Agreement and eligibility
These Terms of Service (“Terms”) are between DarkRisk (Pty) Ltd (“DarkRisk”, “we”, “us”, or “our”) and the person or organisation accessing or using our websites, third-party risk management platform, software, support, and related services (together, the “Services”).
By accessing or using the Services, creating an account, or accepting an order that refers to these Terms, you agree to them. If you use the Services for an organisation, you represent that you have authority to bind it, and “you” means that organisation. If you do not agree, do not use the Services.
You must be at least 18 and legally capable of entering into a binding agreement. The Services are intended for business use. If a signed master agreement, order form, data processing agreement, or other written agreement between you and DarkRisk conflicts with these Terms, that agreement controls to the extent of the conflict.
Accounts and authority
You must provide accurate account information and keep it current. Account credentials are personal to the authorised user and may not be shared. You are responsible for activity under your account and for ensuring that your authorised users comply with these Terms.
Keep credentials and authentication methods secure, use reasonable safeguards, and notify us promptly at [email protected] if you suspect unauthorised access or misuse. We may rely on instructions given through your account. Customer administrators may manage users, permissions, integrations, and Customer Data associated with their organisation.
Services and changes
Subject to these Terms and any applicable order, DarkRisk grants you a limited, non-exclusive, non-transferable, non-sublicensable right during the subscription term to access and use the Services for your internal business purposes. The Services may include risk assessments, ratings, questionnaires, findings, reports, integrations, dashboards, and other tools.
We may improve, update, or modify the Services over time. We will not materially reduce the core functionality of a paid Service during an active subscription term without reasonable notice, except where necessary for security, legal compliance, or to prevent harm. Preview, beta, or evaluation features may be changed or withdrawn at any time and are provided without a service-level commitment unless we agree otherwise in writing.
Risk information and outputs are decision-support tools, not legal, audit, financial, or professional advice. Security conditions change, public and third-party data can be incomplete, and no score or assessment guarantees that an organisation is secure or free from incidents. You remain responsible for your decisions, controls, investigations, and vendor relationships.
Acceptable use
You must not, and must not help anyone else to:
- use the Services unlawfully, fraudulently, or to infringe another person's rights;
- upload malicious code or content that is illegal, deceptive, abusive, or harmful;
- probe, scan, penetrate, or test systems without the owner's clear authorisation;
- disrupt the Services, bypass rate limits or safeguards, or gain unauthorised access;
- reverse engineer, decompile, copy, frame, mirror, or create derivative works of the Services except where law expressly permits;
- scrape or extract data at scale, including through automated means, unless DarkRisk has authorised it in writing;
- resell, sublicense, rent, or provide the Services to third parties except as expressly permitted in an order;
- use the Services or their output to build or benchmark a competing product without our written consent;
- remove proprietary notices or misrepresent the source, ownership, or reliability of information; or
- submit information that you do not have the right, authority, or lawful basis to process.
A reference to a third party in a risk workflow does not authorise intrusive testing or access to that party's systems. Security research involving DarkRisk must follow the policy at security.darkrisk.io.
Customer Data
“Customer Data” means information, files, records, and other content submitted to or collected through the Services on your behalf, excluding DarkRisk technology, service telemetry, and information that has been aggregated or de-identified so it cannot reasonably identify you, an individual, or your organisation.
As between you and DarkRisk, you retain your rights in Customer Data. You grant DarkRisk and its authorised subprocessors a worldwide, limited right to host, copy, transmit, display, and otherwise process Customer Data only as necessary to provide, protect, support, and improve the Services, comply with law, and perform our agreement with you. This right lasts only as long as needed for those purposes.
DarkRisk does not sell Customer Data. We do not use Customer Data to train general-purpose artificial intelligence models.
You are responsible for the accuracy, quality, legality, and means of acquiring Customer Data, and for providing notices and obtaining permissions required for us to process it. Do not submit regulated or highly sensitive data unless its processing is covered by your order and any required written agreement.
Privacy and security
Our Privacy Policy describes how we process personal information when acting for our own purposes. Where DarkRisk processes personal information in Customer Data on your instructions, the applicable data processing terms govern that processing.
We maintain reasonable technical and organisational safeguards designed to protect the Services and Customer Data. More information about our security programme is available at security.darkrisk.io. You acknowledge that no online service is completely secure and agree to use the security features made available to you.
Third-party services
The Services may interoperate with or link to services operated by third parties. If you enable an integration, you instruct us to exchange relevant information with that provider. Your use of the third-party service is governed by your agreement with that provider, and DarkRisk is not responsible for third-party products, content, availability, or independent acts.
We use infrastructure providers and subprocessors to deliver the Services. Our current disclosures are maintained at trust.darkrisk.io. We remain responsible for our obligations under these Terms when using subcontractors.
Fees and taxes
Fees, subscription limits, payment dates, and the subscription term are stated in your order. Unless an order says otherwise, fees are quoted exclusive of VAT and other applicable taxes, are payable in South African rand, and are non-cancellable and non-refundable except where these Terms or applicable law expressly provide otherwise.
You must pay undisputed invoices by the due date. If you dispute an invoice in good faith, notify us promptly and work with us to resolve it. We may charge lawful interest on overdue undisputed amounts and suspend paid Services after giving reasonable notice and an opportunity to cure. Subscription renewal and price changes apply only as set out in your order or in a notice provided before the next renewal term.
Intellectual property and trademarks
DarkRisk and its licensors retain all rights, title, and interest in the Services, including software, models, methods, interfaces, documentation, designs, reports and report formats, aggregated insights, and all related intellectual property. Except for the limited access right in these Terms, no rights are granted to you by implication, estoppel, or otherwise.
DarkRisk, the DarkRisk name and logo, and our product names, service names, designs, and slogans are trademarks or protected brand assets of DarkRisk (Pty) Ltd. You may not use them in a business name, domain, product, advertising, endorsement, or manner likely to cause confusion without our prior written permission. Third-party names and marks belong to their respective owners.
If you provide suggestions or feedback, you grant DarkRisk a perpetual, irrevocable, worldwide, royalty-free right to use it without restriction or obligation, provided we do not identify you publicly as its source without permission.
Confidentiality
“Confidential Information” means non-public information disclosed by one party to the other that is marked confidential or should reasonably be understood as confidential, including Customer Data, security information, product plans, pricing, and business or technical information.
The receiving party will use Confidential Information only to perform or exercise rights under the agreement, protect it with at least reasonable care, and disclose it only to personnel, advisers, and service providers who need to know it and are bound by appropriate confidentiality duties. These obligations do not apply to information that the receiving party can show was lawfully known without restriction, independently developed, received lawfully from another source, or made public without breach.
A party may disclose Confidential Information when legally compelled, provided it gives advance notice where legally permitted and reasonable assistance, at the disclosing party's cost, if protection is sought.
Suspension and termination
We may suspend access where reasonably necessary to address a security risk, unlawful use, material breach, threat to the Services or another customer, or overdue undisputed fees. Where practicable, we will give notice and limit the suspension to the affected use while working with you to resolve the issue.
Either party may terminate for a material breach that is not cured within 30 days after written notice, or immediately if the breach cannot be cured. Either party may also terminate if the other enters liquidation, business rescue, or similar insolvency proceedings, subject to applicable law. Convenience termination and non-renewal rights are governed by your order.
On expiry or termination, your right to use the Services ends and outstanding amounts become due. At your written request made before termination or within the retrieval period stated in your order, we will make Customer Data available for export where the Services support it. We may then delete Customer Data in line with our retention practices and legal duties. Provisions intended by their nature to survive—including payment, confidentiality, intellectual property, disclaimers, indemnity, and liability limits—will survive.
Disclaimers
We warrant that paid Services will perform in all material respects in accordance with their applicable documentation. Your exclusive remedy for breach of this warranty is for us to use reasonable efforts to correct the non-conformity; if we cannot do so, either party may terminate the affected Service and we will refund prepaid fees covering the unused remainder of its term.
To the fullest extent permitted by law, and except for that express warranty, the Services are provided “as is” and “as available”. DarkRisk disclaims implied warranties of merchantability, fitness for a particular purpose, non-infringement, uninterrupted availability, and accuracy. We do not warrant that every vulnerability, threat, vendor issue, or security event will be identified or prevented.
Nothing in these Terms excludes a warranty, right, or remedy that cannot lawfully be excluded, including any mandatory rights under the Consumer Protection Act 68 of 2008 where it applies.
Indemnity
To the extent permitted by law, you will defend and indemnify DarkRisk and its officers, employees, and affiliates against third-party claims, damages, and reasonable costs arising from your Customer Data, your unlawful or unauthorised use of the Services, or your material breach of the acceptable-use obligations. This does not apply to the extent a claim was caused by DarkRisk's breach, negligence, or wilful misconduct.
We will promptly notify you of a covered claim and provide reasonable cooperation at your cost. You may control its defence and settlement, but may not admit liability for DarkRisk, require DarkRisk to pay money, or impose non-financial obligations on DarkRisk without our written consent.
Limitation of liability
To the fullest extent permitted by law, neither party will be liable under or in connection with the Services for indirect, incidental, special, exemplary, or consequential loss, or for loss of profits, revenue, goodwill, anticipated savings, or business opportunity, even if advised that such loss was possible.
Except for excluded claims below, each party's total aggregate liability arising out of or relating to the Services will not exceed the fees paid or payable for the affected Services during the 12 months before the event giving rise to liability. If no fee was payable, DarkRisk's total aggregate liability will not exceed ZAR 1,000.
These exclusions and caps do not apply to liability that cannot lawfully be limited, fraud or wilful misconduct, death or personal injury caused by negligence, your payment obligations, your infringement or misuse of intellectual property, or your indemnity obligations. The limitations apply collectively to all claims, regardless of their legal basis.
Governing law and disputes
These Terms and any non-contractual dispute arising from them are governed by the laws of the Republic of South Africa, without regard to conflict-of-law principles. Before starting formal proceedings, each party will give written notice describing the dispute and allow at least 30 days for authorised representatives to try to resolve it in good faith.
If the dispute is not resolved, the parties submit to the courts of South Africa with jurisdiction in Johannesburg, Gauteng. Either party may seek urgent injunctive or similar relief at any time to protect confidential information, intellectual property, security, or data.
General terms
- Notices. Legal notices must be in writing. Notices to DarkRisk must be sent to [email protected]. We may send notices to the account email or through the Services.
- Assignment. You may not assign the agreement without our written consent, except with your entire business in a merger or sale of substantially all relevant assets where the assignee is not our direct competitor and can perform the agreement. We may assign it in connection with a reorganisation, merger, financing, or sale of our business.
- Force majeure. Neither party is liable for delay caused by events beyond its reasonable control, except for payment obligations.
- Independent parties. The parties are independent contractors. These Terms do not create an agency, partnership, joint venture, employment, or fiduciary relationship.
- No third-party beneficiaries. Unless expressly stated, no other person has a right to enforce these Terms.
- Waiver and severability. A failure to enforce a right is not a waiver. If a provision is unenforceable, it will be adjusted only as much as necessary and the remainder will continue in effect.
- Entire agreement. These Terms, each applicable order, and documents incorporated by reference form the entire agreement about the Services and replace earlier proposals or discussions on that subject.
Changes and contact
We may update these Terms to reflect changes in law, security, or the Services. The effective date above identifies the current version. Material changes will apply prospectively, and we will provide reasonable notice where required. For a paid subscription, materially adverse changes will generally take effect at the next renewal unless earlier application is needed by law or for security.
Questions about these Terms or requests for earlier versions may be sent to [email protected].