Terms of Service
Version 0.5. Effective date: October 2, 2026.
1. Who we are
The service is provided by Axyom Cyber Partners SL (“Axyom”), Spanish tax ID (CIF) B75758573, with registered office at Paseo Mare Nostrum 15, 08039 Barcelona, Spain, registered with the Commercial Registry of Barcelona, sheet B-627600, folio 1, volume/IRUS 1000440978057, 1st entry. Axyom is also registered as an insurance broker with the administrative registry of insurance and reinsurance distributors of the Spanish Directorate-General for Insurance and Pension Funds (DGSFP), under key J-4432, and is subject to its supervision. Contact: info@getaxyom.com.
2. Purpose and contractual structure
2.1. These Terms govern access to and use of Axyom’s AI CISO platform (the “Platform”), available at getaxyom.com and through the associated client portal, as well as the other security services Axyom provides under them (together, the “Services”). Depending on the plan purchased, the Platform provides external attack surface scanning, threat intelligence, endpoint detection and response (EDR/MDR), automated penetration testing, management of risk arising from the use of AI, remediation, and generation of security documents.
2.2. Acceptance: these Terms are accepted through an express action of each user on their first access to the Platform and, where applicable, again during the purchase of a paid plan. The contract between Axyom and the client is formed upon acceptance by the first user acting on behalf of the client in accordance with clause 3; acceptances by subsequent users record their awareness and adherence and do not replace the client’s acceptance. Axyom keeps a record of every acceptance identifying the user, the version of the document accepted and the date. By accepting these Terms, the client also accepts the Privacy Policy and, where personal data is processed through the Platform, the attached Data Processing Agreement (DPA).
2.3. Single framework and order of precedence: these Terms act as the framework for all Services, including those contracted through a specific offer, proposal or purchase order (among others, managed MDR per seat, manual penetration testing and Custom plans). Such specific conditions incorporate these Terms by reference and prevail over them only where they expressly modify them. Unless expressly agreed otherwise in writing and signed by both parties, clauses 5 (authorization), 10.4 (confidentiality) and 13 (limitation of liability) apply in all cases to all Services.
3. Scope: companies and professionals only
The Platform is offered exclusively to companies and professionals acting in the course of their business. It is not offered to consumers. Whoever accepts these Terms declares that they act on behalf of a company or as a professional, with sufficient authority to bind it. As this is a business-to-business contract, the withdrawal right provided for consumers does not apply.
4. Account
The client is responsible for the accuracy of the registration data, the safekeeping of its credentials and the activity carried out from its user accounts. It must notify Axyom without delay of any unauthorized access. Plans with unlimited users refer to users within the client’s own organization; the account may not be shared with third parties outside it unless expressly agreed (partner channel or Custom). Axyom may make the activation of the account and of scanning conditional on verification of the client’s ownership or control of the domain, for example through a corporate mailbox on that domain or a DNS verification record.
5. Authorization for scanning and testing
This clause is an essential condition of the service.
5.1. When registering a domain, IP address, asset or mailbox on the Platform, the client represents and warrants that it owns it or has the express and sufficient authorization of its owner to subject it to the activities of the service.
5.2. The client expressly authorizes Axyom to perform on the registered assets the activities inherent to the service: external attack surface scanning, enumeration of subdomains and services, configuration analysis (email, certificates, exposed ports and services), vulnerability detection, automated penetration testing within the scope of the plan, and monitoring of leaked credentials and compromised accounts in open and commercial sources.
5.3. These activities may generate traffic and requests against the client’s infrastructure comparable to those of a standard security assessment. The client is responsible for informing its hosting or infrastructure providers where their terms so require.
5.4. If a registered asset turns out not to belong to the client and not to be covered by its owner’s authorization, the client shall hold Axyom harmless from any claim, penalty, damage or expense (including reasonable legal defense) arising from the scanning of that asset. Axyom may immediately suspend the scanning of any asset over which it receives a third-party claim.
5.5. Deployment of endpoint agents (EDR/MDR): when activating endpoint detection or managed response, the client declares that the devices on which the agent is deployed are owned or managed by it, and authorizes the installation of the agent, the collection of the security telemetry needed for the service and, in the case of managed MDR, the containment actions defined in the service conditions. The client is responsible for complying with its information obligations towards the users of the devices, in particular its employees, under applicable labor and data protection law. The indemnity in clause 5.4 applies equally to devices registered without sufficient ownership or authorization.
6. Acceptable use
The client agrees not to use the Platform to: (a) scan, test or monitor third-party assets without authorization; (b) resell the service or use it for the benefit of third parties without a channel or partner agreement; (c) attempt to circumvent technical limits, allowances or access controls; (d) decompile, massively extract or replicate the Platform or its data; (e) carry out any unlawful activity. Use of the AI capabilities is subject to a fair use policy; Axyom may apply technical limits to usage that degrades the service for other clients, giving prior notice where possible.
7. Plans, prices and payment
7.1. The current plans, their content and their prices are those published at getaxyom.com or shown to the client during the purchase process, which prevail over any other reference. The price applicable to each subscription is the one accepted by the client at the time of contracting, without prejudice to changes notified under clause 7.4. Prices do not include applicable indirect taxes.
7.2. Payment is processed through Stripe. Axyom does not store full card details. Purchasing a paid plan requires express acceptance of these Terms within the payment flow itself, which is recorded in accordance with clause 2.2. Subscriptions renew automatically for periods equal to the one contracted (monthly or annual) unless cancelled in accordance with clause 12.
7.3. Each plan includes reasonable usage allowances and limits (monitored mailboxes, EDR devices, penetration testing scope, AI usage) detailed in the plan description. Axyom may adjust these allowances based on actual cost, applying the changes at the next renewal and with the notice period of clause 14.
7.4. Price changes: Axyom may modify prices by giving at least 30 days’ notice. The new price applies at the first renewal after the notice period. If the client does not agree, it may cancel before that renewal at no additional cost.
7.5. Non-payment: if a charge fails, Stripe retries it and Axyom notifies the client. If non-payment persists for 10 days from the first notice, Axyom may suspend access to the paid capabilities (keeping the account in read-only mode). If it persists for 30 days, Axyom may terminate the subscription under clause 12.3.
7.6. Demos and trial periods: Axyom may grant temporary, free access to paid capabilities, with a scope and an end date communicated to the client. These grants create no payment obligation and no automatic renewal, and Axyom may revoke them before their end date, in particular in the event of use contrary to these Terms. Upon expiry or revocation, the account returns to the capabilities of the plan it has purchased or that is included for it and, failing that, to those of the Free plan. Findings and reports generated during the trial period are governed by clause 10.
7.7. Plans included as a benefit: Axyom may include a paid plan at no cost as a benefit associated with another product or program, including a cyber insurance policy mediated by Axyom or a partner program. The included plan remains in force for as long as the condition giving rise to it subsists. Once that condition ceases, Axyom will notify the client and, after a 30-day grace period, the account will move to the Free plan, without prejudice to the client’s ability to purchase any paid plan.
8. Nature of the service
The Platform is a tool for continuous management of security posture. Except as expressly agreed for the managed response service (MDR) or in Custom plans, the Platform is not an emergency service nor a real-time incident response service, and it does not replace the client’s obligations regarding security, regulatory compliance or notification of breaches to authorities and affected parties.
No security service detects all vulnerabilities or prevents all incidents. Axyom provides the service with the professional diligence required, without guaranteeing the absence of incidents, the detection of every existing risk or specific risk reduction results.
9. Service availability and system downtime
9.1. Availability target: Axyom pursues a monthly availability of the Platform (portal and console) of 99.5%, excluding the cases in clause 9.4.
9.2. Cyclical nature of monitoring: scanning, threat intelligence and automated penetration testing operate in periodic cycles. A temporary interruption of the Platform does not materially interrupt the provision of the service where the affected cycle completes after restoration. Cycles affected by downtime are executed or rescheduled once service is restored.
9.3. Scheduled maintenance: Axyom may carry out maintenance windows with a minimum of 48 hours’ notice through the portal or by email, aiming for low-activity hours (CET). Urgent maintenance for security reasons may be carried out without prior notice, informing as soon as possible.
9.4. Exclusions: the following do not count as unavailability: interruptions caused by (a) notified scheduled maintenance; (b) force majeure; (c) failures of third-party providers beyond Axyom’s reasonable control (cloud infrastructure, payment processor, external data sources); (d) acts or omissions of the client or its providers; (e) legitimate suspensions under these Terms.
9.5. Remedy: if the monthly availability of the Platform falls below 99% for two consecutive months, the client may terminate the subscription without penalty, with a refund of the proportional part of the current period not enjoyed. This remedy is the sole remedy for unavailability in the Free, Base, Pro and Max plans. Service level commitments with credits or reinforced obligations are agreed exclusively in Custom plans.
9.6. Incident communication: Axyom will report relevant availability incidents and their resolution through the portal or by email.
9.7. The availability of the Platform does not condition the validity or coverage of any cyber insurance policies the client may hold with third-party insurers, which are governed by their own terms.
10. Client data and intellectual property
10.1. The data the client provides and the findings, reports and documents generated by the Platform for the client (the “Client Data”) belong to the client. Axyom receives a limited license to process them for the sole purpose of providing, operating, maintaining and supporting the service. Axyom does not use Client Data to train artificial intelligence models, whether its own or third parties’, and does not authorize its AI providers to do so. Product improvement relies exclusively on the aggregated and anonymized data described in clause 10.3.
10.2. The Platform, its software, models, catalogs, templates and trademarks belong to Axyom or its licensors. The subscription does not transfer any intellectual property over the Platform.
10.3. Axyom may produce and use aggregated and anonymized data derived from the use of the service (metrics, threat statistics, benchmarks) provided they do not identify the client or allow its re-identification.
10.4. Confidentiality: each party shall treat as confidential the non-public information of the other to which it gains access in the course of the service, including the client’s security findings, and shall not disclose it to third parties except where legally required. This obligation survives termination for 3 years.
11. Data protection
Where the use of the Platform involves the processing of personal data under the client’s responsibility (for example, monitored corporate mailboxes or employee credentials detected in leaks), Axyom acts as a data processor under the attached DPA, which forms part of these Terms and includes the current list of sub-processors. For the data for which Axyom is the controller (contact and billing data), the Privacy Policy applies.
12. Term, cancellation and termination
12.1. Term: the subscription remains in force for as long as it renews under clause 7.2.
12.2. Cancellation by the client: the client may cancel its subscription at any time from the portal or by writing to info@getaxyom.com. Cancellation takes effect at the end of the period already billed: the client keeps full access until that date and no further charges are generated. No refund applies for the unused part of the current period, except as provided in clauses 9.5 and 12.4. Alternatively, the client may downgrade to Free and keep the account with the capabilities of that plan.
12.3. Termination by Axyom for cause: Axyom may suspend or terminate the subscription with immediate effect, upon notice, in the event of material breach of these Terms, in particular: scanning of assets without authorization (clause 5), prohibited uses (clause 6), persistent non-payment (clause 7.5) or use that endangers the Platform, other clients or third parties. Where the breach can be remedied, Axyom will grant a reasonable period to remedy it before terminating, except in urgent cases.
12.4. Termination by Axyom without cause: Axyom may terminate the subscription for convenience with 30 days’ notice, refunding the proportional part of the period already paid and not enjoyed.
12.5. Effects of termination: on the effective date, scans, monitoring and access to the plan’s capabilities cease. For the following 30 days, the client may request the export of its Client Data in a reasonable, commonly used format. After that period, Axyom will delete the Client Data in accordance with the DPA, except what it must retain by legal obligation. Reports and documents already downloaded by the client remain in its possession.
12.6. Survival: the clauses that by their nature should survive termination shall do so, in particular those on confidentiality, intellectual property, indemnity, limitation of liability and governing law.
13. Limitation of liability
13.1. Neither party excludes or limits liability that cannot legally be excluded or limited, including liability arising from willful misconduct or gross negligence.
13.2. Subject to the above, Axyom’s total aggregate liability towards the client for any cause arising from the Services as a whole, including EDR/MDR, penetration testing and any services contracted under specific conditions, is limited to the amount actually paid by the client to Axyom in the 12 months preceding the event giving rise to the claim (in free plans, to 100 euros).
13.3. Subject to the same exception, neither party shall be liable for indirect damages, loss of profit, loss of business, loss of data beyond its reasonable control or reputational damage. In particular, Axyom is not liable for damages arising from a security incident suffered by the client on the grounds that the Services had not previously detected the exploited vulnerability, without prejudice to any liability arising from a failure to meet the required professional diligence.
13.4. Claims must be notified in writing within 12 months of the event giving rise to them.
14. Changes to these Terms
Axyom may modify these Terms by giving at least 30 days’ notice by email or through a notice in the portal, indicating the version and its effective date. Material changes will require express acceptance at the next login. If the client does not accept, it may cancel under clause 12.2 before the effective date; continued use of the service after that date implies acceptance. Each version is archived and identified with a number and date.
15. Force majeure
Neither party shall be liable for non-performance caused by unforeseeable or unavoidable circumstances beyond its reasonable control (catastrophes, widespread internet infrastructure failures, large-scale attacks against third-party providers, decisions of authorities). The affected party shall give notice and mitigate the effects where possible.
16. General
16.1. Assignment: the client may not assign the contract without Axyom’s consent. Axyom may assign it to companies within its group or in the context of a corporate transaction, preserving the client’s guarantees.
16.2. Notices: notices shall be made by email to the addresses designated by each party and through notices in the portal.
16.3. Severability: if any clause is found to be void, the rest shall remain valid and the affected clause shall be replaced by a valid one with equivalent effect.
16.4. Governing law and jurisdiction: these Terms are governed by Spanish law. The parties submit to the courts of the city of Barcelona, waiving any other forum.
16.5. Language: these Terms are published in Spanish and in English. In the event of any discrepancy between the two versions, the Spanish version prevails.