K9 Security Terms and Conditions
These terms govern use of k9 Security Inc.'s ("Company") software security services, including the k9 Security web application at k9security.io and the k9 Security MCP server at mcp.k9security.io, whether accessed directly or through an MCP-compatible client or AI agent acting on Customer's behalf (collectively, the "Services"). Company's collection and use of information is described in the Privacy Policy at https://www.k9security.io/privacy.
1. Definitions
1.1 "Alert" means a unique software vulnerability finding (identified by CVE, GHSA, or other advisory identifier, together with the affected package and the location where it was found) submitted to the Services for scoring. An Alert scored across multiple Customer-declared execution contexts in a single scoring run is metered as one Alert.
1.2 "Agent" means an MCP-compatible client, AI coding agent, or other software acting on Customer's behalf that accesses the Services using Customer's credentials.
1.3 "Customer Data" means data submitted by or on behalf of Customer to the Services, consisting of: (a) Alert identifiers and associated finding metadata; (b) reachability determinations and related analysis results produced by Customer's Agent; (c) the contents of Customer's risk-context files (e.g., .k9security/risk-context.yaml), including descriptions of Customer's assets, execution contexts, and exposure; and (d) Customer account, configuration, and contact information.
1.4 "Order Form" means a written ordering document for the Services executed by Company and Customer that references this Agreement.
1.5 "Outputs" means the risk scores, verdicts (including FIX_TODAY, REVIEW, SCHEDULE, and DEFER designations), triage reports, and related analyses generated by the Services for Customer.
1.6 "Rubric" means Company's risk-scoring rubric, methodologies, prompt resources, and related documentation, in any form, including as delivered into Customer's environment as MCP prompt resources.
1.7 "Third-Party Data" means threat-intelligence and exploit data licensed by Company from third parties and used in the Services, including VulnCheck KEV catalog data and FIRST EPSS scores, and any comparable substitute sources.
2. SaaS Services and Support
2.1 Subject to the terms of this Agreement, Company will use commercially reasonable efforts to provide Customer the Services in accordance with the Service Level Terms described at https://www.k9security.io/docs/legal/service-level-terms/. As part of the registration process, Customer will identify an administrative user for Customer's Company account, and users will authenticate through Company's designated identity provider. Company reserves the right to refuse or cancel registrations it deems inappropriate.
2.2 Subject to the terms hereof, Company will provide Customer with reasonable technical support services in accordance with the terms set forth at https://www.k9security.io/docs/legal/support-terms/.
2.3 The Services are provided as a standardized, multi-tenant hosted offering. Company does not provide customer-specific infrastructure, deployments, or modifications, and commitments in any Order Form are commercial terms that do not alter the standardized operation of the Services.
3. Restrictions and Responsibilities
3.1 Customer will not, directly or indirectly: reverse engineer, decompile, disassemble or otherwise attempt to discover the source code, object code or underlying structure, ideas, know-how or algorithms relevant to the Services or any software, documentation or data related to the Services ("Software"); modify, translate, or create derivative works based on the Services or any Software (except to the extent expressly permitted by Company or authorized within the Services); use the Services or any Software for timesharing or service bureau purposes or otherwise for the benefit of a third party, except that Customer may share Outputs as expressly licensed in Section 5.5; or remove any proprietary notices or labels. With respect to any Software that is distributed or provided to Customer for use on Customer premises or devices, Company hereby grants Customer a non-exclusive, non-transferable, non-sublicensable license to use such Software during the Term only in connection with the Services.
3.2 Further, Customer may not remove or export from the United States or allow the export or re-export of the Services, Software or anything related thereto, or any direct product thereof in violation of any restrictions, laws or regulations of the United States Department of Commerce, the United States Department of Treasury Office of Foreign Assets Control, or any other United States or foreign agency or authority. As defined in FAR section 2.101, the Software and documentation are "commercial items" and according to DFAR section 252.227 7014(a)(1) and (5) are deemed to be "commercial computer software" and "commercial computer software documentation." Consistent with DFAR section 227.7202 and FAR section 12.212, any use modification, reproduction, release, performance, display, or disclosure of such commercial software or commercial software documentation by the U.S. Government will be governed solely by the terms of this Agreement and will be prohibited except to the extent expressly permitted by the terms of this Agreement.
3.3 Customer represents, covenants, and warrants that Customer will use the Services only in compliance with this Agreement and all applicable laws and regulations. Customer will not use the Services to develop exploits for use against systems Customer is not authorized to test, to harm third parties, or in violation of applicable law. Customer represents and warrants that Customer has all rights, consents, and authorizations necessary to submit Customer Data to the Services and to connect the repositories, findings sources, and systems Customer connects, including, where Customer is an individual using the Services in connection with an employer's or other third party's systems or data, all authorization required from that employer or third party. Customer hereby agrees to indemnify and hold harmless Company against any damages, losses, liabilities, settlements and expenses (including without limitation costs and attorneys' fees) in connection with any claim or action that arises from an alleged violation of the foregoing or otherwise from Customer's use of Services. Although Company has no obligation to monitor Customer's use of the Services, Company may do so and may prohibit any use of the Services it believes may be (or alleged to be) in violation of the foregoing.
3.4 Customer shall be responsible for obtaining and maintaining any equipment and ancillary services needed to connect to, access or otherwise use the Services, including, without limitation, modems, hardware, servers, software, operating systems, networking, web servers, agents, and the like (collectively, "Equipment"). Customer shall also be responsible for maintaining the security of the Equipment, Customer account, passwords (including but not limited to administrative and user passwords) and files, and for all uses of Customer account or the Equipment with or without Customer's knowledge or consent. All access to and use of the Services through an Agent or otherwise using Customer's credentials is deemed access and use by Customer, whether or not authorized by Customer, and Customer is responsible for it.
4. Nature of the Services; No Security Guarantee
4.1 Risk prioritization only. The Services provide risk-prioritization information to assist Customer's own vulnerability management program. Outputs, including any DEFER or SCHEDULE verdict, are informational aids only. They are not remediation directives, and they are not a representation that any vulnerability is or is not exploitable, will or will not be exploited, or may safely be left unremediated. Customer retains sole responsibility for all remediation decisions, their timing, and the operation of Customer's security and vulnerability management program.
4.2 Customer-supplied reachability. Reachability determinations are generated by Customer's Agent, in Customer's environment, from Customer's code and other Customer inputs, applying the Rubric. Company does not access Customer's source code, does not perform or verify reachability analysis, and computes Outputs from Customer Data as supplied, together with Third-Party Data and the Rubric. Customer is responsible for the accuracy and completeness of Customer Data, including reachability determinations and risk-context files.
4.3 Point-in-time threat data. Threat and exploitability data changes continuously. Outputs reflect the Third-Party Data and Rubric version available at the time of scoring and may become outdated at any time, including where an Output identifies a forward-watch trigger or other condition for re-evaluation. Company does not undertake to notify Customer of changes affecting prior Outputs.
4.4 AI-assisted analysis. The Services operate with and through AI systems, including Customer's Agent, and Outputs may contain errors or omissions. Outputs designated REVIEW, and Outputs generally, require review by qualified Customer personnel. Company is not responsible for the conduct, configuration, or output quality of Customer's Agent or the underlying AI models Customer selects.
4.5 No compliance warranty. The Services may present Outputs in formats aligned with recognized frameworks (e.g., NIST SP 800-30). Company does not warrant that any Output will be accepted by any auditor, regulator, customer, or other party, or that use of the Services will satisfy any law, regulation, framework, or contractual obligation of Customer. The Services are not a substitute for Customer's own security program, scanning tools, or professional judgment.
5. Confidentiality; Proprietary Rights
5.1 Each party (the "Receiving Party") understands that the other party (the "Disclosing Party") has disclosed or may disclose business, technical or financial information relating to the Disclosing Party's business (hereinafter referred to as "Proprietary Information" of the Disclosing Party). Proprietary Information of Company includes non-public information regarding features, functionality and performance of the Service, and the Rubric. Proprietary Information of Customer includes Customer Data, including the contents of Customer's risk-context files. The Receiving Party agrees: (i) to take reasonable precautions to protect such Proprietary Information, and (ii) not to use (except in performance of the Services or as otherwise permitted herein) or divulge to any third person any such Proprietary Information. The Disclosing Party agrees that the foregoing shall not apply with respect to any information after five (5) years following the disclosure thereof or any information that the Receiving Party can document (a) is or becomes generally available to the public, or (b) was in its possession or known by it prior to receipt from the Disclosing Party, or (c) was rightfully disclosed to it without restriction by a third party, or (d) was independently developed without use of any Proprietary Information of the Disclosing Party or (e) is required to be disclosed by law; provided that, notwithstanding the foregoing time limit, each party's obligations with respect to any Proprietary Information constituting a trade secret of the other party continue for so long as the information remains a trade secret under applicable law.
5.2 Customer shall own all right, title and interest in and to the Customer Data. Company shall own and retain all right, title and interest in and to (a) the Services, Software, and Rubric, all improvements, enhancements or modifications thereto, (b) any software, applications, inventions or other technology developed in connection with the Services or support, and (c) all intellectual property rights related to any of the foregoing.
5.3 Scope of data collection. The Services are designed to receive only Customer Data as defined in this Agreement. The Services are not designed to receive, and Customer shall not submit, substantial portions of source code, credentials, secrets, or personal data beyond account and contact information. Code excerpts included in finding metadata, reachability rationales, and risk-context descriptions are part of Customer Data and are permitted. If material outside this scope is nevertheless submitted, Company may delete it without notice and has no obligation to preserve or return it.
5.4 Notwithstanding anything to the contrary, Company shall have the right to collect and analyze data and other information relating to the provision, use and performance of various aspects of the Services and related systems and technologies (including, without limitation, information concerning Customer Data and data derived therefrom), and Company will be free (during and after the term hereof) to (i) use such information and data to improve and enhance the Services and for other development, diagnostic and corrective purposes in connection with the Services and other Company offerings, and (ii) disclose such data solely in aggregate or other de-identified form that does not identify Customer or any Customer system.
5.5 Output license. As between the parties, Customer owns the Customer Data embodied in Outputs; Company owns the Rubric, the scoring logic, and the format and structure of Outputs. Company grants Customer a perpetual, non-exclusive, royalty-free license to use, reproduce, and distribute Outputs internally and to Customer's auditors, regulators, customers, prospective customers, and other counterparties in the ordinary course of Customer's business, provided Customer does not (a) remove proprietary notices, or (b) extract Third-Party Data from Outputs for standalone redistribution or resale.
5.6 Rubric license. Company grants Customer a non-exclusive, non-transferable, non-sublicensable license to use the Rubric during the Term solely in connection with the Services. Customer shall not use the Rubric, or permit it to be used, to develop, train, improve, or operate any product or service that competes with the Services.
5.7 Third-Party Data. Third-Party Data is licensed, not sold, and is provided AS IS. Company does not warrant the accuracy, completeness, or continuity of any Third-Party Data source and may substitute sources of comparable coverage at any time. Customer's use of Third-Party Data is limited to use within the Services and as embedded in Outputs.
5.8 No rights or licenses are granted except as expressly set forth herein.
6. Payment of Fees
6.1 Customer will pay Company the then applicable fees described in the subscription plan for the Services in accordance with the terms therein (the "Fees"). Fees are based on Alerts scored per billing period, as described in the plan applicable to Customer's subscription (including included Alert volume and per-Alert overage rates) at https://www.k9security.io/pricing/ or in an Order Form. An Alert scored in multiple Customer-declared execution contexts in a single scoring run is metered once. Each scoring run meters the Alerts it scores; re-scoring an Alert in a later run is metered again, because code, threat intelligence, and risk context change over time. Usage above the included volume is billed at the plan's overage rate in arrears with the next billing cycle, and Customer agrees to pay such additional Fees in the manner provided herein. Company reserves the right to change the Fees or applicable charges and to institute new charges and Fees effective at the start of a subsequent billing period or renewal term, upon thirty (30) days prior notice to Customer (which may be sent by email). If Customer believes that Company has billed Customer incorrectly, Customer must contact Company no later than 60 days after the closing date on the first billing statement in which the error or problem appeared, in order to receive an adjustment or credit. Inquiries should be directed to Company's customer support department at support@k9security.io.
6.2 Where Company bills through invoices under an Order Form, full payment for invoices issued in any given month must be received by Company thirty (30) days after the mailing date of the invoice. Unpaid amounts are subject to a finance charge of 1.5% per month on any outstanding balance, or the maximum permitted by law, whichever is lower, plus all expenses of collection and may result in immediate termination of Service. Customer shall be responsible for all taxes associated with Services other than U.S. taxes based on Company's net income.
7. Subscriptions; Term and Termination
7.1 Self-serve subscriptions. Unless an Order Form provides otherwise, subscriptions are month-to-month, renew automatically each billing period, and may be cancelled by Customer at any time through the account interface, effective at the end of the then-current billing period. Amounts paid are non-refundable except as required by law or expressly provided in this Agreement.
7.2 Order Form subscriptions. Where the parties execute an Order Form, this Agreement continues for the Initial Service Term specified in the Order Form and shall be automatically renewed for additional periods of the same duration (together with the Initial Service Term, the "Term"), unless either party requests termination at least thirty (30) days prior to the end of the then-current term, or as otherwise stated in the Order Form. For self-serve subscriptions, the "Term" is the period during which Customer maintains an active subscription.
7.3 Free trials. Company may offer free trials. Trial use is provided AS IS, without warranties, service levels, or support commitments, and either party may terminate a trial at any time. Company may modify or discontinue trial offerings at its discretion. If Customer does not subscribe within 30 days after a trial ends, Company may delete Customer Data associated with the trial.
7.4 In addition to any other remedies it may have, either party may also terminate this Agreement upon thirty (30) days' notice (or without notice in the case of nonpayment), if the other party materially breaches any of the terms or conditions of this Agreement. Customer will pay in full for the Services up to and including the last day on which the Services are provided.
7.5 Effect of termination; data export. Upon termination or expiration: (a) for 30 days, Customer may obtain an export of Customer Data and Outputs by written request to support@k9security.io; (b) thereafter, Company will delete Customer Data within 60 days, except as retained in routine backups (which expire in the ordinary course) or as required by law; and (c) Customer is responsible for retaining copies of any Outputs Customer requires for compliance, audit, or evidentiary purposes.
7.6 All sections of this Agreement which by their nature should survive termination will survive termination, including, without limitation, accrued rights to payment, confidentiality obligations, the Output license in Section 5.5, warranty disclaimers, and limitations of liability.
8. Warranty and Disclaimer
Company shall use reasonable efforts consistent with prevailing industry standards to maintain the Services in a manner which minimizes errors and interruptions in the Services. Services may be temporarily unavailable for scheduled maintenance or for unscheduled emergency maintenance, either by Company or by third-party providers, or because of other causes beyond Company's reasonable control, but Company shall use reasonable efforts to provide advance notice in writing or by e-mail of any scheduled service disruption. HOWEVER, COMPANY DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR FREE; NOR DOES IT MAKE ANY WARRANTY AS TO THE RESULTS THAT MAY BE OBTAINED FROM USE OF THE SERVICES. WITHOUT LIMITING SECTION 4, EXCEPT AS EXPRESSLY SET FORTH IN THIS SECTION, THE SERVICES ARE PROVIDED "AS IS" AND COMPANY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT.
9. Limitation of Liability
NOTWITHSTANDING ANYTHING TO THE CONTRARY, EXCEPT FOR BODILY INJURY OF A PERSON, COMPANY AND ITS SUPPLIERS (INCLUDING BUT NOT LIMITED TO ALL EQUIPMENT AND TECHNOLOGY SUPPLIERS), OFFICERS, AFFILIATES, REPRESENTATIVES, CONTRACTORS AND EMPLOYEES SHALL NOT BE RESPONSIBLE OR LIABLE WITH RESPECT TO ANY SUBJECT MATTER OF THIS AGREEMENT OR TERMS AND CONDITIONS RELATED THERETO UNDER ANY CONTRACT, NEGLIGENCE, STRICT LIABILITY OR OTHER THEORY: (A) FOR ERROR OR INTERRUPTION OF USE OR FOR LOSS OR INACCURACY OR CORRUPTION OF DATA OR COST OF PROCUREMENT OF SUBSTITUTE GOODS, SERVICES OR TECHNOLOGY OR LOSS OF BUSINESS; (B) FOR ANY INDIRECT, EXEMPLARY, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES; (C) FOR ANY MATTER BEYOND COMPANY'S REASONABLE CONTROL; OR (D) FOR ANY AMOUNTS THAT, TOGETHER WITH AMOUNTS ASSOCIATED WITH ALL OTHER CLAIMS, EXCEED THE FEES PAID BY CUSTOMER TO COMPANY FOR THE SERVICES UNDER THIS AGREEMENT IN THE 12 MONTHS PRIOR TO THE ACT THAT GAVE RISE TO THE LIABILITY, IN EACH CASE, WHETHER OR NOT COMPANY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
10. Modification of Terms
Company may modify this Agreement by posting the revised terms and providing notice by email or in-product message at least 30 days before the effective date. Revisions become effective on the stated effective date; Customer's continued use of the Services after that date constitutes acceptance. If a revision materially reduces Customer's rights, Customer may terminate the Agreement before the effective date and receive a pro-rata refund of prepaid, unused Fees. Where the parties have executed an Order Form, modifications to this Agreement do not reduce rights expressly negotiated in that Order Form or its addenda during its then-current term.
11. Miscellaneous
If any provision of this Agreement is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that this Agreement will otherwise remain in full force and effect and enforceable. This Agreement is not assignable, transferable or sublicensable by Customer except with Company's prior written consent. Company may transfer and assign any of its rights and obligations under this Agreement without consent. This Agreement, together with any Order Form and the documents incorporated by reference, is the complete and exclusive statement of the mutual understanding of the parties and supersedes and cancels all previous written and oral agreements, communications and other understandings relating to the subject matter of this Agreement. If there is a conflict among documents, the following order of precedence applies, each solely with respect to the conflict: (1) an executed Order Form and its addenda; (2) this Agreement; (3) the Service Level Terms and Support Terms; (4) documentation and policies incorporated by reference. Waivers must be in a writing signed by the waiving party; where the parties have executed an Order Form, amendments to that Order Form and its addenda must be in a writing signed by both parties, and this Agreement may otherwise be modified only as provided in Section 10. No agency, partnership, joint venture, or employment is created as a result of this Agreement and Customer does not have any authority of any kind to bind Company in any respect whatsoever. In any action or proceeding to enforce rights under this Agreement, the prevailing party will be entitled to recover costs and attorneys' fees. All notices under this Agreement will be in writing and will be deemed to have been duly given when received, if personally delivered; when receipt is electronically confirmed, if transmitted by facsimile or e-mail; the day after it is sent, if sent for next day delivery by recognized overnight delivery service; and upon receipt, if sent by certified or registered mail, return receipt requested. This Agreement shall be governed by the laws of the State of Arizona without regard to its conflict of laws provisions.
