Terms of Service
These terms are the agreement between you and cloudDFN LLP for using the Kervo AI platform, which we previously sold as cDFN WatchTower. They cover the platform itself, its scanners, AI agents and integrations, and the website at https://kervo.ai.
We process it only to provide the Platform, as your processor.
You may only connect, scan or test assets you own or are authorised to assess.
AI CISO, AI Analyst and compliance evidence support your decisions. They do not replace them.
1. Acceptance of these Terms
These Terms of Service (the "Terms") are a binding agreement between cloudDFN LLP ("cloudDFN", "we", "us", "our") and the customer named in a Quotation, Purchase Order or account registration ("Customer", "you"). They govern access to and use of the Kervo AI platform, which we previously offered as cDFN WatchTower, along with its scanners, agents, integrations, APIs, documentation and the website at https://kervo.ai (together, the "Platform").
You accept these Terms when you issue a Purchase Order against one of our Quotations, pay one of our Invoices, create an account, accept an invitation, or use the Platform. If you are acting for an organisation, you confirm that you have authority to bind it, and "you" means that organisation.
If a Quotation, master services agreement or Data Processing Agreement ("DPA") between you and cloudDFN conflicts with these Terms, that document governs for its own subject matter. Terms printed on or attached to a Purchase Order do not apply unless we accept them in writing.
2. Definitions
Authorised Users means your employees and contractors, and, where you use the vendor risk features, the vendor representatives you invite to the Platform under your account.
Customer Environment means the domains, IP ranges, cloud accounts, code repositories, devices, identity providers, endpoints and other systems you connect to or register with the Platform.
Customer Data means data that you or your Authorised Users submit to the Platform, and data the Platform collects from your Customer Environment on your instruction. It includes asset inventories, configurations, findings, evidence, logs and reports.
Quotation means the written quotation or proposal we issue to you. It sets out the capabilities included, the scope, the fees and the subscription term.
Purchase Order means the written order you issue to accept a Quotation.
Invoice means the invoice we issue to bill the fees in a Quotation and Purchase Order.
Proof of Value or Trial means time-limited access to the Platform that we provide free of charge so you can evaluate it.
Third-Party Services means products and services that cloudDFN does not provide and that you connect to the Platform, such as cloud providers, EDR tools, scanners, code hosts, ticketing systems and messaging tools.
3. The Platform
Kervo AI is a continuous exposure management platform. It is organised as five stages, described below. Which capabilities you can use depends on your Quotation.
3.1 Know. The platform discovers what you have and what is exposed. It keeps one live asset inventory across cloud, network, application, code and identity. You can integrate your other tools, such as cloud environments, code repositories, EDR tools, vulnerability scanners and other security tools, to bring their assets and findings into that inventory. The platform also discovers and monitors your internet-facing assets, including services, certificates, DNS and SSL/TLS configuration, and look-alike domains. It watches breach data, paste sites, forums and marketplaces for leaked credentials, exposed data and mentions of your brand. It monitors the publicly visible security posture of your vendors and lets you send them invitations and questionnaires. It scans the code repositories you connect for static analysis findings, vulnerable dependencies, secrets, and software and cryptographic bills of materials. It also runs phishing simulations and measures security awareness across your own workforce.
3.2 Evaluate. The platform decides what matters. It re-ranks findings by exploitability, reachability and business impact, using signals such as EPSS and known exploited vulnerability lists. It correlates findings across domains into the attack paths that lead to your critical assets and scores each fix by how many paths it removes. It detects misconfiguration and drift in the cloud accounts you connect. It includes network, web application and penetration testing scanners, and scanner agents you can deploy inside your own network. It produces posture, ransomware readiness and risk scores.
3.3 Resolve. The platform helps you fix what matters. AI Analyst investigates and triages findings and explains its verdicts. Guided remediation gives you specific fixes, tracks the work, and scores risk before and after. On your instruction, the platform sends actions and notifications to your ticketing, messaging and security tools.
3.4 Validate. The platform helps you prove your posture holds. It maps controls and collects evidence continuously for frameworks and regulations including SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIS2, NIST CSF, and RBI, SEBI and IRDAI requirements, and many more. The Trust Center is a public page you manage that presents your security and compliance posture, policies and documents. You can generate audit reports and evidence packages on demand.
3.5 Orchestrate. The platform runs the programme as one system. AI CISO produces board-level reporting and priorities from live posture data. Automations move work between stages without manual hand-offs. Integrations connect cloud providers, identity providers, endpoint and EDR tools, vulnerability scanners, code hosts, and ticketing and messaging tools. Roles, role-based access control, agent management and audit logging cover governance.
3.6 Deployment. The Platform is available as cloud software, as a private deployment, and with regional data residency, as set out in your Quotation.
3.7 Changes. We add, change and retire capabilities as the Platform develops. Before we retire a capability you actively use, we will give you reasonable notice.
4. Accounts and Authorised Users
You are responsible for your Authorised Users and for everything done under your account. Keep credentials confidential, use the multi-factor and one-time code protections the Platform provides, and deactivate users promptly when they leave your organisation.
Tell us immediately at support@clouddfn.com if you become aware of unauthorised use of your account.
If you ask cloudDFN support to access your account to resolve a problem, that access is limited to your request, is logged, and ends when the request is resolved.
Vendors you invite through the vendor risk features receive a limited account scoped to the questionnaire or assessment you send them. You are responsible for the invitations you issue.
6. Acceptable use
You must not do any of the following, or let anyone else do them through your account:
- use the Platform to attack, disrupt, damage, or gain unauthorised access to any system, network or data;
- use findings, leaked credentials or other intelligence from the Platform to access an account or system you are not authorised to access;
- reverse engineer, decompile or scrape the Platform or its models, or use them to build a competing product;
- resell, sublicense, time-share or otherwise provide the Platform to third parties, unless your Quotation expressly allows it (for example, for a managed service arrangement);
- interfere with the security, integrity or performance of the Platform, or probe the Platform itself other than through a coordinated disclosure to support@clouddfn.com;
- upload malicious code, or content that is unlawful, infringing, or that you have no right to provide;
- use the Platform in breach of applicable law, including data protection, employment, export control and sanctions law.
7. Integrations and Third-Party Services
The Platform connects to Third-Party Services using credentials, API keys, tokens or roles that you provide. Grant only the access each integration needs, keep that access current, and comply with the third party's terms. We store integration credentials encrypted and use them only to run the integration you configured.
When the Platform creates tickets, sends messages, opens pull requests or triggers workflows in a Third-Party Service, it does so on your instruction and according to your configuration. cloudDFN is not responsible for Third-Party Services, for their availability, or for changes they make to their APIs. An integration may stop working if the third party changes or withdraws access.
8. Customer Data and privacy
8.1 Ownership. You keep all rights in Customer Data. You grant cloudDFN a limited, non-exclusive licence to host, process, analyse, transmit and display Customer Data, but only to provide, secure and support the Platform for you, and as you otherwise instruct.
8.2 Our role. For Customer Data, cloudDFN is a data processor and you are the data controller. Our DPA, available on request, and our Privacy Policy govern that processing. For account, billing and website data, we are a controller.
8.3 No training on Customer Data. We do not sell Customer Data, and we do not use it to train AI models. We collect usage telemetry, such as page views, sessions, feature usage and errors, in de-identified form that does not identify you or any individual, and we use it only to operate and improve the Platform. Usage telemetry is not Customer Data.
8.4 Data residency. If your Quotation specifies a hosting region or a private deployment, Customer Data is stored and processed there. Otherwise we may process it in the regions where the Platform runs, using appropriate transfer safeguards.
8.5 Retention and deletion. We keep Customer Data for the period configured in your plan. After termination you can export your data for 30 days. We delete it within 90 days of termination unless the law requires us to keep it longer.
8.6 Security. We maintain administrative, technical and organisational safeguards, including encryption in transit and at rest, tenant isolation, role-based access, audit logging and secure development practices. If a personal data breach affects Customer Data, we will notify you without undue delay.
8.7 Sub-processors. We use third-party sub-processors to provide the Platform, including cloud hosting providers and AI model providers. When you use AI features, the Customer Data needed for the request, such as findings, asset details and your prompts, is sent to an AI model provider to generate the output. AI model providers may process that data outside your hosting region unless your Quotation says otherwise. We choose sub-processors that commit to appropriate data protection terms, and we remain responsible for their processing. A list of our current sub-processors is available on request, and we will keep it up to date.
9. Dark web and threat intelligence data
Dark web monitoring, leaked credential alerts, look-alike domain detection and vendor posture signals come from public sources, breach corpora and third-party intelligence. That data can be incomplete, out of date or wrong, and the absence of a result does not mean an exposure does not exist.
When the Platform surfaces credentials or personal data about individuals, handle it lawfully. Use it only to protect your organisation and the people concerned, restrict who can see it, never use it to access an account, and meet any notification duties you have to affected individuals or regulators.
10. AI features
AI CISO, AI Analyst and the platform's generated summaries, verdicts, remediation guidance, reports and chat responses are produced by machine learning models. They can be incomplete or wrong, and they may not reflect the current state of your environment.
AI output is there to support your decisions. A qualified person must review it before you rely on it or act on it in a way that affects production systems, people or regulatory obligations. AI output is not legal, regulatory, audit or other professional advice. You are responsible for decisions and actions you take based on it.
To produce AI output, the Platform sends the Customer Data needed for the request to third-party AI model providers acting as our sub-processors, as described in Section 8.7. We do not use your prompts, findings or Customer Data to train AI models.
11. Compliance content and Trust Center
Framework mappings, control tests, evidence collection, gap analyses and audit reports help you prepare for and maintain compliance. They are not a certification, an attestation, an audit opinion or legal advice, and they do not guarantee that you meet any framework or regulation. Frameworks and regulator requirements change, and we update mappings on a best-effort basis. You remain responsible for your own compliance and for engaging auditors, assessors and advisers where you need them.
The Trust Center publishes only what you choose to publish. You are responsible for the accuracy of the posture, policies and documents you make public and for keeping them current. You grant cloudDFN the right to host and display that content on your behalf.
12. Security findings
No scanner, model or platform can find every vulnerability, misconfiguration or exposure, and the Platform may report findings that are not exploitable in your environment. Findings, scores, attack paths and priorities are advisory. They depend on the scope you connect, the access you grant, and the state of your environment when it was assessed. The Platform is one input to your security programme. It does not guarantee that you are free of vulnerabilities, breaches or compliance gaps.
13. Fees, quotations, purchase orders and invoices
13.1 How we sell. We send you a Quotation. You accept it by issuing a Purchase Order. We then bill the fees by Invoice according to the Quotation and your Purchase Order.
13.2 Payment. Unless the Quotation says otherwise, subscription fees are invoiced annually in advance, include applicable GST as shown on the Invoice, and are due by the date stated on the Invoice. Fees are non-refundable except where the law requires a refund. If an undisputed Invoice is more than 30 days overdue, we may suspend your access to the Platform after giving you notice.
13.3 Renewal. Unless the Quotation says otherwise, a subscription renews for a further term of the same length unless either party gives at least 30 days' written notice before the current term ends. We will send a renewal Quotation and Invoice before the renewal date. We may change fees at renewal with at least 30 days' notice.
13.4 Trials and proof of value. Trials and proofs of value are free, run for the period we specify (usually 14 days), are for evaluation only, and are provided as is. We may limit, change or end a trial at any time. We delete trial data 30 days after the trial ends unless you convert to a paid subscription.
14. Intellectual property and feedback
The Platform, including the software, scanners, models, methods, framework mappings, documentation, and the Kervo AI and cDFN names and marks, belongs to cloudDFN LLP and its licensors and is protected by intellectual property law. You get the right to use the Platform during your subscription under these Terms, and no other rights.
Reports, evidence packages and other output generated for you from Customer Data are yours to use for your own security and compliance purposes, including sharing them with your auditors, customers and regulators.
If you give us feedback or suggestions, we may use them without any obligation to you.
15. Confidentiality
Each party will protect the other's confidential information with at least the care it uses for its own, and no less than reasonable care. Each party will use that information only to perform under these Terms and will share it only with staff and advisers who need it and are bound by confidentiality. These duties do not apply to information that is public through no fault of the recipient, that the recipient already knew, that it developed independently, or that it must disclose by law (in which case it will give notice where the law permits). Customer Data is your confidential information. The Platform, our pricing and our unpublished roadmap are ours.
16. Support, availability and changes
We provide support through the channels and at the levels set out in your Quotation. We aim to keep the cloud-hosted Platform available around the clock, subject to scheduled maintenance (announced in advance where practical), emergency maintenance, and events outside our reasonable control. Any service level commitments and remedies are in your Quotation.
We may change the Platform, including by adding, changing or retiring features and integrations. During a subscription term we will not materially reduce the core functionality you have paid for without offering you a remedy.
17. Warranties and disclaimers
We warrant that we will provide the Platform with reasonable skill and care and substantially in line with the documentation. If we breach that warranty, your only remedy is for us to correct the problem or, if we cannot, to end your access to the affected parts of the Platform and refund the prepaid fees for the unexpired term.
Except as stated in these Terms, the Platform is provided as is and as available. To the fullest extent the law allows, cloudDFN disclaims all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement, and any warranty that the Platform will be uninterrupted or error free, or will identify every vulnerability, exposure or compliance gap.
18. Indemnification
18.1 By you. You will defend and indemnify cloudDFN against claims, damages and costs arising from scanning, testing or connecting any target you were not authorised to scan, test or connect; from your use of the Platform in breach of Section 5 or 6 or of applicable law; or from Customer Data or content you publish through the Trust Center.
18.2 By us. We will defend and indemnify you against third-party claims that the Platform, as we provide it and as you use it under these Terms, infringes that third party's intellectual property rights. This does not cover claims arising from Customer Data, Third-Party Services, or modifications or combinations we did not make. If such a claim arises, we may obtain the right for you to keep using the Platform, change it so it no longer infringes, or end your access to the affected parts of the Platform and refund the prepaid fees for the unexpired term.
18.3 Process. The indemnified party must give prompt notice, let the indemnifying party control the defence, and cooperate reasonably.
19. Limitation of liability
To the fullest extent the law allows, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill or data, however they arise. Each party's total liability under or in connection with these Terms is limited to the fees you paid or owed cloudDFN in the twelve months before the event giving rise to the claim.
These limits do not apply to a party's indemnification obligations, to breach of confidentiality, to your breach of Section 5 or 6, or to liability that the law does not allow to be limited, including for death, personal injury, fraud or wilful misconduct.
20. Term, suspension and termination
These Terms apply for the subscription term in your Quotation and any renewals. Either party may terminate for a material breach that is not cured within 30 days of written notice, or immediately if the other party becomes insolvent. We may suspend access to the Platform immediately where that is necessary to prevent harm to the Platform, other customers or third parties, or where the law requires it, and we will restore access once the cause is resolved.
When these Terms end, your right to use the Platform ends. You can export Customer Data for 30 days, after which we delete it within 90 days as described in Section 8. Sections that by their nature should survive, including 8, 9, 10, 11, 12, 14, 15, 17, 18, 19 and 24, survive termination.
21. Export control and sanctions
The Platform may be subject to export control and sanctions laws. You confirm that you are not located in, and are not a national or resident of, a country under comprehensive sanctions, and that you are not on any restricted party list. You will not use or export the Platform in breach of export control or sanctions law.
22. Changes to these Terms
We may update these Terms. For material changes we will give at least 30 days' notice by email or in the Platform before they take effect. If you keep using the Platform after the effective date, you accept the changes. If you do not agree to a material change, you may terminate the affected subscription before it takes effect and receive a refund of prepaid fees for the unexpired term.
23. General
These Terms, together with your Quotation, your Purchase Order, the DPA and the policies they refer to, are the entire agreement between the parties for the Platform and replace earlier agreements on the same subject. Neither party may assign these Terms without the other's consent, except to a successor in a merger, acquisition or sale of substantially all of its assets, with notice. Notices must be in writing and sent to the addresses in the Quotation, or, for cloudDFN, to sales@clouddfn.com. If a provision is unenforceable, it will be modified as little as necessary and the rest stays in effect. Neither party is liable for delay or failure caused by events beyond its reasonable control. The parties are independent contractors.
24. Governing law and disputes
Unless your Quotation says otherwise, these Terms are governed by the laws that apply at cloudDFN LLP's place of registration, and the courts there have exclusive jurisdiction over disputes arising from them. Before starting proceedings, the parties will try in good faith to resolve the dispute through discussion between senior representatives for at least 30 days. Either party may still seek urgent injunctive relief.
25. Contact
Questions about these Terms: sales@clouddfn.com
Security and vulnerability reports: support@clouddfn.com
Privacy and data protection: support@clouddfn.com
cloudDFN LLP operates Kervo AI, formerly cDFN WatchTower.
Have questions about this document?
We typically respond to privacy and legal requests within 24 hours.
