Version: 1.1 Effective date: 2026-05-22 Provider: Seccops Cyber Security Technologies Inc. and its affiliates, operating under the Penaxtra brand (the "Provider")
These Terms of Service (the "Terms") form a binding legal agreement between the Provider and the customer organisation or individual ("Customer", "you") accessing or using the Penaxtra AI Security Posture Management platform and any associated software, agents, runtime gateway binaries, APIs, documentation, and websites (collectively, the "Service"). By creating an account, deploying an agent, calling the API, or otherwise using any part of the Service, you accept these Terms in their entirety. If you do not agree, do not use the Service.
1. Acceptance and binding effect
You enter into these Terms either on your own behalf as an individual or on behalf of the legal entity for which you are authorised to act. By accepting these Terms you represent and warrant that (a) you are at least eighteen years of age, (b) you have the legal authority to bind the Customer entity, (c) you have read and understood these Terms, the Privacy Policy, the Data Processing Addendum, the Acceptable Use Policy, and the Cookie Policy in full, and (d) the Customer entity is not a sanctioned person under any applicable economic-sanctions regime.
2. Account and workspace
A Customer subscription provisions one or more workspaces. Each workspace is logically isolated from every other workspace by database-level row-level security. The Customer designates an owner; the owner may invite additional members. The Customer is solely responsible for the acts and omissions of every member, integration, agent binary, API token, or third party operating under credentials issued to a workspace controlled by the Customer, regardless of whether the Customer authorised the act in question.
The Customer is solely responsible for safeguarding account credentials, API tokens, enrollment tokens, and signing keys. Any action performed under a workspace credential is conclusively attributed to the Customer.
3. Subscription, billing, and currency
The Service is offered in tiers at the prices and currencies published on the pricing page from time to time. Subscriptions renew automatically on the cadence stated at purchase unless the Customer cancels before the renewal date. Enterprise contracts may set bespoke renewal, billing, and notice terms; in case of conflict, the enterprise contract prevails.
All charges are exclusive of any applicable indirect taxes, value-added taxes, withholding taxes, or import duties, which are the Customer's responsibility. Card payments are processed by PCI DSS Level 1 certified processors; the Provider does not store cardholder data and is not responsible for the acts or omissions of those processors.
All fees are non-refundable except where refunds are mandated by applicable law.
4. Acceptable use
Use of the Service is at all times subject to the Acceptable Use Policy at /legal/aup, which is incorporated into these Terms by reference and forms a material part of them. Without limiting the Acceptable Use Policy, the Customer shall not, and shall not permit any third party to:
- Use the Service to scan, probe, or otherwise interact with any system the Customer does not own or for which the Customer does not have prior, written authorisation from the rightful owner.
- Use the Service to generate, distribute, store, or facilitate malware, ransomware, illegal content, child sexual abuse material, weaponised exploits, or material that infringes the rights of any third party.
- Reverse engineer, decompile, disassemble, or attempt to derive any source code, model weights, signing keys, or proprietary algorithms underlying the Service, except to the strict extent permitted by mandatory applicable law and only after written notice to the Provider.
- Resell, sublicense, time-share, white-label, or expose the Service or any output of the Service to third parties as a hosted offering without a separate written agreement signed by the Provider.
- Bypass, disable, or circumvent any technical limit, rate cap, security control, or licence enforcement mechanism of the Service.
- Use the Service in any way that violates applicable law, regulation, or order of a competent authority.
A breach of this clause is a material breach permitting the Provider to suspend or terminate the Customer's access without notice and without refund.
5. Intellectual property
The Provider retains all right, title, and interest in and to the Service, including all software, agent binaries, runtime gateway code, signed policy blobs, rule libraries, probe catalogues, judge configurations, machine-readable outputs, documentation, trademarks, and brand assets. No licence is granted to the Customer except the limited, non-exclusive, non-transferable right to access and use the Service during the subscription term in accordance with these Terms.
The Customer retains all right, title, and interest in and to the Customer's underlying source data submitted to the Service ("Customer Data"). The Customer grants the Provider a worldwide, royalty-free, non-exclusive licence to process Customer Data solely to operate, secure, monitor, support, debug, and improve the Service in accordance with the Data Processing Addendum.
Findings, scan reports, statistical aggregates, and anonymised model-behaviour data generated by the Service may be used by the Provider in aggregated, de-identified form to improve the Service and its underlying probes, judges, and rules. The Provider will not disclose Customer-identifying information in any public output.
6. Customer data
The Provider acts as a data processor for personal data processed within Customer Data, as described in the Data Processing Addendum at /legal/dpa. Upon termination of the subscription the Provider will return or delete Customer Data in accordance with the Data Processing Addendum, save where retention is required by applicable law or by a competent regulator.
The Customer is solely responsible for the lawfulness, accuracy, completeness, and consented basis of Customer Data, including any personal data, special-category data, sensitive commercial information, or trade secrets submitted to the Service. The Customer represents and warrants that it has obtained all required permissions and consents to submit Customer Data and to authorise the Provider to process it.
7. Confidentiality
Each party shall protect the other party's Confidential Information using at least the same degree of care it applies to its own confidential information of like sensitivity (and in no event less than reasonable care) and shall use Confidential Information solely to perform its obligations under these Terms. Confidential Information does not include information that is or becomes publicly available through no breach of these Terms, was lawfully known to the receiving party prior to disclosure without confidentiality obligations, was independently developed by the receiving party, or was received from a third party without confidentiality obligations.
8. NO WARRANTY; AS-IS, AS-AVAILABLE, WITH ALL FAULTS
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE IS PROVIDED "AS IS", "AS AVAILABLE", AND "WITH ALL FAULTS". THE PROVIDER MAKES NO REPRESENTATIONS, WARRANTIES, CONDITIONS, OR GUARANTEES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, COURSE-OF-DEALING, OR USAGE-OF-TRADE, AND HEREBY DISCLAIMS ALL OF THEM, INCLUDING WITHOUT LIMITATION:
- Warranties of merchantability, fitness for a particular purpose, satisfactory quality, non-infringement, accuracy, reliability, timeliness, completeness, security, privacy, freedom from defects, or uninterrupted operation.
- Any warranty that the Service will detect every vulnerability, prompt injection, model attack vector, data exfiltration path, supply-chain risk, agentic-tool misuse, regulatory non-conformity, or any other defect or attack within the Customer's environment, in any external endpoint scanned, or in any third-party model invoked.
- Any warranty that any finding, scan report, judge verdict, posture score, framework mapping, audit-evidence export, redaction, DLP block, or other output is correct, complete, current, free from false positives, free from false negatives, sufficient for regulatory compliance, or sufficient for any procurement, audit, or legal purpose.
- Any warranty that the runtime gateway agent, the model scanner agent, or any other downloadable binary is free from defects, malware, vulnerabilities, or compatibility issues with the Customer's infrastructure.
- Any warranty as to the availability, integrity, or behaviour of any third-party large language model provider, cloud provider, hosting provider, network provider, identity provider, or downstream service that the Service interoperates with.
The Customer expressly acknowledges that adversarial security testing is probabilistic; that large language models are non-deterministic and evolve continuously on the provider side; and that the absence of a finding does NOT constitute proof of the absence of a vulnerability. The Customer is solely responsible for all security decisions, configuration choices, regulatory determinations, deployment choices, and operational outcomes in its environment. The Customer assumes all risk arising from use of the Service.
9. LIMITATION OF LIABILITY; NO LIABILITY ACCEPTED
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, THE PROVIDER, ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, SUPPLIERS, SUBPROCESSORS, AND LICENSORS SHALL HAVE NO LIABILITY WHATSOEVER, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE, OR ANY OTHER LEGAL OR EQUITABLE THEORY, ARISING OUT OF OR IN CONNECTION WITH THESE TERMS, THE SERVICE, ITS USE, OR ITS NON-USE, FOR ANY OF THE FOLLOWING, REGARDLESS OF WHETHER THE PROVIDER WAS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND REGARDLESS OF WHETHER ANY REMEDY FAILS OF ITS ESSENTIAL PURPOSE:
- Lost profits, lost revenue, lost contracts, lost business opportunity, lost goodwill, or loss of anticipated savings.
- Loss of, corruption of, unauthorised access to, deletion of, or inability to access any data, including Customer Data, prompts, completions, scan transcripts, findings, audit logs, or backups.
- Costs of procurement of substitute goods, services, or technology.
- Regulatory fines, audit findings, certification denials, compliance penalties, contractual penalties payable by the Customer to its own customers, or any other regulatory or contractual consequence.
- Damage caused by, or arising from, any vulnerability that the Service failed to detect, mis-classified, classified as low severity, or otherwise did not flag in a manner that would have prevented the harm.
- Damage caused by a false-positive finding that the Customer acted upon.
- Damage caused by, or arising from, third-party services, including but not limited to large language model providers, cloud providers, hosting providers, network providers, identity providers, payment processors, and email providers.
- Damage caused by the Customer's own use, misuse, misconfiguration, or non-use of the Service.
- Indirect, incidental, special, consequential, exemplary, punitive, aggravated, or non-compensatory damages of any kind.
- Reputational harm, emotional distress, or non-pecuniary damages.
Where applicable law does not permit the wholesale exclusion of liability set out above, the Provider's total aggregate cumulative liability under these Terms, in the aggregate across all claims and all causes of action over the entire lifetime of the relationship between the parties, shall not exceed the LESSER of (a) the fees actually paid by the Customer to the Provider in the three (3) calendar months immediately preceding the event giving rise to the claim, or (b) EUR 100 (one hundred euros). This cap applies even where a remedy fails of its essential purpose.
Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited under applicable mandatory law (for example death or personal injury caused by negligence, or fraud or fraudulent misrepresentation). The exclusions and limitations in this clause are reasonable and have been negotiated in light of the price paid by the Customer for the Service. The parties agree that the allocation of risk reflected in these Terms is a fundamental element of the basis of the bargain between them.
10. Customer indemnification of the Provider
The Customer shall defend, indemnify, and hold harmless the Provider, its affiliates, officers, directors, employees, agents, and subprocessors from and against any and all claims, demands, suits, proceedings, losses, damages, fines, penalties, regulatory actions, settlements, costs, and expenses (including reasonable legal fees) arising out of or in connection with:
- The Customer's breach of these Terms, the Acceptable Use Policy, the Data Processing Addendum, or any applicable law.
- The Customer's use of, or inability to use, the Service in its environment.
- The Customer's failure to obtain any required authorisation before scanning, probing, or testing any system through the Service.
- Any allegation that Customer Data, or the Customer's use of the Service, infringes, misappropriates, or violates any third-party right.
- Any third-party claim that any finding, scan report, redaction, DLP block, or output of the Service caused, contributed to, or failed to prevent any harm.
The Customer's indemnification obligation is independent of, and survives, termination of these Terms.
11. No provider indemnification
The Provider does NOT indemnify the Customer for any third-party claim of any kind. Each party bears its own risk relative to third-party claims against it.
12. Force majeure
Neither party shall be liable for any failure or delay in performance to the extent caused by circumstances beyond its reasonable control, including acts of God, acts of governmental or regulatory authority, war, civil unrest, terrorism, cyber-attack, pandemic, embargo, fire, flood, earthquake, labour dispute, failure of telecommunications, internet, electrical, or third-party cloud-infrastructure services, or the act or omission of any large language model provider or other third party on whom the Service depends.
13. Termination
Either party may terminate these Terms upon thirty (30) days' prior written notice. The Provider may suspend or terminate access to the Service immediately and without notice for: (a) any actual or suspected breach of the Acceptable Use Policy; (b) non-payment beyond fifteen (15) days of the invoice due date; (c) any conduct that, in the Provider's reasonable judgement, exposes the Provider, its other customers, or its infrastructure to legal, security, or reputational risk; or (d) any requirement to do so under applicable law or under order of a competent authority.
Upon termination the Customer's right to access the Service ends immediately. Clauses 4 (Acceptable use), 5 (IP), 7 (Confidentiality), 8 (No warranty), 9 (Limitation of liability), 10 (Customer indemnification), 14 (Governing law), and 18 (Miscellaneous) survive termination.
14. Governing law and dispute resolution
These Terms are governed by, and shall be construed in accordance with, the substantive laws of Ireland, without regard to its conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Any dispute, controversy, or claim arising out of or in connection with these Terms, including any question regarding its existence, validity, or termination, shall be referred to and finally resolved by binding arbitration administered by the International Chamber of Commerce (ICC) under its Rules of Arbitration in force at the time of the request for arbitration. The seat of arbitration shall be Dublin, Ireland. The arbitration shall be conducted in the English language by a sole arbitrator. The Customer and the Provider waive any right to a trial by jury and any right to participate in any class, collective, or representative action or arbitration. The Provider may, at its sole discretion, seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property, confidential information, or signing keys without first resorting to arbitration.
15. Export, sanctions, and trade controls
The Service may be subject to export control, sanctions, and trade-control laws. The Customer represents and warrants that it is not located in, organised under the laws of, or ordinarily resident in any country or territory subject to comprehensive economic sanctions, and that it is not a sanctioned person or owned or controlled by a sanctioned person. The Customer shall not use the Service in violation of any export-control or sanctions law and shall not export, re-export, or transfer the Service or any related technology to any prohibited destination or person.
16. Assignment
The Customer may not assign or transfer these Terms, by operation of law or otherwise, without the Provider's prior written consent. The Provider may assign these Terms in whole or in part at any time, including in connection with a merger, acquisition, corporate reorganisation, or sale of all or substantially all of its assets, without consent or notice.
17. Changes to these Terms
The Provider may amend these Terms at any time. Material changes will be communicated at least thirty (30) days in advance by email or in-product notice. Non-material changes (clarifications, typographical corrections, updates to subprocessor lists) take effect on publication. Continued use of the Service after the effective date of any change constitutes acceptance of the amended Terms.
18. Miscellaneous
These Terms, together with the Privacy Policy, Data Processing Addendum, Acceptable Use Policy, Cookie Policy, and any order form or enterprise agreement executed by the parties, constitute the entire agreement between the parties relating to the Service and supersede all prior or contemporaneous communications, representations, and agreements relating to its subject matter. If any provision of these Terms is held to be unenforceable, that provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall remain in full force and effect. No waiver of any provision shall be effective unless in writing and signed by an authorised representative of the waiving party. The parties are independent contractors; nothing in these Terms creates an agency, partnership, joint venture, or employment relationship. Notices to the Provider must be sent to [email protected] and are deemed delivered on receipt.
19. Contact
Questions about these Terms: [email protected].