Legal
Terms of Use
Effective Date: July 17, 2026
Last Updated: July 17, 2026
These Terms of Use (“Terms”) constitute a legally binding agreement between you and Ironhawk Group, the operator of Cybermatic.ai (“Cybermatic,” “Cybermatic.ai,” “Ironhawk Group,” “we,” “us,” or “our”).
These Terms govern your access to and use of:
- The Cybermatic.ai website and customer portal;
- Cybermatic.ai cloud security posture management services;
- Asset discovery and inventory services;
- Artificial intelligence-assisted security analysis;
- Risk findings, risk scores, attack scenarios, and recommendations;
- Generated remediation code and instructions;
- Compliance assessments and generated compliance documentation;
- Cybermatic Copilot, the artificial-intelligence security assistant;
- Executive reports, board reports, security questionnaires, roadmaps, and related documents;
- Application programming interfaces, integrations, dashboards, support materials, and documentation; and
- Any other products or services that reference these Terms.
Collectively, these are referred to as the “Service.”
By accessing the Site, creating an account, beginning a trial, purchasing a subscription, connecting an environment, clicking a button indicating acceptance, or otherwise using the Service, you agree to these Terms and our Privacy Policy.
If you use the Service on behalf of a company, customer, government agency, nonprofit organization, or other legal entity, you represent that you have authority to bind that entity. In that case, “you” and “Customer” refer to that entity and its authorized users.
If you do not agree to these Terms, you must not access or use the Service.
1. Business Use
The Service is intended primarily for business, professional, organizational, and governmental use. It is not intended for personal, family, household, or consumer purposes.
You must be at least 18 years old and legally capable of entering into a binding contract to use the Service.
You may not create an account or use the Service on behalf of an organization unless you have permission to do so.
2. Definitions
For purposes of these Terms:
“Authorized User” means an employee, contractor, consultant, managed service provider, advisor, or other person whom Customer authorizes to access the Service.
“Customer Data” means information, files, configuration data, asset information, account information, prompts, manually entered assets, credentials, connection information, and other material submitted to or collected through the Service on Customer’s behalf.
“Customer Environment” means any cloud account, subscription, tenant, project, application, network, endpoint, system, SaaS service, Microsoft 365 environment, manually entered asset, or other technology environment connected to or evaluated through the Service.
“Documentation” means user guides, support articles, technical specifications, onboarding materials, and other documentation that we make available regarding the Service.
“Output” means findings, scores, explanations, reports, documents, code, commands, recommendations, roadmaps, answers, summaries, and other material generated or presented through the Service.
“Order Form” means an ordering document, online checkout page, enterprise agreement, statement of work, or similar document identifying the Service purchased by Customer.
“Site” means the Cybermatic.ai website, customer portal, dashboard, and associated webpages.
3. Description of the Service
Cybermatic.ai provides artificial intelligence-assisted cybersecurity posture management and related decision-support services.
Depending on the selected plan, the Service may include:
- Cloud and SaaS asset discovery;
- Security configuration analysis;
- Identification and prioritization of potential vulnerabilities, exposures, identity risks, credential risks, and misconfigurations;
- Generation of remediation recommendations, code, commands, and policy changes;
- Compliance readiness assessments and documentation;
- AI-assisted answers relating to Customer’s security environment;
- Risk scores, benchmarks, executive summaries, board reports, and remediation roadmaps;
- APIs and third-party integrations;
- Periodic or continuous scanning, subject to the applicable subscription;
- Support, advisory, or onboarding services; and
- Additional features introduced from time to time.
Features, scanning frequency, supported environments, asset limits, support levels, integrations, and availability depend on Customer’s subscription plan and applicable Order Form.
4. Cybermatic.ai Is a Decision-Support Platform
Cybermatic.ai is a decision-support platform. Unless expressly stated in a separate written agreement, Cybermatic.ai is not acting as:
- Customer’s chief information security officer;
- A managed security services provider;
- A managed detection and response provider;
- An incident response provider;
- A penetration testing provider;
- A law firm or legal advisor;
- A certified public accounting firm;
- An auditor or certification body;
- An insurance broker or insurer;
- A regulatory authority;
- A compliance assessor; or
- A substitute for Customer’s own qualified personnel and professional advisors.
Customer retains responsibility for its systems, security decisions, compliance obligations, risk acceptance decisions, remediation actions, incident response, backups, business continuity, and regulatory obligations.
5. Artificial Intelligence and Generated Output
The Service uses artificial intelligence and automated analysis. Artificial intelligence systems can produce incomplete, inaccurate, outdated, misleading, non-unique, or inappropriate Output.
Customer acknowledges that:
- Output may contain false positives, false negatives, omissions, or incorrect conclusions.
- The absence of a finding does not mean that a system is secure, compliant, vulnerability-free, or properly configured.
- A risk score, severity level, benchmark, or readiness percentage is an estimate and not an assurance, certification, warranty, or professional opinion.
- Output may be affected by incomplete permissions, unavailable APIs, stale data, third-party service limitations, Customer configuration, or information that Customer did not provide.
- Similar or identical Output may be generated for other customers.
- Customer must independently evaluate all Output before relying on it or communicating it to another person.
- Customer is solely responsible for decisions made based on Output.
Customer must not represent AI-generated Output as having been independently verified, audited, certified, or approved by Cybermatic.ai unless we have expressly provided that verification or approval in a separate signed writing.
6. Remediation Code and Commands
The Service may generate Terraform, cloud command-line instructions, PowerShell, Python, policy language, configuration changes, scripts, or other remediation materials.
Cybermatic.ai does not automatically apply remediation changes unless Customer and Cybermatic.ai enter into a separate written agreement expressly authorizing that functionality.
Before applying generated remediation material, Customer must:
- Review the complete Output;
- Confirm that resource names, identifiers, regions, accounts, permissions, dependencies, and assumptions are accurate;
- Determine whether the change is appropriate for Customer’s environment;
- Test the change in a non-production environment when reasonably possible;
- Maintain current backups;
- Prepare a tested rollback or recovery procedure;
- Follow Customer’s change-management and approval procedures; and
- Obtain any required authorization from system owners.
Customer assumes responsibility for applying or failing to apply remediation Output.
Cybermatic.ai is not responsible for outages, access failures, configuration changes, data loss, service interruption, security weaknesses, increased cloud costs, or other consequences resulting from Customer’s use of generated code, commands, instructions, or recommendations.
7. Compliance Documents and Reports
The Service may generate policies, control descriptions, risk assessments, evidence lists, control mappings, compliance summaries, questionnaires, executive reports, and other documentation relating to frameworks such as SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, CIS, or similar standards.
Generated documents are drafts requiring Customer review, customization, approval, implementation, and maintenance.
Use of the Service does not:
- Establish or guarantee legal or regulatory compliance;
- Guarantee that Customer will pass an audit or assessment;
- Constitute an audit, attestation, certification, legal opinion, or accounting opinion;
- Guarantee acceptance by an auditor, regulator, customer, insurer, bank, investor, or business partner;
- Create, implement, or operate the controls described in a generated document;
- Satisfy Customer’s obligation to collect or retain evidence;
- Replace legal, compliance, accounting, audit, privacy, or security advice; or
- Automatically create a valid HIPAA business associate agreement, data processing agreement, or other regulated contract.
Customer must have generated documents reviewed by appropriate legal, compliance, security, privacy, audit, human-resources, and management personnel before adoption or external distribution.
Customer is responsible for ensuring that adopted documentation accurately reflects Customer’s actual practices.
8. Authorization to Connect Systems
Customer may connect only systems, accounts, subscriptions, projects, tenants, domains, assets, and environments that Customer owns or is expressly authorized to access and assess.
Customer represents and warrants that:
- It has all rights, permissions, notices, and consents necessary to connect each Customer Environment;
- Its use of the Service will not violate any contract, policy, law, regulation, court order, or third-party right;
- It has authority to provide any cloud role, API credential, application credential, service-account key, tenant information, or other connection information submitted to the Service; and
- Any managed service provider, consultant, employee, or contractor using the Service on Customer’s behalf is properly authorized.
Customer must not use the Service to scan, assess, investigate, monitor, or obtain information about a system without the owner’s permission.
Cybermatic.ai may request evidence of authorization and may suspend or terminate access if authorization is unclear.
9. Cloud Access and Credentials
The Service is designed to use read-only or equivalent limited-access cloud permissions for ordinary asset discovery and security analysis.
Customer is responsible for reviewing all roles, policies, permissions, templates, application registrations, service accounts, and credentials before approving or installing them.
Customer must:
- Protect credentials associated with the Service;
- Promptly rotate credentials when compromise is suspected;
- Revoke credentials belonging to departed personnel;
- Limit access according to least-privilege principles;
- Notify Cybermatic.ai of suspected unauthorized use; and
- Revoke the Service’s access when it is no longer required.
Cybermatic.ai is not responsible for permissions that Customer modifies, expands, misconfigures, or grants outside the instructions supplied by Cybermatic.ai.
10. Accounts and Account Security
Customer must provide accurate and current account information.
Customer is responsible for:
- All activity conducted through its account;
- Maintaining the confidentiality of usernames, passwords, authentication codes, recovery codes, API keys, and credentials;
- Using multifactor authentication where available;
- Ensuring Authorized Users use individual accounts where required;
- Promptly removing access for people who no longer require it;
- Reviewing account activity; and
- Immediately reporting suspected unauthorized access.
Customer must not share accounts with unauthorized people, sell account access, or allow the number of Authorized Users to exceed applicable plan limits.
We may rely on instructions received through Customer’s authenticated account.
11. Customer Responsibilities
Customer is responsible for:
- The accuracy, quality, legality, and completeness of Customer Data;
- Customer’s security policies and procedures;
- Maintaining independent inventories and records where required;
- Maintaining backups and recovery capabilities;
- Monitoring Customer’s own systems;
- Responding to actual or suspected incidents;
- Applying security updates and patches;
- Reviewing and prioritizing findings;
- Correcting configuration errors;
- Verifying compliance requirements;
- Training Customer personnel;
- Managing vendors and third parties;
- Determining whether additional security testing is required;
- Obtaining professional advice where appropriate; and
- Ensuring that use of the Service complies with applicable laws and contracts.
Cybermatic.ai is not responsible for an incident merely because the Service did not identify, prioritize, prevent, or provide notice of the condition associated with that incident.
12. Prohibited Uses
Customer and Authorized Users may not use the Service to:
- Access, test, scan, or analyze systems without authorization;
- Conduct unlawful surveillance or collect information unlawfully;
- Develop, distribute, deploy, or operate malware, ransomware, destructive code, credential-stealing tools, or unauthorized access mechanisms;
- Attack, exploit, disrupt, overload, or interfere with any system or network;
- Facilitate phishing, fraud, identity theft, extortion, harassment, or unlawful activity;
- Circumvent authentication, access controls, rate limits, subscription limits, or security measures;
- Upload malicious code or content;
- Probe or test Cybermatic.ai’s infrastructure without written authorization;
- Reverse engineer, decompile, disassemble, copy, scrape, or attempt to derive the source code or non-public components of the Service, except where applicable law expressly prohibits this restriction;
- Use the Service or Output to build, train, benchmark, or improve a competing product or artificial intelligence model without written permission;
- Resell, sublicense, lease, time-share, or provide the Service to third parties except as authorized by an applicable plan or written agreement;
- Remove proprietary notices;
- Misrepresent Output as independently certified or verified;
- Submit classified information, export-controlled technical data, cardholder data, protected health information, or other specially regulated workload content unless expressly permitted under a separate written agreement;
- Violate sanctions, export-control laws, privacy laws, intellectual-property rights, or other applicable requirements; or
- Encourage or assist another person in doing any of the above.
We may investigate suspected violations and cooperate with lawful investigations.
13. Customer Data
As between Customer and Cybermatic.ai, Customer retains its rights in Customer Data.
Customer grants Cybermatic.ai and its subprocessors a limited, non-exclusive, worldwide right to host, access, copy, transmit, process, analyze, display, and otherwise use Customer Data only as reasonably necessary to:
- Provide and secure the Service;
- Authenticate users;
- Operate requested integrations;
- Generate Output;
- Prevent fraud and abuse;
- Provide support;
- Meet legal obligations; and
- Improve the Service as permitted by these Terms and the Privacy Policy.
Customer represents that it has all rights and permissions necessary to provide Customer Data and authorize its processing.
Unless Customer expressly opts in through a separate written process, Cybermatic.ai will not use Customer’s non-public environment data to train a generalized artificial intelligence model made available to unrelated third parties.
Cybermatic.ai may use aggregated or de-identified information to operate, secure, analyze, and improve the Service, provided the information does not reasonably identify Customer or an individual.
14. Sensitive and Regulated Information
The Service is intended primarily to process cloud configuration metadata, asset information, security findings, account information, and related business information.
Unless expressly authorized in a separate agreement, Customer must not intentionally submit:
- Classified government information;
- Payment-card magnetic-stripe or authentication data;
- Complete financial-account credentials;
- Biometric templates;
- Patient medical records;
- Social Security numbers;
- Government identification documents;
- Unnecessary production database content;
- Customer workload content unrelated to security analysis; or
- Information whose processing would require Cybermatic.ai to enter into a specialized regulated agreement.
The submission of necessary cloud connection credentials in accordance with the Documentation is not prohibited by this section.
Customer is responsible for determining whether a data processing agreement, business associate agreement, government contract clause, or other specialized agreement is required.
15. Privacy
Our Privacy Policy describes how we collect, use, disclose, protect, and retain personal information.
By using the Service, Customer acknowledges the Privacy Policy.
If Customer processes personal information through the Service, Customer is responsible for:
- Providing required notices;
- Establishing an appropriate legal basis;
- Responding to individual rights requests;
- Maintaining required consents;
- Complying with retention requirements; and
- Entering into any required data processing agreement.
If these Terms conflict with an executed data processing agreement regarding the processing of personal information, the data processing agreement controls for that conflict.
16. Confidentiality
Each party may receive non-public information from the other party that is identified as confidential or that reasonably should be understood to be confidential.
Customer Confidential Information includes non-public Customer Data, cloud configuration information, security findings, credentials, vulnerability information, asset inventories, reports, and business information.
Cybermatic.ai Confidential Information includes non-public software, architecture, pricing, security controls, product plans, source code, credentials, documentation, and technical information.
The receiving party will:
- Use Confidential Information only to perform or receive the Service;
- Protect it using at least reasonable care;
- Disclose it only to personnel, contractors, advisors, and subprocessors who need access and are bound by confidentiality obligations; and
- Notify the disclosing party of unauthorized disclosure when legally permitted and reasonably practicable.
Confidential Information does not include information that the receiving party can demonstrate:
- Was already lawfully known without restriction;
- Becomes public without breach of an obligation;
- Is received lawfully from another source without a confidentiality duty; or
- Is independently developed without use of the other party’s Confidential Information.
A party may disclose Confidential Information when legally required, provided it gives notice when legally permitted and reasonably assists with efforts to seek protective treatment.
These obligations survive for three years after termination, except that trade secrets remain protected for as long as they qualify as trade secrets under applicable law.
17. Ownership of the Service
Cybermatic.ai and its licensors retain all rights, title, and interest in:
- The Service;
- Software, interfaces, databases, models, workflows, and algorithms;
- Documentation;
- Site content;
- Trademarks, logos, and branding;
- Templates and report structures;
- Improvements and derivative works; and
- Related intellectual property.
Except for the limited rights expressly granted in these Terms, no rights are transferred to Customer.
Subject to payment of applicable fees and compliance with these Terms, Cybermatic.ai grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the subscription term to access and use the Service for Customer’s authorized business purposes.
18. Use of Output
Subject to these Terms and the applicable subscription plan, Customer may use Output for:
- Customer’s internal business purposes;
- Customer security and compliance operations;
- Board and management reporting;
- Customer questionnaires;
- Insurance applications;
- Audit preparation;
- Communications with Customer’s professional advisors; and
- Services performed for Customer by its authorized managed service provider.
If Customer is an authorized managed service provider or consultant, Customer may use Output for its clients only to the extent permitted by its subscription or separate written agreement.
To the extent Cybermatic.ai owns intellectual-property rights in Output generated specifically for Customer, Cybermatic.ai grants Customer a non-exclusive, worldwide, perpetual license to use, reproduce, modify, distribute, and display that Output for Customer’s authorized business purposes.
This license does not transfer ownership of the underlying Service, models, software, templates, or technology.
Because Output may not be unique, Cybermatic.ai does not represent that Customer will have exclusive rights in Output.
19. Feedback
If Customer provides suggestions, ideas, enhancement requests, recommendations, or other feedback, Customer grants Cybermatic.ai a perpetual, irrevocable, worldwide, royalty-free right to use that feedback without restriction or compensation.
This provision does not authorize Cybermatic.ai to identify Customer publicly without permission.
20. Third-Party Services and Integrations
The Service may interoperate with or depend on third-party products and services, including cloud providers, artificial intelligence providers, identity providers, payment processors, communications platforms, ticketing systems, and other integrations.
Customer authorizes Cybermatic.ai to transmit Customer Data to a third-party service when necessary to enable an integration selected or requested by Customer.
Third-party services are governed by their own terms, privacy policies, availability, security, and functionality.
Cybermatic.ai does not control and is not responsible for:
- Third-party outages or service changes;
- Discontinued APIs;
- Changes in permissions or pricing;
- Third-party acts or omissions;
- Customer’s relationship with a third party;
- Data retained by a third party;
- The accuracy of third-party information; or
- Damage caused by a third-party service.
Cybermatic.ai may modify, suspend, or discontinue an integration when a third party changes or discontinues its service.
21. Trials, Beta Features, and Early Access
Cybermatic.ai may provide free trials, previews, prototypes, beta features, early-access functionality, or evaluation accounts.
Unless otherwise stated:
- Trials and beta features may be modified or discontinued at any time;
- They may contain errors or incomplete functionality;
- They may not be suitable for production use;
- Support and service-level commitments may not apply;
- Data generated during a trial may be deleted after the retention period described in the Documentation or Privacy Policy; and
- Cybermatic.ai may impose additional limits.
A free trial will not automatically become a paid subscription unless Customer affirmatively selects a paid plan or otherwise authorizes payment.
22. Subscriptions, Billing, and Renewal
Paid subscriptions are billed according to the selected plan or Order Form.
Unless otherwise stated:
- Subscriptions are billed monthly in advance;
- Subscriptions automatically renew for successive monthly periods until canceled;
- Customer authorizes the applicable payment processor to charge the payment method on file;
- Fees are stated in United States dollars;
- Fees are non-refundable except where required by law or expressly stated in an Order Form;
- Customer is responsible for applicable sales, use, value-added, withholding, and similar taxes, excluding taxes based on Cybermatic.ai’s net income; and
- Customer must keep billing and payment information current.
If a payment is overdue, Cybermatic.ai may suspend access after providing notice when reasonably practicable.
Customer may cancel through the available billing portal or by contacting Cybermatic.ai. Cancellation takes effect at the end of the current paid billing period unless otherwise stated.
Upgrades may take effect immediately. Downgrades ordinarily take effect at the next renewal.
Cybermatic.ai may change subscription pricing by providing reasonable advance notice. Continued use after the effective date of a pricing change constitutes acceptance of the new price, unless Customer cancels before renewal.
23. Plan Limits and Usage
Customer must comply with applicable limits regarding assets, accounts, users, scans, reports, documents, API calls, storage, integrations, or other usage measurements.
Cybermatic.ai may:
- Enforce technical usage limits;
- Require an upgrade for excess usage;
- Restrict unusually burdensome usage;
- Apply reasonable rate limits; or
- Contact Customer to discuss an appropriate enterprise plan.
Customer may not divide an organization, create duplicate accounts, or otherwise structure usage to avoid applicable limits or fees.
24. Support and Availability
Support is provided according to the applicable plan, Documentation, or Order Form.
Any response time is a target unless expressly identified as a binding service-level commitment in a signed agreement.
Cybermatic.ai may temporarily suspend access for:
- Scheduled maintenance;
- Emergency maintenance;
- Security issues;
- Third-party outages;
- Legal requirements;
- Protection of the Service or customers; or
- Events beyond our reasonable control.
Except for an expressly executed service-level agreement, Cybermatic.ai does not guarantee any particular availability percentage, response time, scan completion time, or time to resolution.
An advertised Enterprise service-level commitment applies only when incorporated into an executed Enterprise Order Form or agreement.
25. Suspension
Cybermatic.ai may suspend all or part of Customer’s access when reasonably necessary to:
- Prevent or address a security threat;
- Prevent unauthorized or unlawful use;
- Protect another customer or third party;
- Address nonpayment;
- Comply with law or a legal request;
- Investigate a suspected violation;
- Prevent material harm to the Service; or
- Address use that materially exceeds plan limits.
When reasonably practicable, Cybermatic.ai will provide notice and an opportunity to cure.
Cybermatic.ai is not liable for a suspension made in good faith under this section.
26. Term and Termination
These Terms begin when Customer first accepts them or uses the Service and continue until terminated.
Customer may terminate by canceling its subscription and discontinuing use.
Cybermatic.ai may terminate these Terms or Customer’s access if:
- Customer materially breaches these Terms and does not cure the breach after reasonable notice;
- Customer fails to pay required fees;
- Customer’s use creates a security, legal, or operational risk;
- Customer becomes insolvent;
- Continuing to provide the Service becomes unlawful; or
- Cybermatic.ai discontinues the applicable Service.
Cybermatic.ai may terminate a free account or trial at any time, subject to applicable law.
Upon termination:
- Customer’s right to access the Service ends;
- Outstanding fees remain due;
- Customer must stop using Cybermatic.ai intellectual property;
- Customer should export available Customer Data before termination; and
- Cybermatic.ai may delete Customer Data according to its retention practices, Privacy Policy, Documentation, and legal obligations.
Sections that by their nature should survive termination will survive, including ownership, confidentiality, indemnification, disclaimers, limitations of liability, dispute resolution, and payment obligations.
27. Indemnification
To the maximum extent permitted by law, Customer will defend, indemnify, and hold harmless Cybermatic.ai, Ironhawk Group, their affiliates, and their respective officers, directors, employees, contractors, licensors, and agents from claims, damages, judgments, settlements, penalties, losses, liabilities, costs, and reasonable attorneys’ fees arising out of or relating to:
- Customer Data;
- Customer’s or an Authorized User’s use of the Service;
- Customer’s connection of an unauthorized environment;
- Customer’s violation of these Terms;
- Customer’s violation of law or third-party rights;
- Customer’s application of generated remediation material;
- Customer’s external distribution or representation of Output;
- A dispute between Customer and one of its Authorized Users, clients, vendors, employees, or contractors; or
- Customer’s fraud, willful misconduct, or gross negligence.
Cybermatic.ai will provide reasonable notice of a covered claim and may participate through counsel of its choosing.
Customer may not settle a claim in a manner that admits liability by Cybermatic.ai, imposes obligations on Cybermatic.ai, or restricts Cybermatic.ai without written consent.
28. WARRANTY DISCLAIMERS
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SITE, SERVICE, DOCUMENTATION, OUTPUT, INTEGRATIONS, AND SUPPORT ARE PROVIDED “AS IS” AND “AS AVAILABLE.”
CYBERMATIC.AI DISCLAIMS ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING WARRANTIES OF:
- MERCHANTABILITY;
- FITNESS FOR A PARTICULAR PURPOSE;
- TITLE;
- NON-INFRINGEMENT;
- ACCURACY;
- COMPLETENESS;
- SECURITY;
- AVAILABILITY;
- QUIET ENJOYMENT;
- COMPATIBILITY; AND
- RESULTS.
CYBERMATIC.AI DOES NOT WARRANT THAT:
- THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE;
- EVERY ASSET, VULNERABILITY, MISCONFIGURATION, THREAT, CREDENTIAL, OR RISK WILL BE IDENTIFIED;
- FINDINGS WILL BE COMPLETE OR ACCURATE;
- OUTPUT WILL BE CURRENT, CORRECT, OR SUITABLE FOR CUSTOMER’S PURPOSE;
- GENERATED CODE WILL OPERATE WITHOUT ERROR OR ADVERSE EFFECT;
- USE OF THE SERVICE WILL PREVENT AN ATTACK, BREACH, LOSS, OR INCIDENT;
- CUSTOMER WILL ACHIEVE OR MAINTAIN COMPLIANCE;
- AN AUDITOR, REGULATOR, INSURER, CUSTOMER, OR BUSINESS PARTNER WILL ACCEPT OUTPUT;
- CUSTOMER WILL PASS AN AUDIT OR OBTAIN A CERTIFICATION;
- THIRD-PARTY SERVICES WILL REMAIN AVAILABLE; OR
- THE SERVICE WILL MEET EVERY CUSTOMER REQUIREMENT.
CUSTOMER ASSUMES THE RISK OF USING THE SERVICE AND OUTPUT.
Some jurisdictions do not allow certain warranty exclusions. In those jurisdictions, these exclusions apply only to the maximum extent permitted by law.
29. EXCLUSION OF CERTAIN DAMAGES
TO THE MAXIMUM EXTENT PERMITTED BY LAW, CYBERMATIC.AI, IRONHAWK GROUP, THEIR AFFILIATES, AND THEIR RESPECTIVE OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, LICENSORS, SUBPROCESSORS, AND AGENTS WILL NOT BE LIABLE FOR ANY:
- INDIRECT DAMAGES;
- INCIDENTAL DAMAGES;
- SPECIAL DAMAGES;
- CONSEQUENTIAL DAMAGES;
- EXEMPLARY DAMAGES;
- PUNITIVE DAMAGES;
- LOSS OF PROFITS;
- LOSS OF REVENUE;
- LOSS OF BUSINESS;
- LOSS OF GOODWILL;
- LOSS, CORRUPTION, OR UNAVAILABILITY OF DATA;
- BUSINESS INTERRUPTION;
- SYSTEM OUTAGE;
- COST OF SUBSTITUTE SERVICES;
- LOSS OF ANTICIPATED SAVINGS;
- REGULATORY FINE OR PENALTY;
- THIRD-PARTY CLAIM;
- FAILURE TO IDENTIFY A SECURITY CONDITION;
- SECURITY INCIDENT, CYBERATTACK, OR DATA BREACH; OR
- DAMAGE RESULTING FROM CUSTOMER’S RELIANCE ON OR APPLICATION OF OUTPUT.
THIS EXCLUSION APPLIES REGARDLESS OF THE LEGAL THEORY ASSERTED AND EVEN IF CYBERMATIC.AI WAS ADVISED THAT THE DAMAGE WAS POSSIBLE.
30. LIMITATION OF LIABILITY
30.1 Aggregate Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF CYBERMATIC.AI, IRONHAWK GROUP, THEIR AFFILIATES, AND THEIR RESPECTIVE OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, LICENSORS, SUBPROCESSORS, AND AGENTS ARISING OUT OF OR RELATING TO THE SITE, SERVICE, OUTPUT, DOCUMENTATION, THESE TERMS, OR THE PARTIES’ RELATIONSHIP WILL NOT EXCEED:
THE GREATER OF:
- FIFTY UNITED STATES DOLLARS ($50.00); OR
- THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO CYBERMATIC.AI FOR THE SPECIFIC SERVICE GIVING RISE TO THE CLAIM DURING THE TWELVE MONTHS IMMEDIATELY PRECEDING THE EVENT THAT FIRST GAVE RISE TO LIABILITY.
For a free trial, free account, website visitor, or other person who has not paid Cybermatic.ai, the maximum aggregate liability is fifty United States dollars ($50.00).
30.2 One Cap Per Customer Entity
The liability cap applies collectively to:
- Customer;
- Customer’s parent companies;
- Customer’s subsidiaries and affiliates;
- Customer’s Authorized Users;
- Customer’s representatives; and
- Every person or entity claiming through Customer.
It does not apply separately per user, affiliate, account, subscription, environment, incident, event, claim, legal theory, or form of relief.
All related claims will be treated as a single claim for purposes of the liability cap.
30.3 Scope
The limitations apply to claims based on:
- Contract;
- Warranty;
- Tort;
- Negligence;
- Misrepresentation;
- Strict liability;
- Statute;
- Restitution;
- Indemnity; or
- Any other legal or equitable theory.
They apply even if a limited remedy fails of its essential purpose.
30.4 Non-Excludable Liability
Nothing in these Terms excludes or limits liability to the extent that applicable law prohibits that liability from being excluded or limited.
30.5 Allocation of Risk
Customer acknowledges that the warranty disclaimers, exclusions of damages, and liability limitations are an essential part of the parties’ agreement, reflect an agreed allocation of risk, and enable Cybermatic.ai to offer the Service at the stated prices.
31. Claims Deadline
To the maximum extent permitted by law, any claim arising from or relating to the Service or these Terms must be filed within one year after the event giving rise to the claim.
A claim filed after that period is permanently barred.
This provision does not shorten a limitations period that applicable law prohibits the parties from shortening.
32. Informal Dispute Resolution
Before initiating arbitration or litigation, a party must send written notice describing:
- The party’s name and contact information;
- The relevant account;
- The facts supporting the dispute;
- The legal basis for the claim;
- The requested resolution; and
- The amount claimed, if applicable.
The parties will attempt in good faith to resolve the dispute for at least 30 days after notice is received.
Notices to Cybermatic.ai must be sent to info@cybermatic.ai with the subject line “Legal Dispute Notice.”
33. Binding Arbitration
This section requires individual arbitration and limits the manner in which disputes may be resolved.
Except for the exceptions below, any dispute arising out of or relating to the Service, these Terms, an Order Form, Output, Customer Data, or the relationship between the parties will be resolved through final and binding arbitration.
Arbitration will be administered by the American Arbitration Association under its applicable Commercial Arbitration Rules.
The arbitration will:
- Be conducted by one neutral arbitrator;
- Take place in Dallas County, Texas, unless the parties agree to remote proceedings;
- Be conducted in English;
- Permit reasonable exchange of relevant, non-privileged information; and
- Result in a written decision stating the essential findings and conclusions.
The arbitrator may award relief available under applicable law, subject to the limitations in these Terms.
Judgment on the award may be entered in any court with jurisdiction.
Either party may bring an individual action in small-claims court if the claim qualifies. Either party may also seek temporary or injunctive relief to prevent unauthorized access, misuse, infringement, misappropriation, or disclosure of intellectual property, credentials, or Confidential Information.
34. Class-Action and Jury-Trial Waiver
TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY AGREES THAT CLAIMS MAY BE BROUGHT ONLY IN ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF, CLASS MEMBER, OR REPRESENTATIVE IN A CLASS, COLLECTIVE, CONSOLIDATED, MASS, OR REPRESENTATIVE ACTION.
The arbitrator may not combine claims belonging to different customers or preside over a representative proceeding.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY WAIVES THE RIGHT TO A TRIAL BY JURY.
If the class-action waiver is found unenforceable for a particular claim, that claim must proceed in court and not in arbitration.
35. Governing Law and Venue
These Terms are governed by the laws of the State of Texas, without regard to conflict-of-law rules.
For disputes not subject to arbitration, the parties consent to exclusive jurisdiction and venue in the state and federal courts located in Dallas County, Texas.
The United Nations Convention on Contracts for the International Sale of Goods does not apply.
36. Export Controls and Sanctions
Customer may not access or use the Service in violation of United States export-control or economic-sanctions laws.
Customer represents that it is not:
- Located in a jurisdiction subject to comprehensive United States sanctions;
- Identified on a prohibited-party list; or
- Owned or controlled by a prohibited party.
Customer may not use the Service for prohibited end uses or provide access to a prohibited person.
37. Government Use
If Customer is a United States government entity, the Service and Documentation are commercial products and commercial computer software developed exclusively at private expense.
Government rights are limited to those provided under these Terms and any applicable signed government agreement.
No government-specific requirement applies unless expressly accepted by Cybermatic.ai in a signed writing.
38. Changes to the Service
Cybermatic.ai may improve, modify, add, remove, suspend, or discontinue features.
We will use reasonable efforts to provide notice before a material discontinuation that substantially reduces the core functionality of a paid Service.
We are not required to maintain a particular feature, integration, model, interface, report format, or third-party provider unless expressly stated in an Order Form.
39. Changes to These Terms
Cybermatic.ai may update these Terms from time to time.
When changes are material, we may provide notice by email, through the Service, during login, or by another reasonable method.
Updated Terms become effective on the stated effective date.
Continued use after the effective date constitutes acceptance, except where applicable law requires additional consent.
If Customer does not agree to a material change, Customer must stop using the Service and may cancel its subscription before the change becomes effective.
40. Electronic Communications and Acceptance
Customer consents to receiving electronic communications concerning:
- Account administration;
- Security notices;
- Billing;
- subscription changes;
- Service updates;
- Legal notices; and
- Support.
Electronic communications satisfy legal requirements that communications be in writing.
An electronic acceptance, checkbox, button click, digital signature, or authenticated use of the Service has the same effect as a handwritten signature to the maximum extent permitted by law.
41. Publicity
Cybermatic.ai will not use Customer’s name or logo in public marketing materials without Customer’s permission, except to identify Customer privately within the Service or as otherwise necessary to provide support.
Any case study, testimonial, public logo use, or public attribution requires separate authorization.
42. Force Majeure
Cybermatic.ai is not responsible for delay or failure caused by circumstances beyond its reasonable control, including:
- Natural disasters;
- Fire, flood, or severe weather;
- War, terrorism, civil unrest, or government action;
- Labor disputes;
- Internet or telecommunications failures;
- Utility failures;
- Cloud-provider outages;
- Artificial-intelligence-provider outages;
- Cyberattacks;
- Denial-of-service attacks;
- Epidemics or public-health emergencies; or
- Failures of third-party services.
Payment obligations are not excused by this section.
43. Order of Precedence
If documents conflict, the following order applies unless expressly stated otherwise:
- A separately negotiated and signed master services agreement;
- An executed Enterprise Order Form;
- An executed data processing agreement or business associate agreement, but only for matters within its scope;
- These Terms;
- The Privacy Policy;
- Documentation; and
- Other Site content.
A purchase order issued by Customer is for administrative convenience only. Additional or conflicting purchase-order terms are rejected unless expressly accepted in a signed writing by Cybermatic.ai.
44. Assignment
Customer may not assign or transfer these Terms without Cybermatic.ai’s written consent, except in connection with a merger, acquisition, or sale of substantially all of Customer’s assets, provided the successor is not a Cybermatic.ai competitor and agrees to these Terms.
Cybermatic.ai may assign these Terms to an affiliate or in connection with a merger, acquisition, financing, reorganization, or sale of assets.
An unauthorized assignment is void.
45. Severability
If any provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable.
If modification is not possible, the provision will be severed and the remaining provisions will remain effective.
46. Waiver
A failure or delay in enforcing a provision does not waive the right to enforce it later.
A waiver must be in writing and signed by the party granting it.
47. No Partnership or Agency
These Terms do not create a partnership, joint venture, employment relationship, fiduciary relationship, franchise, or agency relationship.
Neither party may bind the other without written authorization.
48. No Third-Party Beneficiaries
Except for Cybermatic.ai parties expressly protected by the disclaimers, indemnification provisions, and liability limitations, these Terms do not create rights for third parties.
49. Entire Agreement
These Terms, applicable Order Forms, the Privacy Policy, and any signed agreements referenced in them constitute the entire agreement regarding the Service and supersede prior or contemporaneous discussions and communications concerning the same subject matter.
50. Contact Information
Questions, legal notices, and requests concerning these Terms may be sent to:
Cybermatic.ai by Ironhawk Group
Email: info@cybermatic.ai
Phone: (800) 439-3040
Mailing address: 9330 Lyndon B Johnson Fwy, Suite 900, Dallas, TX 75243, United States
Legal dispute notices should include the subject line:
Legal Dispute Notice