Terms of Service
Last updated: Jul 24, 2026
These Terms of Service ("Terms") govern access to and use of OUTSIDE, including the website at outsideguardian.eu, associated applications, APIs, reports, monitoring services and related features.
The service is provided by VeDomEll s. r. o. ("OUTSIDE", "we", "us" or "our").
By accessing or using OUTSIDE, creating an account, starting a subscription or accepting an order that refers to these Terms, you agree to be bound by them.
If you use OUTSIDE on behalf of a company or other organization, you represent that you have authority to bind that organization. In that case, "you" and "Customer" refer to that organization.
Questions about these Terms may be sent to security@outsideguardian.eu.
1. The service
OUTSIDE is an external attack surface management and security-monitoring platform.
Depending on the selected plan and configuration, the service may:
- discover publicly observable internet-facing assets;
- collect technical evidence from public sources;
- map relationships between assets;
- generate security findings;
- calculate exposure or posture scores;
- monitor verified domains for changes;
- generate reports;
- provide plain-language explanations and remediation guidance;
- integrate with customer-selected systems;
- preserve historical security observations.
The precise functionality available to you depends on your plan, account permissions, configuration and applicable usage limits.
2. Security information, not a guarantee
OUTSIDE is a decision-support and visibility tool.
It is not:
- a firewall;
- a web application firewall;
- an endpoint-protection product;
- an intrusion-prevention system;
- a penetration-testing engagement;
- a managed security service unless separately agreed;
- a guarantee that a system is secure;
- a guarantee that every asset, weakness, vulnerability or compromise will be detected.
The absence of a finding does not establish that a domain, organization, application or infrastructure is secure.
Findings, scores, recommendations and AI-generated explanations must be reviewed by appropriately qualified personnel before decisions are made or changes are implemented.
3. Eligibility and accounts
You must provide accurate and current account information.
You are responsible for:
- maintaining the confidentiality of credentials;
- using appropriate authentication safeguards;
- restricting access to authorized personnel;
- all activity performed through your account;
- promptly removing users who no longer require access;
- notifying us of suspected unauthorized access.
You must not share individual credentials between multiple people unless the selected plan expressly permits this.
4. Authority to assess targets
You may use OUTSIDE only in relation to domains, systems and organizations that:
- you own;
- you administer;
- you are contractually authorized to assess;
- you have otherwise received clear lawful permission to assess.
You must maintain evidence of authorization and provide it to us where reasonably requested.
A domain being publicly accessible does not automatically mean that you are authorized to conduct intrusive testing against it.
OUTSIDE is designed primarily for passive discovery and controlled observation. Any feature involving active verification, deeper inspection, authenticated integration or provider-side action must be used only where you possess the necessary authority.
5. Acceptable use
You must not use OUTSIDE to:
- access or attempt to access systems without authorization;
- exploit vulnerabilities;
- gain persistence;
- deploy malware;
- exfiltrate information;
- intercept communications;
- disrupt availability;
- perform denial-of-service activity;
- evade access controls;
- bypass rate limits;
- obtain passwords, tokens or private keys;
- scan targets for harassment, surveillance or intimidation;
- facilitate criminal, fraudulent or abusive conduct;
- violate sanctions or export-control laws;
- infringe intellectual-property or privacy rights;
- test systems where you lack authorization;
- resell access except through an authorized plan or agreement;
- reverse engineer protected parts of the service except where mandatory law permits it;
- interfere with the operation or security of OUTSIDE;
- use automated means to overload or scrape the service;
- misrepresent OUTSIDE output as proof of compromise where no such evidence exists.
You must not use findings to make deceptive, defamatory or unsupported public claims about another organization.
6. Domain verification and active features
We may require domain verification or additional authorization before enabling monitoring, active-observation features, integrations or sensitive reports.
Verification may involve:
- DNS records;
- email confirmation;
- file-based confirmation;
- account or provider integration;
- another reasonable method.
Verification confirms control over a verification method at a point in time. It does not establish ownership of all associated systems or provide unlimited permission to test them.
We may suspend monitoring if verification expires, becomes invalid or appears fraudulent.
7. Customer data
"Customer Data" means information submitted to OUTSIDE by or for you, excluding OUTSIDE technology, public technical data collected independently and aggregated or de-identified service data.
You retain ownership of Customer Data.
You grant us a limited, non-exclusive right to host, process, transmit, reproduce and display Customer Data only as necessary to:
- provide the service;
- maintain security;
- prevent abuse;
- comply with law;
- enforce these Terms;
- improve reliability using aggregated or de-identified information.
You represent that:
- you have all rights and permissions required to provide Customer Data;
- processing Customer Data through OUTSIDE is lawful;
- your instructions do not violate third-party rights;
- you will not submit unnecessary special-category or highly sensitive personal data.
8. Public technical data
OUTSIDE may independently obtain publicly observable technical information from public internet infrastructure, registries, certificate-transparency logs, public webpages, vulnerability databases and other lawful sources.
Public technical data may be shared among product functions where necessary to provide accurate discovery, correlation, monitoring and security intelligence.
OUTSIDE does not claim ownership over third-party data. Third-party source terms may apply.
9. Data protection
Each party will comply with applicable data-protection law.
Where we process personal data on your behalf as a processor, the parties may enter into a Data Processing Agreement.
You remain responsible for:
- determining whether your use of OUTSIDE is lawful;
- providing required notices;
- establishing a lawful basis;
- responding to data-subject requests relating to your processing;
- configuring retention appropriately;
- avoiding the submission of unnecessary personal data.
Our Privacy Policy describes how we process personal data for our own purposes.
10. Subscriptions and payment
Paid features may require a subscription.
Unless otherwise stated:
- fees are charged in advance;
- subscriptions renew automatically for the selected billing period;
- fees are exclusive of applicable taxes;
- you are responsible for taxes other than taxes imposed on our income;
- usage above included limits may be charged separately or restricted;
- fees are non-refundable except where required by law or expressly agreed.
You authorize the applicable payment provider to charge the selected payment method.
If payment is overdue, we may:
- retry payment;
- restrict paid features;
- suspend the account;
- terminate the subscription;
- recover reasonable collection costs where permitted.
Changing or cancelling a subscription takes effect according to the billing terms shown at the time of purchase.
11. Trials and free services
Trials, free snapshots and free plans may be limited by:
- scan frequency;
- asset count;
- historical retention;
- report availability;
- integrations;
- monitoring intervals;
- support;
- other technical or commercial limits.
Free functionality may be modified, suspended or discontinued at any time.
Data generated through a trial or free plan may be deleted after the applicable retention period.
12. Intellectual property
OUTSIDE, including its source code, interface, design, detection logic, documentation, trademarks, reports, templates and underlying technology, is owned by or licensed to VeDomEll s. r. o.
Except for the limited right to use the service under these Terms, no intellectual-property rights are transferred to you.
You may use reports generated for your organization for internal business and security purposes.
You must not:
- remove proprietary notices;
- copy substantial parts of the service;
- create a competing service using protected OUTSIDE materials;
- disclose non-public detection logic;
- use our marks in a misleading way.
13. Feedback
If you provide suggestions, correction requests or product feedback, you grant us a perpetual, worldwide, royalty-free right to use that feedback to improve and develop OUTSIDE.
This does not transfer ownership of your Customer Data or confidential information.
14. Third-party services
OUTSIDE may integrate with or link to third-party services.
Your use of third-party services is governed by their own terms. We are not responsible for:
- third-party availability;
- third-party data accuracy;
- changes to external APIs;
- third-party security incidents;
- losses caused by customer configuration of an integration;
- third-party suspension or termination.
We may replace or discontinue an integration if its provider changes access, pricing, functionality or legal conditions.
15. Artificial intelligence output
AI-assisted explanations and recommendations may contain errors, omissions or outdated information.
You must not rely on AI output as:
- proof of exploitation;
- proof of compromise;
- legal advice;
- compliance certification;
- a substitute for professional review;
- an instruction to make an untested production change.
You are responsible for reviewing AI-assisted output and validating any remediation step before implementation.
16. Service changes
We may improve, update or modify OUTSIDE.
We may change or discontinue individual features where reasonably necessary due to:
- security;
- legal requirements;
- third-party dependencies;
- product development;
- misuse;
- technical limitations;
- commercial viability.
We will use reasonable efforts to avoid materially reducing paid core functionality during a prepaid subscription period, unless the change is necessary for security, compliance or prevention of abuse.
17. Availability and maintenance
We aim to operate OUTSIDE reliably but do not guarantee uninterrupted or error-free availability unless a separate service-level agreement expressly applies.
The service may be unavailable due to:
- scheduled maintenance;
- emergency maintenance;
- infrastructure failure;
- cyber incidents;
- third-party outages;
- internet routing or DNS problems;
- force majeure;
- customer configuration;
- events outside our reasonable control.
18. Beta and experimental features
Features identified as beta, preview, experimental or similar may:
- change without notice;
- be incomplete;
- produce inaccurate output;
- have limited support;
- be discontinued;
- be unsuitable for production decisions.
You use such features at your own risk.
19. Confidentiality
Each party may receive non-public information that is marked confidential or should reasonably be understood as confidential.
The receiving party must:
- use it only for the contractual relationship;
- protect it with reasonable care;
- disclose it only to personnel and providers who need access and are subject to confidentiality obligations.
Confidential information does not include information that:
- becomes public without breach;
- was lawfully known before disclosure;
- is received lawfully from another source;
- is independently developed.
Disclosure required by law is permitted, provided notice is given where legally allowed.
20. Suspension
We may suspend access where reasonably necessary to:
- prevent security harm;
- stop unauthorized scanning;
- address abuse;
- protect third-party systems;
- comply with law;
- respond to overdue payment;
- investigate a material breach;
- protect OUTSIDE or other users.
Where practicable, we will provide notice and an opportunity to remedy the issue.
21. Termination
You may stop using OUTSIDE and cancel your subscription according to the applicable billing process.
We may terminate access if:
- you materially breach these Terms;
- you fail to cure a remediable breach within a reasonable period;
- your use creates security or legal risk;
- continued provision becomes unlawful;
- required third-party services become unavailable;
- the service is discontinued.
Upon termination:
- your right to use the service ends;
- outstanding fees remain payable;
- Customer Data may be deleted according to the applicable retention period;
- provisions intended to survive will remain effective.
You should export required data before termination.
22. Disclaimers
To the maximum extent permitted by law, OUTSIDE is provided on an "as is" and "as available" basis.
We disclaim implied warranties of:
- merchantability;
- fitness for a particular purpose;
- non-infringement;
- uninterrupted availability;
- completeness;
- accuracy;
- detection of every relevant asset or risk.
We do not warrant that:
- every finding is correct;
- every risk will be detected;
- every recommendation will be suitable;
- third-party intelligence is accurate or current;
- use of OUTSIDE will prevent an incident;
- a particular security or compliance outcome will be achieved.
Nothing in these Terms excludes warranties or rights that cannot lawfully be excluded.
23. Limitation of liability
To the maximum extent permitted by law, neither party will be liable for:
- indirect or consequential loss;
- loss of profits;
- loss of revenue;
- loss of business;
- loss of goodwill;
- loss of anticipated savings;
- loss or corruption of data;
- losses arising from unsupported reliance on findings or AI output.
To the maximum extent permitted by law, the total aggregate liability of VeDomEll s. r. o. arising from or related to the service will not exceed the fees paid or payable by the Customer to us during the twelve months immediately preceding the event giving rise to liability.
For free services, our aggregate liability will not exceed USD 100 or the equivalent amount in the applicable currency.
These limitations do not apply where liability cannot legally be limited, including liability for fraud, intentional misconduct or death or personal injury caused by negligence where applicable law prohibits exclusion.
24. Indemnification
You will defend and indemnify VeDomEll s. r. o. against third-party claims, damages, penalties and reasonable costs arising from:
- your unauthorized assessment of a target;
- unlawful Customer Data;
- your breach of these Terms;
- infringement caused by Customer Data;
- misuse of findings;
- illegal or abusive use of the service.
This obligation applies only to the extent permitted by law and subject to reasonable notice and cooperation.
25. Governing law and disputes
These Terms are governed by the laws applicable at the registered office of VeDomEll s. r. o., excluding conflict-of-law principles.
The courts having territorial and subject-matter jurisdiction over the registered office of VeDomEll s. r. o. will have exclusive jurisdiction, unless mandatory law requires otherwise.
Before initiating formal proceedings, the parties should attempt in good faith to resolve the dispute through written notice and reasonable commercial discussion.
26. Assignment
You may not assign these Terms without our prior written consent, except in connection with a merger or sale of substantially all relevant assets, provided the assignee agrees to these Terms.
We may assign these Terms as part of a merger, restructuring, financing, acquisition or sale of the service or business.
27. Notices
Notices relating to these Terms may be delivered:
- through the service;
- by email;
- to the contact information associated with the account;
- by publication where appropriate for general updates.
Legal notices to us must be sent to security@outsideguardian.eu.
28. Changes to these Terms
We may update these Terms.
Material changes will take effect after reasonable notice where required. Continued use after the effective date constitutes acceptance of the updated Terms.
If you do not agree, you must stop using the service before the updated Terms take effect.
29. General provisions
If any provision is unenforceable, the remaining provisions remain effective.
Failure to enforce a provision is not a waiver.
These Terms, together with the Privacy Policy, applicable order, subscription terms and any Data Processing Agreement, constitute the entire agreement concerning the service unless otherwise agreed in writing.
30. Contact
VeDomEll s. r. o.
Alžbetina 55, 040 01 Košice – mestská časť Staré Mesto, Slovakia
IČO: 52498751 · DIČ: 2121045729 · IČ DPH: SK2121045729
security@outsideguardian.eu