Legal
Terms of Service
The rules that apply when an organisation uses the 0DaySecure platform — what we owe you, what you warrant to us, and what happens when either side gets it wrong.
- Last updated
- 9 September 2026
- Status
- Draft template
Template — not legal advice
This terms of service is an unreviewed draft template. No lawyer has looked at it.
It was written as a starting point for the 0DaySecure team, not as a binding document. It has to be reviewed by qualified counsel in the relevant jurisdictions and rewritten to match what the company actually does before the site goes live. Every bracketed placeholder needs a real value, and every statement of practice needs to be checked against reality.
The liability cap, the indemnities and the governing law clause are commercial decisions, not drafting details. They are placeholders here. Nothing on this page has been negotiated or approved.
Do not rely on this document. Do not publish it as-is.
Section 1Agreement and acceptance
These terms are a contract between [COMPANY LEGAL NAME] (“0DaySecure”, “we”, “us”) and the organisation named on the Order Form (“Customer”, “you”). They apply when you sign an Order Form, accept them electronically, or use the Service.
If you are agreeing on behalf of an organisation, you confirm you have authority to bind it. If you do not have that authority, do not use the Service.
Where an Order Form, a data processing agreement or a separately negotiated master agreement conflicts with these terms, that document takes precedence over these terms to the extent of the conflict.
Section 2Definitions
- Agreement — these terms, the Order Form, and any document either expressly incorporates.
- Service — the 0DaySecure platform and its modules: dark web monitoring, attack surface management and brand protection, together with any managed takedown work we agree to perform.
- Scope — the domains, subdomains, IP addresses and ranges, autonomous system numbers, brand names, trade marks, mobile application identifiers, social handles and other identifiers you designate for monitoring.
- Customer Data — data you or your Users upload, enter or configure, including Scope definitions, user records, integration settings and triage decisions.
- Intelligence Data — material we collect from external sources in relation to your Scope, and the metadata we derive from it.
- Findings — the individual, prioritised items we present to you in the Service, each assembled from Intelligence Data.
- User — an individual you authorise to access the Service under your subscription.
- Takedown Action — a request or complaint we submit to a registrar, host, platform, app store or other intermediary on your behalf, asking for infringing or malicious content to be removed or suspended.
- Subscription Term — the period stated on the Order Form, and any renewal of it.
Section 3The service and its availability
During the Subscription Term we will make the Service available to you for your internal business purposes, in accordance with the Agreement and the module entitlements on your Order Form.
We may change the Service. Features get added, refined and occasionally retired. We will not materially reduce the core functionality of a module you have paid for during a Subscription Term without giving you notice and, where the reduction is material, the option to terminate the affected module and receive a pro-rated refund of prepaid fees.
Availability commitments, support response targets and any service credits are set out in [SERVICE LEVEL DOCUMENT REFERENCE]. Where no such document is attached to your Order Form, the Service is provided without a contractual uptime commitment.
We may suspend all or part of the Service where we reasonably believe suspension is necessary to protect the Service, our other customers, or a third party from imminent harm; where required by law; or where you are in material breach of section 6 or section 7. We will restore the Service as soon as the cause is resolved, and will tell you what happened.
Reviewer note
Decide whether an SLA will exist at launch. If it will, it needs its own document with a measurable definition of availability, exclusions, and a credit schedule. Do not publish an uptime figure anywhere on the site until it can be measured and stood behind.
Section 4Accounts and access
You are responsible for your account. That means keeping credentials confidential, keeping your list of Users accurate, removing access promptly when someone leaves, and everything done through your account whether you authorised it or not.
- Accounts are for named individuals. Do not share a login between people or create a shared generic account for a team.
- You must not exceed the number of Users or the Scope volume on your Order Form without agreeing an adjustment with us.
- Where single sign-on is configured, you remain responsible for the identity provider, its group mappings and its deprovisioning.
- Tell us promptly at security@0daysecure.com if you suspect unauthorised access to your tenant.
Section 5Your obligations
You agree to:
- keep your Scope accurate, and remove identifiers you no longer own or control;
- use Findings for your own security, fraud prevention and brand protection purposes, and not resell or redistribute them as an intelligence product;
- comply with all laws applicable to your use of the Service, including data protection, computer misuse and export control laws;
- give us the information and cooperation we reasonably need to deliver the Service, including a technical contact for scope validation and, for Takedown Actions, evidence of the rights you are asserting;
- treat Findings as confidential, and handle any personal data they contain — including credential material — in line with your own legal obligations.
Section 6Authorisation to scan
This clause matters more than any other in this agreement. The attack surface management module actively queries systems on the internet. It must only ever be pointed at systems you are entitled to have examined.
6.1 You declare the Scope
You define the Scope, and only you can change it. We do not add identifiers to your Scope on our own initiative. Where our discovery suggests an asset is probably yours — a subdomain, a cloud tenancy, a certificate, an IP block — we present it to you as a candidate and wait for you to confirm or reject it before we treat it as in Scope.
6.2 Your warranty of authority
You represent and warrant, on each occasion you add an identifier to the Scope and continuously thereafter, that for every identifier in the Scope you either:
- own or lawfully control the asset it identifies; or
- hold current written authorisation from the person who does, sufficient to permit the assessment activity described in clause 6.4, and you will produce that authorisation to us on request.
You further warrant that the Scope does not include any asset belonging to a third party for which you lack that authorisation, and that adding it does not breach any agreement you have with that third party.
6.3 Shared and third-party infrastructure
Assets you use but do not own — cloud services, SaaS applications, managed hosting, CDNs, payment gateways, subsidiaries you do not fully control — are frequently governed by the provider’s own acceptable use or testing policy. Contractual authority over your own tenancy is not the same as the provider’s permission to have its infrastructure examined. Obtaining that permission, where it is needed, is your responsibility.
We may decline to include, or may remove, any identifier where we cannot satisfy ourselves that authorisation exists, or where a provider policy or a legal requirement prevents collection. We do not have to explain a refusal in detail, and a refusal is not a breach of this agreement by us.
6.4 What our assessment does and does not do
Within the Scope, our collection is designed to be observational rather than intrusive. We:
- resolve DNS, enumerate subdomains from public sources, read certificate transparency logs and registration data;
- connect to internet-facing services to identify what is running — banners, headers, TLS configuration, exposed paths — at rate-limited volumes;
- fetch publicly reachable content in order to fingerprint software and identify exposures.
We do not, as part of the Service:
- attempt to exploit a vulnerability, escalate privilege, or move laterally;
- attempt to authenticate to your systems, or test credential material we have found against any live service, yours or anyone else’s;
- conduct denial-of-service testing, password spraying, credential stuffing or brute force;
- modify, delete or exfiltrate data from a system in Scope.
The Service is not a penetration test and is not a substitute for one. [ENGINEERING TO CONFIRM EACH BULLET MATCHES THE SHIPPED SCANNER]
6.5 Withdrawing Scope
You may remove any identifier from the Scope at any time through the Service or by written notice. We will cease active collection against a removed identifier within [N] business days. Findings already generated remain in your tenant until deleted under section 13.
6.6 If the warranty turns out to be wrong
If we receive a credible complaint that an identifier in your Scope is not yours and not authorised, we may remove it immediately and suspend collection pending investigation. Your indemnity under section 16 covers claims arising from Scope you were not entitled to declare. Repeated or knowing breach of this section is a material breach for which we may terminate without a cure period.
Reviewer note
Counsel should review this clause against computer misuse legislation in every jurisdiction where scanning targets may sit — not only where the customer or 0DaySecure is established. Also consider whether an explicit signed scope authorisation form should be a condition of onboarding rather than a contractual warranty alone.
Section 7Acceptable use
You must not use the Service to:
- monitor, profile or investigate a person or organisation for a purpose unconnected with protecting your own organisation — including surveillance of employees beyond what your local law permits, of competitors, of journalists or of activists;
- gather intelligence for offensive operations, or to identify targets for attack;
- use credential material obtained through the Service to access any account or system, including your own users’ accounts, other than through your own authorised password-reset and incident-response processes;
- resell, sublicense, syndicate or publish Intelligence Data or Findings as a product or feed;
- reverse engineer the Service, probe it for vulnerabilities outside our disclosure programme, or circumvent rate limits, entitlements or tenant boundaries;
- submit a Takedown Action you know to be unfounded, or use the takedown process to suppress lawful speech, criticism, comparative advertising or legitimate reporting;
- upload malware to the Service, other than a sample you are submitting to us for analysis through a channel we designate for that purpose;
- do anything unlawful, or anything that puts us in breach of a sanctions or export control regime.
We may investigate suspected breaches of this section, and we may report unlawful conduct to the authorities.
Section 8Intelligence data and completeness
We want to be straight about the limits of this product category, because a vendor that implies otherwise is misleading you.
- Coverage is never complete. Criminal marketplaces appear and vanish, forums go dark, sellers gate access, and some breaches never surface publicly at all. The absence of a Finding is not evidence that you are not exposed.
- Source material can be false. Actors exaggerate, recycle old dumps as new ones, and fabricate listings to build reputation. We label what we can about provenance and confidence, but a Finding reflects what a source claims, not a verified fact about your environment.
- Discovery is a best effort. Asset attribution relies on public records that are sometimes wrong or out of date. Expect both assets we miss and candidates that turn out not to be yours.
- Severity is a judgement. Prioritisation helps you triage. It is not a substitute for your own assessment of risk in your own environment.
- Timing is not guaranteed. We aim to surface a Finding quickly after it becomes observable to us, but we cannot commit to detecting anything within a fixed window unless your Order Form says so expressly.
You are responsible for the decisions you take on the basis of Findings, including whether to reset a credential, take a system offline, notify a regulator or notify an individual. We do not provide legal advice and a Finding is not a legal determination that a breach has occurred.
Section 9Takedown and enforcement requests
Where your Order Form includes managed takedowns, we will prepare and submit Takedown Actions against lookalike domains, phishing pages, counterfeit applications and impersonation accounts you instruct us to pursue.
- You authorise us to act as your agent for the limited purpose of submitting those requests, and you warrant that you hold the trade mark, copyright or other right you ask us to assert.
- We cannot guarantee an outcome. The decision belongs to the registrar, host or platform. Their criteria, queues and appetite vary, and some will refuse a request we think is well founded.
- We will tell you what we submitted, when, and what came back, and will escalate where an escalation route exists.
- Some matters need a lawyer rather than an abuse report — a UDRP complaint, a court order, a criminal referral. We will say so rather than filing something that will not work.
- You will indemnify us for claims arising from a Takedown Action submitted on your instruction, other than to the extent it results from our own error.
Section 10Fees and billing
- Fees, currency, billing frequency and payment terms are on the Order Form. Unless it says otherwise, fees are invoiced annually in advance and payable within [N] days of the invoice date.
- Fees exclude VAT, sales tax and other transaction taxes, which you pay in addition where they apply. If you are required to withhold tax, the amount payable to us is grossed up so that we receive what we invoiced.
- Fees are non-refundable except where these terms say otherwise. Removing Users or reducing Scope mid-term does not reduce the fee for the current term.
- If your usage exceeds the entitlements on your Order Form, we will contact you to agree an adjustment. We do not meter-bill you by surprise.
- Overdue amounts may accrue interest at [RATE], and we may suspend the Service after giving you [N] days written notice of non-payment.
- Unless the Order Form says otherwise, the Subscription Term renews automatically for successive periods of the same length. Either party may prevent renewal with written notice at least [N] days before the end of the current term. Renewal pricing may change on [N] days notice.
Section 11Confidentiality
Each party may receive information from the other that is marked confidential or that a reasonable person would understand to be confidential. Your Customer Data, your Findings and your Scope are your confidential information. Our non-public pricing, roadmap and technical documentation are ours.
The receiving party will use the other’s confidential information only to perform this Agreement, will protect it with at least reasonable care, and will limit access to people who need it and are bound by comparable obligations. These duties do not apply to information that is public through no fault of the recipient, was already known to it, or is independently developed.
If a party is compelled by law to disclose the other’s confidential information, it will give notice where it is lawfully able to, so the other party can seek protective measures.
Section 12Intellectual property
We own the Service, including its software, models, detection logic, interface and documentation, together with all intellectual property rights in them. Nothing in this Agreement transfers those rights to you. You get a non-exclusive, non-transferable right to use the Service during the Subscription Term for your internal business purposes.
You own your Customer Data. You grant us the rights we need to host and process it in order to provide the Service, and to collect and analyse Intelligence Data against your Scope.
As between us and you, Findings delivered to you are yours to use internally without restriction, subject to section 7.
We may use aggregated, de-identified statistics about how the Service is used to operate and improve it — for example, how long a class of scan takes, or how often a detection produces a false positive. We will not use your Customer Data, your Findings or the identifiers in your Scope to build or improve a product feature in a way that could identify you. We will not disclose your name as a customer without your written permission.
If you send us feedback we may act on it freely and without obligation, but we will not attribute it to you publicly without asking.
Section 13Term and termination
This Agreement runs for the Subscription Term. Either party may terminate it for material breach if the breach is not cured within [N] days of written notice describing it. Either party may terminate immediately if the other becomes insolvent or enters an equivalent process.
On termination or expiry:
- your right to access the Service ends;
- you may export your Findings and Customer Data during a window of [N] days after the end date;
- we will delete Customer Data, Intelligence Data and Findings associated with your tenant within [N] days after that window closes, except where we must retain something to comply with law, and except for backups which are overwritten on their ordinary cycle;
- you pay any fees accrued up to the end date, and we refund prepaid fees for the unused remainder of the term only where we are the party in breach.
Sections 8, 11, 12, 14, 15, 16, 17 and this section survive termination.
Section 14Disclaimers
Except as expressly stated in this Agreement, the Service is provided “as is”. To the maximum extent the law allows, we disclaim all other warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, non-infringement and any warranty arising from course of dealing.
In particular, we do not warrant that:
- the Service will find every exposure, credential leak, internet-facing asset or impersonation relating to you;
- Intelligence Data is accurate, complete, current or free of third-party fabrication;
- a Takedown Action will succeed;
- the Service will be uninterrupted, or free of errors or false positives;
- use of the Service will prevent a security incident, or satisfy any regulatory or contractual obligation you are under.
Some jurisdictions do not allow the exclusion of certain warranties, so parts of this section may not apply to you.
Section 15Limitation of liability
Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost goodwill or lost or corrupted data, however caused and regardless of the theory of liability, even if it was told such damages were possible.
Each party’s total aggregate liability arising out of or related to this Agreement is limited to [CAP — e.g. fees paid in the 12 months before the claim].
Nothing in this Agreement limits liability that cannot lawfully be limited, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for a party’s wilful misconduct. Nor does it limit your obligation to pay fees.
Reviewer note
The cap, whether there are super-caps for confidentiality or data protection breaches, and whether the exclusion of consequential loss is mutual are all commercial decisions. They need a decision from the business and a review by counsel — and they need to be consistent with whatever the insurance actually covers.
Section 16Indemnification
We will defend you against a third-party claim that the Service, used in accordance with this Agreement, infringes that third party’s intellectual property rights, and will pay damages finally awarded or agreed in settlement. This does not apply where the claim arises from your Customer Data, your Scope, your use of the Service in breach of this Agreement, or a modification you made.
You will defend us against a third-party claim arising from:
- an identifier in your Scope that you were not entitled to declare under section 6;
- a Takedown Action submitted on your instruction, except to the extent it results from our own error;
- your use of Findings or Intelligence Data in breach of section 7 or of applicable law;
- your Customer Data.
The indemnified party must give prompt notice of the claim, allow the indemnifying party to control the defence, and cooperate reasonably. No settlement that imposes an obligation on the indemnified party may be agreed without its consent.
Section 17Governing law and disputes
This Agreement, and any dispute arising out of it, is governed by the laws of [JURISDICTION], without regard to its conflict of laws rules. The courts of [JURISDICTION] have exclusive jurisdiction, and both parties submit to it.
Before starting proceedings, each party will escalate the dispute to a senior representative and attempt to resolve it in good faith for [N] days. Nothing in this section prevents either party from seeking urgent injunctive relief.
The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Reviewer note
[JURISDICTION] appears twice above and must be set to one place, consistent with where the company is incorporated and where its insurance responds. Decide separately whether to offer arbitration, whether to add a class-action waiver for US customers, and whether enterprise customers will be permitted to negotiate this clause.
Section 18Changes to these terms
We may update these terms. For changes that materially affect your rights or obligations, we will give you at least [N] days notice by email to your administrative contact and by a notice in the Service, and the change will take effect at your next renewal. Other changes take effect when we post them and update the “last updated” date.
If a material change is unacceptable to you, you may terminate the affected subscription before it takes effect and receive a pro-rated refund of prepaid fees for the unused remainder of the term.
Section 19General
- Assignment. Neither party may assign this Agreement without the other’s consent, except to a successor in a merger or sale of substantially all assets, on notice.
- Subcontractors. We may use subcontractors and sub-processors to deliver the Service, and remain responsible for their performance. Sub-processors are listed in our privacy policy.
- Force majeure. Neither party is liable for delay or failure caused by an event beyond its reasonable control, provided it tells the other party and works to mitigate.
- Notices. Notices to us go to [LEGAL NOTICES ADDRESS]. Notices to you go to the administrative contact on your Order Form.
- Severability. If a provision is unenforceable, the rest stands and the provision is read down to the minimum extent needed to make it enforceable.
- No waiver. Failure to enforce a provision is not a waiver of it.
- Independent parties. Nothing here creates a partnership, agency or employment relationship, except the limited agency in section 9.
- Entire agreement. The Agreement is the whole agreement between the parties on its subject matter and replaces earlier discussions. Terms in your purchase order do not apply unless we agree to them in writing.
Section 20Contact
Questions about these terms: sales@0daysecure.com. Support: support@0daysecure.com. Security matters, including vulnerability reports: security@0daysecure.com — see our responsible disclosure policy.
Need this in a signable form?
Order forms, data processing agreements and security reviews go through our team. Tell us what your procurement process needs and we will work to it.
- Enterprise terms negotiable
- DPA available for review
- Security questionnaires answered