Terms of use

The agreement under which Cloudheal is provided, and what each side owes the other.

This is the wording in force. It took effect on .

The agreement

These terms govern use of Cloudheal, the exposure management platform provided by Cloudheal Solutions (India) Private Limited ("Authorised User") at easm.cloudheal.com. These terms are binding on the customer organisation. The customer must ensure that every person to whom it provides access to Cloudheal complies with the provisions of these terms that relate to use of and access to the platform, including the Acceptable Use Schedule.

The acceptable use schedule and the privacy notice form part of them.

What the platform does

Cloudheal discovers what an organisation exposes to the internet and reports what it finds. A customer adds a root domain, and the platform discovers the subdomains and assets beneath it rather than requiring each to be listed.

One scan runs every module the customer holds. A scan normally takes six to eight hours and varies widely, and long quiet periods while one runs are normal. Access to a module governs which findings may be read rather than what the scan looks for.

Findings are graded, and the exposure score runs from zero to nine hundred where a higher score is safer.

What the platform does not promise

We provide the platform with reasonable skill and care. We do not promise that it will find every exposure an organisation has, and an absence of findings is not a statement that no exposure exists. What a scan can see depends on what is reachable while it runs.

Findings are information for the customer to act on. They are not advice, and using the platform is not a substitute for the customer's own security programme. The customer is responsible for evaluating findings, determining the appropriate response and implementing any remediation or security measures. We do not warrant that a finding is free from false positives or false negatives or that remediation of a finding will eliminate all security risk.

Except as set out in these terms, and to the extent the law allows, all other warranties and conditions are excluded.

Liability

Neither party limits its liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot be limited by law.

Neither party is liable to the other for loss of profit, loss of revenue, loss of goodwill, loss of anticipated savings, or for any indirect or consequential loss.

Each party's total aggregate liability arising out of or in connection with this agreement in any twelve-month period will not exceed the total amount actually paid by the customer for the credits allocated to the account at the time of the event giving rise to the claim.

Accounts and access

Access is by invitation. A person is invited by email and sets their own password through a one-time link, so no password is ever issued to them or known to anyone else.

One email address is one account, and one account belongs to one organisation. A person who needs access to more than one organisation needs a separate account on a separate address, and they cannot hold both open in one browser at the same time.

An administrator may change a person's role, disable them, or remove them from the organisation. Disabling stops a person signing in and keeps their history. Removal hides them from the organisation and does not erase what they did.

The customer is responsible for who it invites, for the acts of the people it invites, and for keeping their credentials secure. The customer will tell us promptly if it believes an account has been compromised. The customer must ensure that each Authorised User keeps their account credentials confidential and does not share or permit another person to use their account. The customer is responsible for activity carried out through its Authorised Users' accounts, except to the extent caused by our breach of this agreement or failure to maintain the security of the platform.

Authorisation to scan

A scan is an active test against live infrastructure. The customer may add only domains it owns or holds written authorisation to test. This is set out in the acceptable use schedule. The customer is solely responsible for ensuring that it has all rights, permissions and authorisations necessary for Cloudheal and its service providers to perform the scans and security testing requested by the customer.

Credits

Scans are paid for in credits. A credit is committed when a scan starts, and the number of assets a scan covered is known only once it has finished, so the platform holds an amount at the start and settles it against the true figure at the end.

Stopping a scan pauses it. The credits committed stay held while it is paused, and are neither returned nor spent until the scan completes or ends.

Credits are not refundable and do not expire. Where a scan ends without completing, the treatment of the amount held is set out in the applicable invoice, purchase order, or executed customer agreement. Credits are non-refundable except as expressly stated in the applicable invoice, purchase order, or executed contract. The validity or expiry of credits and the treatment of credits committed to a scan that does not complete will be as set out in the applicable invoice, purchase order, or executed contract.

The customer's data

As between the parties, the customer retains all rights in data and information supplied by or on behalf of the customer to Cloudheal ("Customer Data"). The customer may use findings and reports generated by Cloudheal for its internal business and cybersecurity purposes, subject to these terms. We hold them to provide the platform and for no other purpose, and we do not use them to train models or to build products.

How personal data is handled is set out in the privacy notice. Where we process personal data on behalf of the customer as a Data Processor, such processing will also be subject to any applicable data processing terms agreed between the parties.

Removing a domain, a scan or an organisation hides it rather than erasing it, so that audit records, the credit ledger and the record of who revealed a dark web value survive. The privacy notice explains what this means and what erasure is available.

Intellectual property

We and our licensors retain all right, title and interest in and to Cloudheal, including the software, technology, methodologies, interfaces, documentation, designs and other intellectual property used to provide the platform.

Subject to these terms and payment of the applicable charges, we grant the customer a limited, non-exclusive, non-transferable right during the term to permit its Authorised Users to access and use Cloudheal for the customer's internal business and cybersecurity purposes.

Except for the rights expressly granted under these terms, no intellectual property rights are transferred to the customer.

Confidentiality

Each party will keep the other's confidential information confidential, will use it only to perform this agreement, and will disclose it only to those who need it and are under equivalent obligations. This does not apply to information that is public through no fault of the receiving party, was already known to it, is lawfully received from a third party without an obligation of confidentiality, or is independently developed without use of the other party's confidential information or must be disclosed by law.

A customer's findings are its confidential information.

Suspension

We may suspend a customer's access, or one person's access, where we reasonably believe that the platform is being used to scan assets the customer is not authorised to test, that an account has been compromised, that the acceptable use schedule has been breached, or that continued access presents a risk to the platform or to a third party.

Where it is practical to do so we will tell the customer before we suspend, and say why. Where the risk does not allow that, we will tell them within one working day of suspending.

Access is restored once the matter is resolved to our reasonable satisfaction. A suspension does not relieve the customer of charges falling due during it, and does not extend the term.

Term and termination

This agreement begins for a customer organisation when its first user account or administrator ID is created. It remains in effect until the organisation's access is formally terminated or revoked.

Account status and credits: The presence of an active credit balance on an account constitutes an assumption and acknowledgment by both parties that the customer has already paid for those services. The agreement remains active while paid credits are being consumed in accordance with the "Credits" section.

Termination rights: A customer organisation may terminate this agreement at any time by requesting the removal or deletion of their organisation account. We reserve the right to terminate this agreement and permanently revoke access to the organisation and all associated user IDs instantly and without prior notice at our sole discretion, including but not limited to cases of suspected platform abuse, credential sharing, or any breach of these terms.

Effect of termination

The moment this agreement ends or an organisation's access is permanently revoked:

General

These terms are governed by the laws of India, and the courts at Mumbai have exclusive jurisdiction, subject to the paragraph below.

Each party will comply with applicable laws and regulations in connection with its performance of this agreement. The customer will use Cloudheal only for lawful purposes and in accordance with the Acceptable Use Schedule.

If the dispute is not resolved through such discussions, it will be referred to and finally resolved by arbitration in accordance with the Arbitration and Conciliation Act, 1996. The arbitration will be conducted by a sole arbitrator mutually appointed by the parties. If the parties are unable to agree on the appointment, the arbitrator will be appointed in accordance with the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration will be Mumbai, India, and the arbitration will be conducted in English.

Neither party may assign this agreement without the other's written consent, which will not be unreasonably withheld, except to a purchaser of substantially the whole of its business.

Any change to these terms must be in writing. We may change them on thirty days' written notice; if the customer does not accept a change it may end this agreement before it takes effect, without penalty.

Notices must be in writing and sent to Unit 101/B-1, First Floor, Raheja Plaza-1, LBS Marg, Ghatkopar West, Mumbai - 400086 or to the address the customer gave, and are treated as received on delivery or, if by email, on the next working day.

Neither party is liable for failure to perform caused by something beyond its reasonable control, provided it tells the other and works to resume.

These terms, the acceptable use schedule, the privacy notice and the applicable invoice, purchase order, or executed customer agreement are the whole agreement between the parties on this subject. If any provision is unenforceable the rest stands. If there is any conflict between the documents forming this agreement, the applicable invoice, purchase order, or executed customer agreement will prevail over these Terms of Use in respect of the commercial terms expressly stated in it, these Terms of Use will prevail over the Acceptable Use Schedule, and the Privacy Notice will govern the processing of personal data. A failure to enforce a right is not a waiver of it. Nothing in this agreement creates a partnership, and no third party may enforce it.

These terms are version V1, issued on 30 September 2026.