Terms of Service
The terms governing access to and use of the veyrisk exposure management platform. For businesses only. Last updated: September 2026. The German version is legally binding; this English version is provided for convenience.
1. Provider and scope
These Terms of Service (the "Terms") govern access to and use of the "veyrisk" platform and all related services, applications, and websites (collectively, the "Services"). veyrisk is provided by neonotu GmbH, Edelsbergstr. 8, 80686 Munich, Germany, registered with the commercial register of the Munich Local Court (Amtsgericht München) under HRB 313206, represented by its managing director, Armin Haller ("veyrisk", "we", "us").
The Services are offered exclusively to entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB), legal entities under public law, and special funds under public law ("Customer", "you"). We do not enter into contracts with consumers within the meaning of Section 13 BGB.
Deviating, conflicting, or supplementary terms of the Customer do not become part of the contract, even if we do not expressly object to them. If veyrisk and Customer have entered into a separate written agreement that expressly references these Terms, its deviating provisions prevail in the event of a conflict; these Terms otherwise apply in addition.
2. Definitions
- "Data Processing Agreement" or "DPA" means the agreement on processing personal data on behalf of Customer pursuant to Article 28 GDPR under Section 11.
- "Findings" means the results, ratings, priorities, reports, and recommendations generated by the Services.
- "Customer Data" means all electronic data and information that Customer or its Users enter or provide via the Services, including scan targets and the Findings generated from them.
- "User" means an individual authorized by Customer to use the Services, such as an employee, contractor, or consultant of Customer.
- "Services" means veyrisk's cloud-based software-as-a-service platform for discovering, monitoring, and prioritizing Customer's externally reachable attack surface, including associated documentation and support.
- "Plan" means the scope of services booked by Customer (Basis, Business, or Professional).
- "Verified Domain" means a domain for which Customer has proven ownership or control by means of a DNS TXT record under Section 5.
3. Conclusion of contract
The contract is concluded through online registration and booking of a Plan. The presentation of Plans on the website does not constitute a binding offer. By completing the booking, Customer submits a binding offer; the contract is concluded upon our confirmation by email or upon activation of the Plan.
By booking, Customer confirms that it acts as an entrepreneur. A person acting on behalf of a company represents that they are authorized to do so. We may request proof of business status, such as a VAT identification number.
4. Description of the Services
veyrisk provides a multi-tenant SaaS platform that discovers, monitors, and assesses Customer's externally reachable attack surface. This includes passive checks of publicly observable information, such as subdomains from certificate transparency logs, DNS, TLS, and email configuration, HTTP security headers, and reachable administration interfaces. Passive checks do not circumvent any security control and do not obtain access to internal systems.
Active checks, in particular port checks and vulnerability scans using OpenVAS, are performed exclusively for Verified Domains (Section 5).
The specific features are determined by the booked Plan and the current service description on the website. Manual review of Findings by qualified staff is included only in the Professional Plan.
Support is provided per Plan as follows:
- Basis: by email, response within two (2) business days;
- Business: by email, response within one (1) business day;
- Professional: prioritized, response within four (4) hours for critical Findings.
Response times refer to the time until the first qualified reply, not until resolution. Business days are Monday to Friday, excluding public holidays in Bavaria.
veyrisk may modify the Services as part of its ordinary product development, provided that core functionality is not materially reduced during a current subscription term. Because the Services run on a shared, multi-tenant architecture, security, privacy, and usage terms apply uniformly to all customers; customer-specific deviations are generally not possible absent an express written agreement.
5. Proof of ownership, authorization, and scans
Active checks require proof that Customer is entitled to control the domain. Proof is provided by a DNS TXT record specified by us. If the record is removed, we may stop active checks for that domain.
Customer represents and warrants that it is authorized to have all systems it specifies as targets, or that are reachable under a Verified Domain, checked by veyrisk, and that it has obtained any required consent of third parties, such as hosting providers, cloud platforms, or service providers operating systems on its behalf.
Customer shall indemnify neonotu GmbH against all third-party claims arising from a check that Customer was not authorized to have performed, including reasonable costs of legal defense. This does not apply to the extent Customer is not responsible for the breach.
If there are indications of abuse, in particular checks of third-party systems without authorization, we may suspend checks immediately and block Customer's access to the extent necessary to prevent harm. We will inform Customer without undue delay where possible.
Active checks are performed with care. In rare cases they may nevertheless affect systems, for example through increased load, log entries, or alerts in security systems. Customer shall inform its IT, hosting providers, and other affected service providers of the checks in advance and maintain current backups.
6. Registration, accounts, and account security
Use of the Services requires the creation of an account. Customer will ensure that registration information is accurate, complete, and kept up to date.
Two-factor authentication is mandatory for all Users. Customer assigns roles (owner, admin, member) and is responsible for granting access only to authorized persons and removing access that is no longer needed.
Customer is responsible for all activity occurring under its account and the accounts of its Users, and for maintaining the confidentiality of login credentials and second factors. Customer will promptly notify veyrisk of any unauthorized access.
Customer is responsible for ensuring that its Users comply with these Terms and will be liable for any breach by its Users as if committed by Customer itself.
7. Beta features
Features identified as "beta" are provided "as is" without any warranty. veyrisk assumes no liability for them to the extent permitted by law; Section 15 paragraph 1 remains unaffected.
8. Prices and payment
The Services are purchased as subscriptions with monthly or annual billing. The prices of the respective Plan stated at the time of booking apply. All prices are net prices plus applicable statutory VAT.
Fees are due in advance for each billing period (month or year). Payment is processed by the payment service provider Mollie by credit card, SEPA direct debit, or PayPal. Invoices are provided electronically as PDF (ZUGFeRD) by email and in the customer area; Customer agrees to electronic invoicing. We announce every charge by email in advance, at least five days before the due date for monthly billing and fourteen days for annual billing; the pre-notification period for SEPA direct debits is shortened accordingly.
A change to a higher Plan or from monthly to annual billing takes effect immediately; the difference for the remaining term is charged pro rata immediately. A change to a lower Plan or from annual to monthly billing takes effect at the end of the paid billing period; until then the current Plan remains in place. There is no refund for the current billing period. The same applies to add-ons.
If a payment fails, for example due to a chargeback or declined card, we will request payment from Customer. If payment is not made within the period set in the payment reminder, we may, without limiting our other rights, restrict or suspend access to the Services until the outstanding amount is paid. Costs of a chargeback caused by Customer are borne by Customer.
Fees already paid are non-refundable except as set forth in Section 9.
9. Term and termination
Monthly subscriptions renew for one month at a time and annual subscriptions for one year at a time unless terminated. Customer may terminate monthly subscriptions effective at the end of the current billing month and annual subscriptions effective at the end of the current billing year. Termination is done in the customer area; termination in text form is also possible. veyrisk may terminate with thirty (30) days' notice effective at the end of a billing period.
Either party may terminate the contract for cause without notice, in particular if the other party materially breaches a contractual obligation and fails to cure such breach within thirty (30) days of notice in text form, or if insolvency proceedings are opened over the other party's assets or rejected for lack of assets. Checks without authorization under Section 5 also constitute cause for veyrisk.
If Customer terminates for cause due to veyrisk's uncured material breach, veyrisk will refund any prepaid, unused fees for the remainder of the billing period. In all other cases, fees already paid are non-refundable.
Following termination, veyrisk may delete Customer Data after a reasonable transition period of up to thirty (30) days, unless a longer retention period is required by law. Customer may export its Findings and reports before the contract ends.
10. License grant and usage restrictions
veyrisk grants Customer a non-exclusive, non-transferable right to use the Services during the contract term within the booked Plan for Customer's internal business purposes.
Customer will not use the Services to:
- make the Services available to, or use them for the benefit of, anyone other than its authorized Users;
- resell, sublicense, rent, or lease the Services, or include them in a service bureau offering;
- check systems it is not authorized to have checked;
- store or transmit unlawful, defamatory, or infringing material, or malicious code;
- build a competing product or for competitive purposes, in particular to monitor the availability, performance, or functionality of the Services as a direct competitor of veyrisk;
- circumvent contractual usage limitations, interfere with the integrity of the Services, or attempt to gain unauthorized access to the Services or related systems;
- replicate the Services by reverse engineering, decompiling, or similar methods, except to the extent mandatory law expressly permits.
veyrisk may temporarily suspend a User's access if there is reasonable suspicion of a violation of this Section or a threat to the Services or other customers. Any suspension will be limited to what is necessary and, where practicable, announced to Customer in advance.
11. Customer Data and data protection
As between the parties, Customer retains all rights in Customer Data. veyrisk uses Customer Data solely to provide the Services, to address technical issues, and, in anonymized and aggregated form, for internal analytics and product improvement that do not identify Customer.
Where veyrisk processes personal data on Customer's behalf, it does so as a processor within the meaning of Article 28 GDPR. The Data Processing Agreement forms part of the contract and is provided to Customer separately. veyrisk's then-current Privacy Policy otherwise applies.
The Services are operated on servers in Germany.
Customer represents that it has the right to disclose any personal data it provides to veyrisk and that it complies with all applicable data protection laws, including the GDPR.
veyrisk maintains appropriate technical and organizational measures to protect Customer Data against unauthorized access, loss, or alteration, and will notify Customer without undue delay upon becoming aware of a security incident affecting Customer Data.
12. Intellectual property
veyrisk and its licensors retain all right, title, and interest in the Services, the underlying technology, and any derivative works. Except for the rights granted under Section 10, nothing in these Terms transfers any rights to Customer. Customer may use Findings and reports for its own purposes without restriction.
If Customer provides feedback or suggestions regarding the Services, Customer grants veyrisk a royalty-free, worldwide, transferable, and perpetual right to use them without attribution.
13. Confidentiality
Each party (the "Receiving Party") will protect the confidential information of the other party (the "Disclosing Party") that is marked confidential or would reasonably be understood to be confidential, using at least the same degree of care it uses for its own comparable information and no less than commercially reasonable care, and will use it solely to perform its obligations under these Terms. Findings on Customer's vulnerabilities are always confidential.
These obligations do not apply to information that is or becomes publicly available, was already known to the Receiving Party, was rightfully received from a third party, or was independently developed. Disclosure required by law or by a public authority is permitted, provided the Disclosing Party is informed in advance where legally permitted.
14. Warranty
veyrisk warrants that the Services will perform materially in accordance with the service description and will be provided with commercially reasonable care.
Except as expressly set forth in this Section, the Services are provided without further warranty, express or implied; in particular, veyrisk gives no warranty of fitness for a particular purpose pursued by Customer, to the extent permitted by law.
Findings are based on automatically collected data, partly from third-party sources, and reflect an assessment rather than a guarantee of the actual security posture. veyrisk does not warrant that all systems, vulnerabilities, or misconfigurations will be detected; individual Findings may be inaccurate. The Services do not replace a penetration test. Customer remains responsible for its own decisions and measures taken on the basis of the Services.
15. Limitation of liability
Both parties are liable without limitation for intent and gross negligence, for injury to life, body, or health, and under mandatory statutory liability, in particular under the German Product Liability Act.
For damages caused by slight negligence, veyrisk is liable only for breach of a material contractual obligation (cardinal obligation), the fulfillment of which is essential to the proper performance of the contract and on which Customer may regularly rely. In that case, liability is limited to the damage typically foreseeable for this type of contract at the time of the damaging event and in any event to the fees paid by Customer in the twelve (12) months preceding the event giving rise to the claim.
Any further liability is excluded, in particular for lost profits, indirect damages, or consequential damages, to the extent not covered by the preceding paragraphs.
16. Changes to these Terms
veyrisk may amend these Terms with effect for the future to reflect changes in applicable law, the functionality of the Services, or other legitimate interests. Material changes will be notified to Customer with reasonable advance notice, generally at least thirty (30) days before they take effect, in text form (e.g., by email or through the Services).
If Customer does not object to a material change within thirty (30) days of receiving the notice, the change is deemed accepted; the notice will specifically point out this consequence. If Customer objects, the prior version continues to apply until the end of the current billing period; either party may then terminate effective at the end of that billing period.
17. Governing law and jurisdiction
These Terms are governed by the laws of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and the conflict-of-laws rules of private international law.
If Customer is a merchant (Kaufmann), a legal entity under public law, or a special fund under public law, the exclusive place of jurisdiction for all disputes arising out of or in connection with these Terms is the registered seat of neonotu GmbH in Munich, Germany.
18. General provisions
Entire agreement. These Terms, together with the booked Plan, the Privacy Policy, and the Data Processing Agreement, constitute the entire agreement between the parties regarding use of the Services and supersede all prior agreements on that subject.
Assignment. Customer may not assign rights and obligations under these Terms without veyrisk's prior written consent. veyrisk may assign these Terms without Customer's consent in connection with a restructuring, sale, or merger.
Severability. If any provision of these Terms is or becomes invalid, the validity of the remaining provisions remains unaffected.
Force majeure. Neither party is liable for delays or failures caused by circumstances beyond its reasonable control, including natural events, governmental action, internet outages, or pandemics.
No waiver. Failure to assert a right under these Terms does not constitute a waiver of that right.
Notices. Legal notices to veyrisk should be sent to neonotu GmbH, Edelsbergstr. 8, 80686 Munich, Germany, with a copy to contact@veyrisk.com. Notices to Customer are sent to the email address stored in the account.
19. Contact
neonotu GmbH (provider of veyrisk)Edelsbergstr. 8
80686 Munich
Germany
Commercial register: Munich Local Court (Amtsgericht München), HRB 313206
Managing director: Armin Haller
Email: contact@veyrisk.com