Terms of Service
These terms govern your use of Crucible and this website, provided by BMC Operations LLC, a Limited Liability Company organised in Delaware, United States.
These are template terms and have not been reviewed by counsel. They are published so you can see our intent, and so that diligence has something concrete to read. Before relying on them commercially, have a lawyer review them against your actual contracting posture.
1. Acceptance
By using Crucible or this site you agree to these terms and to the Responsible Use Policy, which is incorporated by reference. If you are agreeing on behalf of an organisation, you confirm you have authority to bind it.
2. Authorisation is a condition of use
Crucible performs adversarial testing against AI systems. You may use it only against systems you own or are explicitly authorised in writing to test. Breach of this condition terminates your rights under these terms immediately and may be unlawful. See the Responsible Use Policy for detail.
3. Licence
Subject to these terms, BMC Operations LLC grants you a non-exclusive, non-transferable, revocable licence to use Crucible for its intended purpose. Open-source components are governed by their own licences, which prevail over this section where they conflict.
4. Your responsibilities
- Obtaining and maintaining authorisation for everything you test.
- The security of any API keys you configure, and any charges they incur with third-party providers.
- Choosing campaign budgets appropriate to the target, including on production systems.
- Triaging, disclosing and remediating what you find.
- Rotating any canary value that appears in a finding.
5. What Crucible does not promise
Absence of a proven breach is not proof of security. A campaign tests the objectives it ran, within the budget it was given, against the exact endpoint and model version present at the time. It cannot establish that no vulnerability exists.
Control mappings to the EU AI Act, NIST AI RMF, OWASP and ISO/IEC 42001 are engineering judgement offered to assist a conformity assessment. They are not legal advice, do not constitute certification, and do not transfer responsibility. A qualified assessor remains accountable for any determination.
6. Third-party services
Crucible can route model traffic through providers you configure. Your use of those providers is governed by your agreement with them, you are responsible for their charges, and we are not liable for their acts or omissions.
7. Disclaimer of warranties
Crucible is provided “as is”, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that it will be uninterrupted, error-free, or that it will identify every vulnerability in a tested system.
8. Limitation of liability
To the maximum extent permitted by law, BMC Operations LLC is not liable for any indirect, incidental, consequential, special or punitive damages, nor for lost profits, revenue, data or goodwill, arising from use of Crucible. Our aggregate liability is limited to the greater of the amounts you paid us in the twelve months preceding the claim, or USD 100.
This includes damage arising from running campaigns against your own systems. Adversarial testing sends hostile traffic by design; choose your environment and budgets accordingly.
9. Indemnity
You will indemnify BMC Operations LLC against claims arising from your use of Crucible, including any claim that you tested a system without authorisation.
10. Changes
We may update these terms. Material changes will be reflected in the “last updated” date below, and continued use after a change constitutes acceptance.
11. Governing law
These terms are governed by the laws of the State of Delaware, United States, without regard to conflict of law principles.
12. Contact
Last updated 2026-10-07. These documents are published by BMC Operations LLC and are provided for transparency. They are not legal advice.