Terms of Service¶
Last updated: 2026-05-03
TODO: review by counsel before sending to any customer. Drafted by Secruna's engineering team for refinement by a CEE-licensed law firm. The clauses below reflect what we actually intend to commit to operationally; counsel should tighten the legal phrasing without weakening any substantive position.
1. Definitions¶
- Service — the Secruna compliance platform accessible at
app.secruna.comandapi.secruna.com, plus any first-party connectors and command-line tools released by Secruna. - Customer — the legal entity contracting for the Service.
- User — an individual authorised by the Customer to access the Service.
- Order — the order form, online sign-up flow, or other documented agreement that subscribes the Customer to the Service.
- Connected System — an external account that the Customer authorises Secruna to read via a connector (e.g., the Customer's AWS account, GitHub organisation, OpenAI organisation).
- Customer Data — data about the Customer's AI systems, Users, and Connected Systems that flows to Secruna as a consequence of operating the Service. Customer Data is governed by the DPA.
- Documentation —
docs.secruna.com(when published) and the customer documents underdocs/customer/in the Secruna repository as referenced.
2. Service description¶
Secruna provides:
- Discovery of AI systems through customer-controlled connectors (Azure, AWS, GCP, GitHub, M365 Power Platform, OpenAI, Anthropic, Databricks).
- Classification of those systems against EU AI Act Annex III using a rule book of high-risk use-case definitions.
- Workflow tooling for review, approval, and audit of those classifications.
- Reporting (per-tenant compliance dashboard, audit log export, PDF compliance report).
The Service is decision-support, not a regulator-issued attestation. Secruna's classification is a draft to be reviewed and approved by a qualified human reviewer at the Customer (implemented as a 2-eyes Human-in-the-Loop step in the platform). The final Annex III classification of the Customer's AI systems is the Customer's responsibility.
3. Customer obligations¶
3.1 Authority¶
The Customer represents that:
- It owns or has the right to operate the AI systems it connects to the Service.
- It has the authority to grant Secruna read access to the Connected Systems it connects (i.e., the person who clicks Install on a GitHub App or pastes an AWS Role ARN has the right to do so).
- It is responsible for the legality of its own use of AI under the EU AI Act and other applicable law. The Service informs that compliance posture; it does not replace it.
3.2 Account hygiene¶
The Customer will:
- Provision and deprovision User accounts in line with its own joiner-mover-leaver process.
- Rotate connector credentials when its security policy requires (e.g., on employee offboarding for the OAuth-consenting admin).
- Not share authentication credentials between humans or between humans and machines.
- Not attempt to circumvent the rate limits, RLS isolation, or any other technical control of the Service.
3.3 Lawful use¶
The Customer will not:
- Use the Service to enumerate, attack, or exfiltrate data from any system that is not a Connected System under the Customer's control.
- Use the Service to process personal data outside the categories documented in the DPA.
- Reverse-engineer, copy, or build a competing service from the Documentation, classification rule book, or Service output, except as permitted by mandatory law.
4. Service levels¶
4.1 Availability¶
We target 99.5% monthly availability for api.secruna.com
and app.secruna.com, measured per docs/ops/slos.md. This
target reflects the single-region deployment posture documented
in the DPA §6.6.
4.2 Latency¶
We target p95 < 10 seconds for verdict-classification
endpoints, measured over a rolling 7-day window per
docs/ops/slos.md.
4.3 Discovery¶
We target ≥ 95% completion rate of discovery runs over a
rolling 7-day window per docs/ops/slos.md. A persistent
connector failure that drops below this target triggers internal
remediation.
4.4 Status page and notification¶
The Customer can subscribe to email notifications from
status.secruna.com for incident updates. For S0/S1 incidents
affecting the Customer's tenant, Secruna will additionally
notify the tenant administrator by email once impact is
characterised.
4.5 Service credits¶
For first paying customers Secruna does not commit financial service-credits for SLO breach during the MVP phase. The Customer's remedy is termination for cause if the SLO is missed by more than 25% in two consecutive months. (TODO: counsel review — this is a gap relative to enterprise SaaS norms; we may need a credit table for banking customers.)
5. Pricing and billing¶
For the MVP phase the Service is provided at the price specified in the Order. Billing in production will run through Stripe (planned, P2). Until billing is active, invoicing is manual and stipulated in the Order.
6. Confidentiality¶
Each party will protect the other's Confidential Information with at least the same care it uses to protect its own confidential information of similar importance, and not less than reasonable care.
Confidential Information does not include information that is: publicly known through no fault of the receiving party; independently developed without reference to the disclosing party's information; or rightfully obtained from a third party without obligation of confidence.
7. Intellectual property¶
7.1 Secruna IP¶
Secruna retains all right, title, and interest in the Service, the rule book, the classification logic, the Documentation, and any improvements thereto.
7.2 Customer Data¶
The Customer retains all right, title, and interest in Customer Data. Secruna's right to process Customer Data is limited to the purposes set out in §2 of this ToS and the DPA.
7.3 Feedback¶
If the Customer provides feedback or suggestions about the Service, Secruna may use that feedback to improve the Service without obligation, provided no Confidential Information of the Customer is disclosed.
7.4 Aggregate analytics¶
Secruna may use aggregated, de-identified statistics about Service usage for product improvement and benchmarking. Such statistics will not identify the Customer or any individual User. (Note: today no aggregate analytics pipeline exists; if one is built, we will document it in this section and on the subprocessors page.)
8. Liability¶
8.1 Cap¶
To the maximum extent permitted by law, each party's aggregate liability under this Agreement is capped at the fees paid by the Customer in the 12 months preceding the event giving rise to liability.
8.2 Excluded damages¶
Neither party is liable for indirect, consequential, special, exemplary, or punitive damages, or for lost profits, lost revenue, lost data (except where Secruna's negligence specifically caused the loss and a backup restore was not possible due to a failure of Secruna's stated backup posture), or business interruption.
8.3 Carve-outs¶
The cap and exclusions in §8.1 and §8.2 do not apply to:
- A party's indemnity obligations for IP infringement (§9);
- Either party's breach of confidentiality (§6);
- Secruna's breach of the DPA causing direct fines from a data protection authority levied against the Customer;
- Either party's gross negligence or wilful misconduct;
- Liabilities that cannot be limited under applicable law (including under GDPR Articles 82–84).
9. Indemnity¶
Secruna will defend and indemnify the Customer against third-party claims that the Service, used as permitted under this Agreement, infringes that third party's intellectual property rights, subject to the Customer giving prompt written notice and reasonable cooperation.
The Customer will defend and indemnify Secruna against third-party claims arising from the Customer's breach of §3 (Customer Obligations).
10. Term and termination¶
10.1 Term¶
The Agreement starts on the Order's Effective Date and runs for the Initial Term in the Order. It auto-renews for further 12-month terms unless either party gives 60 days' written notice before the end of the current term.
10.2 Termination for cause¶
Either party may terminate for material breach if the breach is not cured within 30 days of written notice of breach.
10.3 Termination on subprocessor change¶
Per subprocessors.md, the Customer has the right to terminate the affected service if a reasoned objection to a new subprocessor cannot be resolved.
10.4 Effect of termination¶
On termination:
- The Customer's User access is revoked at the end of the term (or immediately for cause).
- The Customer's data is returned or deleted per §11 of the DPA.
- Accrued and undisputed fees become payable.
- Sections that by their nature should survive (Confidentiality, IP, Liability, Indemnity, Governing Law) survive.
11. Suspension¶
Secruna may suspend the Service to the Customer with reasonable advance notice (at least 5 business days, or immediately for security or legal reasons) if:
- The Customer is in material breach of §3;
- Continued operation poses a security or legal risk to Secruna or other customers;
- The Customer is more than 30 days late on undisputed fees.
We will not use suspension as a routine enforcement tool. The expectation is that 99% of operational issues are resolved through email and dashboard notifications, not service cut-off.
12. Force majeure¶
Neither party is liable for failure to perform caused by events beyond its reasonable control: war, civil unrest, natural disaster, governmental restriction, internet or major cloud- provider outage, pandemic. Each party will use reasonable efforts to mitigate.
13. Governing law¶
This Agreement is governed by the laws of the Republic of Poland. Disputes will be resolved by the courts of Warsaw, Poland, except that either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or confidential information.
The choice of Polish law is rooted in Secruna's incorporation and the CEE-focused customer base. Customers headquartered in another EU member state may, by agreement at the Order stage, substitute the courts of their own jurisdiction; this is a negotiable point.
14. Miscellaneous¶
14.1 Entire agreement¶
This ToS, the DPA, and the Order form the entire agreement between the parties on the subject matter, superseding any prior representation. In case of conflict, the Order > the DPA > this ToS.
14.2 Assignment¶
Neither party may assign this Agreement without the other's written consent, except that either may assign to a successor in a corporate restructuring (merger, acquisition, sale of substantially all assets) on written notice.
14.3 Notices¶
Notices to Secruna: TODO legal@secruna.com. Notices to the
Customer: the contact email on the most recent Order, plus a
copy to the User who created the tenant.
14.4 Independent contractors¶
The parties are independent contractors. Nothing in this Agreement creates an agency, partnership, joint venture, or employment relationship.
14.5 No waiver¶
Failure to enforce any provision is not a waiver of that provision or any other.
14.6 Severability¶
If any provision is held unenforceable, the remainder of the Agreement remains in effect and the provision is reformed to the minimum extent necessary to be enforceable.
TODO: review by counsel before sending to any customer.