1. Acceptance of Terms
These Terms of Service (the “Terms”) govern access to and use of SolrSunrise LLC’s websites, web application, portals, dashboards, scanner orchestration tools, APIs, reports, remediation workflows, support channels, documentation, and related online services (collectively, the “Application”). By accessing or using the Application, creating an account, accepting an invitation, enrolling a scanner, launching a scan, or using any feature made available through the Application, you agree to these Terms.
If you use the Application on behalf of a company, managed-security customer, account, or other organization, you represent that you have authority to bind that organization. That organization is responsible for all activity by its authorized users.
2. Relationship to Signed Agreements
These Terms apply to general Application access. If SolrSunrise LLC and a customer have signed a Master Services Agreement, Statement of Work, Data Processing Addendum, security testing authorization, order form, or other written agreement, that written agreement controls over these Terms for the specific services and data covered by it. If there is a conflict, the signed written agreement controls to the extent of the conflict.
3. Application Purpose
SolrSunrise provides cybersecurity exposure management, asset inventory, vulnerability and configuration finding workflows, scanner policy management, tenant-scoped scanner enrollment, risk prioritization, remediation tracking, evidence capture, reporting, and related implementation and managed-service features.
The Application is designed to support authorized defensive security work. It is not a guarantee that systems are secure, compliant, breach-proof, or fully remediated, and it is not a substitute for professional security judgment, incident-response planning, legal review, or customer authorization.
4. Eligibility and Account Access
You may use the Application only if you are at least 18 years old and legally able to enter into these Terms, or if you are an authorized user of an organization that has permitted your access. You must provide accurate account information and keep it current.
Access may be invitation-only. SolrSunrise may assign or recognize different scopes, roles, and permissions, including platform, account, customer, scanner, billing, administrative, analyst, remediation-owner, or other role-based access. You may access only the accounts, assets, customers, records, scan results, workflows, and features for which you are authorized.
5. Credentials, Sessions, Scanner Identity, and Security Responsibilities
You are responsible for maintaining the confidentiality of credentials, one-time codes, sessions, devices, access links, API tokens, scanner enrollment tokens, scanner certificates, and private keys. You must promptly notify SolrSunrise of suspected unauthorized access, credential compromise, scanner compromise, improper role assignment, or security incident involving the Application.
You may not share accounts, bypass authentication, defeat session controls, impersonate scanners, access another user’s account, interfere with audit logging, or use another person’s credentials. SolrSunrise may suspend access where it reasonably believes an account, scanner, token, certificate, asset, or workflow presents a security, compliance, nonpayment, legal, or operational risk.
6. Authorized Security Testing and Restrictions
You may use the Application only for lawful, authorized, defensive security and business operations purposes authorized by your organization and applicable agreements. You may not:
- scan, probe, attack, test, or collect data from assets you do not own or lack authorization to assess;
- launch denial-of-service, destructive, credential-stuffing, social-engineering, phishing, malware, persistence, lateral-movement, or exploitation activity through the Application;
- upload malware, exploit code, scraping tools, credential-stuffing tools, stolen data, or destructive content except where a signed agreement expressly authorizes a controlled defensive workflow;
- bypass scanner authorization, tenant isolation, customer boundaries, rate limits, logging, monitoring, infrastructure, or availability controls;
- submit data you do not have the right to submit;
- use findings, reports, AI outputs, scanner results, or remediation recommendations as the sole basis for legal, employment, insurance, lending, or other regulated decisions;
- represent that SolrSunrise has certified compliance, completed remediation, or guaranteed security unless expressly confirmed in writing; or
- use the Application in a way that violates computer-crime law, privacy law, data-protection obligations, export controls, sanctions, vulnerability-disclosure rules, or your organization’s policies.
7. Customer Assets, Scan Scope, and Evidence
Customers and authorized users remain responsible for defining authorized scan scope, confirming asset ownership or authorization, choosing scanner policies, reviewing findings, validating remediation, coordinating maintenance windows, and ensuring that scans comply with laws and third-party service terms.
Customer Data may include asset inventories, hostnames, IP addresses, scan configuration, vulnerability findings, screenshots, request/response evidence, remediation notes, audit events, customer records, and reports. Customers retain ownership of Customer Data. SolrSunrise receives a limited right to host, process, transmit, display, secure, troubleshoot, back up, and otherwise use Customer Data as necessary to provide, improve, secure, support, and operate the Application and related services, subject to applicable written agreements.
8. Scanner Policies, Nuclei Templates, and User Content
The Application may allow customers to create scanner policies, including Nuclei-compatible YAML templates or derived policy metadata. You are responsible for ensuring custom policies are lawful, safe, scoped, and authorized. SolrSunrise may validate, reject, disable, quarantine, or limit policies that appear unsafe, destructive, noncompliant, or outside authorized use.
You represent that you have all rights, permissions, consents, notices, and lawful bases required to submit Customer Data, policies, templates, evidence, notes, and reports to the Application and permit SolrSunrise to process them.
9. AI and Automation Outputs
The Application may include AI-assisted summaries, classifications, routing, risk-prioritization suggestions, remediation drafts, evidence explanations, or generated content. AI outputs may be inaccurate, incomplete, biased, delayed, non-deterministic, or inappropriate for a particular context. Authorized users must review outputs before relying on them or sending them to customers, employees, regulators, insurers, auditors, or third parties.
SolrSunrise does not guarantee that AI outputs or scanner findings will be error-free, legally compliant, risk-complete, or suitable for any regulated decision. You are responsible for human review, approval, documentation, and downstream use.
10. Third-Party Services and Integrations
The Application may use or integrate with third-party hosting, cloud infrastructure, email, payment, analytics, security, database, AI model/API, ticketing, messaging, SIEM, EDR, cloud-provider, scanner, container, or other service providers. Third-party services may be governed by their own terms and privacy practices. SolrSunrise is not responsible for third-party systems outside its control, but will use commercially reasonable efforts to manage contracted providers consistent with applicable agreements.
11. Payments, Billing, and Subscriptions
Paid services, subscriptions, implementation fees, usage charges, scanner orchestration fees, hosting fees, support fees, and billing terms may be described in a signed agreement, order form, invoice, or checkout flow. Unless a written agreement states otherwise, fees are due when invoiced or charged, are non-refundable except as required by law, and may be automatically billed to the payment method on file.
SolrSunrise may suspend or limit access for overdue amounts, failed payments, suspected fraud, chargebacks, or billing disputes that are not promptly resolved.
12. Intellectual Property
SolrSunrise and its licensors own the Application, software, interfaces, designs, workflows, dashboards, templates, documentation, scanner orchestration logic, know-how, AI configurations, prompts, libraries, reusable methods, trademarks, logos, and other materials provided by SolrSunrise, excluding Customer Data. No rights are granted except the limited right to use the Application as permitted by these Terms and applicable written agreements.
Feedback, suggestions, or improvement ideas may be used by SolrSunrise without restriction or compensation, provided SolrSunrise does not disclose Customer Data in violation of applicable agreements.
13. Confidentiality
Non-public product, technical, pricing, security, customer, workflow, vulnerability, asset, report, and business information exchanged through the Application may be confidential. You may not disclose SolrSunrise confidential information except as authorized. SolrSunrise will handle customer confidential information consistent with applicable agreements and law.
14. Availability, Changes, and Support
SolrSunrise may modify, improve, suspend, or discontinue Application features. Support, uptime, maintenance, response times, data export, backups, scan scheduling, scanner availability, and transition assistance are governed by applicable written agreements or posted support policies. The Application may be unavailable because of maintenance, outages, third-party failures, security events, force majeure events, scanner capacity, network conditions, or other causes.
15. Termination
You may stop using the Application at any time. SolrSunrise may suspend or terminate access if you violate these Terms, if access is no longer authorized by the customer organization, if a contract ends, if fees are not paid, if required for security or legal reasons, or if continued access may create risk. Sections that by their nature should survive termination will survive, including intellectual property, confidentiality, payment, disclaimers, limitations of liability, indemnity, dispute resolution, and data-handling provisions.
16. Disclaimers
THE APPLICATION IS PROVIDED “AS IS” AND “AS AVAILABLE” EXCEPT AS EXPRESSLY STATED IN A SIGNED WRITTEN AGREEMENT. TO THE MAXIMUM EXTENT PERMITTED BY LAW, SOLRSUNRISE DISCLAIMS WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, AVAILABILITY, SECURITY, ERROR-FREE OPERATION, COMPLETE DETECTION, COMPLETE REMEDIATION, AND THAT SCANNER, AI, OR AUTOMATION OUTPUTS WILL BE CORRECT OR SUITABLE FOR ANY SPECIFIC USE.
SolrSunrise does not provide legal, accounting, tax, insurance, compliance-certification, law-enforcement, or incident-response advice through the Application unless expressly stated in a signed agreement.
17. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, SOLRSUNRISE WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, LOST-PROFIT, LOST-REVENUE, LOST-DATA, BUSINESS-INTERRUPTION, REPUTATIONAL, SECURITY-INCIDENT, BREACH, OR SUBSTITUTE-SERVICE DAMAGES. EXCEPT FOR AMOUNTS THAT CANNOT BE LIMITED BY LAW OR AS EXPRESSLY STATED IN A SIGNED AGREEMENT, SOLRSUNRISE’S TOTAL LIABILITY ARISING FROM OR RELATED TO THE APPLICATION WILL NOT EXCEED THE AMOUNTS PAID TO SOLRSUNRISE FOR THE APPLICATION OR SERVICE GIVING RISE TO THE CLAIM DURING THE TWELVE MONTHS BEFORE THE CLAIM.
18. Indemnity
To the extent permitted by law and applicable written agreements, you and the organization you represent will defend, indemnify, and hold SolrSunrise harmless from claims, damages, liabilities, penalties, costs, and expenses arising from unauthorized scanning or testing, Customer Data submitted without required rights or consents, misuse of scanner policies or outputs, violation of law, breach of these Terms, or use of the Application outside authorized defensive security scope.
19. Governing Law and Disputes
Georgia law governs these Terms, without regard to conflict-of-law rules, unless applicable law requires otherwise. Venue for disputes will be in state or federal courts located in Georgia, unless a signed agreement states otherwise or applicable consumer law requires a different forum.
20. Changes to These Terms
SolrSunrise may update these Terms from time to time. The updated version will be posted with a new effective date. Material changes may also be communicated through the Application, email, or other reasonable notice. Continued use after the effective date means you accept the updated Terms.
21. Contact
Questions about these Terms may be sent to legal@solrsunrise.com.
