Skip to content

Terms of Service

The terms and conditions governing your use of our platform.

Last updated: 2026-07-22

1. Acceptance of Terms

By accessing or using the Black Cat Security platform (the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms. If you do not agree to these Terms, you must not access or use the Service.

2. Description of the Service

Black Cat Security provides a SaaS Security Posture Management (SSPM) platform that enables organizations to monitor, assess, and improve the security configuration of their cloud-based software applications. The Service includes automated security assessments, compliance monitoring, risk scoring, and remediation guidance.

3. Account Registration

To use the Service, you must create an account by providing accurate, current, and complete information. You are responsible for maintaining the confidentiality of your login credentials and for all activities that occur under your account. Each account is personal and may not be shared. You must be at least 15 years of age (the digital age of consent applicable in France under Article 45 of the French Data Protection Act) or the digital age of consent applicable in your country, whichever is higher.

You agree to notify us immediately of any unauthorized use of your account or any other breach of security. Black Cat Security shall not be liable for any loss or damage arising from your failure to protect your account credentials.

You represent and warrant that you own, control, or are duly authorized to connect and scan every SaaS account, tenant, workspace, or environment that you connect to the Service; that you have obtained all internal approvals and all third-party authorizations required to do so; and that you will not connect any account, tenant, or environment belonging to a third party without that party's authority. Any connection of accounts or environments without sufficient rights or authorization is a material breach of these Terms and may constitute a criminal offence under applicable law.

4. Subscription and Billing

5. Acceptable Use

6. Intellectual Property

The Service, including all software, content, design, documentation, trademarks, and other intellectual property, is and remains the exclusive property of Black Cat Security or its licensors. These Terms do not grant you any right, title, or interest in the Service beyond a limited, non-exclusive, non-transferable, revocable licence to access and use the Service for its intended purpose during the term of your subscription.

You retain all rights in the data you submit to or process through the Service ("Customer Data"). No rights in Customer Data are transferred to Black Cat Security other than those necessary to provide the Service.

7. Customer Data

8. Service Availability and Support

Black Cat Security will use commercially reasonable efforts to ensure the availability and performance of the Service. However, we do not guarantee 100% uptime. The Service may be temporarily unavailable due to scheduled maintenance (for which we will provide reasonable advance notice), emergency maintenance, or circumstances beyond our control.

Support is provided via email at [email protected]. Response times and support levels depend on your subscription plan.

9. Warranties and Disclaimers

Except as expressly set out in these Terms or the Data Processing Agreement, to the maximum extent permitted by applicable law, the Service is provided "AS IS" and "AS AVAILABLE", without warranties of any kind, whether express, implied, or statutory. Black Cat Security does not warrant that the Service will be uninterrupted, timely, secure, or error-free, or that any defects will be corrected.

The Service is a security monitoring and assessment tool. It does not guarantee the detection of all misconfigurations, vulnerabilities, or threats, nor the accuracy or completeness of its findings; it does not prevent, and cannot be relied upon to prevent, security incidents, intrusions, or data breaches; and it is not a substitute for the Customer's own security programme, testing, personnel, and judgement. The Customer remains solely responsible for the security of its systems, applications, and data, and for reviewing and acting upon the findings produced by the Service.

The compliance frameworks, scores, mappings, controls, and reports made available through the Service — including those relating to DORA, NIS2, SOC 2, ISO 27001, and any other framework or standard shown in the Service — are provided as informational tools only. They do not constitute legal, regulatory, audit, or professional advice, and they do not guarantee or certify the Customer's compliance with any law, regulation, standard, or contractual obligation. The Customer remains solely responsible for its own regulatory compliance and should seek the advice of qualified counsel or a certified auditor.

The Service relies on connectors that access the application programming interfaces (APIs) of third-party SaaS providers. Those providers may change, deprecate, rate-limit, suspend, or revoke access to their APIs at any time and without notice, which may affect the availability or functionality of the corresponding Service features. Black Cat Security is not responsible for third-party services, for the acts or omissions of their providers, or for any consequence that changes to third-party APIs may have on the operation of the Service.

10. Limitation of Liability

To the maximum extent permitted by applicable law, the aggregate liability of Black Cat Security for all claims arising out of or in connection with these Terms or the Service shall not exceed the total fees paid by you to Black Cat Security during the 12 months immediately preceding the event giving rise to the claim (the "General Liability Cap").

For claims arising out of or in connection with a breach of the Data Processing Agreement (DPA), a breach of confidentiality obligations, or a failure to implement the security measures described in the DPA, the aggregate liability of either party shall not exceed two times (2x) the total fees paid by the Customer during the 24 months immediately preceding the event giving rise to the claim (the "Enhanced Liability Cap").

To the maximum extent permitted by applicable law, in no event shall Black Cat Security be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, loss of data, business interruption, or loss of goodwill, regardless of the theory of liability. Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law.

Notwithstanding the foregoing, nothing in these Terms limits or excludes liability for: (i) death or personal injury caused by negligence; (ii) fraud or fraudulent misrepresentation; (iii) wilful misconduct or gross negligence (faute lourde ou dolosive within the meaning of Article 1231-3 of the French Civil Code); or (iv) any liability that cannot lawfully be limited or excluded under applicable law, including liability owed to data subjects under Article 82 of the GDPR.

11. Indemnification

Each party agrees to indemnify, defend, and hold harmless the other party and its officers, directors, employees, and agents from and against any third-party claims, losses, liabilities, damages, costs, and expenses (including reasonable legal fees) arising out of or related to the indemnifying party's breach of these Terms or violation of applicable law.

In addition to the foregoing, the Customer shall indemnify, defend, and hold harmless Black Cat Security and its officers, directors, employees, and agents from and against any third-party claims, losses, liabilities, damages, costs, and expenses (including reasonable legal fees) arising out of or related to: (a) the Customer Data; (b) the Customer connecting or scanning any account, tenant, or environment without sufficient rights or authorization; (c) the Customer's use of, or reliance on, any finding, score, mapping, or report produced by the Service; or (d) the Customer's violation of the Acceptable Use Policy.

12. Force Majeure

Neither party shall be liable for any failure or delay in performing its obligations under these Terms where such failure or delay results from a force majeure event within the meaning of Article 1218 of the French Civil Code, including but not limited to natural disasters, war, terrorism, epidemics, government actions, power failures, internet disruptions, or cyberattacks.

If a force majeure event continues for more than 90 consecutive days, either party may terminate these Terms by written notice to the other party without incurring liability.

13. Termination

Either party may terminate these Terms by providing 30 days' written notice to the other party. Black Cat Security may terminate or suspend your access to the Service immediately upon written notice if you materially breach these Terms and fail to cure such breach within 15 days of receiving notice thereof.

Upon termination, you will have a period of 30 days to export your Customer Data. After this period, we will delete your data in accordance with our Data Processing Agreement.

For consumer subscriptions subject to French law, in accordance with Article L215-1 of the Consumer Code (Loi Chatel), we will notify you in writing between three months and one month before each tacit renewal date, informing you of your option not to renew. If this notice is not sent within the required timeframe, you may terminate the renewed contract free of charge at any time after the renewal date, and any sums paid after that date that do not correspond to actual use of the Service will be reimbursed within 30 days.

14. Governing Law and Jurisdiction

These Terms are governed by and construed in accordance with the laws of the French Republic. Any dispute arising out of or in connection with these Terms shall be submitted to the exclusive jurisdiction of the courts of Paris, France, subject to mandatory consumer protection rules providing for a different jurisdiction.

15. Modifications to These Terms

We reserve the right to modify these Terms at any time. Material modifications will be communicated to you by email at least 30 days before they take effect. If you do not agree to the modified Terms, you may terminate your subscription before the new Terms come into force. Continued use of the Service after the effective date constitutes acceptance of the modified Terms.

16. Contact

For any questions regarding these Terms of Service, please contact us at [email protected].

Change history
  • 2026-04-18 — Added liability carve-outs (gross negligence, fraud, personal injury, GDPR Art. 82).
  • 2026-04-18 — Added Loi Chatel renewal-reminder clause for consumer subscriptions (Code conso. L215-1).
  • 2026-04-18 — Minimum account age aligned to 15 (digital age of consent in France).
  • 2026-05-15 — Added Enhanced Liability Cap (2x / 24 months) for DPA, security, and confidentiality breaches (§9).
  • 2026-07-22 — Billing section (§4) rewritten: {COMPANY_NAME} sells directly, Stripe is the payment processor, Qonto issues invoices, VAT under franchise en base (art. 293 B CGI). Removed Merchant-of-Record wording.
  • 2026-07-22 — Added Warranties and Disclaimers section (AS IS / AS AVAILABLE, security tool disclaimer, no legal or compliance advice, third-party API dependencies) as §9; subsequent sections renumbered §10–§16. Added scan-authorization representation and warranty to §3. Added Customer indemnification triggers (Customer Data, unauthorized scanning, reliance on findings, AUP violation) to §11.