1. The agreement
These Terms cover your use of the Cremit platform, our websites, our APIs and everything that goes with them, together, the Services. They are an agreement between you and Cremit Inc., which this document calls we or us.
You agree to them when you start using the Services, when you click a button that says you agree, or when you sign an order form that points to them. Whichever comes first.
If you are signing up for an organisation, you are telling us you have the authority to commit that organisation, and from there on, you means the organisation, not you personally. If you do not have that authority, or you do not agree with what is written here, please do not use the Services.
This is a binding contract. If you also sign an order form or an enterprise agreement that refers to these Terms and it says something different, that document wins on the point where they disagree.
2. Words we use
A few words carry a specific meaning throughout this document.
- An Authorized User is an employee, contractor or agent of yours that you let into the Services.
- Customer Data is everything you or your Authorized Users put into the Services or generate through them, secrets, identity metadata, logs and scan results included.
- The Documentation is the guides, technical docs and policies we publish.
- An Order Form is a document you and we both sign that sets out which Services you are buying, for how long, and at what price.
- A Subprocessor is a company we bring in to handle some part of Customer Data so that we can run the Services.
- Your Subscription Term is the period you have paid for, including any renewals.
3. The service and your licence
3.1 What the Services do
Cremit is a security platform for non-human identity. It finds machine identities and secrets, scans repositories and infrastructure for credentials that have been left exposed, helps you manage secrets through their life, and detects and responds to problems it finds. Which features you get, and any limits on how much you can use them, are set out in the Documentation and in your Order Form.
3.2 What you may do with them
As long as you keep to these Terms and pay what you owe, you may use the Services anywhere in the world, for your own organisation's work, for as long as your Subscription Term runs, in the way the Documentation describes. That permission is yours alone: you cannot transfer it or grant it to anyone else, and we can give the same permission to other customers.
3.3 What the licence does not cover
Neither you nor anyone acting through you may:
- reverse engineer or decompile the Services, or otherwise try to get at their source code;
- resell, sublicense, rent or lease the Services;
- use the Services to build something that competes with them, or benchmark them without asking us in writing first;
- get around usage limits, rate limits or access controls, or interfere with how the Services run;
- point the Services at systems, repositories or identities you have no right to scan.
4. Your account and connected sources
Keep your account credentials safe. What happens under your account is your responsibility, including what your Authorized Users do, and you need to make sure they follow these Terms too. If someone gets in who should not have, if credentials leak, or if you suspect a security incident touching the Services, tell us straight away.
Register with accurate details and keep your billing and admin contacts current, so our notices reach a real person. You also need the rights, consents and permissions that let us run the Services and handle Customer Data the way this agreement describes.
4.1 Sources you connect
The Services scan what you connect to them: repositories, messaging workspaces, cloud accounts and similar systems. For each one, you are telling us three things. That you own it or are allowed to grant access to it. That connecting it does not break that provider's own terms. And that scanning it is allowed under any agreement you have with third parties whose data might be sitting in it.
You decide how much access to give, and you can narrow it or take it back whenever you want. We work within whatever scope you set and do not ask for more.
We rely on what you tell us here. So do not connect a source you are not entitled to connect, and disconnect one once your authority over it ends.
5. What you must not do
You, your Authorized Users, and anyone acting through you must not:
- break the law or infringe anyone else's rights;
- upload or send malware, viruses, or anything else meant to damage or disrupt the Services or any other system;
- try to reach parts of the Services, other customers' accounts, or our own infrastructure that you have not been given access to;
- use the Services to harass or defame anyone, to invade someone's privacy, or to collect personal information without a lawful basis for doing so;
- probe, scan or test the Services for vulnerabilities, unless you are following a coordinated-disclosure programme we have published.
If we think one of these has happened, we may look into it, and we may suspend the account. Section 14 explains how.
6. Your data
6.1 It stays yours
Customer Data belongs to you. Nothing here changes that. You give us permission to handle it for a narrow set of reasons, to run the Services, keep them secure, maintain them and improve them, and for anything else these Terms or our Privacy Policy allow. Nothing beyond that.
6.2 Personal data
When we handle personal data on your behalf, our Privacy Policy governs how, along with a Data Processing Addendum where one applies. If the GDPR, the UK GDPR, Korea's PIPA or a comparable law applies to you, ask us and we will provide a DPA.
6.3 How we protect it
We keep administrative, technical and physical safeguards in place to protect Customer Data from being accessed, lost or disclosed without authorisation, at the standard expected of a SaaS provider.
6.4 Companies we bring in
We use Subprocessors to run the Services. Ask us for the current list and we will send it. Each of them is held to data-protection obligations at least as strict as the ones in this agreement.
7. Fees, billing and tax
7.1 What you pay
You pay the fees in your Order Form, or the ones shown when you subscribed online. Unless this agreement says otherwise, fees are not refundable and payments cannot be cancelled once made.
7.2 How we bill
Unless your Order Form sets out something different, we invoice subscription fees up front, monthly or annually. Payment is due within thirty days of the invoice date, or on the date in your Order Form. Late amounts can accrue interest at 1.5% a month, or at the highest rate the law allows, if that is lower.
7.3 Tax
Our prices do not include tax. VAT, sales tax, use tax, withholding tax and anything similar are yours to pay. Tax on our own income is ours.
7.4 Renewal
Subscriptions renew automatically for another period the same length as the last one, unless one of us gives the other written notice at least thirty days before the current period ends.
8. Free trials and beta features
Sometimes we offer the Services, or a particular feature, as a free trial or a beta, Trial/Beta Services. These come as they are, with no warranty of any kind. We can change them, pause them or stop them at any time, and data tied to them may be deleted when the trial or beta ends.
If you do not buy a paid subscription before the trial ends, your access ends with it. Sections 6 (Your data), 9 (Confidentiality), 10 (Who owns what), 12 (Limits on liability), 13 (Third-party claims) and 15 (Other terms) carry on applying afterwards.
9. Confidentiality
Confidential Information is non-public information one of us, the Discloser, gives the other, the Recipient, that is either marked confidential or clearly ought to be treated that way. Ours includes the Services themselves, our pricing and our non-public technical information. Yours includes Customer Data.
Whoever receives it protects it as carefully as they protect their own confidential information of the same kind, and never less carefully than is reasonable. They use it only to do what this agreement requires or allows. They do not pass it on, except to employees, advisers and Subprocessors who are under equivalent confidentiality obligations.
The law can override this. If a Recipient is legally required to disclose Confidential Information, it may, but it tells the Discloser first, with enough notice to respond, unless the law forbids even that.
10. Who owns what
The Services, the Documentation and the intellectual property behind them belong to us and our licensors. Section 3.2 grants you permission to use them; beyond that, nothing here transfers any of it to you.
If you send us Feedback, a suggestion, a complaint, an idea for a feature, we can build it into the Services and use it however we like, worldwide, free of charge, permanently, with nothing owed back to you. Send it anyway; it is how the product gets better.
We would like to name you as a customer on our website and in marketing material, and we will follow your brand guidelines when we do. Tell us in writing to stop, and we stop.
11. What we promise, and what we do not
11.1 Our promise
During your Subscription Term, the Services will work substantially as the Documentation says they do. If they do not, tell us. We will either fix the problem or, if we cannot fix it within reason, end the affected Services and refund whatever you have prepaid for the period after that. That is the remedy for a broken promise under this section, and it is the whole of our liability for it.
11.2 Uptime, and what you get if we miss it
We aim for the Services to be available 99.5% of each calendar month. That leaves room for about three and a half hours of downtime a month, which is what we are willing to stand behind rather than what we hope for.
We measure from outside our own network, from three places at once, Seoul, Tokyo and Singapore. Every five minutes each of them checks both the console and the API, and if either is failing, that moment counts as downtime.
Two rules keep the measurement honest. A check counts as failed only when a majority of the three agree, because one probe going quiet is more often that probe's route than our service. And a failure has to be confirmed by the next check before it counts at all, a single blip is not an outage. Once it is confirmed, though, the clock runs from the first failure rather than the second, so a real outage is measured from when it started.
Monthly uptime is the minutes in the month less the unavailable minutes, divided by the minutes in the month. Time excluded under the list below comes out of both halves of that sum, not just the top.
If we come in under 99.5%, ask and we will credit that month's fees:
- below 99.5%, 10% of the fees for that month
- below 99.0%, 25%
- below 95.0%, 50%
Send the request to security@cremit.io within thirty days of the end of the affected month, with the dates and times you saw. We apply the credit to a future invoice; it is not paid out in cash, and credits for a month cannot exceed that month's fees. This is the remedy for missed uptime, and the only one.
Four things do not count as downtime:
- scheduled maintenance we announce at least 48 hours ahead, which we keep under four hours a month and outside 09:00–18:00 Korean time, plus emergency maintenance where waiting would leave a security hole open;
- problems originating in your own systems, network or configuration, or in a third-party service you connected;
- suspension under Section 14.3, or your own breach of Section 5; and
- events outside our reasonable control, as described in Section 15.7.
Free trials and beta features are not covered by this section.
11.3 What we cannot promise
Apart from the promises in 11.1 and 11.2, the Services come "as is" and "as available". We disclaim every other warranty, whether stated outright or implied by law, including implied warranties of merchantability, fitness for a particular purpose, title and non-infringement.
We do not promise that the Services will run uninterrupted or error-free, that they will be free of harmful components, or that they will catch every security problem in your environment. A scanner that finds nothing is not proof that there is nothing to find, and no security tool should be your only line of defence.
12. Limits on liability
To the fullest extent the law allows, neither of us is liable to the other for indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, lost revenue, lost goodwill or lost data arising out of or in connection with these Terms, even if we were warned that such losses were possible.
Each side's total liability under these Terms is capped at what you paid or owe us for the Services during the twelve months before whatever caused the liability.
Neither limit applies to:
- what either of us owes under Section 13 (Third-party claims);
- fees you owe us;
- a breach of Section 9 (Confidentiality); or
- gross negligence, deliberate misconduct or fraud.
13. Third-party claims
Sometimes an outsider brings a claim that is really about something one of us did. This section decides who handles it.
13.1 Claims we take on
If someone claims the Services infringe a valid patent, copyright or trade secret, we will defend you and cover what is finally awarded against you or agreed in settlement. This covers the Services as we provided them and as you used them under these Terms.
13.2 Claims you take on
You will defend us and cover what is finally awarded against us or agreed in settlement, where the claim arises from your Customer Data, from your breach of Section 5 (What you must not do), or from using the Services in a way that breaks the law.
13.3 How it works in practice
Whichever of us is being defended tells the other about the claim promptly, and hands over control of the defence and any settlement. The one running the defence pays for the cooperation it asks for. A settlement that puts a non-monetary obligation on the defended party needs that party's agreement.
14. Suspension and ending the agreement
14.1 How long this lasts
These Terms apply throughout your Subscription Term and any renewals of it.
14.2 Ending it for breach
Either of us can end this agreement by giving the other thirty days' written notice of a serious breach that is still unfixed when those thirty days run out. We can end it immediately if you breach Section 5, or if an undisputed invoice is still unpaid fifteen days after we have written to you about it.
14.3 Suspending access
We can suspend access if how you are using the Services puts the Services or other people at security risk, degrades things for other customers, or breaks Section 5. We will try to warn you first where that is practical.
14.4 What happens afterwards
Your access ends. For thirty days after that, you can still export Customer Data; once that window closes, we may delete it from our production systems, keeping only what the law requires us to keep. Anything you already owe us, you still owe.
15. Other terms
15.1 Which law applies, and where disputes go
Korean law governs this agreement, without applying its conflict-of-laws rules. Disputes go to the Seoul Central District Court (서울중앙지방법원) as the court of first instance. The exception is urgent injunctive relief, which either of us can seek from any court that will hear it.
15.2 Changes to these Terms
We update these Terms from time to time. For a change that matters, we give you at least thirty days' notice by email or in the product. It takes effect on the date in that notice, and using the Services after that date means you accept it.
15.3 Changes to the Services
We keep working on the product, so features get added, changed and removed. What we will not do is significantly cut back the core of what you are paying for, mid-term, without reasonable notice.
15.4 Handing this agreement to someone else
Neither of us can transfer this agreement without the other's written consent. The exception is a transfer to an affiliate, or as part of a merger, acquisition or sale of substantially all of the business, that needs no consent.
15.5 Notices
Send notices to us at security@cremit.io. We will send ours to the email address on your account, or show them in the product.
15.6 Export control and sanctions
Each of us follows the export-control and sanctions laws that apply to us. You are telling us that you are not in, established under the laws of, or ordinarily resident in a country under comprehensive sanctions; that you are not on a restricted-party list; and that you will not pass the Services to anyone who is. You also will not use the Services in breach of those laws, or export any part of them where that is prohibited.
15.7 Events outside our control
Neither of us is liable for a delay or failure caused by something we could not reasonably control, natural disaster, war, terrorism, industrial action, utility failure or government action.
15.8 The whole agreement
These Terms, together with any Order Form, DPA and our Privacy Policy, are the entire agreement about the Services, and they replace anything agreed before. If a court finds part of them unenforceable, that part is narrowed as far as needed to work and the rest stands. And if one of us does not enforce something straight away, that is not us giving up the right to enforce it later.
15.9 Our relationship
We are independent contractors. This agreement does not make us anyone's agent, partner or joint venturer.
16. Contact
Questions about these Terms? Write to us.