// LEGAL
Terms of Service
These terms govern use of the Veyra Security website and platform. Customer engagements are additionally governed by a signed service agreement and an authorization agreement.
1. Agreement
By using this website or the Veyra platform you agree to these terms. If you use Veyra on behalf of a company, you confirm you have authority to bind that company. Where a signed service agreement exists between Veyra and your company, that agreement takes precedence over these terms in the event of conflict.
2. The service
Veyra provides continuous application security analysis of assets that a customer has explicitly authorized. The service identifies potential security vulnerabilities, correlates them, scores them, and provides remediation guidance.
3. Authorization — the critical term
This is the most important obligation in these terms, for both parties.
- You must own or be contractually authorized to permit security testing of every asset you submit to Veyra. Submitting an asset you are not entitled to have tested is a material breach, and may be unlawful in your jurisdiction.
- Testing does not begin until a written authorization agreement identifies the assets, the environment restrictions, the excluded endpoints, the rate limits, and the authorizing individual.
- You must keep that authorization accurate. If an asset leaves your control, remove it from scope immediately.
- Veyra will not test any asset outside the authorized scope, and will not perform destructive testing, denial of service, or social engineering under any circumstances.
4. Acceptable use
You agree not to use Veyra to test systems you are not authorized to test; to attempt to access another customer's data; to reverse engineer, resell, or provide the service to third parties without a written agreement permitting it; to interfere with the platform's operation; or to use output to attack any system.
5. Your responsibilities
You are responsible for the accuracy of the scope you define, for maintaining the security of your accounts and credentials, for deciding which findings to act on and how, and for testing changes you make in response to findings before deploying them.
6. What Veyra does not warrant
Read this section carefully, because it describes a real and unavoidable limitation of any security product.
- Veyra does not and cannot guarantee that it will identify every vulnerability in your systems. No security tool or service can. A clean assessment means Veyra found nothing using the techniques it applies across the scope you authorized. It does not mean your application is secure.
- A Veyra Security Score represents observed posture across monitored assets. It is not a guarantee of the absence of vulnerabilities and must not be presented to third parties as one.
- Veyra is not a penetration test, a compliance audit, or a certification, and does not issue certifications of any kind.
- The service is provided "as is" to the fullest extent permitted by law, without warranties of merchantability or fitness for a particular purpose.
7. Limitation of liability
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, or consequential damages, or for lost profits or lost data. Veyra's total aggregate liability arising from the service is limited to the fees you paid in the twelve months preceding the claim.
Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot lawfully be limited.
8. Intellectual property
You retain all rights in your source code, systems, and data. Veyra receives only the limited licence necessary to perform the analysis you have requested. Veyra retains all rights in the platform, its methodology, and its documentation. Reports generated for you are yours to use and share.
Veyra may use aggregated, anonymized statistics derived from assessments to improve the service and to publish general research. Such statistics will never identify you, your company, or any specific finding in your systems.
9. Confidentiality
Each party will protect the other's confidential information with at least reasonable care and will not disclose it except to personnel and subprocessors who need it and are bound by equivalent obligations. Your source code, findings, and reports are your confidential information.
10. Fees and billing
Subscription fees are billed monthly or annually in advance through Stripe. Assessment fees are billed on engagement. Monthly subscriptions may be cancelled at any time and end at the close of the current billing period; annual subscriptions run to the end of the term. Fees already paid are non-refundable except where required by law. We will give at least 30 days' notice before any price change affecting your renewal.
11. Termination
You may terminate at any time by cancelling in the dashboard and revoking Veyra's access to your repositories. Veyra may suspend or terminate access for material breach — in particular a breach of section 3 — for non-payment, or if required by law. On termination you may export your findings and reports, and may request deletion as described in the Trust Center.
12. Changes to these terms
We may update these terms. Material changes will be notified to customers by email at least 30 days before taking effect. Continuing to use the service after that date constitutes acceptance.
13. Governing law
These terms are governed by the laws of the State of Delaware, United States, without regard to conflict of law principles. The parties submit to the exclusive jurisdiction of the courts of that state, except that either party may seek injunctive relief in any competent court to protect its confidential information or intellectual property.
14. Contact
Questions about these terms: hello@veyra.example