General Terms and Conditions
Hashfort, Simon Kramarič s.p.
1. General provisions
This document defines the terms of use for services provided by Simon Kramarič s.p., Partizanska pot, Črnomelj, Slovenia. By registering an account or using our services, the user agrees to these terms. We will notify you by email of any material change to these terms at least 30 days before it takes effect. If you do not accept a change, you may cancel your subscription before it takes effect.
2. Description of services
We provide two kinds of service. The first is Arturus, a subscription service for continuous vulnerability assessment, where the user registers an account, selects a package and installs an assessment agent on their machines. The second is consulting, training and related professional services, delivered per engagement on the basis of an offer. The assessment service is a structured vulnerability review with risk prioritisation, and is not a penetration test; a penetration test can be agreed as a separate engagement.
3. Registration and user account
Using the subscription service requires registering an account. You are responsible for the accuracy of the details you give at registration, for keeping your credentials safe, and for all activity on your account. You must notify us without delay if you suspect unauthorised access. The account may be used by you as the registering organisation and by the people you authorise.
4. Packages, billing and payment
The subscription is billed monthly in advance. Your package sets the maximum number of assets and the maximum number of scans per asset per month; these limits are visible in the portal. Unused scans do not carry over to the following month. Prices are stated without VAT. If payment is overdue we may, after prior notice, suspend access to the service; we will not delete your data during such a suspension.
5. Term, renewal and cancellation
The subscription runs for an indefinite period and renews automatically each month. You may cancel at any time with effect at the end of the current billing period; the service remains available for the period already paid for. We do not provide pro rata refunds for the current period. After the subscription ends you should remove the agent from your machines, and we handle your data according to the retention periods in the privacy policy.
6. Customer responsibility and authorisation to assess
The client warrants that it owns every machine, domain and service it submits for assessment, or that it holds the owner's explicit authorisation to commission an assessment of it. This applies in particular to the external scan, which is directed at a domain or a public address. Assessing a system without proper authorisation may be unlawful; the client takes full responsibility for the targets it submits and indemnifies us against third party claims arising from the assessment of an unauthorised target. The client also undertakes to provide correct and complete information and to cooperate during service delivery.
7. Acceptable use
The service may not be used to assess systems without authorisation, to attempt to break into or disrupt any system, to circumvent package limits, to resell the service without our written agreement, or in any way that breaks applicable law. We may terminate an account for a serious or repeated breach, and report the matter to the authorities.
8. Limitation of liability
We deliver our services according to best professional practice, but we cannot guarantee that every vulnerability will be found, nor that your systems are completely secure. An assessment shows the state of a system at the time it ran. We are not liable for indirect damages, loss of profit, loss of data, business damages, security incidents or the actions of third parties. Our total liability is limited to the amount the client paid for the service in the twelve months preceding the event giving rise to the claim. Nothing in these terms excludes liability that cannot be excluded by law, including liability for intent and gross negligence.
9. Confidentiality
All information, data and findings we access while delivering the services are treated as confidential. We undertake not to disclose them to third parties, other than the processors listed in the privacy policy and where the law requires it. We use the data solely to deliver the service. This obligation continues after the subscription ends.
10. Availability and support
We aim to keep the service continuously available, but we do not guarantee availability as a percentage. Planned maintenance is carried out when the impact is lowest, and we give advance notice of longer work. Remote support is included in every package, and we respond to questions within 48 hours. The Enterprise package includes priority support and an agreed escalation path.
11. Intellectual property and use of reports
The platform, its software, our methodologies and the report templates remain our intellectual property. Reports produced for a client may be used by that client without restriction for their own business purposes, including sharing them with employees, auditors, insurers, advisers and business partners. Publishing a complete report publicly requires our prior written agreement, because it can reveal detail that would be useful to an attacker.
12. Applicable law
The law of the Republic of Slovenia applies to the interpretation of these terms. In case of dispute, the competent court is in Slovenia, the District Court in Črnomelj.