Terms of Service
Last updated: July 30, 2026
Courtesy translation. This English text is provided for reference only. The legally binding version of these Terms is the
Traditional Chinese version; in the event of any discrepancy, the Chinese version prevails.
These Terms govern your use of the security assessment services provided by Odysec (the "Service"). By using the Service you confirm that you have read, understood and agreed to these Terms. If you do not agree, do not use the Service.
1. Description of the Service
The Service provides the following:
- Config review (free): you upload configuration file contents and receive hardening advice immediately. The server does not store the files you upload.
- Email security check (free): public DNS records of the domain you enter are queried to review its email anti-spoofing configuration. No connection is made to your mail servers.
- Monthly email re-check subscription (free): after a double-confirmation process, the aforementioned public DNS records are re-queried periodically and you are notified by email when the configuration changes.
- Microsoft 365 tenant configuration review (free): you export your tenant's security configuration yourself using read-only commands, and decide for yourself whether to upload it to receive the review. The Service obtains no access of any kind to your tenant.
- Self-service host check: you download the collector, run it on hosts you own or are authorized to manage, and upload the result file yourself to receive an assessment report.
- Backup restorability verification: you complete a backup restore drill on hosts you own or are authorized to manage, download the verification program to examine the restored artifacts and backup infrastructure offline, and upload the result file yourself to receive a verification report. The verification program makes no outbound connections; neither your backups nor your data contents are uploaded to the Service.
- Continuous monitoring subscription: you schedule the collector on hosts you own or are authorized to manage, periodically reporting the differences against a local baseline to the Service. The baseline is stored on your host and is not uploaded to the Service.
- External attack surface monitoring: the Service periodically reviews, from the internet, the externally visible information of domains you have registered and for which you have completed ownership verification.
- Consulting assessments: performed under individual engagement contracts whose scope and conditions are agreed separately in writing; these Terms apply supplementarily.
Each of the above services is an assessment of state at the time of collection or query. Although the continuous monitoring subscription and external attack surface monitoring run repeatedly on a schedule, they remain periodic assessments in nature — they are not real-time protection and have no capability to block, isolate or respond automatically.
2. Your Authorization Representations and Warranties
This is the most important clause in these Terms. Running assessments against hosts or domains without authorization may constitute the offense of unauthorized computer intrusion under Article 358 of the Taiwan Criminal Code, or give rise to other legal liability.
You represent and warrant that:
- you own, or have obtained the explicit authorization of the owner of, every host on which you run the collector or the backup verification program, and, for backup restorability verification, you are entitled to access the backups under examination and their restored artifacts;
- you are entitled to provide that host's configuration information to the Service for processing;
- for external attack surface monitoring, you own or have obtained explicit authorization for the registered domains and the hosts they resolve to, and will complete DNS ownership verification as instructed by the Service;
- for the Microsoft 365 tenant configuration review, you hold administrative rights to the tenant or have obtained the explicit authorization of its administrator;
- for the email security check and its monthly re-check subscription, the email address you provide is your own, or you have obtained the consent of its holder;
- the order information you provide is true and accurate.
Special note on external attack surface monitoring. This is the only service in which the Service itself initiates network connections toward targets you designate. For this reason the Service mandatorily requires DNS TXT ownership verification before scanning; unverified targets are never scanned, and verification is repeated every 30 days — authorization must remain valid, not merely have been valid once; once the verification record is removed, scanning stops. Scanning is limited to establishing TCP connections and reading publicly offered responses and certificates; no attack payloads are sent, no login attempts are made, and no vulnerabilities are exploited. These technical controls are self-imposed measures of the Service and neither remove nor reduce the representations and warranties you make under this clause.
You bear sole responsibility for any dispute, damage or legal liability arising from your breach of the above representations, and shall indemnify the Service for any damage it suffers as a result.
3. Limitations of Scope
The Service uses baseline comparison and heuristic methods, which have inherent limitations. The following cannot be detected, or can only be detected with difficulty, and each assessment report itemizes them:
- kernel-level rootkits — an implant that has gained operating-system kernel privileges can feed false answers to the Service's queries;
- memory-only implants that establish no persistence mechanism;
- application-layer vulnerabilities. The Service is neither a vulnerability scan nor a penetration test;
- contents inside container image layers;
- Windows and other non-Linux operating systems.
Individual services have the following additional limitations:
- Known-vulnerability matching covers only software installed through the package manager, and currently supports only Debian- and Arch-family distributions; software built from source or installed through language package managers such as pip or npm is not covered. Results follow the distribution's security advisories and list only items for which a fix is available to install.
- External attack surface monitoring reviews only information visible from the internet. For domains behind a content delivery network (CDN), the Service does not perform port review, because the resolved addresses are not your assets. Subdomain enumeration relies on public certificate transparency logs; subdomains covered by wildcard certificates may not appear in those logs.
- Results of the Microsoft 365 tenant configuration review are limited to the contents of the export file you upload. Items that could not be collected because a module was missing or permissions were insufficient are marked "not collected"; that marking means the item was not examined — it does not mean the item is free of problems.
- Backup restorability verification verifies the artifacts of a single restore drill: its conclusions do not guarantee that backup schedules continue to succeed thereafter, do not cover files that were not examined or exceeded size limits (each is listed in the report), and do not verify the semantic correctness of the data or the actual existence of offsite copies. Items that could not be examined due to permissions or environment are marked "undetermined", which is not the same as "no problem".
- The email security check queries public DNS records only; it does not verify actual mail delivery behavior and does not examine your mail servers.
- The detection capability of the continuous monitoring subscription is limited to what the baseline covers. Any state that already existed when the baseline was created is treated as normal and is not reported.
"No findings" means only that no anomalies were observed within the scope and methods used by the Service. It is not proof that a host was never compromised, nor a guarantee that a host is secure.
4. Nature of the Compliance Mapping Section
Assessment reports under certain plans include a section mapping findings to statutes or standards (for example, the security maintenance measures listed in Article 12 of the Enforcement Rules of the Taiwan Personal Data Protection Act, the Annex A controls of ISO/IEC 27001:2022, or the control families of the Information and Communication System Protection Baseline under the Taiwan Cyber Security Management Act). That section is reference material mapping the Service's technical findings to those items, intended to help you incorporate the findings into your existing management documentation.
That section does not constitute legal advice, a compliance audit opinion, or proof of compliance in any form. Whether management systems, operating procedures, training and documentation are adequate lies outside the Service's scope of examination; the Service makes no representation or warranty as to whether you will pass any regulator's inspection, accreditation or third-party audit.
5. Disclaimer and Limitation of Liability
The Service is provided "as is" and "as available". To the maximum extent permitted by law, the Service disclaims all express or implied warranties, including but not limited to merchantability, fitness for a particular purpose, and the completeness, accuracy or freedom from error of assessment results.
Liability cap: to the maximum extent permitted by law, the Service's aggregate liability arising from these Terms or the Service shall not exceed the total fees you actually paid for the Service in the twelve (12) months preceding the event giving rise to the claim.
The Service is not liable for indirect, incidental, consequential or punitive damages, business interruption, loss of data, or loss of profits or goodwill, regardless of whether the Service was advised of the possibility of such damages.
The foregoing limitations do not apply to intentional misconduct or gross negligence of the Service, and do not exclude liability that cannot be excluded or limited in advance by law.
6. Your Responsibilities
- Review the collector's source code before running it. The Service deliberately publishes it as readable source, without minification or obfuscation, and publishes hashes for you to verify.
- Inspect the result file before uploading it, and confirm it contains no information you are unwilling to provide.
- Assessment reports are professional opinions only; whether and how to act on them is your decision and your responsibility.
- Keep order codes and report URLs safe. Anyone holding a report URL can access that report. The order code also serves as the reporting and configuration credential for the continuous monitoring subscription — protect it like a password.
- When using the continuous monitoring subscription, create the baseline only after confirming the host is in a healthy state. Once created, the baseline becomes the reference for all subsequent comparison; if the host was already compromised at creation time, that state will be treated as normal and not reported. Before refreshing a baseline, confirm item by item that every change is attributable to your own operations.
- If you configure a webhook notification URL, satisfy yourself as to the security of that URL and the appropriateness of its recipient.
7. Fees and Orders
Fees, the number of hosts covered, and validity periods follow the plan shown at the time of ordering. Order codes carry usage quotas and expiry dates; uploads are not accepted after expiry or once the quota is exhausted.
Subscription plans (continuous monitoring, external attack surface monitoring) are billed for the period shown at the time of ordering; they do not auto-renew and no automatic charges are made. You may stop using them at any time during the period. When a subscription period ends, the Service stops performing that service, and related data is handled according to the periods set out in the Privacy Policy.
Because the nature of the Service is that results are produced upon execution, refunds are generally not offered except where a material defect of the Service prevents a report from being produced; the same applies to subscription plans terminated early by you. Individual cases may be negotiated separately.
8. Prohibited Conduct
- running the collector on hosts you are not authorized to assess;
- registering domains you do not own or are not authorized for, in external attack surface monitoring;
- entering into the Service's email subscription features an address that is not yours and whose holder has not consented;
- using the Service's free tools (config review, email security check, Microsoft 365 tenant configuration review) for bulk, automated, or on-behalf-of-third-party batch queries;
- making automated bulk requests to the Service or otherwise interfering with its operation;
- attempting to circumvent order quotas, access others' reports, or perform unauthorized testing against the Service's infrastructure;
- reselling, sublicensing or otherwise commercially distributing the collector or assessment reports without the Service's prior written consent.
9. Intellectual Property
Intellectual property rights in the collector, in the format and templates of assessment reports, and in this website's content belong to the Service. You retain your rights in the contents of the result files you provide; you grant the Service the right to use those contents to the extent necessary to perform the Service.
10. Personal Data and Data Processing
The Service's collection, processing and use of data is governed by the Privacy Policy, which forms part of these Terms.
11. Changes, Suspension and Termination of the Service
The Service may modify, suspend or terminate all or part of the Service at any time. If unilateral termination by the Service renders quota you have paid for unusable, the Service will refund fees in proportion to the unused portion.
If you breach these Terms, the Service may disable your order codes and terminate service without refund.
12. Amendments to These Terms
Amendments will be announced on this page with an updated "Last updated" date. Amended Terms apply to new orders placed after the announcement; existing orders remain governed by the version in force when they were placed.
13. Governing Law and Jurisdiction
These Terms are governed by the laws of the Republic of China (Taiwan). The parties agree that the Taiwan Taipei District Court shall be the court of first instance for disputes arising from these Terms.
14. Contact
For questions about these Terms, write to contact@odysec.org.