Terms of Service for Obsekure
1. Acceptance of Terms
By accessing or using Obsekure ("Service"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree, you may not use the Service. The Service is provided by Obsekure ("we," "us," or "our").
2. Description of Services
Obsekure provides the following SaaS tools:
- Qualitative Risk Assessments: Enables users to register business processes, assets, vulnerabilities, and risks; qualify inherent, net, and residual risks; and generate AI-driven risk scenarios.
- Quantitative Risk Assessments: Quantifies potential losses and risk frequency using Monte Carlo simulations.
- Cybersecurity Assessments: Evaluates organizational maturity and compliance with frameworks.
- Incident Register: Supports CISOs in documenting incidents and their impacts on confidentiality, integrity, and availability (CIA).
All outputs are advisory and do not constitute professional cybersecurity, legal, or financial advice.
3. User Obligations
- Account Registration: Provide accurate information and safeguard credentials.
- Compliance: Use the Service lawfully and in accordance with your organization’s policies.
- Prohibited Uses: Reverse engineering, disrupting the Service, or inputting unlawful/harmful data.
- Incident Data: You warrant that all incident/CIA data entered complies with applicable privacy laws.
4. Payment Terms
- Subscription fees, billing cycles, and payment methods are outlined in your Order Form.
- Fees are non-refundable unless required by law.
- We may suspend access for overdue payments.
5. Intellectual Property
- Ownership: Obsekure retains all rights to the Service, including AI models, software, and content.
- User Data: You retain ownership of data you input. You grant us a non-exclusive license to process data to provide the Service.
6. Disclaimers
THE SERVICE IS PROVIDED "AS IS." WE DISCLAIM ALL WARRANTIES, INCLUDING FITNESS FOR A PARTICULAR PURPOSE. WE DO NOT GUARANTEE:
- Accuracy of AI-generated risk scenarios.
- Compliance with NIST, ISO, or CIS standards.
- Immunity from cybersecurity incidents.
7. Limitation of Liability
WE ARE NOT LIABLE FOR:
- Indirect, incidental, or consequential damages (e.g., lost profits, data loss).
- Risk assessment outcomes or actions taken based on the Service.
- Total liability is capped at the fees paid in the prior 12 months.
8. Termination
We may terminate access for breaches of these Terms. Users may export data prior to termination.
9. Changes to Terms
We may update these Terms. Continued use constitutes acceptance.
Privacy Policy for Obsekure
1. Information We Collect
- Account Data: Name, email, payment details.
- Risk/Cybersecurity Data: Business processes, assets, vulnerabilities, incidents, CIA impact assessments.
- Usage Data: IP addresses, logs, cookies.
2. How We Use Information
- Provide, improve, and personalize the Service.
- Train AI models (anonymized and aggregated where possible).
- Comply with legal obligations.
3. Data Sharing
We may share data with:
- Third-Party Providers: Hosting (e.g., AWS, Azure), payment processors.
- Legal Authorities: If required by law.
- Affiliates/Partners: For service delivery.
4. Data Security
We implement industry-standard measures (e.g., encryption, access controls) to protect data.
5. Your Rights
- Access, correct, or delete personal data.
- Opt out of marketing communications.
- Withdraw consent (where applicable).
6. Retention
We retain data as long as necessary to provide the Service or comply with legal obligations.
7. International Transfers
Data may be transferred globally, with safeguards (e.g., GDPR Standard Contractual Clauses).
8. Children’s Privacy
The Service is not intended for users under 18.
9. Updates
We may update this policy. Material changes will be notified via email or in-app alerts.