Back to the site

Terms of Use

Atrekos (the “Service”) is operated by the legal person named in the imprint (the “Operator”, “we”, “us”). These Terms of Use govern access to and use of the Service: the web application, the read API, the reports and exports it produces, and the related documentation. By creating an account, accepting an invitation to an organisation or otherwise using the Service, you agree to them. If you do not agree, do not use the Service.

Last updated

1. Acceptance, parties and order of precedence

The Service is offered to businesses and other organisations, not to consumers. The contracting party is the organisation whose administrator created or accepted the organisation’s account (the “Customer”). Each person who uses the Service under that organisation (a “User”) does so on the Customer’s behalf and must also comply with these Terms.

If you accept these Terms on behalf of an organisation, you represent that you have authority to bind it.

The following documents form part of the agreement, in this order of precedence where they conflict: a signed order form or pilot agreement, if any; the Data Processing Agreement (“DPA”), for the processing of personal data on the Customer’s behalf; these Terms; and the privacy and cookie pages, which are incorporated by reference.

2. Eligibility

You must be at least 18 years old.

You are responsible for ensuring that your use of the Service complies with the laws that apply to you, including data protection, export control and sanctions law.

3. What the Service is

The Service computes a cybersecurity risk assessment for a Target of Evaluation (“TOE”) that a User describes through a questionnaire. A deterministic engine derives risks, mitigations, treatments and regulatory projections, including projections against Annex I of the EU Cyber Resilience Act (“CRA”) and IEC 62443-4-2, from the answers and the catalogue content the Customer’s organisation has been provisioned with.

Depending on the Customer’s plan, the Service also includes organisation administration, catalogue management and org-authored content, licensed regulatory frameworks, reports and exports (PDF, JSON, XLSX), AI-assisted features (Section 8) and a read-only HTTP API (Section 10).

The Service is in a closed pilot and is not generally available. We may add, change, limit or withdraw features, catalogues, frameworks, models or plans. Where a change materially reduces what a paying Customer receives, we give notice as set out in Section 19.

The outputs of the Service are decision support. They are not legal, regulatory or engineering advice, and they do not establish that a product conforms to the CRA, IEC 62443, a harmonised standard or any other requirement. Conformity assessment, and the decision to place a product on the market, remain the Customer’s responsibility.

4. Accounts, organisations and roles

An organisation’s administrator invites members and assigns each a role. What a role may do is shown in the Service beside each role picker. A role change takes effect on the member’s next request.

Each User must have their own credentials. Credentials and API keys are personal and may not be shared, sold or transferred. A business account may not be used as a shared login for several people.

You must keep credentials confidential, keep account information accurate, and tell us promptly at the contact address in the imprint if you suspect unauthorised use. You are responsible for all activity under your credentials until you have told us.

Every organisation’s data is isolated from every other organisation’s. A User may only act within the organisations they are a member of.

5. Customer Content and outputs

Everything the Customer and its Users enter into or upload to the Service, including TOE descriptions, answers, attachments, evidence, org-authored catalogue content and frameworks the Customer owns, is “Customer Content”. Customer Content remains the Customer’s property. You represent that you have the rights needed to use it in the Service.

The Customer grants the Operator a non-exclusive, worldwide, royalty-free licence to store, process, reproduce and display Customer Content solely to provide, secure, support and improve the Service, including to compute assessments, render reports and keep backups. The licence ends when the Customer Content is deleted under Section 15, except for backups, which expire on their own schedule, and records we must keep by law.

We do not use Customer Content or outputs to train machine-learning models, and we contract with the providers in Section 8 so that they do not either.

The engine’s results (risk register, treatments, projections, reports) are generated for the Customer and may be used by the Customer for its internal purposes, including in its own technical documentation, subject to the third-party licence obligations in Section 7 where a report reproduces catalogue or framework content.

The Customer is responsible for Customer Content and for how it uses outputs. Review every output before relying on it.

We may remove or restrict access to Customer Content that violates these Terms or the law, and will tell the organisation’s administrator when we do unless the law prevents it.

6. Intellectual property

The Service, including its software, engine, user interface, designs, templates, documentation and trademarks, is owned by or licensed to the Operator. Except for the limited right to use the Service under these Terms, no rights are granted. You may not copy, modify, distribute, sell, lease, reverse engineer or create derivative works of the Service, except to the extent the law allows despite this clause.

“Atrekos” and the Atrekos logo are marks of the Operator. You may not use them without written permission.

Catalogue content and framework texts carry their own licences, which Section 7 explains. Nothing in this Section restricts rights those licences grant.

7. Catalogue content, frameworks and third-party licences

Every catalogue pack in the Service renders an attribution notice naming each upstream work it derives from, its authors, its licence, the licence text or a link to it, and what the Operator changed. The same notice appears in reports and in exported artifacts. You must not remove or alter it, and you must keep it with any copy or export you make. Where this Section and a notice differ, the notice is the definitive statement of which licence applies to which content.

QuBA-libre. The Standard catalogue pack, and tailorings derived from it, are adaptations of the QuBA-libre risk-assessment workbook, which is Copyright (c) by Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC and SICK AG and is published under the Creative Commons Attribution-ShareAlike 4.0 International licence (CC BY-SA 4.0). Under that licence you may use, copy and adapt that content for your own purposes, including commercially. Any copy or adaptation you distribute must carry the attribution notice, state what you changed, and be licensed under CC BY-SA 4.0 or a compatible licence. You may not add terms or technical measures that restrict what the licence allows others to do with it. The content is provided without warranty, as the licence itself states. Using the content inside the Service, in your assessments and in reports you keep internally, is not a distribution; publishing a report, a pack export or a tailored catalogue outside your organisation is.

MITRE EMB3D™. Parts of some packs are derived from MITRE EMB3D™, © The MITRE Corporation, reproduced and distributed with the permission of The MITRE Corporation. MITRE licenses EMB3D™ for internal business and commercial use on the condition that every copy reproduces MITRE’s copyright designation and the EMB3D™ Terms of Use, and that MITRE is notified of the use at EMB3D@mitre.org. The attribution notice reproduces both, with the scope of what is derived. If you copy or create derivative works of EMB3D™-derived content outside the Service, those terms apply to you directly: reproduce the copyright designation and licence in each copy, notify MITRE, and do not include a charge for EMB3D™ in any sale or licence of a derivative product or service to the U.S. Government. EMB3D™ is a trademark of The MITRE Corporation; its use in the Service does not imply MITRE’s endorsement.

ENISA. Where a pack or framework reproduces material of the European Union Agency for Cybersecurity (ENISA), it does so under ENISA’s copyright notice, which permits reproduction provided the source is acknowledged. The attribution notice gives that acknowledgement, and copies you make must keep it. ENISA publications may contain third-party material whose reuse needs the right holder’s permission; the notice marks such material where we know of it. ENISA does not endorse the Service or its outputs.

Licensed frameworks. Regulatory and standards frameworks (for example IEC 62443-4-2 or a CRA harmonised standard) are licensed to the Operator for display to licensed Customers, and may be shown as full text, titles only or control ids only, as that licence allows. Each framework’s report shows its licence line and the licensor’s required disclaimer. You may use a framework only within the Service and in the reports it produces for your organisation, and may not extract, republish or redistribute its text. When the Operator’s or the Customer’s licence for a framework ends, the framework is withdrawn from new reports and exports; reports already frozen in a completed assessment’s sign-off set remain available.

Org-authored content. Catalogue packs and frameworks the Customer authors itself are Customer Content under Section 5. The Customer chooses their licence, and is responsible for any third-party material it includes.

The Customer will ensure that its Users and anyone it shares outputs with comply with this Section. A breach of an upstream licence is a breach of these Terms.

8. AI-assisted features and model providers

Classification. Some features, such as the CRA classification assistant, send a prompt to a large language model and show its structured answer. The prompt contains the TOE description and answers the User selects, together with the text of the regulation being classified against. Nothing else from the Customer’s organisation is sent.

Catalogue binding checks. When a catalogue manager asks for a binding check on a released catalogue revision, the names and descriptions of that revision’s countermeasures and attack steps, and, for a duplicate check, the name and description of the countermeasure the catalogue manager proposes, are sent to a third-party ranking-model provider, which returns a ranking for human review. Catalogue text only is sent: no assessment or product data, no text harvested from assessments, and no licensed framework text. The ranking orders candidates for a person to decide; it binds nothing by itself.

Where the models run. Classification requests go to Mistral AI (Paris, France), which processes them in the European Union. Binding checks go to the ranking-model provider named in the DPA. Each provider is a processor under the DPA, processes requests in the European Union, and is bound by its terms not to use inputs or outputs to train models and not to retain them beyond what serving the request and the provider’s abuse monitoring require.

We may change the models or providers behind a feature. We keep the DPA’s sub-processor list current and notify the organisation’s administrators of additions as the DPA sets out.

Model outputs are probabilistic. They may be wrong, incomplete, outdated or inconsistent between runs, and they do not replace the deterministic engine, a qualified reviewer or legal advice. A User with the right role must review every model output before it is relied on. Every run, its cost and its result are recorded for the organisation’s administrators.

AI features are subject to the per-run and monthly cost ceilings of the Customer’s plan. A run that would exceed a ceiling is refused, not charged.

Only Users whose role includes the right to trigger a run may do so. Attempting to extract a provider’s model, system prompt or weights, or to use a feature for anything other than what it offers, is prohibited.

9. Hosting, infrastructure and sub-processors

The Service, its database and its stored files run in data centres in the European Union, operated by a hosting provider under a data processing agreement that meets the GDPR. Transactional mail (sign-in, invitation and notification mail) is sent through a mail provider. Model requests go to the providers in Section 8.

The DPA names every sub-processor, its role and the country it processes in. We notify the organisation’s administrators of additions and give the Customer the right to object as the DPA sets out.

We are not responsible for downtime, data loss or defects caused by a third-party provider beyond what Section 17 allows, but we remain responsible to the Customer for our sub-processors under the DPA.

10. Read API and automated access

The Service offers a read-only HTTP API under /api/v1, authenticated with an API key a User mints under Account, or with a signed-in session. An API key is the User’s own credential: it carries the User’s role and organisation, and a demotion or revocation applies on the key’s next use.

Automated access is allowed only through that API, within the published rate limits, and only for reading your own organisation’s data. Scraping the web interface, driving it with bots or headless browsers, circumventing rate limits, quotas, plan limits or access controls, or probing non-public areas is prohibited. Assistive technology used by a person is allowed.

API keys are confidential. Revoke a key you suspect is exposed. The Customer is responsible for every request made with its Users’ keys.

11. Plans, fees, limits and taxes

A plan is attached to the Customer’s organisation and sets the limits that apply to it (for example the number of products, custom packs and own frameworks, and the monthly AI cost ceiling). A refused operation says which limit it hit.

During the closed pilot, the Service is provided under the terms of the pilot agreement. Where no fee is agreed, the Service is provided free of charge and the free-of-charge limit in Section 17 applies.

Fees for paid plans are those in the order form. Unless it says otherwise, fees are invoiced in advance per billing period, payable within 30 days, exclusive of VAT and other taxes, which the Customer bears where they apply. Fees paid are not refundable, except where these Terms or the law require it.

We may change plan prices and limits with at least 30 days’ notice to the organisation’s administrators. A change applies from the next billing period. If the Customer does not accept a price increase, it may terminate at the end of the current period.

12. Acceptable use

You will not, and will not allow Users to:

  • break the law, infringe third-party rights, or process data you have no right to process, including personal data without a lawful basis;
  • upload or generate content that is unlawful, defamatory, harassing or malicious, including malware;
  • breach a third-party licence in Section 7, strip or alter an attribution notice, or redistribute licensed framework text;
  • use AI features for anything other than their stated purpose, or to try to extract a model, a prompt or another organisation’s data;
  • interfere with the Service, its infrastructure or other organisations’ use, or try to reach data outside your organisation;
  • scrape, crawl or automate the web interface, or circumvent limits, quotas or access controls (Section 10);
  • share, sell or transfer accounts or API keys, or let anyone use the Service through your credentials;
  • resell, sublicense or offer the Service to third parties, or use it to build a competing product;
  • present an output as a certification, a conformity assessment or a legal opinion.

13. Security testing and vulnerability disclosure

Do not scan, penetration-test, fuzz or otherwise test the security of the Service without our prior written authorisation. Authorised testing is limited to the scope, time and systems the authorisation names.

If you find a vulnerability, report it to the contact address in the imprint and give us a reasonable time to fix it before disclosing it. Do not access, change or delete data that is not yours, and stop as soon as you have enough to demonstrate the issue.

14. Confidentiality

Each party will keep the other’s confidential information confidential, use it only for the purposes of the agreement, and protect it with at least the care it uses for its own. Customer Content is the Customer’s confidential information. The Service’s non-public features, pricing and security information are the Operator’s.

This does not apply to information that is public without breach, was already known, is independently developed, or must be disclosed by law, in which case the disclosing party gives notice where allowed.

This Section survives for three years after the agreement ends, and for Customer Content for as long as we hold it.

15. Term, suspension, termination and data

The agreement runs until terminated. The Customer may terminate at any time by notice to the contact address in the imprint; a paid plan ends at the end of the current billing period.

We may suspend an organisation or a User with notice where reasonable, and without notice where necessary, for an actual or suspected material breach of these Terms, non-payment after reminder, a security risk to the Service or to other organisations, or where the law requires it. We lift a suspension once the cause is resolved.

We may terminate for cause where a material breach is not cured within 30 days of notice, and for convenience with 90 days’ notice to a paid Customer, or 30 days to a pilot Customer.

On request before termination, and for 30 days after, we provide an export of the organisation’s data in the Service’s export formats.

After that period, the organisation’s data is purged. The purge is irreversible. Backups expire on their own schedule, and audit and security records are kept for the limited retention window the privacy page describes.

Sections 5 (no training), 6, 7, 14, 16, 17, 18 and 20 survive termination.

16. Warranties and disclaimers

We will provide the Service with reasonable skill and care and in accordance with the documentation.

Beyond that, and to the extent the law allows, the Service, its outputs and all third-party content are provided “as is” and “as available”, without warranty of any kind, including merchantability, fitness for a particular purpose, non-infringement, accuracy or completeness.

In particular, we do not warrant that an output is correct or complete, that it reflects the current state of a regulation or standard, or that a product assessed with the Service conforms to any legal requirement. We do not warrant that the Service will be uninterrupted, error-free or secure, or that Customer Content will never be lost; the Customer keeps its own copies of what matters to it.

Third-party content is provided under its own licence and its own warranty disclaimer, which the attribution notice reproduces.

17. Limitation of liability

Nothing in these Terms excludes or limits liability for intent or gross negligence, for injury to life, body or health, or any other liability that cannot be excluded under the applicable law.

Subject to that, neither party is liable for indirect or consequential loss, loss of profit, revenue, business, goodwill or data, or for the cost of substitute services, however arising.

Subject to the two paragraphs above, each party’s total liability under or in connection with the agreement in any twelve-month period is limited to the fees the Customer paid for the Service in the twelve months before the event giving rise to the claim. Where the Service is provided free of charge, the Operator’s liability is limited to CHF 1,000.

The Customer is responsible for its Users’ acts and omissions as if they were its own.

18. Indemnification

The Customer will defend and indemnify the Operator against third-party claims, and the resulting damages, costs and reasonable legal fees, arising from Customer Content, from the Customer’s or its Users’ use of outputs, or from a breach of Sections 7, 12 or 13 or of applicable law.

The Operator will defend and indemnify the Customer against third-party claims that the Service as provided infringes a third party’s intellectual property right in Switzerland, the EU or the EEA, except where the claim arises from Customer Content, from third-party content used under its own licence, or from use contrary to these Terms. The Operator may procure a right to continue, modify the Service, or terminate the affected part and refund prepaid fees for the remaining period.

The indemnified party gives prompt notice, lets the indemnifying party control the defence, and does not settle without consent.

19. Changes to these Terms

We may change these Terms. For a material change we give the organisation’s administrators at least 30 days’ notice by email and post the new version with its “Last updated” date. A change the law requires, or that only adds a feature, may take effect sooner.

Continued use after the effective date is acceptance. A Customer who does not accept a material change may terminate before it takes effect, and we refund any prepaid fees for the period after termination.

20. Governing law and venue

These Terms and any dispute arising from them or from use of the Service are governed by Swiss law, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods.

The courts at the Operator’s registered seat, as stated in the imprint, have exclusive jurisdiction, subject to any mandatory forum.

21. Privacy, cookies and data processing

The privacy page explains what personal data the Service processes, why, who else sees it and what you can ask for. The cookies page explains what is stored on your device and how to change your choice.

Where we process personal data on the Customer’s behalf, the DPA applies and prevails over these Terms for that processing.

22. General

The Customer may not assign the agreement without our consent, which we will not unreasonably withhold. We may assign it to a successor of the business on notice.

Neither party is liable for a failure caused by events beyond its reasonable control, except for payment obligations.

If a clause is invalid, the rest stays in force and the clause is replaced by a valid one closest to its purpose.

These Terms, with the documents in Section 1, are the entire agreement on their subject and replace earlier terms.

Notices to the Operator go to the contact address in the imprint. Notices to the Customer go to its administrators’ registered email addresses.

23. Contact

The Operator, its registered address, its contact address and, where appointed, its data protection officer are named in the imprint.

Atrekos uses only its own, technically necessary cookies to operate.