PREVIEWCISO360AI is offered as-is while in preview. Features and data may change. Learn more.

Terms of Service

Last updated: 2026-09-30 — Version: 2026-09-30

Provider: alterSec Limited (NZBN 9429047827035), trading as CISO360AI ("we", "us", "our"), a company incorporated in New Zealand.

1. Acceptance & changes

By creating an account or using the CISO360AI service (the "Service") you agree to these Terms of Service (the "Terms"). If you do not agree, do not use the Service.

We may revise these Terms from time to time. Material changes will be announced by email to the address on file for your account, with reasonable notice. Your continued use of the Service after such notice constitutes acceptance of the revised Terms. The latest version is always available at /legal/terms.

2. The Service

CISO360AI is a multi-tenant cybersecurity management platform offering AI-assisted analysis, vulnerability and asset tracking, attack-surface discovery, and compliance workflows.

The Service is currently offered in PREVIEW. Features, data and availability may change without notice; prices change only as set out in clause 7A. During the preview the Service may contain bugs or errors, data may be reset, migrated or deleted as we iterate, and there is no service-level commitment.

3. Eligibility & account

You must be at least 18 years old to use the Service. Registration requires a corporate email address; personal email domains are not accepted. You are responsible for safeguarding your credentials and for all activity under your account, and you must keep your contact information current so that we can reach you with notices.

You are responsible for everyone you give access to your organisation's account ("Authorised Users"), for making sure they comply with these Terms, and for removing access when someone should no longer have it. We may refuse registration to anyone whose access we have previously terminated for breach of these Terms.

If you accept these Terms on behalf of an organisation, you confirm that you have authority to bind it, and "you" includes that organisation.

3A. Territory and eligibility

The Service is provided from New Zealand by a New Zealand company, under New Zealand law. It is designed to meet New Zealand requirements, not those of every other country. You are responsible for deciding whether using a New Zealand-based service is compatible with the laws, regulations and contracts that apply to your organisation where it operates, including rules on cross-border data transfers, and for any approvals or notices those require.

The Service is not yet offered to organisations established in, or individuals located in, the European Economic Area, Switzerland or the United Kingdom. By registering you represent that your organisation is not established in any of those places and that you do not ordinarily use the Service from them. You must not use a VPN or any other means to misrepresent your location. We may refuse, suspend or terminate any account that does not meet this clause, without liability. We will update this clause if we extend the Service to further regions.

4. Acceptable use

You agree not to:

  • reverse engineer, decompile, or attempt to derive the source of the Service;
  • resell, sublicense, white-label or distribute access to the Service without a written partner agreement with us;
  • circumvent rate limits, scrape, or perform automated access outside of documented APIs;
  • upload malware or use the Service to attack, intrude into, or otherwise harm any third party or system;
  • submit confidential third-party data without proper authority;
  • attempt to access another organisation's data, or probe, scan or test the security of the Service other than through its own features used as intended, or as our Vulnerability Disclosure Policy permits;
  • use the Service in breach of any law, including laws on computer misuse and privacy.

If you come across a security vulnerability in the Service, report it to us under our Vulnerability Disclosure Policy. That policy sets strict limits on security research; nothing in these Terms authorises any research beyond them.

4A. Export controls and sanctions

You represent that neither you nor your organisation, its owners or its Authorised Users (a) are located in, organised under the laws of, or ordinarily resident in any country or region where providing or using the Service is prohibited or restricted by sanctions, embargoes or export-control laws of New Zealand, the United Nations, the United States, the United Kingdom, the European Union or Australia, or (b) are named on, or owned or controlled by a party named on, any sanctions or restricted-party list maintained under those laws. It is your responsibility to check whether these laws apply to you. You will not use, export or re-export the Service or its outputs in breach of applicable export-control or sanctions laws, including for a military end use. We may suspend access immediately, without refund or liability, where we reasonably believe this clause has been breached.

4B. Services for your clients

You may use the Service to deliver services to your own clients, for example as a managed service provider, consultant or virtual CISO. For each client you must hold its authority for the targets, data and people you bring into the Service for it (see clause 5), and keep each client's information separate from other clients'. You are responsible for your clients' use of the Service through your account and for your agreements with them. We have no obligations to your clients, and they have no rights against us under these Terms. Each client must meet clauses 3A and 4A as if it were our customer. Your clients may use the Service only through your account, as Authorised Users; reselling, white-labelling or otherwise distributing access to the Service — offering it to others as your own product or service — requires a written partner agreement with us.

5. Authorisation to scan and analyse targets

You represent and warrant that, for every system, asset, domain, IP address, credential, or dataset that you submit to the Service for scanning, analysis, or assessment (each a "target"), you have all necessary authority, permissions, and consents from the owner or controller of that target. You will not use the Service to assess any target you are not legally authorised to assess. The targets you enter are your responsibility.

When you add or edit scan targets, you further acknowledge and agree that:

  • the person acting on your behalf has authority to authorise assessment of all targets in scope;
  • where a target is hosted by a third party (for example a cloud provider such as AWS, Azure, or Google Cloud), it remains your responsibility to check that provider's current acceptable-use policy and to obtain any permissions or notifications it requires;
  • you remain the agency responsible (in GDPR terms, the controller) for any personal information disclosed to or accessible by the Service during an assessment, and you are permitted to disclose it under the New Zealand Privacy Act 2020 or, for Australian-based customers, the Australian Privacy Act 1988 (Cth);
  • security testing uses tools and techniques designed to detect vulnerabilities, some active tests attempt to confirm them, not all risk can be eliminated, and you have taken reasonable steps to mitigate loss or damage (including verified backups and excluding unstable or legacy systems from scope);
  • scans generate network traffic that security monitoring on the target is likely to detect, and may affect the availability or performance of the target; you are responsible for warning anyone who operates or monitors it.

We may ask you at any time for evidence of your authority to assess a target, and may pause scanning of that target, or suspend your access, until you provide it.

You will indemnify and hold us harmless from any third-party claim arising out of your unauthorised use of the Service against targets you did not have permission to assess. We rely on your warranty in this clause whenever the Service assesses a target for you.

6. Your data

You retain ownership of the data you upload to or generate within the Service ("Customer Data"). We process Customer Data only to provide and operate the Service and as described in our Privacy Policy. We may use anonymised, aggregated information derived from the operation of the Service to improve the platform.

6A. Processing on your behalf

When we process personal information contained in Customer Data, we do so on your behalf and on your instructions, which are these Terms and your use of the Service. We will: keep it confidential and use it only to provide and operate the Service; protect it with appropriate technical and organisational security measures; use only the sub-processors described in our Privacy Policy or on the full list available to you on request, and require them to protect it to the same standard; notify you without undue delay after becoming aware of a security breach affecting it; reasonably help you respond to requests from the people it concerns; and delete it at the end of the Service as set out in clause 11. You warrant that you have all the rights, consents and lawful authority needed for us to process Customer Data as these Terms describe. If your organisation needs a separate data processing agreement, contact us.

Information you must not store in the Service: the Service is not intended for health information (as defined in the Health Information Privacy Code 2020), for other sensitive personal information — information about a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, sex life or sexual orientation, or criminal record — or for payment-card data. You must not upload or store any of it in the Service. This does not cover the security data the Service gathers to do its job, such as leaked credentials and breach records found by identity-exposure monitoring, or information a scan comes across incidentally; we handle that only to provide the Service to you and do not seek out or use it for any other purpose.

7. Our intellectual property

We own all rights in the Service, including the platform, models, workflows, templates, and documentation. Subject to your compliance with these Terms, we grant you a non-exclusive, non-transferable, revocable licence to use the Service for your own business purposes, including serving your clients under clause 4B, during the term of your subscription.

Reports, findings and other outputs the Service produces from your Customer Data are part of your Customer Data. The templates, content libraries, framework mappings and other material we provide remain ours or our licensors', and you may use them only with the Service and in your outputs. Third-party content in the Service, such as compliance frameworks and standards, remains subject to its owner's licence terms, which you must follow. We may use the general skills, techniques and know-how we gain from operating the Service, but never your confidential information.

If you give us suggestions or feedback about the Service, we may use them without restriction or obligation to you. We will not name your organisation as a customer, or use its name or logo, without your permission.

7A. Fees, payment and renewal

A "paid plan" is any plan for which fees are payable, whether it applies to your organisation or to a single project; everything else is the "free plan". Paid plans are charged at the prices shown when you subscribe, in the currency shown (currently US dollars), in advance for each billing period, through our payment provider. Prices exclude taxes such as GST unless stated otherwise. Subscriptions renew automatically at the end of each billing period until cancelled. You can cancel at any time in the Service; your plan then stays active until the end of the period you have paid for and does not renew. Fees are not refundable except where the law requires. If a payment fails we may, after giving you notice, suspend paid features or move your organisation to the free plan until it is paid. We will give you at least 30 days' notice of a price change, which applies from your first renewal at least 30 days after the notice. If you change plan, the new price applies as shown when you make the change.

Annual plans are paid for the full year: cancelling part-way through stops the renewal but does not refund the rest of the year. Promotional prices, discounts and invitation-code terms apply only as stated when offered and for the stated period, after which the standard price applies. At the end of a free trial of a paid plan, the plan continues as a paid subscription unless you cancel before the trial ends. Prepaid credits, such as top-ups, are not refundable, have no cash value and lapse when your organisation's account is closed.

8. As-is — no warranties

EXCEPT AS EXPRESSLY STATED IN THESE TERMS, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, AND ANY TERMS IMPLIED BY THE CONTRACT AND COMMERCIAL LAW ACT 2017. We do not guarantee that the Service will detect all vulnerabilities, weaknesses, misconfigurations, or compliance gaps, or that it will be uninterrupted, secure, accurate, or error-free. There is no service-level agreement during the preview unless you have one with us in writing.

No guaranteed security outcome: the Service helps you find and manage security and compliance issues, but no particular security outcome is guaranteed. We do not warrant that the Service will detect, prevent, contain or remediate any incident, breach, vulnerability or threat. Results depend on matters outside our control, including how your systems are configured and covered, the information you provide, and a threat landscape that keeps changing.

Not professional advice or certification: the Service is not legal, financial, insurance or other professional advice, and it is not an audit, certification or attestation under any standard or law, including ISO/IEC 27001, SOC 2, the NIST frameworks, the Health Information Security Framework or the Privacy Act 2020. Compliance scores, maturity results, reports and other outputs are for information only. Get your own professional advice, and use an accredited auditor where certification is required.

Your decisions: you remain responsible for your systems, controls and people, and for deciding whether and how to act on anything the Service or its AI features suggest, including implementing a recommendation correctly and in time.

Third-party services: services you connect to the Service, such as Microsoft 365 or your own AI agent, are provided by their own providers under their own terms. We are not responsible for them, for their availability, or for what they do with information you give them.

AI outputs: the Service may use artificial intelligence to generate suggestions, summaries, or analyses. AI-generated outputs may be inaccurate, incomplete, or misleading. You are solely responsible for reviewing and verifying any AI output before relying on it for security, compliance, or business decisions.

Consumer law: you acquire the Service for the purposes of a business. To the extent the law allows, the parties agree that the Consumer Guarantees Act 1993 does not apply (section 43) and that sections 9, 12A, 13 and 14(1) of the Fair Trading Act 1986 do not apply (section 5D), and agree that this is fair and reasonable. Nothing in these Terms excludes, restricts or modifies any right or remedy that cannot lawfully be excluded, including under the Australian Consumer Law; where the law allows our liability for a breach of such a right to be limited, it is limited to supplying the Service again or paying for it to be supplied again.

9. Limitation of liability

For use of the Service on the free plan, our liability is excluded to the maximum extent permitted by applicable law. We shall not be liable for any direct, indirect, incidental, consequential, special, or exemplary damages, including lost profits, lost data, or loss of goodwill, arising out of or in connection with your use of the Service.

For paid plans, we are not liable for any indirect, incidental, consequential, special or exemplary loss, or for loss of profits, revenue, data or goodwill, and our aggregate liability arising out of or relating to these Terms will not exceed the fees you paid to us in the twelve months preceding the event giving rise to the claim.

On a paid plan, and except to the extent caused by our breach of clause 6A or 10, we are also not liable for regulatory fines or penalties, the cost of notifying individuals or regulators, credit-monitoring or identity-remediation services, forensic investigation by third parties, or ransom payments. Nor are we liable for any security incident, vulnerability, compromise or breach in your environment, whether it began before you started using the Service or later, including one the Service did not detect or report.

Neither party is liable for a failure to the extent it is caused by the other party's failure to meet these Terms, or by the other party's negligence or misconduct, and each party must take reasonable steps to limit its own loss. Any claim against us must be notified to us in writing, with reasonable detail, within 12 months of when you became aware, or ought reasonably to have become aware, of the facts giving rise to it; a claim not notified in that time is waived. No indemnity is given except as these Terms expressly state.

The limits in this clause do not apply to your obligation to pay fees or to your indemnity in clause 5. Nothing in these Terms limits any liability that cannot be excluded by law, including liability for death or personal injury caused by negligence, fraud, or wilful misconduct.

10. Confidentiality

Each party will protect the other's non-public information disclosed in connection with the Service with the same degree of care it uses for its own confidential information (and at least reasonable care), and will use it solely to perform under these Terms. Your Customer Data, including every finding, scan result and report the Service produces about your targets, is your confidential information.

These obligations do not apply to information that is or becomes public through no fault of the recipient, that the recipient already held lawfully or received lawfully from someone else without restriction, or that it developed independently. A party may disclose confidential information where the law requires it to, after telling the other party where it lawfully can.

11. Term & termination

These Terms apply for as long as you use the Service. You may stop using the Service and close your organisation's account at any time. Closing the account does not cancel a paid plan: cancel it first, as set out in clause 7A. During the preview we may end the Service, or your access to it, at any time by giving notice. Either party may terminate immediately by notice if the other becomes insolvent, has a receiver, liquidator or administrator appointed, or stops carrying on business.

We may suspend or terminate your access immediately for material breach of these Terms, security risk, suspected unauthorised use, a breach of clause 3A or 4A, unpaid fees, where continuing would breach the law or compromise a law-enforcement or regulatory process, or as required by law. You can export your data using the Service's export features before your access ends. Upon termination, we will delete your Customer Data within 30 days, subject to backups and any legal-retention obligations. Clauses that by their nature should continue after termination (including 4B, 5, 6, 6A, 7, 7A for fees owed, 8, 9, 10, 12 and 12A) continue to apply.

12. Governing law & jurisdiction

These Terms are governed by the laws of New Zealand, without regard to its conflict-of-laws principles. The courts of New Zealand have exclusive jurisdiction over any dispute arising from or relating to these Terms or the Service. Before starting proceedings, a party will notify the other of the dispute and both will try in good faith to resolve it for at least 20 working days, except where urgent relief is needed. Each party will keep performing its obligations, as far as it can, while a dispute is being resolved.

12A. General

  • Entire agreement: these Terms, together with the policies they refer to and any order form, statement of work or other agreement we sign with you (such as a master services agreement), are the whole agreement between us about the Service. If a signed agreement conflicts with these Terms, it prevails for the matters it covers. Neither party has relied on any statement or promise that is not set out in them.
  • Force majeure: neither party is liable for a failure or delay caused by events beyond its reasonable control, including a large-scale cyber-attack or ransomware campaign, or a systemic failure of cloud, internet or telecommunications providers, to the extent the security measures in clause 6A could not reasonably have prevented it (other than a failure to pay).
  • Assignment: you may not assign or transfer these Terms without our written consent. We may assign them to a successor to our business on notice to you.
  • Subcontractors and relationship: we may use subcontractors and sub-processors to provide the Service and remain responsible for their performance of our obligations. The parties are independent contractors; nothing in these Terms creates a partnership, joint venture or agency. No one other than you and us has rights under these Terms.
  • Anti-corruption and modern slavery: each party will comply with the anti-bribery, anti-corruption and modern-slavery laws that apply to it in connection with the Service.
  • Severability and waiver: if any provision is unenforceable, the rest continues in force. A waiver is effective only if it is in writing, and not enforcing a right is not a waiver of it.
  • Notices: we will send notices to the email address on your account, and you can send notices to legal@ciso360.ai. An email notice is received when sent, unless the sender learns it was not delivered.
  • International sale of goods: the United Nations Convention on Contracts for the International Sale of Goods does not apply.

13. Contact

Questions about these Terms can be sent to legal@ciso360.ai.

alterSec Limited · NZBN 9429047827035 · Auckland, New Zealand