Terms & Conditions
Cytrusst Intelligence Private Limited
Introduction
- These Terms & Conditions (“Terms”) are intended to make you aware of your legal rights and responsibilities in relation to your access to and use of the Cytrusst website, software platform, web applications, dashboards, APIs, integrations, reports, documentation, and other services provided by Cytrusst Intelligence Private Limited (“Cytrusst”, “Company”, “We”, “Us” or “Our”).
- The Cytrusst platform is a cybersecurity and Governance, Risk and Compliance (“GRC”) platform designed to assist organizations in managing governance, risk, compliance, audit, security, third-party risk, vulnerability management, attack surface management, cloud security, AI governance, evidence management, assessments, reporting, and related activities.
- The Services may include, without limitation, GRC management, policy management, framework and control management, evidence management, audit and assessment management, risk management, Third-Party Risk Management (“TPRM”), Risk-Based Vulnerability Management (“RBVM”), Attack Surface Management (“ASM”), Cloud Security Posture Management (“CSPM”), compliance monitoring, dashboards, reporting, workflow management, integrations, and other current or future functionality made available by Cytrusst.
- The Services may be provided through Software-as-a-Service (“SaaS”) deployment, On-Premises deployment, or other deployment models as may be agreed between Cytrusst and the Customer.
- By accessing, registering, subscribing to, or otherwise using the Cytrusst platform or Services, you agree to be bound by these Terms and the applicable Privacy Policy and other applicable agreements.
- If you do not agree with these Terms, you should discontinue use of the Services immediately.
Definitions
For the purposes of these Terms:
- Services“Services” means the Cytrusst platform, website, applications, software, dashboards, APIs, integrations, reports, documentation, workflows, notifications, and associated services made available by Cytrusst from time to time.
- Customer“Customer” means the organization, company, institution, or other legal entity that purchases, subscribes to, or is otherwise authorized to access or use the Services.
- User“User” means any employee, representative, consultant, contractor, administrator, or other individual authorized by the Customer to access or use the Services.
- Customer Data“Customer Data” means any information, documents, records, configurations, policies, evidence, assessments, contracts, vendor information, risk information, security information, vulnerability information, logs, Personal Data, reports, files, or other information uploaded, submitted, transmitted, generated, or otherwise provided by or on behalf of the Customer through the Services.
- Cytrusst Content“Cytrusst Content” means all content, software, interfaces, workflows, dashboards, designs, documentation, methodologies, templates, algorithms, models, reports, graphics, text, databases, and other materials created, developed, owned, or made available by Cytrusst in connection with the Services.
- User Content“User Content” means any information or material submitted, uploaded, entered, transmitted, or otherwise provided by a User through the Services.
- Third-Party Services“Third-Party Services” means third-party applications, APIs, cloud platforms, security tools, software, systems, integrations, or services that may be connected to or used with the Cytrusst platform.
- Personal Data“Personal Data” means information relating to an identified or identifiable individual as defined under applicable privacy and data protection laws.
- AI Features“AI Features” means artificial intelligence or machine-learning-enabled capabilities made available through the Services, including analysis, classification, recommendations, summarization, risk analysis, compliance analysis, evidence analysis, AI inventory, AI risk assessment, and related functionality.
Terms of Service
- Cytrusst shall provide the Services in accordance with the applicable subscription, Order Form, proposal, quotation, Master Services Agreement, Service Level Agreement, or other agreement entered into with the Customer.
- Cytrusst may provide different editions, modules, features, integrations, deployment models, and service configurations depending upon the Customer's subscription or contractual arrangement.
- Certain features may require additional configuration, licensing, technical prerequisites, third-party services, or Customer-provided infrastructure.
- Cytrusst may modify, enhance, update, replace, or discontinue individual features of the Services from time to time, provided that such changes are subject to any applicable contractual commitments.
- Cytrusst shall use reasonable efforts to maintain the availability and security of the Services. However, temporary interruption may occur due to maintenance, upgrades, security activities, emergency changes, infrastructure failures, third-party service interruptions, or circumstances beyond Cytrusst's reasonable control.
- Where an SLA has been separately agreed, service availability, support response times, maintenance windows, and related commitments shall be governed by the applicable SLA.
Terms of Use
- Cytrusst grants the Customer a limited, non-exclusive, non-transferable, and non-sublicensable right to access and use the Services solely for its authorized internal business, governance, risk, compliance, cybersecurity, audit, security, and related purposes during the applicable subscription or contractual period.
- The Customer shall ensure that only authorized Users access the Services and shall be responsible for the activities performed through its accounts.
- The Customer shall comply with all applicable laws, regulations, contractual obligations, and internal policies while using the Services.
- The Customer shall not use the Services:
- For any unlawful, fraudulent, malicious, or unauthorized purpose
- To obtain unauthorized access to the Cytrusst platform, infrastructure, networks, systems, or accounts
- To circumvent authentication, security, access-control, or other technical restrictions
- To introduce malware, ransomware, viruses, malicious code, or other harmful content
- To interfere with or disrupt the operation of the Services
- To conduct unauthorized penetration testing, vulnerability scanning, denial-of-service testing, or other intrusive security testing against Cytrusst infrastructure
- To reverse engineer, decompile, disassemble, modify, or attempt to derive source code from the Services except where expressly permitted by applicable law
- To scrape, copy, reproduce, extract, or systematically collect Cytrusst Content without prior written authorization
- To resell, sublicense, lease, distribute, or commercially exploit the Services without authorization
- To impersonate another person or organization
- To upload content that infringes the intellectual property, privacy, confidentiality, or other rights of any third party; or
- In any manner that may damage, disable, overburden, impair, or compromise the security, availability, integrity, or performance of the Services.
- The Customer shall not share account credentials with unauthorized individuals or permit unauthorized access to the Services.
- The Customer shall promptly notify Cytrusst of any suspected unauthorized access, compromised credentials, security incident, or misuse of the Services.
Account and Access Management
- Where access to the Services requires registration or account creation, the Customer shall provide accurate and complete information.
- The Customer is responsible for maintaining the confidentiality of its usernames, passwords, API keys, access tokens, certificates, and other authentication credentials.
- The Customer shall establish and maintain appropriate access permissions and role assignments for its Users.
- The Customer shall promptly revoke or disable access for Users who no longer require access.
- The Customer shall remain responsible for activities performed through its accounts, except to the extent that such activity is directly attributable to a security incident caused by Cytrusst.
- Where the Customer becomes aware of unauthorized use of an account or other security compromise, the Customer shall notify Cytrusst without undue delay.
Customer Data and Content
- The Customer retains all rights, title, and interest in Customer Data submitted to or processed through the Services.
- The Customer represents that it has all necessary rights, permissions, authorizations, and lawful bases required to provide Customer Data to Cytrusst for processing.
- The Customer shall be responsible for the accuracy, legality, quality, and appropriateness of Customer Data submitted through the Services.
- Cytrusst may access, host, store, process, transmit, and otherwise use Customer Data solely to the extent reasonably necessary to:
- Provide and operate the Services
- Authenticate and manage Users
- Provide technical and customer support
- Process evidence and assessments
- Generate compliance, audit, risk, and security reports
- Execute Customer-configured workflows
- Operate authorized integrations
- Maintain backups and disaster recovery
- Detect and prevent security incidents and abuse
- Maintain the reliability, security, and performance of the Services; and
- Comply with applicable legal and regulatory requirements.
- Cytrusst will not sell Customer Data to third parties.
- Unless expressly authorized or otherwise agreed in writing, Cytrusst will not use Customer Data to train publicly available third-party AI models.
Data Processing and Privacy
- Cytrusst takes the privacy and security of Customer Data and Personal Data seriously and maintains appropriate technical and organizational measures for their protection.
- Where Cytrusst processes Personal Data on behalf of the Customer, the Customer will generally determine the purposes and means of processing, while Cytrusst will process such Personal Data in accordance with the Customer's documented instructions, applicable agreements, and applicable law.
- The Customer shall be responsible for determining the applicable lawful basis for processing Personal Data and for providing required privacy notices and obtaining consent or other required authorizations where applicable.
- Cytrusst shall process Personal Data only to the extent necessary to provide, maintain, secure, support, and improve the Services, fulfil contractual obligations, comply with applicable law, or for other purposes expressly authorized by the Customer or agreed between the parties.
- Cytrusst shall apply appropriate measures to support data minimization, purpose limitation, accuracy, confidentiality, integrity, availability, retention limitation, and other applicable privacy principles.
- Cytrusst shall not sell Customer Personal Data.
- Unless expressly authorized or otherwise agreed in writing, Cytrusst will not use Customer Personal Data to train publicly available third-party AI models.
- Where reasonably applicable to the Services, Cytrusst shall provide reasonable assistance to the Customer in responding to requests relating to applicable Personal Data protection obligations, subject to the applicable agreement, technical capabilities, and legal requirements.
- Where Cytrusst becomes aware of a Personal Data breach affecting Customer Personal Data, Cytrusst shall handle the incident in accordance with its applicable incident management procedures and applicable contractual and legal requirements.
- Where required by applicable law or contractual requirements, the Customer and Cytrusst may enter into a separate Data Processing Agreement (“DPA”) defining the processing activities, responsibilities, security measures, subprocessors, data transfers, retention, deletion, and other applicable privacy requirements.
- Further information regarding the collection and processing of Personal Data by Cytrusst is provided in the applicable Cytrusst Privacy Policy and, where applicable, the relevant DPA.
AI-Enabled Services and AI Governance
- Cytrusst may provide artificial intelligence functionality as part of the Services.
- AI Features may include evidence analysis, compliance analysis, risk analysis, classification, recommendations, summarization, AI inventory, AI risk assessment, security analysis, report generation, and related capabilities.
- Cytrusst maintains governance processes for the responsible development, deployment, operation, monitoring, and improvement of applicable AI-enabled functionality.
- Cytrusst applies a risk-based approach to identifying, assessing, managing, and monitoring risks associated with applicable AI systems and AI-enabled functionality.
- AI-generated outputs are generated based on the information available to the applicable system, model configuration, Customer Data, contextual information, and other technical factors.
- AI-generated outputs may contain inaccuracies, omissions, incomplete information, outdated information, or other limitations and should not automatically be treated as authoritative, complete, or error-free.
- The Customer shall conduct appropriate human review and validation before relying on AI-generated outputs for material business, security, compliance, legal, regulatory, or other consequential decisions.
- The Customer remains responsible for decisions, actions, assessments, or outcomes resulting from its use of AI-generated outputs.
- Cytrusst may implement appropriate human oversight, monitoring, testing, validation, security controls, and other safeguards for applicable AI-enabled functionality based on the nature and risk of the AI system.
- Cytrusst shall take reasonable measures to protect information processed by applicable AI-enabled functionality against unauthorized access, disclosure, alteration, loss, or misuse, subject to the applicable architecture and service configuration.
- Unless expressly authorized or otherwise agreed in writing, Customer Data and Customer Personal Data shall not be used to train publicly available external AI models.
- Where third-party AI models, platforms, APIs, or AI service providers are used to provide AI Features, such services may be subject to separate technical, contractual, privacy, security, and service conditions.
- Cytrusst may modify, update, replace, or discontinue AI Features, including changes to underlying models, algorithms, configurations, or supporting services, where reasonably necessary for security, performance, functionality, compliance, risk management, or service improvement, subject to applicable contractual commitments.
- Customers shall not use AI Features for unlawful purposes or in a manner that violates applicable law, contractual obligations, privacy requirements, security requirements, or the rights of individuals or third parties.
- Where Cytrusst identifies a material AI-related security, privacy, safety, or operational incident affecting the Services, Cytrusst shall handle the matter in accordance with its applicable incident management, risk management, and contractual processes.
- AI Features are intended to support, and not replace, appropriate human judgment, organizational governance, professional expertise, or applicable legal and regulatory obligations.
Data Subject Rights
- Where applicable under relevant privacy and data protection laws, individuals may have rights relating to their Personal Data, including rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, or other rights provided by applicable law.
- Where Cytrusst processes Personal Data on behalf of a Customer, requests relating to the exercise of applicable data subject rights shall generally be directed to the relevant Customer as the applicable data controller or equivalent entity.
- Where reasonably required and applicable, Cytrusst shall provide appropriate assistance to the Customer in responding to valid data subject requests, subject to the Customer's instructions, applicable law, technical capabilities, and contractual requirements.
- Cytrusst may be required to retain certain information where retention is necessary to comply with applicable legal, regulatory, contractual, security, or other legitimate requirements.
Data Hosting and Processing
- For SaaS deployments, Customer Data may be hosted and processed using infrastructure operated by Cytrusst and/or authorized cloud service providers, including AWS and other approved infrastructure providers.
- The applicable hosting location may depend upon the Customer's subscription, deployment architecture, contractual requirements, data residency requirements, and applicable regulatory obligations.
- Customer Data may be accessed or processed from locations where Cytrusst, its authorized service providers, cloud infrastructure, or security infrastructure operate, subject to applicable contractual and legal requirements.
- Where Customer Data is transferred across jurisdictions, Cytrusst shall implement appropriate safeguards as required by applicable law and contractual requirements.
- For On-Premises deployments, Customer Data will primarily remain within the Customer's designated infrastructure.
- Cytrusst may require controlled and authorized access to an On-Premises environment for installation, configuration, maintenance, troubleshooting, updates, technical support, or authorized security and compliance activities.
Data Retention and Deletion
- Cytrusst shall retain Customer Data for the period reasonably necessary to provide the Services, fulfil contractual obligations, maintain security, comply with applicable legal and regulatory requirements, resolve disputes, and maintain required business records.
- Specific retention periods may be defined in the applicable agreement, Customer requirements, regulatory obligations, or Cytrusst's applicable data retention and secure deletion procedures.
- Following expiry or termination of the Customer's subscription, access to the Services may be disabled and Customer Data shall be handled in accordance with the applicable retention and deletion requirements.
- Customer Data may remain temporarily within backup systems following deletion from production systems until the applicable backup retention cycle is completed.
- Cytrusst may retain information for a longer period where required by applicable law, regulatory requirements, legal proceedings, dispute resolution, investigations, or legal claims.
- Where technically supported and legally permissible, the Customer may request deletion or export of Customer Data in accordance with the applicable agreement and technical capabilities.
Intellectual Property Rights and Content
- The Customer acknowledges that the Services contain proprietary software, technology, methodologies, workflows, designs, algorithms, APIs, documentation, templates, databases, and other intellectual property developed or acquired by Cytrusst.
- Cytrusst is the owner or authorized licensee of all rights, title, and interest in the Services and Cytrusst Content, including applicable copyrights, trademarks, service marks, logos, trade names, software, source code, APIs, workflows, algorithms, designs, and other intellectual property rights.
- Except for the limited rights expressly granted under these Terms or an applicable agreement, no right, title, or license is granted to the Customer in relation to Cytrusst's intellectual property.
- The Customer shall not copy, reproduce, modify, distribute, sell, lease, sublicense, reverse engineer, or create derivative works based upon Cytrusst intellectual property except as expressly permitted by applicable law or written agreement.
- Any unauthorized use of Cytrusst intellectual property may result in suspension or termination of access and may give rise to applicable legal remedies.
AI-Enabled Services
- Cytrusst may provide AI-enabled functionality as part of the Services.
- AI Features may include evidence analysis, compliance analysis, risk analysis, classification, recommendations, summarization, AI inventory, AI risk assessment, security analysis, report generation, and related capabilities.
- AI-generated outputs are generated based on the information available to the applicable system, model configuration, Customer Data, contextual information, and other technical factors.
- AI-generated outputs may contain inaccuracies, omissions, incomplete information, or recommendations requiring validation.
- The Customer shall conduct appropriate human review before relying on AI-generated outputs for material business, security, compliance, legal, regulatory, or other consequential decisions.
- Cytrusst does not represent or warrant that AI-generated outputs will always be accurate, complete, unbiased, current, or suitable for a particular purpose.
- Unless expressly agreed otherwise in writing, Customer Data shall not be used to train publicly available external AI models.
Subprocessors and Third-Party Providers
- Cytrusst may engage authorized third-party service providers, subprocessors, cloud service providers, AI service providers, security providers, infrastructure providers, and other technology providers in connection with the delivery, security, operation, and support of the Services.
- Such third parties may process Customer Data or Personal Data only to the extent necessary to provide the relevant services and subject to applicable contractual, confidentiality, security, privacy, and data protection requirements.
- Cytrusst shall maintain appropriate processes for evaluating and managing relevant third-party risks based on the nature of the services and information involved.
- Where required by applicable law or contractual requirements, Cytrusst may provide information regarding relevant subprocessors or third-party providers and applicable processing arrangements.
- The use of third-party AI services may be subject to additional terms, privacy practices, security controls, data processing arrangements, and technical limitations applicable to those services.
- Cytrusst shall remain responsible for managing its contractual and governance relationships with relevant third-party providers in accordance with applicable requirements.
Fees, Subscription and Payment
- Fees applicable to the Services shall be specified in the relevant Order Form, proposal, quotation, subscription agreement, or other applicable commercial agreement.
- The Customer shall pay all applicable fees within the payment period agreed between the parties.
- Applicable taxes and statutory charges shall be payable in accordance with applicable law.
- Subscription access and features may vary depending upon the applicable subscription plan or commercial arrangement.
- Cytrusst may modify its pricing or subscription plans for future subscription periods subject to applicable contractual requirements.
- Where applicable, Cytrusst may suspend Services following material non-payment after providing appropriate notice.
- Refunds, if applicable, shall be governed by the applicable commercial agreement.
Confidentiality
- All non-public information, technical information, security information, software, documentation, workflows, algorithms, architecture, business information, and other proprietary information disclosed by Cytrusst shall be treated as confidential information.
- The Customer shall not disclose Cytrusst's confidential or proprietary information to any third party without prior written authorization, except where disclosure is required by law.
- The Customer shall implement reasonable measures to prevent unauthorized access, copying, disclosure, or use of confidential information.
- Cytrusst shall similarly protect confidential Customer information received in connection with the Services.
- Confidentiality obligations shall survive termination of the Services for the period specified in the applicable agreement or as required by applicable law.
Security Testing
- The Customer shall not conduct penetration testing, vulnerability scanning, automated security testing, denial-of-service testing, or other intrusive testing against Cytrusst infrastructure without prior written authorization.
- Any authorized testing shall be performed within an agreed scope, target, methodology, timeframe, and testing window.
- The Customer may conduct security testing against its own On-Premises deployment provided that such testing does not adversely affect Cytrusst infrastructure, personnel, systems, or other Customers.
Disclaimer and Liability
- The Services are provided on an “AS IS” and “AS AVAILABLE” basis to the maximum extent permitted by applicable law.
- Cytrusst does not warrant that the Services will be uninterrupted, completely error-free, or capable of identifying every cybersecurity threat, vulnerability, risk, compliance gap, or security incident.
- Cytrusst does not warrant that all information obtained through integrations or third-party services will always be accurate, complete, current, or available.
- Cytrusst does not warrant that AI-generated outputs will always be accurate, complete, unbiased, or suitable for a particular purpose.
- The Services are intended to support the Customer's governance, risk, compliance, audit, cybersecurity, and security activities. The Customer remains responsible for its own legal, regulatory, security, compliance, business, and risk decisions.
- To the maximum extent permitted by applicable law, Cytrusst shall not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, revenue, business opportunities, goodwill, or data.
- Cytrusst's aggregate liability arising out of or relating to the Services shall be limited to the amount specified in the applicable commercial agreement.
- Where no separate liability cap has been agreed, Cytrusst's aggregate liability shall be limited to the fees actually paid by the Customer for the applicable Services during the twelve (12) months immediately preceding the event giving rise to the claim.
- Nothing in these Terms shall exclude or limit liability to the extent such exclusion or limitation is prohibited by applicable law.
Indemnification / Liability for Losses
- The Customer agrees to indemnify and hold Cytrusst harmless from claims, losses, damages, liabilities, costs, and expenses arising from
- Unauthorized use of the Services by the Customer or its Users
- Violation of these Terms
- Unlawful processing of Customer Data
- Infringement arising from Customer Content
- Misuse of the Services; or
- Violation of applicable law by the Customer.
- Additional indemnification obligations may be established under the applicable commercial agreement.
Service Suspension and Termination
Cytrusst may suspend or restrict access to the Services where reasonably necessary to
- Protect the security of the Services
- Prevent unauthorized access
- Address malicious or abusive activity
- Comply with applicable law
- Address a material breach of these Terms
- Address material non-payment; or
- Prevent harm to Cytrusst, its customers, or third parties.
- Where reasonably practicable, Cytrusst shall provide notice before suspension.
- Immediate suspension may be implemented where necessary to address an actual or suspected security threat, legal requirement, or material risk to the Services or other Customers.
- Upon termination, the Customer's access rights shall cease and Customer Data shall be handled in accordance with the applicable retention and deletion provisions.
- Any outstanding fees or other amounts due to Cytrusst shall remain payable following termination.
General
- These Terms, together with the applicable Order Form, Master Services Agreement, Service Level Agreement, Data Processing Agreement, Privacy Policy, and other expressly incorporated documents, constitute the agreement governing the Customer's use of the Services.
- Cytrusst may modify, update, or revise these Terms from time to time to reflect changes in the Services, technology, security requirements, legal or regulatory requirements, or business practices.
- Any updated Terms shall identify the applicable effective date. Continued use of the Services following the effective date may constitute acceptance of the revised Terms, subject to applicable contractual requirements.
- If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
- The failure of Cytrusst to enforce any provision of these Terms shall not constitute a waiver of its right to enforce such provision in the future.
- These Terms may be supplemented or modified by a written agreement between Cytrusst and the Customer.
- In the event of any inconsistency between these Terms and an applicable signed commercial agreement, the applicable commercial agreement shall prevail to the extent of such inconsistency.
Governing Law and Dispute Resolution
- These Terms shall be governed by and construed in accordance with the laws of India.
- The parties shall first attempt to resolve any dispute arising from or relating to these Terms through good-faith discussions between their authorized representatives.
- Where the dispute cannot be resolved through good-faith discussions, the dispute may be referred to arbitration or another dispute-resolution mechanism as specified in the applicable commercial agreement.
- Subject to any agreed dispute-resolution mechanism, courts having appropriate jurisdiction in Bengaluru, Karnataka, India shall have jurisdiction over disputes arising from these Terms.
Force Majeure / Events Beyond Our Control
Cytrusst shall not be liable for any failure or delay in performing its obligations where such failure or delay results from circumstances beyond its reasonable control, including natural disasters, government actions, war, civil unrest, telecommunications or internet failures, cloud infrastructure failures, widespread cyberattacks or security incidents, power failures, epidemics, pandemics, labor disruptions, or other circumstances beyond reasonable control.
Cytrusst shall take reasonable steps to mitigate the impact of such events and restore affected Services where reasonably practicable.
Contact Us
If you have any questions, concerns, or requests relating to these Terms, the Cytrusst Services, data processing, security, or privacy, you may contact us at:
Cytrusst Intelligence Private LimitedBengaluru, Karnataka, India- Website
- https://www.cytrusst.com/
- [email protected]
- Privacy Contact
- [email protected]
Acceptance
By accessing, registering, subscribing to, or using the Cytrusst Services, you acknowledge that you have read, understood, and agreed to these Terms & Conditions.