Legal
Acceptable use policy
Elenchia is built for authorised mobile application security testing and quality assurance. This page states plainly what that permits and what it excludes.
Last updated: 19 July 2026
The core condition
You may use Elenchia only against applications and services that you own, or for which you hold written authorisation from the owner to conduct security testing. This condition is not waivable, and it applies regardless of how the testing is described.
Permitted use
- Security assessment of applications you publish
- Penetration testing and red-team work conducted under a written engagement with the application owner
- Regulatory or compliance testing you are contracted to perform
- Functional, regression and compatibility testing on real device behaviour
- Creating test accounts within an application you own or are authorised to assess, where the application's own terms permit it
Prohibited use
The platform includes capabilities — device identity control, per-device network egress, account creation, SMS verification handling — that are necessary for legitimate testing and open to misuse. The following are prohibited without exception.
- Testing, probing or automating any application you do not own and are not authorised in writing to assess
- Creating accounts at scale on third-party services to evade their limits, pricing, eligibility rules or bans
- Circumventing fraud controls, promotional-abuse controls, or identity verification on services that are not yours
- Any use that violates the target application's terms of service
- Denial of service, load generation against third parties, or mass targeting
- Accessing, extracting or retaining personal data belonging to real users other than as required by an authorised engagement
- Any activity unlawful in your jurisdiction or the jurisdiction of the target
Evidence of authorisation
We may ask you to evidence your authorisation to test a given application at any time, including before onboarding. During early access we ask for it up front, as a matter of course.
Enforcement
Accounts found in breach are suspended. Where a breach involves unlawful activity we will cooperate with lawful requests from the affected party and from relevant authorities.
Reporting misuse
If you believe Elenchia is being used against your application without your authorisation, contact hello@elenchia.com and we will investigate.