Last updated: 2026-08-05 · Plain text version of this document

Security Services Addendum

DRAFT — NOT YET IN FORCE. This addendum plus a signed Data Processing Agreement is what enterprise buyers will ask for during procurement. Counsel review required. Items marked [VERIFY] need a business decision.

This addendum applies in addition to our Terms of Service (plain text) when you use any of our security products, including PasswordRoast, BetterPhish, DarkThreat, ThreatDefense, LLMSecurity, BetterSpam, MailBlocks, and VeriBits.

Where this addendum conflicts with the Terms of Service, this addendum wins for those products.

1. Why this exists

Our security products differ from ordinary software in two ways that matter legally.

They can cause harm if misused. Tools that find weaknesses can be used to exploit them.

The people whose data you upload did not agree to anything with us. When you submit your organisation's credentials, email samples, or scan targets, the individuals involved are your employees or your users. They have a relationship with you, not with us. That makes you the controller and us your processor, and it changes our obligations to you and yours to them.

2. Authorisation — your responsibility

You represent and warrant that, for every system you test, scan, or submit data about, you either own it or hold documented authorisation from its owner.

You must keep evidence of that authorisation for as long as you use the service and for 12 months afterwards, and produce it to us within 5 business days of a reasonable request.

We may suspend access immediately, without notice, where we reasonably believe a product is being used against a system without authorisation. We may report apparent unlawful use to the relevant authority.

3. Controller and processor

For Customer Security Data — the data you submit about your own systems and people — you are the controller and we are the processor.

We will:

For Account Data — your name, email, billing details, and how you use the service — we are the controller and our Privacy Policy (plain text) applies.

A signed Data Processing Agreement is required before you submit Customer Security Data. Request one at privacy@afterdarksys.com. [VERIFY: DPA template still to be drafted.]

4. Breach and credential data

Some products check whether credentials appear in known breach corpora.

5. Findings and reports

Findings we generate about your systems belong to you. We may retain them for the retention period in section 7 so you can access your history.

We may publish aggregate statistics and threat research only where it cannot identify you, your organisation, your systems, or any individual.

6. Security measures

[VERIFY: this section must describe measures actually in place. Every line here is a contractual commitment enforceable by your customers.]

Our practices are informed by ISO/IEC 27001 and the NIST Cybersecurity Framework. We are not certified against either, and we do not claim to be.

7. Retention

Data Retention
Submitted samples and scan inputs deleted on completion, or [VERIFY: 30 days?] if retained for re-analysis
Findings and reports life of the account, then 90 days
Credentials submitted for breach checking not retained
Audit logs of your use 12 months

You may request earlier deletion at any time.

8. Audit

Once per year, or after a personal data breach affecting your data, you may audit our compliance with this addendum. We will first offer our current security documentation and any third-party assessment. If that is not enough for your regulator, we will accommodate a reasonable on-site or remote audit at your cost, on 30 days' notice, under confidentiality.

9. Breach notification

We will tell you without undue delay, and in any event within [VERIFY: 48 or 72 hours?] of becoming aware, of any personal data breach affecting Customer Security Data, with the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures we are taking.

10. Prohibited uses

In addition to the acceptable use rules in the Terms of Service, you may not use these products to:

11. Contact