Legal

Terms of Service

Last updated: February 9, 2025

1

1. Definitions

In these Terms of Service, the following definitions apply:

  • "Service" — the Secure Tenant platform, including all web applications, APIs, scanning tools, dashboards, and reports provided by Secure Tenant.
  • "Customer" / "You" — the legal entity or individual who registers for and uses the Service.
  • "Customer Data" — all data that the Customer provides or makes accessible to Secure Tenant, including Microsoft 365 Tenant Data.
  • "Tenant Data" — security configuration data, audit logs, user metadata, and compliance settings retrieved from the Customer's Microsoft 365 environment via read-only OAuth access.
  • "Scan" — an automated, read-only assessment of a Microsoft 365 tenant's security posture against industry benchmarks.
  • "Health Check" — a free-tier Scan providing a limited security overview.
  • "Premium Scan" — a paid Scan providing a comprehensive security audit with full remediation guidance.
  • "Credits" — prepaid units that may be used to purchase individual Premium Scans.
  • "MSP" (Managed Service Provider) — a Customer who manages multiple Microsoft 365 tenants on behalf of third-party clients.
  • "We" / "Us" / "Secure Tenant" — Secure Tenant, registered at the Dutch Chamber of Commerce (KVK) under number 84249242, with its registered address at Diepmeerven 33, 5645KG Eindhoven, the Netherlands.
2

2. Acceptance of Terms

By creating an account, accessing, or using the Service, you confirm that you have read, understood, and agree to be bound by these Terms. If you are accepting these Terms on behalf of an organization, you represent and warrant that you have the authority to bind that organization. If you do not agree to these Terms, you may not use the Service.

3

3. Service Description

Secure Tenant provides automated security and compliance auditing for Microsoft 365 environments. The Service operates exclusively via read-only OAuth access to the Microsoft Graph API. Secure Tenant does not install agents, require shared passwords, or modify any settings in your Microsoft 365 environment. The Service includes:

  • Automated scanning of Microsoft 365 security configurations against industry benchmarks (CIS, ISO 27001, SOC 2).
  • Generation of security assessment reports with risk scoring and prioritized remediation guidance.
  • A live dashboard for monitoring security posture over time.
  • Historical drift tracking and benchmarking (Premium).
  • Multi-tenant management capabilities for MSPs (Enterprise).
4

4. Account Registration and Security

To use the Service, you must register an account with a valid email address. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You must notify us immediately at contact@secure-tenant.com if you become aware of any unauthorized use of your account. Secure Tenant requires you to grant read-only OAuth consent to access your Microsoft 365 tenant. You represent and warrant that you have the administrative authority to grant this consent for each tenant you connect to the Service.

5

5. Subscription Plans and Billing

5.1 Plans

The Service is offered in the following tiers: (a) Free Health Check — limited security overview at no cost; (b) Pro Auditor — comprehensive auditing for a monthly or annual subscription fee; (c) MSP Enterprise — custom multi-tenant solution with dedicated support. Current pricing is displayed on our website and may be updated from time to time.

5.2 Payment Processing

All payments are processed securely by Stripe, Inc. Secure Tenant does not store your credit card details. By subscribing, you also agree to Stripe's terms of service.

5.3 Billing Cycle and Renewal

Paid subscriptions renew automatically at the end of each billing cycle (monthly or annual) unless cancelled at least 24 hours before the renewal date. You may cancel your subscription at any time via your account settings.

5.4 Credits

Credits for individual Premium Scans are non-refundable after purchase and do not expire. Credits are non-transferable between accounts.

5.5 Price Changes

We will provide at least 30 days' written notice before any price increase takes effect. If you do not agree to the new pricing, you may cancel your subscription before the increase takes effect.

5.6 Taxes

All prices are exclusive of applicable taxes (including VAT/BTW). You are responsible for all taxes associated with your use of the Service, except for taxes based on Secure Tenant's net income.

6

6. Free Tier Terms

The Free Health Check tier is provided "as is" without any warranty or service level commitment. Secure Tenant reserves the right to modify, limit, or discontinue the free tier at any time without prior notice. Free-tier accounts that remain inactive for more than 12 months may be automatically deleted after a 30-day prior notice via email. Data retention for free-tier scan results is limited to 30 days.

7

7. License Grant and Restrictions

Subject to your compliance with these Terms, Secure Tenant grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Service for your internal business purposes. You may not: (a) sublicense, sell, resell, or distribute the Service (except as explicitly permitted under an MSP Enterprise agreement); (b) modify, reverse engineer, decompile, or disassemble the Service or its scanning algorithms; (c) use the Service to build a competing product; (d) access the Service through automated means beyond the provided API, or circumvent any rate limits or access controls.

8

8. Intellectual Property

The Service, including all software, algorithms, scanning methodologies, user interface designs, and documentation, is and remains the exclusive property of Secure Tenant. Customer Data remains the Customer's property at all times. Scan results generated by the Service are owned by the Customer. Secure Tenant may use aggregated, anonymized data derived from the Service for product improvement, benchmarking, and research purposes, provided such data cannot be used to identify any individual Customer or their tenant.

9

9. Customer Data and Processing

You retain all rights, title, and interest in your Customer Data. You grant Secure Tenant a limited license to process your Customer Data solely as necessary to provide the Service. Secure Tenant processes Microsoft 365 Tenant Data on your behalf as a data processor. The details of this processing are governed by our Data Processing Agreement (DPA), which forms an integral part of these Terms. You are responsible for ensuring that you have the necessary rights and legal basis to provide Customer Data to Secure Tenant and to authorize the processing described in the DPA.

10

10. Confidentiality

Each party agrees to treat as confidential all non-public information disclosed by the other party in connection with the Service ("Confidential Information"). This includes, without limitation, Customer Data, scan results, business plans, and technical information. Neither party shall disclose Confidential Information to any third party without the prior written consent of the disclosing party, except as required by law or as necessary to provide the Service (e.g., to sub-processors bound by equivalent confidentiality obligations). These confidentiality obligations survive termination of these Terms for a period of three (3) years.

11

11. Representations and Warranties

Secure Tenant represents and warrants that: (a) the Service will perform materially as described in our documentation; (b) we will comply with applicable laws in providing the Service; (c) we will implement appropriate technical and organizational security measures.

  • You represent and warrant that: (a) you have the legal authority to enter into these Terms; (b) you have the administrative authority to grant OAuth access to each Microsoft 365 tenant you connect; (c) you own or have the necessary rights to the Customer Data you provide; (d) your use of the Service will comply with all applicable laws and these Terms.
12

12. Security Assessment Disclaimer

THIS IS A CRITICAL CLAUSE. THE SERVICE PROVIDES AUTOMATED SECURITY ASSESSMENTS FOR INFORMATIONAL PURPOSES ONLY. YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT:

  • No automated scanning tool can detect 100% of security misconfigurations, vulnerabilities, or compliance gaps.
  • Scan results and recommendations do not constitute professional security consulting, legal advice, or a guarantee of security.
  • Following the Service's recommendations does not guarantee the prevention of security breaches or incidents.
  • The Service is a tool to assist your security efforts, not a replacement for professional security judgment, penetration testing, or comprehensive security programs.
  • You are solely responsible for evaluating and implementing any recommendations provided by the Service.
  • Secure Tenant does not guarantee that your Microsoft 365 environment is or will become compliant with any particular standard or regulation as a result of using the Service.
13

13. Read-Only Access Disclaimer

The Service operates exclusively in read-only mode via the Microsoft Graph API. Secure Tenant cannot and does not modify, alter, delete, or write any data or configurations in your Microsoft 365 environment. You are solely responsible for implementing any configuration changes recommended by the Service. Secure Tenant bears no liability for any consequences arising from your implementation or non-implementation of recommended changes.

14

14. Limitation of Liability

14.1 Liability Cap

To the maximum extent permitted by applicable law, Secure Tenant's total aggregate liability arising out of or in connection with the Service shall not exceed the total fees paid by you to Secure Tenant in the twelve (12) months immediately preceding the event giving rise to the claim. For free-tier users, Secure Tenant's total aggregate liability shall not exceed one hundred euros (EUR 100).

14.2 Exclusion of Damages

In no event shall Secure Tenant be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, loss of data, loss of business, business interruption, reputational damage, or cost of procurement of substitute services, regardless of the cause of action or theory of liability.

14.3 Exceptions

The limitations in this section do not apply to: (a) liability arising from fraud or willful misconduct; (b) liability for death or personal injury caused by negligence; (c) any liability that cannot be limited or excluded under applicable Dutch law.

15

15. Indemnification

15.1 By Secure Tenant

Secure Tenant shall indemnify, defend, and hold harmless the Customer from and against any third-party claims arising from: (a) Secure Tenant's infringement of a third party's intellectual property rights through the Service; (b) Secure Tenant's material breach of its data protection obligations under the DPA; (c) Secure Tenant's gross negligence or willful misconduct.

15.2 By Customer

You shall indemnify, defend, and hold harmless Secure Tenant from and against any third-party claims arising from: (a) your unauthorized scanning of Microsoft 365 tenants you do not own or are not authorized to manage; (b) your violation of the Acceptable Use Policy; (c) claims from your end users or managed clients related to your use of the Service; (d) your misrepresentation of administrative authority over a connected tenant.

16

16. Term and Termination

16.1 Term

These Terms are effective from the date you first access or use the Service and continue until terminated.

16.2 Termination for Convenience

You may terminate your account at any time via your account settings. Secure Tenant may terminate free-tier accounts at any time with 30 days' notice. For paid subscriptions, Secure Tenant may terminate with 90 days' notice.

16.3 Termination for Cause

Either party may terminate immediately upon written notice if: (a) the other party materially breaches these Terms and fails to cure within 30 days after receiving written notice; (b) the other party becomes insolvent or enters bankruptcy proceedings.

16.4 Effect of Termination

Upon termination: (a) your right to access the Service ceases immediately; (b) you may request export of your Customer Data within 30 days; (c) after the 30-day export period, Secure Tenant will delete all Customer Data within 30 additional days, except where retention is required by law.

17

17. Modifications to Terms

Secure Tenant may modify these Terms at any time. For material changes, we will provide at least 30 days' notice via email or through the Service. Your continued use of the Service after the effective date of any modifications constitutes acceptance of the modified Terms. If you do not agree to the modified Terms, you may terminate your account before they take effect.

18

18. Governing Law and Dispute Resolution

These Terms are governed by and construed in accordance with the laws of the Netherlands, without regard to its conflict of laws provisions. Any disputes arising from or in connection with these Terms shall be submitted to the exclusive jurisdiction of the competent court in Oost-Brabant, the Netherlands. In the event of any discrepancy between the English and Dutch versions of these Terms, the English version shall prevail.

19

19. Force Majeure

Neither party shall be liable for any failure or delay in performance resulting from circumstances beyond its reasonable control, including but not limited to: natural disasters, war, terrorism, pandemic, government actions, internet or telecommunications failures, power outages, and changes to the Microsoft Graph API, Microsoft 365 platform, or Microsoft's OAuth consent framework that affect the Service's ability to function as intended.

20

20. Miscellaneous

  • Severability: If any provision of these Terms is held to be unenforceable, the remaining provisions shall continue in full force and effect.
  • Entire Agreement: These Terms, together with the DPA, Privacy Policy, Acceptable Use Policy, and any applicable order forms, constitute the entire agreement between the parties.
  • Assignment: You may not assign or transfer these Terms without Secure Tenant's prior written consent. Secure Tenant may assign these Terms in connection with a merger, acquisition, or sale of assets.
  • No Waiver: Failure by either party to enforce any right or provision shall not constitute a waiver of that right or provision.
  • Notices: All notices shall be sent via email. Notices to Secure Tenant shall be sent to contact@secure-tenant.com. Notices to you shall be sent to the email address associated with your account.
  • Export Compliance: You agree to comply with all applicable export and import laws and regulations.
21

21. Contact

For questions about these Terms, contact us at:

  • Secure Tenant
  • KVK: 84249242
  • Address: Diepmeerven 33, 5645KG Eindhoven, Netherlands
  • Email: contact@secure-tenant.com