1. Parties
These terms are between Uwitz Corporate ("we", "us") and you or the organisation you represent ("you"). Uwitz Corporate is not yet a fully incorporated entity — we are preparing to legally register and operate in Estonia in the foreseeable future. We operate under a Founder's Agreement from Uwitz, which is available to parties we work with upon request.
If you are agreeing on behalf of an organisation, you confirm you have authority to bind it. These are business-to-business terms; our products are not offered to consumers, and nothing here is intended to exclude rights that cannot lawfully be excluded.
2. Definitions
- Product — commercial security software we develop and support, including Irys SSO and managed infrastructure.
- Services — security audits, penetration testing, deployment engineering, support contracts, and managed infrastructure.
- Order — a quote, order form, or statement of work that we have both accepted.
- Agreement — a signed master services agreement, subscription agreement, or data processing agreement between us.
3. Order of precedence
If you have signed an Agreement with us, that Agreement governs, and these terms apply only to your use of this website. Where documents conflict, they take priority in this order: (1) a signed Agreement, (2) an accepted Order, (3) these terms.
We will not argue that fine print on this page overrides something we negotiated with you in writing.
4. Products and subscriptions
Products are commercial security software we develop and support. A subscription is granted per active seat for the subscription term, and permits you to install and run the software for your own internal business purposes, self-hosted or as a service. It does not permit you to resell or provide the software as a service to third parties without a separate agreement.
Custom software we build for client engagements is proprietary and stays closed to prevent scraping, unlicensed self-hosting, and exposure of client-specific infrastructure.
5. Services
Services are performed against a written scope agreed in advance. We will not test systems outside that scope, and we require signed authorisation from someone entitled to give it before any testing begins.
Deliverables and findings from an audit or penetration test are yours. You may publish them in full. We will not ask for an embargo to protect a commercial relationship, and we will put our name to the version you release. We ask only that you give us the opportunity to correct a factual error before publication.
Where a fixed-scope engagement overruns our own estimate, that is our cost to absorb, not a change order — unless the scope itself changed at your request.
6. Acceptable use
You may not use our products or services to:
- Build or operate surveillance capability directed at a population or at individuals who have not consented.
- Test, attack, or gain access to systems you are not authorised to test.
- Break applicable law, or evade sanctions or export controls.
- Obtain a certificate, attestation, or report while declining to remediate what it identifies, where the purpose is to mislead a third party.
We reserve the right to decline or discontinue work on these grounds. We would rather lose the engagement than the argument about why we took it.
7. Fees and payment
Fees are set out in the applicable Order. Unless your contract says otherwise:
- Payments are due net 30 from the date of the applicable Order or statement.
- Amounts are exclusive of VAT and any other applicable tax, which is added where due.
- Subscriptions renew annually unless either party gives notice at least 30 days before the renewal date. We will remind you before renewing.
- If you dispute a line in good faith, the clock pauses on that line only; the remainder stays due.
- We may suspend services for accounts materially overdue, after written notice and a reasonable opportunity to pay. We will not suspend a security patch for non-payment.
Payments can be made by card or bank transfer via our billing page. Financial transactions are processed via a Financial Representative based in Malaysia.
8. Security research and disclosure
If you find a vulnerability in our software or infrastructure, report it to security@uwitz.co. It reaches engineering directly.
Safe harbour. We will not bring or support legal action against anyone who, in good faith:
- Tests only systems we operate, and stops at the point of proving an issue exists;
- Avoids accessing, modifying, or exfiltrating data belonging to other people, and avoids degrading service for them;
- Reports promptly and gives us a reasonable opportunity to fix the issue before publishing.
We consider such research authorised for the purposes of applicable computer-misuse law. We do not require an NDA to receive a report, we do not use bounty terms to buy silence, and you are free to publish once the issue is fixed or after 90 days, whichever is sooner.
9. Warranties and disclaimers
We warrant that Services will be performed with reasonable skill and care by suitably qualified people, and that our software will materially conform to its documentation during the subscription term. If it does not, we will fix it, or refund the fees for the affected period.
Beyond that, and to the extent the law allows, software is provided without further warranty. In particular: no security assessment proves the absence of vulnerabilities. An audit or penetration test reports what was found in the scope and time agreed. It is evidence, not a guarantee, and any supplier who tells you otherwise is selling you something else.
10. Liability
Neither party excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be excluded.
Subject to that, and unless your Agreement states otherwise, each party's total aggregate liability arising out of the relationship is limited to the fees paid or payable by you in the 12 months preceding the event giving rise to the claim. Neither party is liable for indirect or consequential loss, or for loss of profit, revenue, or anticipated savings.
Where your contract includes an indemnity from us, that indemnity applies on its own terms and is not capped by this section unless it says so.
11. Term, termination, and exit
Subscriptions run for the term stated in the Order. Either party may terminate for material breach that is not remedied within 30 days of written notice, or immediately if the other becomes insolvent.
On termination, your right to run the software ends. We will not engineer a cliff to make leaving painful — runbooks, infrastructure definitions, and documentation are yours throughout.
Where we hold your data or operate infrastructure for you, we will provide it in a documented, machine-readable form on request, and delete our copies within 30 days of confirmation. Runbooks and infrastructure definitions we produced for you are yours throughout the engagement, not on exit from it.
12. Confidentiality
Each party will keep the other's confidential information confidential, use it only for the purposes of the engagement, and protect it with at least the care it applies to its own. This does not cover information that is public through no fault of the receiving party, independently developed, or lawfully received from a third party.
Findings about your systems are your confidential information. We will not use your name as a reference or publish that you are a client without your written agreement.
13. Governing law
Where you have a signed Agreement, that Agreement specifies the governing law and jurisdiction. Where you do not, these terms are governed by the laws of the country in which Uwitz Corporate operates at the time of the dispute, and the courts of that country have exclusive jurisdiction, without prejudice to either party seeking injunctive relief elsewhere.
14. Changes
We may update these terms. The version and effective date above will change, and contract holders will be notified directly of material changes. Changes do not apply retroactively to Orders already accepted.
See also our Privacy Policy. Questions about these terms: hello@uwitz.co.