Security Services Addendum ========================== After Dark Systems — legal.afterdarksys.com Last updated: 2026-08-05 > **DRAFT — NOT YET IN FORCE.** This addendum plus a signed Data Processing > Agreement is what enterprise buyers will ask for during procurement. Counsel > review required. Items marked `[VERIFY]` need a business decision. This addendum applies in addition to our [Terms of Service](terms.html) ([plain text](terms.txt)) when you use any of our security products, including PasswordRoast, BetterPhish, DarkThreat, ThreatDefense, LLMSecurity, BetterSpam, MailBlocks, and VeriBits. Where this addendum conflicts with the Terms of Service, this addendum wins for those products. ## 1. Why this exists Our security products differ from ordinary software in two ways that matter legally. **They can cause harm if misused.** Tools that find weaknesses can be used to exploit them. **The people whose data you upload did not agree to anything with us.** When you submit your organisation's credentials, email samples, or scan targets, the individuals involved are your employees or your users. They have a relationship with you, not with us. That makes you the controller and us your processor, and it changes our obligations to you and yours to them. ## 2. Authorisation — your responsibility You represent and warrant that, for every system you test, scan, or submit data about, you either own it or hold documented authorisation from its owner. You must keep evidence of that authorisation for as long as you use the service and for 12 months afterwards, and produce it to us within 5 business days of a reasonable request. We may suspend access immediately, without notice, where we reasonably believe a product is being used against a system without authorisation. We may report apparent unlawful use to the relevant authority. ## 3. Controller and processor For **Customer Security Data** — the data you submit about your own systems and people — you are the controller and we are the processor. We will: - process it only on your documented instructions - not use it for our own purposes, including product improvement or model training, unless it has been irreversibly aggregated so no individual or customer can be identified - ensure staff with access are bound by confidentiality - apply the technical and organisational measures in section 6 - engage subprocessors only as listed in [Subprocessors](subprocessors.html) ([plain text](subprocessors.txt)), and give notice before adding one - assist you with data subject requests, impact assessments, and regulator consultations, taking into account the nature of the processing - delete or return the data at the end of the service, at your choice - make available the information needed to demonstrate compliance and allow audits under section 8 For **Account Data** — your name, email, billing details, and how you use the service — we are the controller and our [Privacy Policy](privacy.html) ([plain text](privacy.txt)) applies. **A signed Data Processing Agreement is required** before you submit Customer Security Data. Request one at privacy@afterdarksys.com. `[VERIFY: DPA template still to be drafted.]` ## 4. Breach and credential data Some products check whether credentials appear in known breach corpora. - Where possible we use k-anonymity, so a full credential never leaves your environment and we never receive one. `[VERIFY: confirm which products actually implement k-anonymity range queries and which transmit full values. This claim must be exactly true per product or removed.]` - We do not retain submitted credentials after a check completes. `[VERIFY: confirm against the running services.]` - We do not use breach data to contact affected individuals. ## 5. Findings and reports Findings we generate about your systems belong to you. We may retain them for the retention period in section 7 so you can access your history. We may publish aggregate statistics and threat research **only** where it cannot identify you, your organisation, your systems, or any individual. ## 6. Security measures `[VERIFY: this section must describe measures actually in place. Every line here is a contractual commitment enforceable by your customers.]` - Encryption in transit using current TLS - Encryption at rest for Customer Security Data - Single sign-on through Authentik with multi-factor and passkey support - Role-based access control, access limited to what a role requires - Segregation of customer data - Logging of administrative access - Regular patching of infrastructure Our practices are informed by ISO/IEC 27001 and the NIST Cybersecurity Framework. We are **not** certified against either, and we do not claim to be. ## 7. Retention | Data | Retention | |---|---| | Submitted samples and scan inputs | deleted on completion, or `[VERIFY: 30 days?]` if retained for re-analysis | | Findings and reports | life of the account, then 90 days | | Credentials submitted for breach checking | not retained | | Audit logs of your use | 12 months | You may request earlier deletion at any time. ## 8. Audit Once per year, or after a personal data breach affecting your data, you may audit our compliance with this addendum. We will first offer our current security documentation and any third-party assessment. If that is not enough for your regulator, we will accommodate a reasonable on-site or remote audit at your cost, on 30 days' notice, under confidentiality. ## 9. Breach notification We will tell you without undue delay, and in any event within `[VERIFY: 48 or 72 hours?]` of becoming aware, of any personal data breach affecting Customer Security Data, with the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures we are taking. ## 10. Prohibited uses In addition to the acceptable use rules in the Terms of Service, you may not use these products to: - test systems you do not own without documented authorisation - develop or distribute malware outside a controlled environment - gather credentials for unauthorised access - support stalking, harassment, or surveillance of individuals - evade lawful process ## 11. Contact - Security: security@afterdarksys.com - Vulnerability disclosure: [security.txt](/.well-known/security.txt) - Data protection: privacy@afterdarksys.com