Przejdź do treści

Terms of Service

Last updated: 2026-05-03

TODO: review by counsel before sending to any customer. Drafted by Secruna's engineering team for refinement by a CEE-licensed law firm. The clauses below reflect what we actually intend to commit to operationally; counsel should tighten the legal phrasing without weakening any substantive position.


1. Definitions

  • Service — the Secruna compliance platform accessible at app.secruna.com and api.secruna.com, plus any first-party connectors and command-line tools released by Secruna.
  • Customer — the legal entity contracting for the Service.
  • User — an individual authorised by the Customer to access the Service.
  • Order — the order form, online sign-up flow, or other documented agreement that subscribes the Customer to the Service.
  • Connected System — an external account that the Customer authorises Secruna to read via a connector (e.g., the Customer's AWS account, GitHub organisation, OpenAI organisation).
  • Customer Data — data about the Customer's AI systems, Users, and Connected Systems that flows to Secruna as a consequence of operating the Service. Customer Data is governed by the DPA.
  • Documentationdocs.secruna.com (when published) and the customer documents under docs/customer/ in the Secruna repository as referenced.

2. Service description

Secruna provides:

  • Discovery of AI systems through customer-controlled connectors (Azure, AWS, GCP, GitHub, M365 Power Platform, OpenAI, Anthropic, Databricks).
  • Classification of those systems against EU AI Act Annex III using a rule book of high-risk use-case definitions.
  • Workflow tooling for review, approval, and audit of those classifications.
  • Reporting (per-tenant compliance dashboard, audit log export, PDF compliance report).

The Service is decision-support, not a regulator-issued attestation. Secruna's classification is a draft to be reviewed and approved by a qualified human reviewer at the Customer (implemented as a 2-eyes Human-in-the-Loop step in the platform). The final Annex III classification of the Customer's AI systems is the Customer's responsibility.

3. Customer obligations

3.1 Authority

The Customer represents that:

  1. It owns or has the right to operate the AI systems it connects to the Service.
  2. It has the authority to grant Secruna read access to the Connected Systems it connects (i.e., the person who clicks Install on a GitHub App or pastes an AWS Role ARN has the right to do so).
  3. It is responsible for the legality of its own use of AI under the EU AI Act and other applicable law. The Service informs that compliance posture; it does not replace it.

3.2 Account hygiene

The Customer will:

  • Provision and deprovision User accounts in line with its own joiner-mover-leaver process.
  • Rotate connector credentials when its security policy requires (e.g., on employee offboarding for the OAuth-consenting admin).
  • Not share authentication credentials between humans or between humans and machines.
  • Not attempt to circumvent the rate limits, RLS isolation, or any other technical control of the Service.

3.3 Lawful use

The Customer will not:

  1. Use the Service to enumerate, attack, or exfiltrate data from any system that is not a Connected System under the Customer's control.
  2. Use the Service to process personal data outside the categories documented in the DPA.
  3. Reverse-engineer, copy, or build a competing service from the Documentation, classification rule book, or Service output, except as permitted by mandatory law.

4. Service levels

4.1 Availability

We target 99.5% monthly availability for api.secruna.com and app.secruna.com, measured per docs/ops/slos.md. This target reflects the single-region deployment posture documented in the DPA §6.6.

4.2 Latency

We target p95 < 10 seconds for verdict-classification endpoints, measured over a rolling 7-day window per docs/ops/slos.md.

4.3 Discovery

We target ≥ 95% completion rate of discovery runs over a rolling 7-day window per docs/ops/slos.md. A persistent connector failure that drops below this target triggers internal remediation.

4.4 Status page and notification

The Customer can subscribe to email notifications from status.secruna.com for incident updates. For S0/S1 incidents affecting the Customer's tenant, Secruna will additionally notify the tenant administrator by email once impact is characterised.

4.5 Service credits

For first paying customers Secruna does not commit financial service-credits for SLO breach during the MVP phase. The Customer's remedy is termination for cause if the SLO is missed by more than 25% in two consecutive months. (TODO: counsel review — this is a gap relative to enterprise SaaS norms; we may need a credit table for banking customers.)

5. Pricing and billing

For the MVP phase the Service is provided at the price specified in the Order. Billing in production will run through Stripe (planned, P2). Until billing is active, invoicing is manual and stipulated in the Order.

6. Confidentiality

Each party will protect the other's Confidential Information with at least the same care it uses to protect its own confidential information of similar importance, and not less than reasonable care.

Confidential Information does not include information that is: publicly known through no fault of the receiving party; independently developed without reference to the disclosing party's information; or rightfully obtained from a third party without obligation of confidence.

7. Intellectual property

7.1 Secruna IP

Secruna retains all right, title, and interest in the Service, the rule book, the classification logic, the Documentation, and any improvements thereto.

7.2 Customer Data

The Customer retains all right, title, and interest in Customer Data. Secruna's right to process Customer Data is limited to the purposes set out in §2 of this ToS and the DPA.

7.3 Feedback

If the Customer provides feedback or suggestions about the Service, Secruna may use that feedback to improve the Service without obligation, provided no Confidential Information of the Customer is disclosed.

7.4 Aggregate analytics

Secruna may use aggregated, de-identified statistics about Service usage for product improvement and benchmarking. Such statistics will not identify the Customer or any individual User. (Note: today no aggregate analytics pipeline exists; if one is built, we will document it in this section and on the subprocessors page.)

8. Liability

8.1 Cap

To the maximum extent permitted by law, each party's aggregate liability under this Agreement is capped at the fees paid by the Customer in the 12 months preceding the event giving rise to liability.

8.2 Excluded damages

Neither party is liable for indirect, consequential, special, exemplary, or punitive damages, or for lost profits, lost revenue, lost data (except where Secruna's negligence specifically caused the loss and a backup restore was not possible due to a failure of Secruna's stated backup posture), or business interruption.

8.3 Carve-outs

The cap and exclusions in §8.1 and §8.2 do not apply to:

  • A party's indemnity obligations for IP infringement (§9);
  • Either party's breach of confidentiality (§6);
  • Secruna's breach of the DPA causing direct fines from a data protection authority levied against the Customer;
  • Either party's gross negligence or wilful misconduct;
  • Liabilities that cannot be limited under applicable law (including under GDPR Articles 82–84).

9. Indemnity

Secruna will defend and indemnify the Customer against third-party claims that the Service, used as permitted under this Agreement, infringes that third party's intellectual property rights, subject to the Customer giving prompt written notice and reasonable cooperation.

The Customer will defend and indemnify Secruna against third-party claims arising from the Customer's breach of §3 (Customer Obligations).

10. Term and termination

10.1 Term

The Agreement starts on the Order's Effective Date and runs for the Initial Term in the Order. It auto-renews for further 12-month terms unless either party gives 60 days' written notice before the end of the current term.

10.2 Termination for cause

Either party may terminate for material breach if the breach is not cured within 30 days of written notice of breach.

10.3 Termination on subprocessor change

Per subprocessors.md, the Customer has the right to terminate the affected service if a reasoned objection to a new subprocessor cannot be resolved.

10.4 Effect of termination

On termination:

  1. The Customer's User access is revoked at the end of the term (or immediately for cause).
  2. The Customer's data is returned or deleted per §11 of the DPA.
  3. Accrued and undisputed fees become payable.
  4. Sections that by their nature should survive (Confidentiality, IP, Liability, Indemnity, Governing Law) survive.

11. Suspension

Secruna may suspend the Service to the Customer with reasonable advance notice (at least 5 business days, or immediately for security or legal reasons) if:

  • The Customer is in material breach of §3;
  • Continued operation poses a security or legal risk to Secruna or other customers;
  • The Customer is more than 30 days late on undisputed fees.

We will not use suspension as a routine enforcement tool. The expectation is that 99% of operational issues are resolved through email and dashboard notifications, not service cut-off.

12. Force majeure

Neither party is liable for failure to perform caused by events beyond its reasonable control: war, civil unrest, natural disaster, governmental restriction, internet or major cloud- provider outage, pandemic. Each party will use reasonable efforts to mitigate.

13. Governing law

This Agreement is governed by the laws of the Republic of Poland. Disputes will be resolved by the courts of Warsaw, Poland, except that either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or confidential information.

The choice of Polish law is rooted in Secruna's incorporation and the CEE-focused customer base. Customers headquartered in another EU member state may, by agreement at the Order stage, substitute the courts of their own jurisdiction; this is a negotiable point.

14. Miscellaneous

14.1 Entire agreement

This ToS, the DPA, and the Order form the entire agreement between the parties on the subject matter, superseding any prior representation. In case of conflict, the Order > the DPA > this ToS.

14.2 Assignment

Neither party may assign this Agreement without the other's written consent, except that either may assign to a successor in a corporate restructuring (merger, acquisition, sale of substantially all assets) on written notice.

14.3 Notices

Notices to Secruna: TODO legal@secruna.com. Notices to the Customer: the contact email on the most recent Order, plus a copy to the User who created the tenant.

14.4 Independent contractors

The parties are independent contractors. Nothing in this Agreement creates an agency, partnership, joint venture, or employment relationship.

14.5 No waiver

Failure to enforce any provision is not a waiver of that provision or any other.

14.6 Severability

If any provision is held unenforceable, the remainder of the Agreement remains in effect and the provision is reformed to the minimum extent necessary to be enforceable.


TODO: review by counsel before sending to any customer.