Book a call Start a run

Terms of Service

Effective date:

These Terms of Service (the Terms) are an agreement between Zellic AI Inc dba V12 (V12, we, us, or our) and the person or organization that accepts them (Customer, you, or your). They govern access to and use of V12.sh, V12.security, our automated security platform, related websites, software, application programming interfaces, tools, integrations, documentation, support, and other services we provide under these Terms (together, the Service).

Read these Terms before using the Service. Sections 7 and 8 explain how V12 uses Service data and when Customer Materials or Results may be used to train AI models. Section 17 limits our liability. If you do not agree, do not use the Service.

Accepting these Terms

How you accept

You accept these Terms when you click to accept them, create an account, sign an Order Form that refers to them, or access or use the Service after receiving notice of them. If you accept for an organization, you represent that you have authority to bind that organization. In that case, Customer means the organization, not you personally.

If a new version of these Terms materially expands V12’s right to use raw nonpublic Customer Materials or Results already stored in the Service for generalized training or product improvement, the expanded right applies to that material only after Customer affirmatively accepts the new version or otherwise expressly agrees. Until then, V12 may keep processing the stored material to provide, secure, support, and bill for the Service, and may create and use Usage Data and Derived Data as allowed by the version Customer previously accepted.

Age and business use

You must be at least 18 years old and legally able to enter into this agreement. The Service is for business and professional use, not personal, family, or household use.

An Order Form is an ordering document, online checkout, statement of work, or other written order that identifies the Service, fees, plan, term, or special terms. These Terms, each Order Form, and any policies or addenda they expressly incorporate make up the Agreement.

If documents conflict, a signed Data Processing Addendum controls for personal-data processing. Otherwise, this order controls: (1) a signed Order Form; (2) these Terms; and (3) any policy or Documentation expressly incorporated into the Agreement. Documentation describes the Service but is not part of the Agreement unless expressly incorporated. An Order Form changes these Terms only for the Customer and Service it identifies.

If Customer has signed a master services agreement or statement of work with V12 under which V12 personnel perform services for Customer (for example, a managed run or a bundled security assessment), that signed agreement governs those services, the material Customer submits for them, and their deliverables, and these Terms do not apply to them, even if Customer or its Authorized Users access the Service to receive them. These Terms continue to govern Customer’s own use of the Service.

The Service

What V12 does

The Service uses automated systems, including artificial intelligence, to analyze software and related material for security issues. Depending on the feature and plan, the Service may:

  1. analyze a repository, archive, branch, commit, pull request, patch, dependency, or other submitted material;
  2. conduct a full review or a review focused on changes;
  3. generate and run code, test cases, or proof-of-concept exploits in an analysis environment;
  4. produce findings, severity and validity assessments, proposed patches, reports, explanations, and other results;
  5. test a proposed patch or other remediation in the analysis environment;
  6. remember organization-level context, notes, and prior triage decisions;
  7. start or monitor reviews through Autopilot, an API, MCP, or another integration; and
  8. let Authorized Users review, triage, comment on, export, or share Results.

Features vary by plan and may change. Our current product documentation for the Service (Documentation) describes the supported features and technical limits.

Analysis environment and production testing

Customer authorizes V12 to copy, build, execute, instrument, modify, and test Customer Materials, dependencies, generated code, and proof-of-concept artifacts as needed to provide the Service. Unless an Order Form expressly says otherwise, V12 will conduct executable testing only in an analysis environment provided or controlled by V12. Customer does not authorize V12 to scan, exploit, disrupt, or modify a production system, deployed contract, live network, or third-party system. V12 may still retrieve submitted or referenced material through a supported repository, cloud, or other integration.

Proposed patches and write-capable features

Unless the Service clearly identifies a feature as write-capable and Customer enables it, repository access is read-only and each patch is only a proposed artifact. The Service may post review comments through integration permissions Customer grants. V12 does not commit, merge, deploy, publish, or otherwise apply a patch for Customer. If Customer enables a write-capable feature, Customer authorizes the actions the Service describes for that feature. Customer remains responsible for reviewing, testing, approving, and deploying every change.

Changes to the Service

We may add, remove, or change features. Except as Section 15.5 allows, we will not materially reduce the core functionality of a paid Service during its committed Order term unless the change is needed to address law, security, abuse, a third-party dependency, or a risk to the Service or its users. Preview and free features may change or end at any time.

Accounts, organizations, and connected tools

Accounts and Authorized Users

An Authorized User is a person Customer allows to use the Service through Customer’s account or organization. Customer is responsible for its Authorized Users and for activity under its accounts, tokens, keys, and integrations. Customer must keep account information accurate and credentials confidential, use reasonable security controls, and tell us promptly at [email protected] if it suspects unauthorized access.

Administrators

An organization owner or administrator may add or remove Authorized Users, assign roles, manage repositories and integrations, configure automated reviews, transfer eligible credits, set sharing controls, and access Customer Materials and Results within the organization. Customer chooses its administrators and is responsible for their instructions. V12 may treat an administrator’s actions as Customer’s authorized actions.

API tokens, MCP, and other agents

Customer may allow software agents, developer tools, CI/CD systems, or other applications to use the Service through a token, API, MCP connection, or integration. Customer authorizes actions taken with its valid credentials, including starting reviews, retrieving Results, changing supported settings, and consuming credits. Customer is responsible for the permissions it grants, the tools it connects, and the security of its tokens.

A third-party tool that Customer chooses and connects is not an Authorized User or subcontractor of V12. Once Customer directs V12 to send data to that tool, the tool’s own terms and privacy practices govern its handling of the data.

Unauthorized activity

Customer must promptly revoke credentials that are lost, exposed, or no longer needed. Customer remains responsible for charges and actions made through its credentials until it gives us enough information to investigate and stop the activity, except to the extent the activity resulted from V12’s breach of the Agreement.

Customer’s authority and responsibilities

Authority over submitted material and targets

For private repositories, archives, and other nonpublic material Customer submits, Customer represents and warrants that it owns, controls, or has all rights needed for V12 to process that material under the Agreement. Customer also represents that it has authority for each requested analysis and will not use the Service to test a production system, deployed contract, live network, or other live target without that authority.

Customer may submit lawfully accessible public code for analysis in the analysis environment, subject to that code’s license and applicable law. Public availability does not override a license or grant permission to test a live target. For public code, Customer grants only the rights it holds, as stated in Section 8.2, and remains responsible for those grants.

Customer instructions

Customer decides what to submit, which repositories and branches to connect, who may access an organization, which automations to enable, what context to store, and what actions to take based on Results. Customer is responsible for the accuracy, quality, and legality of its instructions and Customer Materials.

Pull requests and third-party contributions

If Customer configures the Service to review pull requests or contributions from outside its organization, Customer instructs V12 to process the submitted code, metadata, and comments as Customer Materials. Customer is responsible for giving any notices and obtaining any permissions required for that processing. Comments and other natural-language content may contain inaccurate, malicious, or conflicting instructions. Customer should not trust contributor text solely because the Service processed it.

Backups and safe deployment

Customer must keep appropriate backups and use its own review, testing, access-control, and deployment process. Customer is responsible for deciding whether and how to use a finding, proof of concept, patch, report, or recommendation.

Acceptable use

Authorized security work is allowed

The Service is designed to find and help fix security issues. The restrictions below do not prohibit Customer from asking the Service to generate or execute code, test cases, or proof-of-concept exploits within the authorized scope in Section 2 and Section 4.

Prohibited use

Customer must not use the Service to:

  1. access, scan, test, exploit, disrupt, or damage a system or codebase without legal authority;
  2. develop or enhance malicious capabilities intended for use against systems Customer is not authorized to test;
  3. deploy malware, ransomware, destructive code, credential theft, persistence, evasion, or an attack against a live target;
  4. weaponize or publish an exploit in a way that creates an unreasonable risk of harm;
  5. bypass access controls, usage limits, rate limits, safety controls, or payment requirements;
  6. use Results to mislead others about the security, certification, endorsement, or audit status of a system;
  7. upload content that violates law or another person’s rights;
  8. scrape, probe, or reverse engineer the Service except to the limited extent a law does not allow us to restrict that activity;
  9. systematically harvest Results, V12 Materials, or nonpublic Service behavior to copy or train a competing security analysis service, except with our written permission; this restriction does not limit Customer’s lawful use of its own Results under Section 6.3;
  10. resell or provide the Service to third parties unless an Order Form permits it; or
  11. help another person do any of the above.

Our response

We may investigate suspected misuse and preserve relevant records. We may remove content, limit a feature, revoke a token, or suspend access when we reasonably believe it is necessary to protect the Service, a customer, a third party, or the public; comply with law; or enforce the Agreement.

Customer Materials and Results

Customer Materials

Customer Materials means all content and data that Customer or an Authorized User submits, connects, sends, stores, or makes available through the Service. It includes:

  1. source code, repositories, archives, files, branches, commits, diffs, dependencies, build files, configuration, and related metadata and history;
  2. pull requests, issues, comments, review instructions, prompts, API or MCP payloads, and other messages;
  3. organization memory, notes, labels, human triage decisions, severity or validity choices, and feedback;
  4. credentials, tokens, secrets, personal data, and other information included in submitted material, whether intentionally or not; and
  5. any other customer-provided text, code, image, record, or signal.

Results

Results means findings, classifications, proof-of-concept artifacts, proposed patches, test outcomes, reports, explanations, recommendations, logs, and other customer-specific material generated by the V12 Service from Customer Materials. Results do not include the Service, V12 Materials, Derived Data, a separate audit report or other deliverable provided by Zellic, Zenith, or another audit provider outside the V12 Service (Audit Deliverables), whether provided under a separate agreement with that provider or under a signed agreement with V12, or a report or other deliverable produced by V12 personnel for Customer under a signed master services agreement or statement of work (Managed Deliverables). Audit Deliverables and Managed Deliverables, including their ownership and use, are governed by the agreement, statement of work, or other terms for that engagement.

Customer ownership of V12 Results

As between the parties, Customer keeps all right, title, and interest in Customer Materials. Subject to V12’s ownership of V12 Materials and the rights Customer grants in Section 8, Customer owns the Results generated specifically for Customer by the V12 Service. The ownership and use rights in this Section 6.3 apply only to V12 Results and do not apply to Audit Deliverables or Managed Deliverables. If applicable law does not automatically vest a Result in Customer, V12 assigns to Customer any right V12 may have in that Result when it is generated and Customer has paid all amounts due for the applicable use.

After paying all amounts due for the applicable use, Customer may use, modify, merge, reproduce, distribute, publish, and otherwise exploit its Results for any lawful business purpose. Those rights are perpetual. Customer may share Results with employees, contractors, auditors, insurers, customers, regulators, investors, and other people who have a legitimate reason to receive them. Customer is responsible for any public disclosure of an unremediated vulnerability and for statements it makes based on Results.

V12 Materials

V12 Materials means the Service and all technology, models, model weights, prompts, agents, detectors, rules, methods, taxonomies, templates, content, interfaces, software, Documentation, and know-how that V12 owned, developed, or licensed independently of Customer Materials. V12 Materials also include improvements to those items and any preexisting or generic V12 component identified as V12 Materials when a Result is delivered. V12 and its licensors own the V12 Materials.

To the extent V12 Materials are embedded in a Result, V12 grants Customer a worldwide, perpetual, nonexclusive, royalty-free license to use, copy, modify, distribute, and display those embedded materials only as part of or in connection with Customer’s use of that Result. Customer does not receive V12’s underlying model, system prompts, detector logic, or other platform technology.

Similar results

Security findings and fixes often follow common patterns. The Service may produce the same or similar content for other customers. Customer does not receive exclusive rights in an idea, method, common vulnerability description, standard remediation, or material that was not derived from Customer’s confidential information.

Feedback and Service data

Feedback

If Customer gives us feedback, suggestions, or ideas about the Service, V12 may use and commercialize them without restriction or payment. Feedback does not include Customer Materials merely because they were submitted through a feedback channel.

Usage Data

Usage Data means technical and operational information about use of the Service, such as device and browser information, feature events, token and API activity, performance, latency, errors, consumption, and security logs. Usage Data does not include source code or the substantive content of prompts, Results, or organization memory merely because those items pass through the Service.

V12 may collect, analyze, and otherwise use Usage Data internally for its business purposes, including to operate, secure, support, analyze, bill for, develop, and improve current and future V12 products and services. V12 may disclose Usage Data only in an aggregated or deidentified form that does not identify Customer or an Authorized User. V12 owns Usage Data, subject to applicable law.

Derived Data

Derived Data means information V12 creates by aggregating or deidentifying Customer Materials, Results, Usage Data, or use of the Service so that it cannot reasonably identify Customer or a person or reveal, reconstruct, or reproduce Customer’s nonpublic source code, unremediated findings, credentials, or other nonpublic Customer Materials or Results.

V12 may create, analyze, and use Derived Data for its business purposes, including security, analytics, research, development, and improving, training, fine-tuning, testing, and evaluating current and future V12 products, services, and models. V12 owns Derived Data, subject to applicable law. Derived Data is not Customer Materials or a Result.

V12 will not use or disclose Derived Data in a way designed to reidentify Customer or a person. If an item reveals, reconstructs, or reproduces Customer’s nonpublic source code, unremediated findings, credentials, or identity, it is not Derived Data and V12’s confidentiality obligations continue to apply.

How V12 may use Customer Materials and Results

Model training

V12 WILL NOT USE RAW, NONPUBLIC CUSTOMER MATERIALS OR RESULTS TO TRAIN ANY AI MODEL, UNLESS CUSTOMER EXPRESSLY AGREES TO THAT USE. WHERE POSSIBLE, V12 HAS OPTED OUT OF MODEL TRAINING WITH THE MODELS PROVIDED ON THE PLATFORM. HOWEVER, V12 IS NOT LIABLE FOR ERRORS OR MISREPRESENTATIONS MADE IN ANY MODEL TERMS DOWNSTREAM.

V12 MAY, WITHOUT FURTHER PERMISSION, USE USAGE DATA AND DERIVED DATA THAT MEETS SECTION 7.3 TO DEVELOP AND/OR IMPROVE CURRENT AND FUTURE V12 PRODUCTS, SERVICES, AND MODELS.

License to V12

Customer grants V12 and its affiliates a worldwide, nonexclusive, royalty-free license, with the right to sublicense to Service Providers, to host, store, copy, transmit, execute, test, modify, and analyze Customer Materials and Results only as reasonably necessary to provide, secure, support, and administer the Service and exercise the rights expressly granted in the Agreement.

The license is limited by Section 8.1, the disclosure restrictions in Section 10, a signed Order Form, an applicable Data Processing Addendum, and law. Customer does not grant V12 more rights than Customer has.

Permitted purposes

V12 may use Customer Materials and Results for the following purposes:

  1. provide, run, host, maintain, support, personalize, and troubleshoot the Service;
  2. perform the analysis Customer requests, including executing code, dependencies, tests, proof-of-concept artifacts, and proposed patches in the analysis environment;
  3. detect, investigate, prevent, and respond to vulnerabilities, fraud, abuse, misuse, harmful content, service failures, and threats to V12, our customers, or others;
  4. measure quality, accuracy, performance, cost, safety, and use of the Service;
  5. enforce the Agreement, bill for the Service, keep business and security records, and comply with law; and
  6. carry out any other purpose Customer requests or expressly agrees to, including model training permitted by Section 8.1.

If V12 identifies an active credential or secret in Customer Materials, V12 may quarantine, redact, or delete it. V12 will not intentionally use the credential or secret itself as a training example after identifying it. V12 may use surrounding material only as allowed by Section 8.1, and may use deidentified surrounding context or the fact that a secret was present to improve secret detection, security analysis, and the Service.

What happens after deletion or termination

After account closure, termination, or a valid deletion request, V12 will delete raw Customer Materials and Results from active systems within 30 days after the Section 15.6 export period ends or, if none applies, within 30 days after account closure, termination, or the request. Backup copies will be deleted or overwritten through ordinary backup cycles within 90 days after active-system deletion. V12 may keep particular information longer when required by law; reasonably needed for security, abuse prevention, fraud investigation, dispute resolution, or legal claims; or retained at Customer’s direction. These periods apply only to systems V12 controls. Provider-held copies follow Section 9.2, the applicable provider arrangement, and any provider retention limit in a signed Order Form.

Deletion does not affect Usage Data or Derived Data or require V12 to undo training or product improvements completed through a use permitted by the Agreement. A signed Order Form or Data Processing Addendum may set a different retention or deletion period for the information it covers.

Customer’s authority to grant these rights

Customer represents and warrants that it has given all required notices and obtained the rights and permissions needed from the people and entities whose material Customer submits. Those rights and permissions must allow V12 to use Customer Materials and Results as described in the Agreement. Customer must not submit material subject to a restriction that prevents this use unless V12 has accepted that restriction in an Order Form.

If Customer cannot grant the rights needed for V12 to process the affected material under this Section 8, Customer must not submit that material unless V12 accepts different terms in a signed Order Form. Customer may ask V12 about different data-use, retention, or provider terms for a paid Service.

Model providers, subprocessors, and connected services

Service Providers

V12 may use affiliates, cloud providers, model providers, security vendors, contractors, and other service providers (Service Providers) to process Customer Materials, Results, Usage Data, and Derived Data for V12. V12 may give a Service Provider only the access we reasonably determine is needed for its role. We remain responsible for our obligations under the Agreement when a Service Provider performs them for us, subject to the limits in the Agreement.

Current information about material Service Providers or subprocessors is available in the Documentation or on request. We will provide a way to receive notice of material changes.

Standard model-provider use

Unless an Order Form says otherwise, V12 may choose and route Customer Materials and Results to model providers under V12’s standard arrangements with those providers. A provider may retain submitted data as allowed by V12’s arrangement with it. V12 will not authorize a provider to use nonpublic Customer Materials or Results to train its own models unless Customer expressly agrees under Section 8.1. Customer authorizes this processing. Current information about provider choices and data terms is available in the Documentation or on request.

Custom provider terms

A requirement to use or avoid a provider, route data in a particular way, impose a provider retention limit, or apply another provider-specific data term binds V12 only when a signed Order Form expressly includes it. A custom provider term applies only to the Customer organization or account and the data, feature, and period identified in the Order Form.

Customer-connected services

Customer may connect services that V12 does not select or control and authorizes V12 to exchange data with them as directed. V12 is not responsible for a customer-connected service’s availability, security, or terms, or for how that service uses data after V12 delivers it.

Confidentiality and security

Confidential Information

Confidential Information means nonpublic information disclosed by one party (Discloser) to the other (Recipient) that is marked confidential or that a reasonable person would understand to be confidential. Customer’s Confidential Information includes nonpublic Customer Materials and Results, including source code, credentials, unremediated findings, proof-of-concept artifacts, patches, organization memory, and notes. V12’s Confidential Information includes nonpublic information about the Service, pricing, security, models, prompts, detectors, and product plans.

Confidential Information does not include information that the Recipient can show: (a) is or becomes public without breach of the Agreement; (b) it lawfully knew without a duty of confidentiality; (c) it receives lawfully from another source without a duty of confidentiality; or (d) it independently develops without using the Discloser’s Confidential Information.

Protection and permitted use

The Recipient will use reasonable care to protect Confidential Information and will use it only to exercise rights or perform obligations under the Agreement. Section 10 restricts disclosure of Confidential Information; it does not restrict V12’s processing permitted by Sections 7 through 9. The Recipient may disclose Confidential Information to its affiliates, workers, professional advisers, and Service Providers who need it for those purposes and are bound by confidentiality duties.

Required disclosure

The Recipient may disclose Confidential Information when law requires it. If legally allowed, the Recipient will give the Discloser reasonable notice and cooperation so the Discloser may seek protection. The Recipient will disclose only what the law requires.

Security

V12 will maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Materials under our control. Information about our security practices is available in the Documentation or on request. No service is completely secure, and V12 does not promise that unauthorized access, loss, or an attack will never occur.

If V12 confirms unauthorized access to or disclosure of nonpublic Customer Materials under our control, V12 will notify Customer without undue delay and provide information reasonably needed for Customer to respond, even if law does not require notice.

Customer is responsible for securing its systems, repositories, credentials, Authorized Users, and connections to the Service. Customer should not intentionally place production secrets or credentials in material submitted for analysis unless they are needed for the requested use and Customer accepts the risk.

Privacy and data processing

Our Privacy Policy at https://V12.sh/privacy-policy explains how we handle personal data as a controller. If V12 processes personal data for Customer as a processor or service provider and applicable law requires a data processing agreement, the V12 Data Processing Addendum, available from V12 on request, applies.

Customer is responsible for determining whether the Service is suitable for data subject to a special law or contractual restriction. Customer must not submit protected health information, payment-card data, government classified information, export-controlled technical data, biometric identifiers, or another specially regulated category unless an Order Form expressly permits it.

Results, AI limits, and customer decisions

Results are not complete or certain

The Service uses automated systems and may make mistakes. Results may be incomplete, inaccurate, outdated, duplicative, or non-unique. The Service may report an issue that is not exploitable, miss an issue, assign the wrong severity or validity, propose a patch that does not work, or produce code that introduces a defect. A clean result does not mean that software is secure.

What “verified” means

When the Service labels a finding or patch as verified, it means only that the specified test or proof-of-concept met the Service’s stated criteria in the analysis environment using the code, dependencies, configuration, assumptions, and Service version available at that time. It does not mean the issue can or cannot be exploited in every environment, that the patch is safe to deploy, or that the software has been certified, audited, or proven secure.

Human review and final decisions

V12 may assign an initial severity, validity, or confidence level. Customer controls its final triage and remediation decisions. Customer must use qualified human review and its own testing before relying on a Result, disclosing a vulnerability, merging a patch, deploying code, changing access, or making a security claim.

Proofs of concept and patches

Proof-of-concept artifacts can be dangerous. Customer must protect them and use them only for authorized defensive work. Proposed patches may change functionality, performance, dependencies, licenses, data handling, or security. Customer is solely responsible for testing and approving them in its own environment.

No professional certification or third-party duty

The Service is a software tool. It does not provide legal advice, an audit opinion, a penetration-test attestation, a compliance certification, or a guarantee of security. V12 owes no duty to a person who receives or relies on a Result but is not a party to the Agreement.

Fees, credits, and automated use

Fees and payment

Customer will pay the fees shown in the Service or an Order Form. Unless an Order Form says otherwise, fees are charged in U.S. dollars, payment obligations are noncancelable, and amounts paid are nonrefundable except where law requires a refund or the Agreement expressly provides one. Customer authorizes V12 and its payment processor to charge the payment method on file for purchases and recurring fees Customer approves.

Fees do not include taxes. Customer is responsible for sales, use, value-added, withholding, and similar taxes, except taxes on V12’s net income.

Credits

The Service may use prepaid or promotional credits. Purchased credits do not expire unless the checkout or Order Form says otherwise. Promotional credits may expire and may be limited to a particular account, organization, feature, or period. Credits have no cash value, cannot be redeemed for cash, and may be transferred only through a transfer feature or Order Form that expressly permits the transfer. This does not limit a refund the Agreement expressly provides in Section 15.5 or 20.1.

Estimates and consumption

A displayed cost is an estimate unless the Service labels it final. Actual consumption may depend on repository size, code complexity, selected scope, model use, retries, generated tests, and other work performed. The Service may reserve or charge credits in full when a run starts and may make a final adjustment when it ends.

A failed or canceled run may consume credits for work already performed. V12 may issue a credit when a failure was caused by the Service, but is not required to do so unless an Order Form says otherwise. Customer must report a disputed charge within 30 days after it appears in the account.

Autopilot and agent-initiated spend

When Customer enables Autopilot, a scheduled review, an API or MCP token, or another automation that can start work, Customer authorizes the Service to consume credits without a separate approval for each run. Customer is responsible for repository rules, scope, tokens, rate limits, budgets, and other available controls. Disabling an automation does not reverse charges for work already started.

Late payment

If an undisputed amount is overdue, V12 may suspend paid features after reasonable notice. Overdue amounts may accrue interest at the lower of 1.5% per month or the highest rate allowed by law, plus reasonable collection costs.

Free, trial, beta, and preview features

We may offer free access, promotional credits, trials, beta features, previews, or experimental models (Preview Services). Preview Services may be incomplete or unstable, and V12 may change or discontinue them without notice. They may have separate data, retention, support, or use limits shown when Customer enables them.

Preview Services are provided as-is, without service levels, support commitments, warranties, indemnities, or a promise of continued availability. To the fullest extent allowed by law, V12’s total liability arising from Preview Services is limited to $100.

Third-party services and software

The Service may interoperate with repositories, model providers, cloud services, developer tools, payment processors, or other third-party services. V12 is responsible for Service Providers as stated in Section 9.1, but not for a service Customer independently chooses or controls. If a third-party service changes, restricts, or stops its interface, V12 may stop supporting the integration.

Customer Materials and Results may contain third-party or open-source software. Customer is responsible for complying with the licenses and terms that apply to that material. V12 does not grant rights in third-party material merely because the Service analyzed it or included it in a Result.

Term, suspension, and termination

Term

These Terms start when Customer accepts them and continue until the Agreement ends. An Order Form may set a fixed or renewing term.

Customer termination

Customer may stop using the Service and close its account at any time. Closing an account does not cancel an Order Form or payment obligation that is still in effect. Unless the Order Form says otherwise, amounts already paid are not refundable.

Suspension

V12 may suspend all or part of the Service immediately if we reasonably believe: (a) Customer breached Section 4 or 5; (b) Customer’s use threatens the Service or another person; (c) suspension is needed to comply with law or a provider requirement; (d) an undisputed payment remains unpaid after the notice described in Section 12.5; or (e) Customer’s account appears compromised. Where practical, we will limit the suspension to the affected account, feature, or data and tell Customer the reason.

Termination for breach

Either party may terminate the Agreement if the other party materially breaches it and does not cure the breach within 30 days after written notice. V12 may terminate immediately for a breach that cannot be cured, deliberate unauthorized security testing, fraud, or repeated violations.

Discontinuation

V12 may end a free Service at any time. We may end a paid Service or terminate a month-to-month account for convenience on 30 days’ notice. If we end a paid Service for convenience and do not offer a substantially similar replacement, Customer’s sole remedy is a prorated refund of prepaid recurring fees for the unused period and the amount paid for unused purchased credits. Promotional credits are not refundable.

Effect of termination

When the Agreement ends, Customer’s right to use the Service ends. Customer should export Results it wishes to keep before termination. Unless access was suspended for illegal or harmful activity, a Customer that paid for the Service or purchased credits may request an export of available Customer Materials and Results for 30 days after termination. Promotional credits, a free trial, or another no-charge use do not qualify. Customer may use that period only to retrieve data. V12 may charge its reasonable costs for a custom export that is not available through the Service.

Sections that by their nature should continue will survive, including Sections 4 through 14, 15.6, and 16 through 20. Termination does not limit V12’s rights to retain and use data under Sections 7 through 9.

Disclaimers

TO THE FULLEST EXTENT ALLOWED BY LAW, THE SERVICE, RESULTS, PREVIEW SERVICES, AND ALL RELATED MATERIALS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” V12 AND ITS LICENSORS DISCLAIM ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ACCURACY.

V12 DOES NOT WARRANT THAT THE SERVICE OR RESULTS WILL BE UNINTERRUPTED, SECURE, ERROR-FREE, COMPLETE, OR ACCURATE; THAT EVERY VULNERABILITY WILL BE FOUND; THAT A FINDING WILL BE EXPLOITABLE; THAT A PATCH WILL WORK OR BE SAFE; OR THAT USE OF THE SERVICE WILL MEET A LEGAL, REGULATORY, INSURANCE, AUDIT, OR SECURITY REQUIREMENT.

Some jurisdictions do not allow certain disclaimers. In those jurisdictions, a disclaimer applies only to the extent the law allows.

Limits on liability

Excluded damages

TO THE FULLEST EXTENT ALLOWED BY LAW, NEITHER PARTY WILL BE LIABLE FOR LOST PROFITS, REVENUE, GOODWILL, BUSINESS, OR DATA; BUSINESS INTERRUPTION; COST OF SUBSTITUTE SERVICES; OR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO THE AGREEMENT, EVEN IF THE PARTY KNEW THOSE DAMAGES WERE POSSIBLE.

Liability cap

TO THE FULLEST EXTENT ALLOWED BY LAW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE AGREEMENT WILL NOT EXCEED THE FEES CUSTOMER PAID OR OWED FOR THE SERVICE GIVING RISE TO THE CLAIM DURING THE 12 MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY. IF CUSTOMER USED ONLY A FREE OR PREVIEW SERVICE, V12’S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED $100.

Exceptions

The exclusions and cap in this Section do not apply to: (a) Customer’s payment obligations; (b) Customer’s indemnity obligations; (c) Customer’s breach of Section 5; (d) Customer’s infringement or misappropriation of V12’s intellectual property rights; or (e) liability that law does not allow a party to limit. Claims against V12 arising from processing authorized by Section 8 remain subject to the exclusions and cap. Customer’s use of a Result or deployment of a patch also remains subject to the cap unless another exception applies.

Allocation of risk

The fees and other terms reflect this allocation of risk. These limits apply even if a limited remedy fails of its essential purpose.

Indemnity

Customer indemnity

Customer will defend V12, our affiliates, and the officers, directors, employees, and agents of V12 and those affiliates against a third-party claim, action, or proceeding arising from or related to:

  1. Customer’s breach of its authority or rights promises in Section 4.1 or 8.5;
  2. Customer’s lack of authority to submit material, authorize analysis, or test a target;
  3. Customer’s use of the Service or Results in violation of the Agreement or law;
  4. Customer’s deployment, publication, weaponization, or other use of a proof of concept, patch, finding, or Result; or
  5. the acts or omissions of an Authorized User, a connected agent, or a customer-controlled integration, except to the extent the claim arises from V12’s breach of the Agreement.

Customer will pay damages, settlements, and reasonable legal fees finally awarded or agreed in a settlement of the covered claim.

Process

V12 will give Customer prompt written notice of a covered claim and reasonable cooperation at Customer’s expense. Customer may control the defense and settlement, but may not admit that V12 is at fault, impose a payment or non-monetary obligation on V12, or settle a claim without fully releasing V12 unless we consent in writing. We may participate with our own counsel at our expense. A delay in notice relieves Customer only to the extent the delay materially harms the defense.

No standard V12 indemnity

V12 does not provide an indemnity under these Terms. An Order Form may include a separate V12 indemnity for a paid enterprise Service.

Export controls and sanctions

Customer must comply with applicable export-control, sanctions, and trade laws. Customer represents that it and its Authorized Users are not prohibited from receiving the Service and will not use the Service for a prohibited end use or in a prohibited country or region. Customer must not submit controlled technical data unless an Order Form expressly authorizes it and the required controls are in place.

General terms

Changes to these Terms

We may update these Terms. We will give at least 30 days’ advance notice of a change that materially reduces Customer’s rights or increases Customer’s obligations, unless an earlier change is needed for law, security, abuse prevention, or a new feature Customer chooses to use. Notice may be given through the Service or by email. The updated Terms apply on the stated effective date. If Customer does not agree, Customer must stop using the affected Service before that date. If Customer stops using the affected Service because of a material adverse change, V12 will refund the amount paid for unused purchased credits. A change will not override a signed Order Form during its committed term unless the Order Form allows it.

Governing law and courts

New York law governs the Agreement, without regard to conflict-of-law rules. The state and federal courts located in New York County, New York have exclusive jurisdiction over a dispute arising out of or related to the Agreement, and each party consents to those courts. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

Jury-trial waiver

TO THE FULLEST EXTENT ALLOWED BY LAW, EACH PARTY WAIVES THE RIGHT TO A JURY TRIAL IN A DISPUTE ARISING OUT OF OR RELATED TO THE AGREEMENT.

Assignment

Neither party may assign the Agreement without the other party’s written consent, except that either party may assign it without consent to an affiliate or in connection with a merger, reorganization, sale of substantially all assets, or change of control, if the assignee agrees in writing to be bound by the Agreement. Any other attempted assignment is void.

Notices

V12 may send operational notices to the account email or through the Service. Legal notices to V12 must be sent to [email protected]. A legal notice to Customer may be sent to the organization owner or billing email in the Service. Email notice is effective when sent unless the sender receives a delivery failure.

Publicity

Neither party may use the other party’s name, logo, or marks in public marketing without written permission. V12 may include Customer’s name in an internal customer list and may identify Customer when required by law or when Customer has made the relationship public.

No third-party beneficiaries

The Agreement benefits only the parties and their permitted successors and assigns. It does not create rights for anyone else.

Independent parties

The parties are independent contractors. The Agreement does not create a partnership, joint venture, fiduciary, employment, franchise, or agency relationship.

Force majeure

Neither party is liable for a delay or failure caused by events beyond its reasonable control, including natural disasters, war, internet or utility failures, provider outages, attacks, or government action. This Section does not excuse payment obligations.

Severability and waiver

If a provision is unenforceable, it will be enforced to the maximum extent allowed and the rest of the Agreement will remain in effect. A waiver must be in writing and applies only to the specific instance stated. A delay in enforcing a right is not a waiver.

Entire agreement

The Agreement is the entire agreement about the Service and replaces prior or contemporaneous agreements, statements, and understandings about the same subject. A purchase order or vendor portal term supplied by Customer is for administrative convenience only and does not change the Agreement, even if V12 accepts or processes it.

Interpretation

Headings are for convenience. Including means including without limitation. Or is inclusive. A reference to a law includes amendments and replacement laws. An electronic signature, click, or acceptance has the same effect as a handwritten signature to the extent allowed by law. The parties agree that ambiguities will not be interpreted against a party merely because that party drafted the language.

Type to search.