1. Definitions and Interpretations
1.1 Services: Refers to all products and functions provided by us through our official website, console, and API, and mobile application (APP), including attack surface intelligence, threat data, vulnerability information, sandbox analysis, report output, and monitoring and alerting.
1.2 User / You: Refers to an individual or entity (enterprise, government, organization) that registers for, accesses, or uses the Services via any platform including website, console, API, and APP.
1.3 Output Content: Refers to all data generated by the Services, including reports, indicators, IOCs (Indicators of Compromise), TIPs (Threat Intelligence Platforms), vulnerability data, attack surface views, and analysis results.
1.4 Confidential Information: Refers to our unpublicized product logic, interfaces, pricing, customer lists, Output Content, technical architecture, documents, and other related information.
1.5 Subscription Period: Refers to the period during which the User is authorized to use the Services after paying the fees, subject to the relevant order/contract.
1.6 API Quota: Refers to the limits on the number of calls, rate, and data volume for the User to access the Services through the API.
1.7 Acceptable Use Policy (AUP): Refers to the legal and compliant use requirements stipulated in this Agreement.
2. Authorization for Use of Services
2.1 We grant the User a non-exclusive, non-transferable, and non-sublicensable limited license to use the Services solely for the User’s internal security purposes.
2.2 The free version is limited to non-commercial internal security purposes; commercial use must be subject to the purchase of an enterprise subscription.
2.3 The account is limited to real name use within the authorized scope, and sharing or lending the account to any third party is prohibited.
2.4 The use of the API must comply with the API Quota and rate limits; bulk crawling, data aggregation, and secondary distribution are prohibited.
3. Prohibited Conduct
The User shall not (and shall not allow any third party to):
3.1 Engage in reverse engineering, decomplication, cracking, or circumvention of the Service restrictions.
3.2 Copy, modify, distribute, sell, sublet, or sublicense the Services or Output Content.
3.3 Use the Services for competitor development, machine learning/AI training, benchmark testing, or public evaluation.
3.4 Engage in automated crawling, bulk scraping, data mining, or screen scraping.
3.5 Use the Services for non-security purposes such as credit evaluation, marketing advertising, user profiling, or customer acquisition and retention.
3.6 Use the Services for illegal activities, hacking activities, extortion, phishing, DDoS attacks, or dissemination of malicious code.
3.7 Conduct targeted collection based on protected characteristics such as race, gender, religion, or nationality.
3.8 Violate laws related to export controls, economic sanctions, data privacy, and cyber security.
3.9 Publicly disclose, publish, or upload the Output Content to public platforms without our prior permission.
3.10 Impair or interfere with the Services or the network security of the servers in any manner.
3.11 Conduct verification of defects or vulnerabilities, or use such defects or vulnerabilities to attack, damage, or hinder the normal operation of the Services. If the User discovers any defects or security vulnerabilities in the Services, the User shall immediately notify us and shall not disclose such defects or security vulnerabilities to the outside world.
4. Intellectual Property Rights
4.1 The Services, Output Content, documents, trademarks, and software are all our exclusive intellectual property rights, protected by copyright law, trade secret law, and trademark law.
4.2 The User retains ownership of the data uploaded by the User itself; the User grants us a global, perpetual, irrevocable, and free license to use such data for providing, optimizing, and operating the Services.
4.3 We may use User feedback (suggestions, requirements, questions) free of charge without additional compensation.
5. Account and Security
5.1 The User is responsible for the security of the account and password and shall be liable for all activities conducted under the account.
5.2 If the User discovers any account abnormality, leakage, or unauthorized use, the User shall immediately notify us.
5.3 We have the right to monitor abnormal use, bulk calls, and unauthorized access, and take restrictive/suspension measures.
5.4 We have the right to suspend/terminate the Services if the subscription expires, fees are overdue, or the User violates this Agreement.
6. Suspension and Termination
6.1 We may immediately suspend/terminate the Services if the User commits a material breach of this Agreement, engages in illegal activities, or violates the AUP.
6.2 The Services will be automatically suspended if the subscription expires without renewal.
6.3 Upon termination:
All usage rights shall immediately become invalid;
The User shall delete all local copies, backups, and exported data;
We shall have no obligation to retain or export the User’s data.
6.4 The following clauses shall survive the termination of this Agreement: Definitions and Interpretations, Intellectual Property Rights, Confidentiality Obligations, Disclaimer, Limitation of Liability, Indemnification, and Governing Law and Dispute Resolution.
7. Confidentiality Obligations
7.1 The User shall strictly keep our Confidential Information confidential, and such information shall only be known to the necessary internal personnel of the User.
7.2 The confidentiality period shall be the period of use and [3] years after the termination of this Agreement.
7.3 If the User is required to disclose the Confidential Information by law, the User shall notify us in advance and cooperate with us to seek confidential treatment.
8. Disclaimer
8.1 The Services are provided "as is" without any warranty of uninterrupted, error-free, or completely accurate operation.
8.2 We do not guarantee the detection of all malicious software, vulnerabilities, or threats.
8.3 We shall not be liable for data delay, data loss, business interruption, loss of profits, or indirect damages.
8.4 Third-party links/data shall be the responsibility of the relevant third party, and we make no warranties in respect thereof.
9. Limitation of Liability
9.1 Our total cumulative liability shall not exceed the total fees paid by the User to us in the past 12 months.
9.2 We shall not be liable for: data loss, loss of goodwill, business interruption, punitive damages, or indirect/consequential damages.
9.3 To the extent that the applicable law does not allow the exclusion of liability, such liability shall be limited to the maximum extent permitted by law.
10. User Indemnification
The User agrees to indemnify us against all losses, claims, and expenses (including attorney fees) arising from the following matters:
10.1 The User’s breach of this Agreement;
10.2 The illegality or infringement of the User’s data;
10.3 Damages caused to third parties by the User’s use of the Services;
10.4 The User’s illegal use of the Services.
11. Compliance Requirements
11.1 The User undertakes to comply with Singapore’s Personal Data Protection Act (PDPA), laws related to cyber security and computer abuse, and applicable export control and economic sanction laws.
11.2 The User shall not provide the Services/data to sanctioned countries, entities, or individuals.
11.3 The User shall not use the Services for purposes related to the military, nuclear, biological, or chemical weapons, drones, missiles, or terrorist activities.
11.4 The Services may contain malicious code samples; the User shall have the ability to handle such samples securely and shall not use them for malicious purposes.
12. Force Majeure
Neither party shall be liable for any failure or delay in performing its obligations under this Agreement due to force majeure, including but not limited to earthquakes, fires, epidemics, wars, policy restrictions, and power or communication failures. Both parties shall make every reasonable effort to resume the performance of their obligations as soon as possible.
13. Governing Law and Dispute Resolution
13.1 This Agreement shall be governed by the laws of Singapore, excluding its conflict of laws rules.
13.2 Any dispute arising out of or in connection with this Agreement shall be finally submitted to the Singapore International Arbitration Centre (SIAC) for arbitration in accordance with its rules, with [one] arbitrator, the seat of arbitration being Singapore, and the language of arbitration being English/Chinese.
13.3 The arbitral award shall be final and binding on both parties.
14. General Provisions
14.1 We have the right to update this Agreement; continued use of the Services via any platform including APP after the update shall be deemed acceptance of the new version.
14.2 If any clause of this Agreement is deemed invalid, illegal, or unenforceable, the validity, legality, and enforceability of the remaining clauses shall not be affected.
14.3 The failure to exercise any right under this Agreement shall not be deemed a waiver of such right.
14.4 The User shall not assign any rights or obligations under this Agreement without our prior written consent.
14.5 Notices shall be given in the form of email, official website announcement, or in-platform message.
14.6 This Agreement constitutes the entire agreement between the parties and supersedes all prior oral or written communications between the parties.
15. Acceptable Use Policy (AUP)
The following uses are prohibited:
15.1 Any illegal, criminal, or hacking activities;
15.2 Discriminatory collection based on protected characteristics;
15.3 Causing personal/property damage, unauthorized access, or damage to infrastructure;
15.4 Fraud, theft of financial/personal sensitive information;
15.5 Harassment, tracking, extortion, pornography, or infringement;
15.6 Infringement of intellectual property rights such as copyrights, trademarks, and trade secrets.
If you have any doubts as to whether your use of the Service complies with these Terms, or security vulnerability of the Service, please contact us at: contactus@threatbook.io