API, webhooks or CSV uploads. No automatic renewal.
- Analyst — USD 24.99/month, up to 150 distinct CVEs per monthly billing period, 30 days of history and 1 user. Web only, no API, webhooks or CSV uploads.
- Pro — USD $99/month, single seat, full API access, and up to 3 personal customer webhooks.
- Team — USD $499/month, up to 3 seats with shared daily quota and organization-owned customer webhooks with no commercial plan count limit, subject to the published fair-use security controls.
- Enterprise — USD $1,499/month, up to 10 seats with per-seat daily quota and organization-owned customer webhooks with no commercial plan count limit, subject to the published fair-use security controls.
Bulk CSV and JSON limits are published on the Pricing page. Every batch must fit both its per-request limit and the applicable remaining quota; an oversized batch is rejected as a whole and is not partially processed. Original upload bytes are discarded after the supported CVE identifiers are normalized. Result-download access expires 30 days after completion. Each signed download link is limited to the shorter of five minutes and the remaining availability window. If account or job access is revoked after a link is issued, that already-issued bearer link may remain usable only until its short TTL expires; no new link is issued. Lifecycle cleanup then schedules removal of any remaining object. Job metadata and previews are retained for up to 90 days. Working rows for an asynchronous job are deleted when it completes, fails, or is cancelled; only a bounded preview remains with its metadata. CSV creation in either processing mode is subject to the published rolling 24-hour fair-use limit on persisted upload attempts; completed, cancelled, failed, and quota-rejected attempts remain part of that window, while an exact idempotent retry does not. Pro and Enterprise are scoped per user; Team shares the limit by organization. A separate rolling creation budget counts unique CVEs submitted to asynchronous jobs—150,000 per Team organization and 200,000 per Enterprise seat. Quota rejection, cancellation, or failure does not remove an attempt from that budget. This abuse-control budget is separate from any refundable lookup quota. Exact idempotent retries do not consume this creation budget. You are responsible for uploading only the supported CVE identifiers and for downloading any result you need before it expires.
Access begins after payment confirmation. A pass expires after 7 days; Analyst renews monthly until canceled. Reopening a CVE in the same paid period consumes no additional allowance. Invalid identifiers, missing CVEs and pending analyses do not consume allowance.
Payments are processed by Creem (Armitage Labs OÜ), acting as Merchant of Record. By purchasing a paid plan, you also accept Creem's Buyer Terms. Creem issues customer invoices and receipts as the legal seller of record and collects and remits applicable taxes. KeyStone Labs is our commercial brand; the purchased product is RealExploit. Creem may also appear on your bank or card statement.
Monthly subscriptions auto-renew at the end of each monthly billing cycle unless cancelled. You may cancel at any time from your account settings; cancellation takes effect at the end of the current billing period, and the Service remains available until that date.
Customer webhook integrations
Entitled plans may configure RealExploit to send signed CVE verdict events to an HTTPS endpoint that you control or are authorized to use. You are responsible for the destination, its security and availability, safeguarding the one-time signing secret, verifying each signature before processing, and making your receiver idempotent using the stable delivery identifier. You must not use webhook configuration to probe or access private networks, third-party systems without permission, or any destination prohibited by Section 4.
Delivery is at least once, not exactly once, and events may arrive out of order. Each automatic retry cycle is limited to approximately 24 hours, but we do not guarantee delivery time or successful receipt. We may pause, revoke, or delete an endpoint after entitlement loss, repeated failures, suspected abuse, security risk, or account/organization lifecycle changes. Rotation, revocation, and deletion can invalidate pending deliveries and remove the encrypted endpoint configuration from the active database. Historical storage and backups remain subject to the retention limits described in our Privacy Policy.
6. Service Availability
RealExploit uses protected HTTPS connections, access controls, and operational monitoring to support service continuity. We do not guarantee specific uptime percentages. The Service is provided AS IS without a Service Level Agreement except as expressly agreed in writing for Enterprise customers. Scheduled maintenance, third-party data-source outages, and network conditions outside our control may affect availability from time to time.
7. Intellectual Property
The Operator and its licensors retain all right, title, and interest in and to the Service, including the API, the scoring algorithm, the web interface, the documentation, trademarks, and logos. These Terms do not grant you any rights in our intellectual property except as explicitly stated.
Aggregated source data is sourced from public-domain or openly licensed catalogs, including CISA KEV (public domain), NIST NVD (United States Government work), FIRST.org EPSS (CC BY 4.0), ExploitDB (open source), the Metasploit Framework (BSD-3-clause, © Rapid7), and Nuclei templates (MIT, © ProjectDiscovery). Attribution and license notices are preserved in API responses and on the landing page.
You retain all rights to the queries, CVE lists, and inputs you submit. We grant you a non-exclusive, non-transferable, revocable license to use the Service and its outputs for the permitted uses set out in Section 4 for the duration of your paid access.
8. Disclaimers
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, OR UNINTERRUPTED OPERATION.
Verdicts are informational signals derived from public data and do not constitute professional security advice. You are solely responsible for your security decisions, patch management, configuration choices, and operational risk acceptance. KeyStone Labs makes no representation that the Service will identify all vulnerabilities relevant to your environment.
9. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE OPERATOR'S AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS SHALL NOT EXCEED THE GREATER OF (A) THE AMOUNTS PAID BY YOU FOR THE SERVICE IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) USD $100.
IN NO EVENT SHALL THE OPERATOR BE LIABLE FOR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING LOST PROFITS, LOST DATA, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Some jurisdictions do not allow the exclusion or limitation of certain warranties or damages; in those jurisdictions, the foregoing limitations apply to the maximum extent permitted by applicable law.
10. Indemnification
You agree to indemnify, defend, and hold harmless the Operator and its authorized contractors and agents from and against any third-party claims, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to your use of the Service in violation of these Terms or applicable law, your violation of any third-party right, or any content or data you submit through the Service.
11. Termination
You may terminate your account at any time from your dashboard settings or by emailing support@realexploit.io. Upon termination, your access to the Service is revoked and your personal data is anonymized in accordance with our Privacy Policy.
Ending or downgrading a subscription may revoke customer webhook endpoints, cancel pending deliveries, and remove their encrypted destination and signing secret from the active database. Historical encrypted copies and limited terminal metadata follow the retention disclosures in the Privacy Policy.
We may terminate or suspend your account immediately, without prior notice, for violation of the Acceptable Use Policy (Section 4), suspected fraud, abuse, non-payment, or activity that poses a security or legal risk to us or other users. We may also terminate any account, for any other reason, with at least 30 days' written notice. Sections that by their nature should survive termination (Intellectual Property, Disclaimers, Limitation of Liability, Indemnification, Governing Law) survive.
12. Force Majeure
Neither party shall be liable for failure to perform its obligations due to causes beyond its reasonable control, including but not limited to upstream service-provider outages, internet disruptions, natural disasters, government actions, cyberattacks, civil unrest, or pandemics. Affected obligations are suspended for the duration of the force-majeure event.
13. Modifications to Terms
We may update these Terms from time to time. For material changes, we will provide at least 30 days' advance notice via email to the address on your account and by posting the updated version on this page with a revised "Last updated" date. Continued use of the Service after the effective date of the updated Terms constitutes acceptance of the changes. If you do not accept the updated Terms, your sole remedy is to terminate your account before the effective date.
14. Governing Law and Disputes
These Terms are governed by Mexican law. This does not limit mandatory consumer protections or access to competent authorities and courts in your jurisdiction. Contact legal@realexploit.io to seek a resolution of a dispute. Purchases processed by Creem are also subject to Creem's Buyer Terms.
15. General Provisions
- Entire agreement. These Terms, together with the Privacy Policy, the Refund Policy, and any plan-specific addenda, constitute the entire agreement between you and KeyStone Labs.
- Severability. If any provision is held unenforceable, the remaining provisions remain in full force and effect.
- No waiver. Failure to enforce any right is not a waiver of that right.
- Assignment. You may not assign these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, or sale of assets.
- Notices. Notices to you may be sent to the email on your account; notices to us must be sent to legal@realexploit.io.
16. Contact
For questions about these Terms, contact support@realexploit.io. For legal or regulatory correspondence, use legal@realexploit.io.