1. Agreement and business use
These Terms govern access to CLAWOLF websites, evaluation environments, documentation, APIs, and CLAWOLF AS-OS services made available by CLAWOLF, Inc. ("CLAWOLF") unless a signed agreement states otherwise. The services are offered for authorized business, cybersecurity, evaluation, and defensive-security purposes.
By affirmatively accepting these Terms, signing or accepting an applicable order, or activating an account after the Terms are presented, each tenant, customer, MSSP, reseller, integrator, vendor, and authorized user agrees to these Terms, including the External Cyberattack Risk Allocation and Release below.
2. The service
CLAWOLF AS-OS is a governed autonomous security runtime. Depending on the agreed scope and deployment, it may receive security signals, build evidence, generate decisions or recommendations, apply policy controls, prepare or dispatch authorized actions, preserve receipts, verify outcomes, and produce operational evidence. Only the applicable order and activated configuration define the purchased service.
3. Accounts and authorized users
Customers are responsible for authorizing users, protecting credentials, configuring roles and approval routes, and notifying CLAWOLF of suspected unauthorized access through a confirmed security contact.
4. Customer systems, integrations, and authorization
The customer represents that it has the right and authority to connect each system and instruct each action within the agreed scope. CLAWOLF may block, abstain from, require human approval for, or decline an action when required context, authority, verification, or rollback information is missing.
5. Autonomous and automated functionality
CLAWOLF does not guarantee that every threat will be detected or that every authorized action will prevent harm. Customers remain responsible for risk decisions and authorization of production actions.
6. Customer Data
As between the parties, the customer retains its rights in Customer Data. CLAWOLF will not sell Customer Data. The Privacy Notice and, where applicable, the Data Processing Addendum address personal-data processing.
7. Acceptable use
Customers must not use the services to access systems without authorization, conduct offensive cyber operations outside an authorized engagement, evade safeguards or tenant boundaries, or violate law. Good-faith security research is governed by the Vulnerability Disclosure Policy.
8. Intellectual property
CLAWOLF and its licensors retain all rights in CLAWOLF technology, software, architecture, documentation, and branding.
9. Disclaimers
Except as expressly stated in a signed agreement, the services are provided "as is" and "as available" to the maximum extent permitted by law.
10. Limitation of liability
External Cyberattack Risk Allocation and Release
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EACH TENANT, CUSTOMER, MANAGED SECURITY SERVICE PROVIDER (MSSP), RESELLER, INTEGRATOR, VENDOR, AUTHORIZED USER, AND ANY OTHER PERSON OR ENTITY THAT ACCESSES, DEPLOYS, CONFIGURES, INTEGRATES, RESELLS, MANAGES, OR USES THE SERVICES (EACH, A "USING PARTY") ASSUMES THE RISKS ASSOCIATED WITH CYBERATTACKS, MALICIOUS ACTIVITY, INTRUSIONS, COMPROMISES, RANSOMWARE, FRAUD, DATA LOSS, SERVICE DISRUPTION, UNAUTHORIZED ACCESS, AND OTHER SECURITY EVENTS ORIGINATING FROM EXTERNAL ACTORS, CUSTOMER ENVIRONMENTS, THIRD-PARTY SYSTEMS, NETWORKS, PRODUCTS, SERVICES, CREDENTIALS, CONFIGURATIONS, OR INTEGRATIONS DURING OR IN CONNECTION WITH ACCESS TO OR USE OF CLAWOLF AS-OS OR ANY RELATED SERVICE.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NO USING PARTY MAY SEEK OR RECOVER FROM CLAWOLF, AND CLAWOLF SHALL HAVE NO LIABILITY FOR, ANY CLAIM, LOSS, DAMAGE, COMPENSATION, REIMBURSEMENT, RESTITUTION, FINE, PENALTY, SANCTION, ASSESSMENT, COST, OR REMEDY ARISING OUT OF OR RELATING TO ANY SUCH EXTERNAL CYBERATTACK OR SECURITY EVENT. THIS EXCLUSION INCLUDES DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, AND PUNITIVE DAMAGES; LOST PROFITS, REVENUE, BUSINESS, OPPORTUNITY, GOODWILL, OR DATA; BUSINESS INTERRUPTION; PROPERTY DAMAGE; REPUTATIONAL HARM; PERSONAL, NON-ECONOMIC, EMOTIONAL, OR MORAL DAMAGES; RESPONSE, INVESTIGATION, RESTORATION, NOTIFICATION, LEGAL, REGULATORY, AND REMEDIATION COSTS; AND ANY SIMILAR ECONOMIC OR NON-ECONOMIC LOSS, REGARDLESS OF THE THEORY OF LIABILITY OR FORM OF ACTION.
EACH USING PARTY IRREVOCABLY RELEASES CLAWOLF, INC. AND ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, LICENSORS, AND SERVICE PROVIDERS FROM SUCH CLAIMS AND ACKNOWLEDGES THAT THIS RISK ALLOCATION IS A MATERIAL BASIS OF CLAWOLF'S AGREEMENT TO PROVIDE ACCESS TO THE SERVICES. THIS RELEASE AND EXCLUSION APPLY TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW. ANY LIABILITY THAT APPLICABLE LAW EXPRESSLY PROHIBITS THE PARTIES FROM EXCLUDING REMAINS LIMITED TO THE MINIMUM LIABILITY REQUIRED BY THAT LAW.
For clarity, the aggregate liability cap for claims within this External Cyberattack Risk Allocation and Release is zero, except solely to the minimum extent that applicable law prohibits a zero cap.
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages arising from these Terms. Unless a signed agreement states otherwise, each party's aggregate liability arising from the services will not exceed the fees paid or payable for the affected service during the 12 months preceding the event giving rise to liability.
11. Governing law and venue
These Terms are governed by the laws of the State of Delaware, without regard to conflict-of-law rules. The state and federal courts located in Delaware will have exclusive jurisdiction, and each party consents to those courts, unless a signed agreement states otherwise.
12. Changes
CLAWOLF may update these Terms prospectively. The page identifies the effective date and version.
13. Contact
CLAWOLF, Inc.
Delaware, United States
[email protected]