Threat Detective Sign in

Service Agreement

Last updated 2026-07-24

1. About this Agreement

This Service Agreement is a binding contract between Threat Detective Ltd (a company incorporated in England and Wales) ("we", "us") and the organisation on whose behalf it is accepted (the "Customer", "you"). It governs the Customer's access to and use of the Threat Detective SaaS service ("the Service").

2. Acceptance and authority

This Agreement is accepted electronically when a person creates an organisation in the Service on the Customer's behalf. By accepting, that person confirms they are authorised to enter into this Agreement for the Customer. If you do not have that authority, or the Customer does not agree to these terms, do not create an organisation.

If the Customer and Threat Detective Ltd have signed a separate written agreement covering the Service (for example a master services agreement or order form), that signed agreement prevails over this one to the extent of any conflict.

3. The Service

The Service helps customers manage software bills of materials and vulnerability documentation across their projects. The Service is provided on a business-to-business basis and is not intended for consumer use.

4. Free trial

New organisations receive a free trial of the Service for the period stated at sign-up. During the trial the Service is provided "as is" and without any commitment as to availability; some features are limited (for example, exported reports carry a trial watermark and machine-readable exports are unavailable). We may modify or withdraw trial features, or end a trial, at any time. On trial expiry the organisation's data becomes read-only; section 6 applies to deletion.

5. Users and acceptable use

The Customer is responsible for the people it allows into its organisation ("users"), for the accuracy of the information they provide, and for their compliance with this Agreement. Each user must also accept our Acceptable Use Policy at sign-up; it is incorporated into this Agreement by reference, and a material breach of it by the Customer's users is a material breach of this Agreement.

6. Customer content and intellectual property

The Customer retains all rights in the content it submits to the Service (SBOMs, component data, triage decisions, reports and other materials — "Customer Content"). The Customer grants us a non-exclusive licence to host and process Customer Content solely to provide and support the Service. We and our licensors retain all rights in the Service itself. Vulnerability and advisory data presented in the Service is drawn from third-party sources and is provided for information; the Customer remains responsible for its own regulatory submissions and decisions.

7. Data protection

Where we process personal data on the Customer's behalf as part of the Service, the Data Processing Agreement is incorporated by reference and forms part of this Agreement. Our current list of subprocessors is published at /subprocessors.

8. Subscription, renewal and fees

Beyond the free trial, the Service is provided on a subscription basis. The applicable plan, fees and billing cadence are set out in the order form, online checkout or written quotation that the Customer accepts when starting or changing a subscription ("Order").

Fees are payable in advance for each billing period. Subscriptions renew automatically for successive periods of equal length unless either party gives written notice of non-renewal at least 30 days before the end of the then-current period. We may change fees with effect from the next renewal by giving at least 30 days' written notice; if the Customer does not accept the change, it may give notice of non-renewal during that period.

All fees exclude VAT and other applicable taxes, which are payable in addition. If an invoice is more than 30 days overdue, we may suspend the Service after giving reasonable notice and an opportunity to pay.

9. Term and termination

This Agreement takes effect when it is first accepted and continues for as long as the Customer has an organisation in the Service. Either party may terminate this Agreement:

On termination or expiry: (a) the Customer's right to access the Service ceases; (b) for 30 days after termination, the Customer may export Customer Content using the export tools we provide; (c) we will delete Customer Content within 90 days of termination, save for backups (which are overwritten on a rolling basis) and records we are required by law to retain.

10. Warranties and limitation of liability

We will provide the Service with reasonable skill and care. To the fullest extent permitted by law, we disclaim all other warranties, whether express, implied, statutory or otherwise, including any implied warranty of satisfactory quality or fitness for a particular purpose.

Nothing in this Agreement limits or excludes liability for: (i) death or personal injury caused by negligence; (ii) fraud or fraudulent misrepresentation; (iii) any liability that cannot be limited or excluded under applicable law.

Subject to the paragraph above, neither party shall be liable for any loss of profits, loss of revenue, loss of business, loss of goodwill or for any indirect or consequential loss arising under or in connection with this Agreement.

Subject to the paragraph beginning "Nothing in this Agreement" above, each party's total aggregate liability arising under or in connection with this Agreement (whether in contract, tort (including negligence), for breach of statutory duty, or otherwise) shall not exceed an amount equal to 100% of the fees paid or payable by the Customer under this Agreement in the 12 months immediately preceding the event giving rise to the liability, and the exclusions in this section do not apply to the Customer's payment obligations or to either party's breach of section 7 or section 11.

11. Confidentiality

Each party may receive Confidential Information from the other in connection with this Agreement. "Confidential Information" means any non-public information disclosed by one party to the other that is marked or reasonably understood to be confidential, including business plans, technical information, Customer Content, and the terms of any Order.

The receiving party will: (a) use the Confidential Information only to perform its obligations or exercise its rights under this Agreement; (b) protect it using at least the same degree of care it uses for its own confidential information of similar sensitivity, and in any event no less than reasonable care; and (c) disclose it only to its personnel and professional advisers who need to know and who are bound by confidentiality obligations no less protective than these.

Confidential Information does not include information that: is or becomes public other than through breach of this Agreement; was lawfully known to the receiving party before disclosure; is lawfully received from a third party without restriction; or is independently developed without use of the disclosing party's Confidential Information.

The obligations in this section survive for 3 years after termination of this Agreement, except for trade secrets and personal data, which are protected for as long as they remain confidential or as required by law.

12. Governing law and jurisdiction

This Agreement is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.

13. Changes to this Agreement

We may update this Agreement from time to time. For material changes we will give existing customers at least 14 days' notice in the Service before the new version takes effect, and will ask an organisation owner to re-accept. New organisations accept the current version at creation.