Back to ThreatWire

Terms of Service & Liability Waiver

Version 2026-04-23 · Effective April 23, 2026

1. Acceptance of Terms

These Terms of Service and Liability Waiver ("Terms") constitute a legally binding agreement between you ("you", "User", or "Customer") and ThreatWire, Inc. ("ThreatWire", "we", "us", or "our"). By creating an account, accessing, installing, or using any ThreatWire software, agent, VPN, dashboard, mobile application, API, or related service (collectively, the "Service"), you acknowledge that you have read, understood, and agree to be bound by these Terms in full. If you do not agree, you must not access or use the Service.

2. Description of the Service

ThreatWire provides network security visibility tools, including but not limited to: a host-installed monitoring agent, intrusion detection systems (Suricata and Zeek) running on dedicated WireGuard VPN concentrators, AI-assisted threat analysis ("Nova"), DNS filtering, threat intelligence enrichment, alerting, reporting, and a mobile and web dashboard. The Service is provided as a software-as-a-service offering and is delivered "as-is" and "as-available."

3. Security Architecture & Tenant Isolation

ThreatWire takes commercially reasonable measures to isolate user traffic and protect customer data. These measures include, without limitation:

  • Per-tenant WireGuard VPN concentrators with cryptographically unique key pairs and pre-shared keys generated per device and stored in encrypted form.
  • Logical network isolation on shared concentrators via per-tenant IP allocation, namespace separation, and firewall rules preventing peer-to-peer routing between tenants.
  • Per-tenant API keys required for every health, telemetry, and configuration request; keys are rotated on revocation events.
  • Database-level multi-tenancy with row-level filtering by user identifier on every query path.
  • Encrypted traffic in transit using WireGuard (Curve25519, ChaCha20-Poly1305) for VPN tunnels and TLS 1.2+ for all dashboard, API, and agent communication.
  • Hardened VPS images with automatic OS updates, restrictive firewall defaults, fail2ban, signed package repositories, and disabled password authentication.
  • Automated key revocation on device removal or account termination, preventing further tunnel establishment.
  • Idle reaping of unused VPS instances to limit attack surface.
  • Independent telemetry pipelines for IDS alerts, NetFlow, DNS, and system metrics, with deduplication and per-tenant quotas.
  • Audit logging of authentication events, configuration changes, admin actions, and key access.

Notwithstanding these measures, no security control is perfect, and no system connected to the public Internet can be guaranteed to be immune from intrusion, defect, vulnerability, misconfiguration, or compromise. You expressly acknowledge this and agree to the limitations and disclaimers below.

4. Your Network, Devices, and Data

You are solely responsible for: (a) the security, configuration, patching, and operation of your own networks, routers, firewalls, endpoints, servers, IoT devices, applications, accounts, credentials, and any other systems you operate or connect to the Service ("Your Systems"); (b) compliance with all applicable laws, regulations, and contractual obligations governing Your Systems and the data flowing through them; (c) lawful authority to monitor any network or device on which you install, configure, or use the Service; (d) reviewing alerts, dashboards, notifications, and recommendations and taking appropriate action; and (e) maintaining backups, business continuity plans, and incident response capabilities independent of the Service.

You acknowledge that ThreatWire is a monitoring and detection tool. ThreatWire does not act as a managed security service provider, does not guarantee detection or prevention of any specific threat, and does not assume operational control of Your Systems.

5. NO WARRANTIES — DISCLAIMER

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE.

To the fullest extent permitted by applicable law, ThreatWire and its officers, directors, employees, contractors, suppliers, partners, and licensors expressly disclaim all warranties, including without limitation warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, completeness, reliability, security, uninterrupted access, error-free operation, freedom from harmful components, and any warranties arising from course of dealing, course of performance, or trade usage. ThreatWire does not warrant that the Service will: (a) detect or prevent any particular threat, malware, intrusion, exfiltration, ransomware, vulnerability, breach, or attack; (b) be free from defects, vulnerabilities, false positives, false negatives, or downtime; (c) meet your requirements; or (d) interoperate with any specific hardware, software, or environment.

6. LIMITATION OF LIABILITY — RELEASE & WAIVER

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THREATWIRE SHALL NOT BE LIABLE FOR ANY LOSS, DAMAGE, OR HARM ARISING FROM OR RELATED TO YOUR USE OF — OR INABILITY TO USE — THE SERVICE.

Without limiting the foregoing, you release, waive, and discharge ThreatWire, its affiliates, officers, directors, employees, contractors, investors, suppliers, partners, and licensors (collectively, the "Released Parties") from any and all claims, demands, actions, damages, losses, costs, and expenses (including attorneys' fees) of any kind, whether known or unknown, foreseen or unforeseen, arising out of or relating to:

  • any compromise, intrusion, breach, ransomware, malware infection, account takeover, credential theft, data loss, data exposure, extortion, downtime, or business interruption affecting Your Systems, your users, customers, employees, or third parties;
  • any failure of the Service to detect, prevent, alert on, classify, or respond to any threat, vulnerability, attack, or anomaly;
  • any false positive, false negative, missed alert, delayed alert, misclassification, or inaccurate enrichment;
  • any action or inaction taken by you, your administrators, or third parties in reliance on Service output;
  • any unauthorized access to, alteration of, or destruction of Your Systems or your data, regardless of whether the Service was running, misconfigured, disabled, offline, or otherwise affected;
  • any loss, corruption, deletion, or unavailability of data, including telemetry, logs, configurations, or reports;
  • any service degradation, latency, packet loss, throughput limitation, VPN disconnection, or downtime, including planned maintenance;
  • any defect, vulnerability, bug, regression, or compromise in third-party components used by the Service (including but not limited to Linux, WireGuard, Suricata, Zeek, PostgreSQL, DigitalOcean, Resend, Stripe, Replit, OpenAI, Anthropic, Google, and any other vendor);
  • any act, omission, or breach by any third party, including hosting providers, payment processors, or telecommunications carriers;
  • any regulatory, contractual, reputational, financial, or legal consequence resulting from any of the foregoing.

IN NO EVENT SHALL THE AGGREGATE LIABILITY OF THE RELEASED PARTIES TO YOU FOR ANY AND ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICE EXCEED THE GREATER OF (A) THE AMOUNTS PAID BY YOU TO THREATWIRE FOR THE SERVICE DURING THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS (US$100).

The Released Parties shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, including without limitation lost profits, lost revenue, lost data, loss of goodwill, business interruption, or cost of substitute services, even if advised of the possibility of such damages and regardless of the theory of liability (contract, tort, strict liability, statute, or otherwise).

7. Acknowledgment of Risk

You expressly acknowledge that operating any system connected to the Internet involves inherent and substantial risk, including the risk of unauthorized access, malware, ransomware, denial of service, supply-chain compromise, zero-day exploitation, social engineering, insider threat, hardware failure, and human error. You voluntarily and knowingly assume all such risks. You agree that any harm to Your Systems remains your sole responsibility, even where ThreatWire monitoring is in use.

8. Indemnification

You agree to defend, indemnify, and hold harmless the Released Parties from and against any and all claims, liabilities, damages, losses, and expenses (including reasonable attorneys' fees) arising from or related to: (a) your use of the Service; (b) your violation of these Terms or any applicable law; (c) your infringement of any intellectual property or privacy right; (d) any incident affecting Your Systems; and (e) any content, configuration, or data you submit to or process through the Service.

9. Acceptable Use

You agree not to (and not to permit any third party to): (a) use the Service to monitor any network or device without lawful authority; (b) use the Service to attack, scan, exfiltrate from, or otherwise harm systems you do not own or are not authorized to assess; (c) reverse-engineer, decompile, or attempt to extract source code from the Service except to the extent permitted by law; (d) interfere with or disrupt the integrity or performance of the Service or its underlying infrastructure; (e) use the Service to violate any law, regulation, or third-party right; or (f) resell, sublicense, or redistribute the Service without express written permission.

10. Privacy & Data Processing

Your use of the Service is also governed by our Privacy Policy. ThreatWire processes telemetry strictly to operate, secure, and improve the Service. You represent and warrant that you have all necessary rights, consents, and notices to provide ThreatWire with any data submitted through the Service, including data about end users, devices, and network activity.

11. Subscription, Billing & Termination

Paid plans are billed in advance on a recurring basis. You authorize ThreatWire and its payment processor to charge your payment method. During the paid beta, the Service is pre-release and features may change; you can cancel anytime from the billing portal, and you may request a full refund within 30 days of your first beta payment by contacting support@threatwire.ai. Otherwise, fees are non-refundable except where required by law. We may suspend or terminate your access at any time for breach of these Terms, non-payment, suspected abuse, security risk, or for any other reason, with or without notice. Upon termination, your right to use the Service ceases immediately, and we may delete your data after a reasonable retention period.

12. Modifications

We may modify these Terms at any time. Material changes will be communicated through the Service or via email. Your continued use of the Service following any modification constitutes acceptance of the updated Terms. If you do not agree, you must stop using the Service.

13. Governing Law & Dispute Resolution

These Terms are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws principles. Any dispute, claim, or controversy arising out of or relating to these Terms or the Service shall be resolved exclusively by binding individual arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, conducted in English in Wilmington, Delaware, or by remote means. You waive any right to a jury trial and any right to participate in a class, collective, or representative action. Notwithstanding the foregoing, either party may seek injunctive relief in any court of competent jurisdiction to protect intellectual property or confidential information.

14. Severability & Entire Agreement

If any provision of these Terms is held to be unenforceable, the remaining provisions shall remain in full force and effect, and the unenforceable provision shall be modified to the minimum extent necessary to make it enforceable while preserving its intent. These Terms, together with the Privacy Policy and any order form or written agreement signed between you and ThreatWire, constitute the entire agreement between the parties and supersede all prior or contemporaneous agreements, communications, and understandings, whether oral or written.

15. Contact

Questions about these Terms may be sent to legal@threatwire.ai. Security issues may be reported to security@threatwire.ai.

By clicking "I Accept" you confirm that you have read, understood, and agree to be bound by these Terms of Service and Liability Waiver (Version 2026-04-23), and that you are at least 18 years of age and authorized to enter into this agreement on behalf of yourself and any organization on whose behalf you are using the Service.