Terms of Service
Effective Date: 25 August 2026
These Terms of Service ("Terms") govern Customer's access to and use of Osto's Platform and any other Osto offering identified in an applicable Order Form. By signing or otherwise accepting an Order Form, or by using the Platform where electronic acceptance is provided, Customer agrees to be bound by these Terms.
The applicable Order Form sets out the commercial scope of your purchase, including the applicable Platform offering, Subscription Period, Fees, quantities, usage limits, and any specific scope. These Terms govern that purchase.
The contracting entity is Osto Cybersecurity Inc. or Osto Cybersecurity Pvt. Ltd., as identified in the applicable Order Form.
Legal notices: legal@osto.one.
Security reports: security@osto.one.
1. About These Terms
1.1 Scope. These Terms govern Customer's access to and use of the Osto Platform, Osto website, and any other functionality expressly identified in an applicable Order Form.
1.2 Osto Platform. Osto is a product company that develops and operates a SaaS-based cyber platform. Customer's primary purchase is access to the Platform. Osto does not provide standalone consulting, staffing, managed security, managed services, implementation, or other independent professional services as part of the standard Platform offering.
1.3 Platform Support Activities. Activities performed by Osto, its Affiliates, or its authorized personnel in connection with the Platform, including onboarding, configuration, VAPT, code assessment, and similar activities, are performed to configure, enable, support, operate, or improve Customer's use of the Platform and form part of the applicable Platform offering. The involvement of Osto, its Affiliates, or its authorized personnel, or the provision of a report, finding, configuration, assessment, or other output, does not by itself constitute a standalone professional service.
1.4 vCISO Advisory. The exception to Section 1.3 is vCISO advisory support where expressly identified in the applicable Order Form. Such advisory support is limited to the scope stated in the Order Form and does not make Osto or its affiliate or authorised personnel as Customer's legal, regulatory, executive, compliance, or security decision-maker.
1.5 One-Time Offerings. Certain Platform capabilities, including VAPT assessments, may be purchased for a fixed one-time fee. The payment structure does not by itself convert the applicable capability into a consulting or professional-services engagement.
1.6 Acceptance and Authority. If a person accepts an Order Form or these Terms on behalf of an entity, that person represents that they have authority to bind that entity. "Customer" means that entity. These Terms use "Customer" throughout and do not separately use "you."
1.7 Business Customers. Osto primarily provides the Platform to businesses. Nothing in these Terms limits any rights or protections that cannot lawfully be waived.
2. Definitions
2.1 Account. The account through which Customer and its Users access the Platform.
2.2 Affiliate. An entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of more than fifty percent (50%) of the voting interests.
2.3 Aggregated Data. Statistics, metrics, trends, benchmarks, or analytics derived from use of the Platform that have been aggregated or de-identified so that they do not reasonably identify Customer, its Users, or any individual.
2.4 AI Features. Artificial intelligence or machine-learning functionality made available through the Platform.
2.5 AI Output. Content, findings, recommendations, summaries, classifications, scores, or other output generated by AI Features.
2.6 Customer Data. Data, content, files, prompts, configurations, credentials, security and compliance evidence, findings, logs, telemetry, and other information submitted to, collected by, transmitted through, stored in, or processed by the Platform on behalf of Customer or its Users, including information collected from connected systems and environments. Customer Data excludes Feedback and Aggregated Data.
2.7 Documentation. Osto's then-current technical, product, and support documentation made available for the applicable Platform offering.
2.8 Fees. The fees and other charges specified in an applicable Order Form.
2.9 Order Form. A document, electronic ordering record, subscription confirmation, renewal confirmation, or other ordering record accepted by Customer and Osto that identifies the applicable Platform offering, scope, Subscription Period, Fees, quantities, usage limits, or other applicable commercial terms.
2.10 Osto Technology. The Platform, website, Documentation, software, models, detection logic, methods, workflows, templates, know-how, and other technology or intellectual property owned or licensed by Osto.
2.11 Platform. Osto's cloud-based cybersecurity platform and the functionality made available under an applicable Order Form.
2.12 Platform Support Activities. Activities performed by Osto personnel in connection with a Platform offering, including onboarding, enablement, configuration, VAPT, code assessment, security testing, and similar activities. These activities form part of the applicable Platform offering and are not standalone services, except for vCISO advisory support expressly scoped in an Order Form.
2.13 Restricted Data. The categories of sensitive data described in Section 9.2.
2.14 Security Incident. Unauthorized access to or acquisition of Customer Data in Osto's possession or control that compromises its confidentiality, integrity, or availability, excluding unsuccessful attempts and events caused solely by Customer systems, credentials, Users, or third-party services.
2.15 Sub-processors. Third parties engaged by Osto to process Customer Data in connection with the Platform.
2.16 Subscription Period. The period specified in an Order Form during which Customer is authorized to use the applicable Platform offering.
2.17 User. A person authorized by Customer to access or use the Platform, including an employee, contractor, adviser, or administrator.
3. Orders, Platform Use and Enablement Support
3.1 Order Forms. Each Order Form identifies the Platform offering purchased and may specify the applicable modules, support package, Subscription Period, Fees, usage limits, and specific scope.
3.2 Governing Terms. Each purchase is governed by the applicable Order Form and these Terms. A purchase order, procurement portal, vendor form, onboarding form, or similar document does not modify these Terms unless Osto expressly accepts the modification in writing.
3.3 Right to Use. Subject to the applicable Order Form and payment of the applicable Fees, Osto grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable Subscription Period to permit its authorized Users to access and use the Platform for Customer's internal business purposes in accordance with these Terms and the Documentation.
3.4 Platform Capabilities. The Platform may include any of the following capabilities, as applicable to the scope specified in the applicable Order Form:
- Real-Time Cybersecurity. Web application protection, API security, web application scanning, mobile application scanning, cloud security posture management, endpoint detection and response, device control, disk encryption, screen lock, swipe clean, application filtering, data leakage prevention, secure server access, DNS security, domain filtering, code and dependency security, email security, identity and access management, and other cybersecurity capabilities made available by Osto from time to time.
- Compliance Automation. Frameworks including SOC 2, ISO 27001, GDPR, and other applicable frameworks, together with security awareness training, AI-assisted security questionnaires, and related compliance capabilities.
- VAPT and Source Code Assessment. Capabilities for web applications, APIs, mobile applications, cloud infrastructure, GenAI applications, blockchain applications, and other environments or technologies supported by the Platform from time to time.
- Cyber Insurance. Access to or facilitation of cyber insurance through Osto's insurance partners or third-party insurance providers.
- vCISO Advisory. vCISO advisory and related cybersecurity, governance, risk, and compliance guidance, where expressly included in the applicable Order Form.
- Logging and Data. Collection, processing, and storage of security events, findings, and related data, together with other security, compliance, and Platform functionality made available by Osto.
3.5 Platform Changes. Osto may update, enhance, replace, or modify the Platform from time to time. During a committed Subscription Period, Osto will not materially reduce the core functionality purchased, except where reasonably required for security, applicable law, technical reasons, or an upstream dependency. Where reasonably practicable, Osto will provide advance notice of material feature retirement.
3.6 Usage Limits. Customer must remain within the usage limits specified in the applicable Order Form or Documentation. If Customer exceeds a stated limit, Osto may, after reasonable notice where practicable, charge applicable overage Fees, require additional capacity, or restrict usage exceeding the applicable limit.
3.7 Platform Support Activities. Platform Support Activities are performed to configure, enable, or improve Customer's use of the Platform. They are not separate consulting, implementation, staffing, managed-security, managed-services, or other professional-services engagements.
3.8 Customer Cooperation. Customer must provide timely access, information, permissions, credentials, environments, approvals, and other inputs reasonably required for the Platform or applicable Platform Support Activities. Osto is not responsible for delays resulting from Customer's failure to provide such inputs.
3.9 Assessments and Testing. Where the Platform includes VAPT, security testing, source code assessment, or similar capabilities, Customer must own the applicable target or have all necessary authorization to test it. Customer is responsible for ensuring that such activities are legally authorized and appropriately scoped. Testing may affect availability, performance, data, or third-party security controls, and Customer is responsible for maintaining appropriate backups and following applicable testing controls or windows specified by Osto.
3.10 Platform Outputs. Findings, scores, reports, recommendations, assessments, AI Output, compliance status, and other outputs generated through the Platform reflect the information, access, configuration, scope, and conditions available to the Platform at the relevant time. Such outputs do not guarantee that every vulnerability, security issue, compliance gap, or risk has been identified or resolved. Customer remains responsible for reviewing Platform outputs and for remediation, risk acceptance, compliance decisions, implementation, and other decisions based on them.
3.11 vCISO Advisory. Where expressly included in an Order Form, Osto may make vCISO advisory support available through its affiliated or associated cybersecurity professionals within the specified scope. Customer may authorize such professional to communicate with and advise Customer's customers, management, board, or other stakeholders on Customer's behalf. Such authorization does not make the professional Customer's employee, officer, director, statutory auditor, or legal representative, or give the professional authority to make final decisions or accept risks on Customer's behalf. Customer remains responsible for its security program, legal and regulatory obligations, risk acceptance, business decisions, and implementation of recommendations.
4. Customer Support, Availability and Maintenance
4.1 During the Subscription Period, subject to Customer's payment of all applicable Fees, Osto will use commercially reasonable efforts to provide support, maintenance and uptime for the Platform.
4.2 Osto offers three support packages: Standard, Express and Elite. Each is described in the Support Policy. The package you receive is the one identified on your Order Form. If your Order Form does not identify a package, Standard applies.
4.3 The Platform may be unavailable or degraded because of scheduled maintenance, emergency maintenance, Customer systems or connectivity, third-party systems, or events outside Osto's reasonable control. Osto will provide advance notice of scheduled maintenance where reasonably practicable.
4.4 Osto may temporarily restrict functionality where reasonably necessary to protect the Platform, Customer, other customers, or third-party systems.
5. Trial Access & Beta Offerings
5.1 Trial and Evaluation Services. Osto may, upon Customer's request and at its discretion, provide free proof-of-concept, evaluation or trial access to the Platform or specific Platform capabilities where Osto determines that the request is genuine and appropriate. If approved, Osto will communicate the applicable access period to Customer. Such access will end on the earlier of: (a) expiry of the communicated period; (b) commencement of a paid subscription; or (c) termination by Osto. Unless otherwise stated, trial and evaluation access is for internal evaluation and not production use. Osto may modify, suspend or discontinue such access at any time.
5.2 Beta Offerings. Osto may make pre-release features or functionality available as alpha, beta, preview, early access, experimental or similar offerings ("Beta Offerings"). Beta Offerings may be provided at no charge, may be incomplete or contain defects, may change without notice, and may never become generally available. Unless otherwise stated, a Beta Offering will end when the applicable functionality becomes generally available or when Osto otherwise discontinues it. Osto may discontinue any Beta Offering at any time. Beta Offerings are provided "as-is" and "as-available" and are not subject to separate support, service-level or performance commitments unless expressly stated by Osto.
5.3 Customer Data. Osto has no obligation to retain any Customer Data provided, submitted or made available during a trial or evaluation period. Unless Customer commences a paid subscription or Osto otherwise agrees in writing, such Customer Data will be permanently deleted following the expiry or termination of the applicable trial or evaluation period. Customer is responsible for exporting any Customer Data it wishes to retain before the trial or evaluation period ends.
6. Customer Account and Responsibilities
6.1 Authorized Access. Access to the Platform is limited to authorized Users and applicable usage limits. Each User must use unique credentials, and credentials must not be shared.
6.2 Account Responsibility. Customer is responsible for all activity conducted through its Account by its Users, contractors, or any other person using Customer's credentials.
6.3 Account Security. Customer must keep its account information accurate and up to date, protect its passwords, authentication factors, API keys, and other credentials, remove access when no longer required, and promptly notify Osto of any suspected unauthorized access or credential compromise.
6.4 Customer-Controlled Systems. Customer is responsible for maintaining the security, availability, backups, connectivity, configurations, and third-party systems that it controls.
6.5 Customer Data. Customer is responsible for the accuracy, legality, quality, and completeness of Customer Data and for all instructions it provides to Osto.
6.6 Rights and Permissions. Customer represents that it has all rights, permissions, notices, consents, and lawful bases required to provide Customer Data to Osto and to connect the third-party systems it enables.
6.7 Endpoint and Device Monitoring. Where endpoint agents or device-monitoring functionality are used, Customer is responsible for complying with all applicable privacy, employment, labor, surveillance, device-monitoring, and works-council requirements. Customer must not deploy such agents on devices that it does not manage or have authority to monitor.
6.8 Compliance Responsibility. Customer remains responsible for determining which compliance frameworks apply to it, designing and operating its controls, maintaining evidence, remediation, risk acceptance, and determining whether its program satisfies applicable legal, regulatory, contractual, audit, or certification requirements.
6.9 Platform Outputs. Customer must not represent any Platform-generated status, score, report, finding, or output as an independent audit opinion, certification, legal conclusion, or guarantee of compliance.
7. Authorized Scanning and Acceptable Use
7.1 Authorized Scanning and Testing. Before directing any scan, assessment, probe, simulated attack, or active test at a target, Customer must ensure that it owns and controls the target or has obtained written authorization from the target owner and any relevant hosting, cloud, managed-service, registrar, or upstream provider whose authorization is required. Osto may request evidence of such authorization and may refuse, pause, or stop testing where authorization is missing or unclear.
7.2 Prohibited Uses. Customer must not:
- resell, sublicense, rent, lease, or make the Platform available to any third party without Osto's prior written consent;
- reverse engineer, decompile, disassemble, or attempt to discover the source code or non-public architecture of the Platform, except where applicable law expressly permits it;
- copy, modify, or create derivative works of the Platform;
- bypass security, access, rate, or usage controls, or interfere with the Platform;
- introduce malicious code into the Platform;
- use the Platform unlawfully, fraudulently, deceptively, abusively, or to infringe or violate another person's rights;
- publicly benchmark the Platform or use it to build, train, or improve a competing product;
- scrape or harvest data except through interfaces provided by Osto;
- direct the Platform at any target that Customer is not authorized to test;
- submit Restricted Data except as expressly permitted under Section 7.3;
- deploy the Platform in a High-Risk Environment except as expressly permitted under Section 7.4; or
- use the Platform contrary to the Documentation, applicable law, sanctions, or another person's rights.
7.3 Restricted Data. Unless expressly permitted in an Order Form with appropriate safeguards, Customer must not intentionally submit highly sensitive categories of data, including health or medical data, genetic data, biometric identifiers, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, criminal records, government identifiers such as Aadhaar, PAN, national ID, passport, tax or driving-license numbers, payment-card data, or financial-account numbers.
If Restricted Data appears incidentally in logs, files, or scan output, that incidental appearance will not itself constitute a breach of these Terms. Osto will protect such data as Customer Data subject to the applicable security and data-protection commitments.
7.4 High-Risk Environments. Customer must not deploy blocking, endpoint-control, application-control, device-control, domain-filtering, or similar functionality in an environment where failure or misconfiguration could cause death, serious injury, or severe physical or environmental damage, including emergency services and dispatch, clinical care, medical devices, industrial control and safety systems, nuclear facilities, aviation and air traffic control, autonomous vehicles, or comparable environments, unless the applicable Order Form expressly permits such deployment and specifies appropriate additional controls.
7.5 Suspension. Osto may suspend or restrict affected access if Customer: (a) engages in a Prohibited Use; (b) creates a material security, legal, operational, or financial risk; (c) fails to pay Fees when due; (d) is required to be suspended by law or court order; (e) exceeds applicable usage limits and does not correct the issue after notice; or (f) materially breaches these Terms and suspension is reasonably necessary to limit harm.
Where practicable, Osto will provide notice and an opportunity to correct the issue. Osto may act immediately where waiting would materially increase risk. Suspension will be limited to the affected functionality where reasonably practicable and will not suspend payment obligations or extend the Subscription Period.
8. Fees, Payment, Cancellation and Refunds
8.1 Subscription Fees. Customer will pay the subscription fees specified in the applicable Order Form ("Subscription Fees") for the Subscription Term. Subscription Fees are based on the scope, subscription plan, number of Users, devices, assets, usage limits, modules, or other parameters specified in the applicable Order Form. Unless expressly stated otherwise, all Subscription Fees are exclusive of applicable taxes, duties, levies, or similar governmental charges, which will be payable by Customer.
8.2 Subscription Commitment. Subscription Fees are committed for the entire Subscription Term. Customer's payment obligations will not be reduced or suspended due to reduced or non-use of the Platform, reduction in Users, devices or assets, suspension of access, changes in Customer's business or circumstances, or discontinuation of Customer's business. Subscription Fees paid or payable for the applicable Subscription Term are non-refundable, except where expressly provided in these Terms or required by applicable law.
8.3 Invoicing and Payment. Osto will invoice Customer in accordance with the billing schedule specified in the applicable Order Form. Unless otherwise specified, invoices are issued in advance and are payable within five (5) days of the invoice date through the payment method specified by Osto, including Stripe or net banking or any other.
8.4 Taxes. Customer is responsible for all applicable taxes, including sales, use, withholding, value-added, or similar taxes arising from its purchase or use of the Platform, except taxes imposed on Osto's net income. If Customer is required by law to withhold any amount from a payment, Customer will provide Osto with appropriate documentation evidencing such withholding and will ensure that Osto receives the full amount that would have been received absent the withholding, to the extent permitted by applicable law.
8.5 Late Payments. If any undisputed amount remains unpaid after its due date, Osto may charge interest at the lesser of 1.5% per month or the maximum rate permitted by applicable law, from the due date until payment. Customer will also reimburse Osto for reasonable costs incurred in collecting overdue amounts.
8.6 Suspension for Non-Payment. If an undisputed invoice remains unpaid for more than fifteen (15) days after its due date, Osto may suspend Customer's access to the affected Platform or Services after providing notice. Suspension will not relieve Customer of its payment obligations for the Subscription Term. Osto will restore access after all overdue amounts and applicable charges have been paid.
8.7 Renewal. Unless otherwise specified in the applicable Order Form, each Subscription will automatically renew for successive twelve (12)-month periods ("Renewal Term") unless either party provides written notice of non-renewal at least thirty (30) days before the expiry of the then-current Subscription Term. Renewal will be subject to the fees applicable at the time of renewal, unless otherwise agreed in writing.
8.8 Renewal Pricing. Unless otherwise agreed in writing, the Subscription Fees for each Renewal Term will increase by at least ten percent (10%) over the Subscription Fees applicable to the immediately preceding Subscription Term, provided that such preceding Subscription Fees were based on standard, non-discounted pricing. Where the preceding Subscription Fees were discounted, promotional, waived, or otherwise reduced from Osto's standard pricing, the Renewal Term Fees may be revised to Osto's then-current standard pricing and applicable commercial terms and may therefore result in a substantially greater increase.
8.9 Changes to Subscription Scope. Any addition, removal, or change to the Platform scope, modules, Users, devices, assets, usage limits, or other subscription parameters must be agreed by Osto and Customer and may result in corresponding changes to the Subscription Fees. Any upsell, cross-sell, expansion, or additional subscription purchased during the Subscription Term will be charged at the applicable fees agreed between the parties. Unless otherwise agreed, a reduction in scope during an active Subscription Term will not reduce the committed Subscription Fees for that Subscription Term.
8.10 One-Time Engagement Fees. Fees for one-time engagements, including VAPT, cyber insurance facilitation, source code assessments, vCISO advisory services, or other separately priced offerings, will be charged in advance or otherwise agreed in writing. Such fees are non-refundable once the applicable payment has been made.
8.11 No Cancellation During Subscription Term. Customer may not terminate, cancel, pause, or prematurely discontinue a paid subscription during an active Subscription Term except as expressly permitted under these Terms or agreed in writing by Osto. Termination of access does not eliminate Customer's obligation to pay committed Subscription Fees for the remainder of the applicable Subscription Term.
8.12 Refunds. All Subscription Fees and other fees paid to Osto are non-refundable. Termination, suspension, non-use of the Platform, reduction in usage, or discontinuation of Customer's business will not create a right to a refund or credit.
8.13 No Set-Off. Customer may not withhold, set off, or deduct any amount from fees payable to Osto unless required by applicable law or expressly agreed by Osto in writing.
9. Term and Termination
9.1 Term. These Terms become effective when Customer first accepts them and remain in effect for as long as Customer uses the Platform or any applicable Osto offering. Each Order Form will remain effective for the Subscription Period specified in that Order Form.
9.2 Termination by Osto. Osto may terminate an applicable Order Form if Customer:
- commits a Prohibited Use that cannot reasonably be cured;
- repeatedly breaches these Terms;
- uses the Platform in a manner that creates a material legal or security risk;
- remains suspended for non-payment for thirty (30) consecutive days; or
- becomes insolvent, makes an assignment for the benefit of creditors, enters liquidation, has a receiver appointed, or becomes subject to bankruptcy or a similar proceeding that is not dismissed within sixty (60) days, to the extent permitted by applicable law.
9.3 Effect of Termination or Expiry. Upon termination or expiry of an Order Form, Customer's right to access and use the applicable Platform offering will immediately end. Customer must stop using the applicable Platform offering, remove any Osto agents or software where applicable, and pay all amounts accrued and payable through the effective date of termination. Any committed and unpaid Fees for the remainder of the applicable Subscription Term will also become immediately due and payable, to the extent permitted by applicable law.
9.4 Customer Data Export and Deletion. Customer may export Customer Data during the Subscription Period using the export functionality provided by Osto. Following termination or expiry, Osto will make such export functionality available for thirty (30) days. After that period, Osto may delete or render irrecoverable Customer Data from its production systems within a further sixty (60) days, except for data that Osto is required to retain by law, data maintained in routine encrypted backups until overwritten through normal backup rotation, and Aggregated Data. Any Customer Data retained by Osto will continue to be protected in accordance with these Terms and the applicable Data Processing Addendum. Upon Customer's written request, Osto will confirm deletion of Customer Data to the extent applicable.
If Customer's access has been suspended for non-payment, Osto is not required to restore access solely to enable Customer to export Customer Data unless all overdue Fees have been paid.
9.5 Survival. Provisions relating to accrued payment obligations, intellectual property, confidentiality, Customer Data return and deletion, disclaimers, indemnification, limitation of liability, dispute resolution, and any other provisions that by their nature are intended to survive termination or expiry will survive.
10. Intellectual Property and Customer Data
10.1 Osto Technology. Osto and its licensors retain all right, title, and interest in and to the Platform, website, Documentation, software, models, detection logic, methods, workflows, templates, know-how, and all related intellectual property. Except for the limited rights expressly granted under these Terms, no rights in or to the foregoing are transferred to Customer.
10.2 Customer Data. Customer retains all right, title, and interest in and to Customer Data. Customer grants Osto and its Sub-processors the rights necessary to host, copy, transmit, process, display, and use Customer Data to provide, operate, secure, maintain, support, and improve the Platform, perform Platform Support Activities, follow Customer's instructions, prevent fraud and misuse, and comply with applicable law.
10.3 Feedback and Improvements. Osto may use any suggestions, ideas, recommendations, feedback, or other input provided by Customer, including information arising from support interactions, without payment or restriction. Osto may use such information to improve, develop, operate, and maintain its products and services or for marketing purpose, provided that Osto will not disclose Customer's identity or any Customer Confidential Information in connection with such use. Osto will not use Customer's Confidential Information without Customer's prior written consent.
10.4 Aggregated Data. Osto may generate Aggregated Data from the use and operation of the Platform and may use Aggregated Data to operate, secure, analyze, improve, and develop its products and services, create benchmarks, and publish insights. Osto will not attempt to re-identify Aggregated Data or disclose it in a form that reasonably identifies Customer, its Users, or any individual. Aggregated Data may be retained and used after termination or expiry of the applicable Order Form.
10.5 Customer Name and Logo. Osto may identify Customer as a customer of Osto and may use Customer's name and logo for this purpose. Any broader use of Customer's name, logo, review, case study, or other Customer-specific materials requires Customer's prior written consent or express authorization in an applicable Order Form.
11. Privacy, Security and Data Processing
11.1 Security Measures. Osto maintains administrative, technical, physical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of Customer Data, appropriate to the Platform and the nature of the data processed.
11.2 Data Processing. Where Osto processes Personal Data contained in Customer Data on Customer's behalf, the applicable Osto Data Processing Addendum ("DPA") will apply. Where applicable, Customer acts as the controller or data fiduciary, and Osto acts as the processor.
11.3 Sub-processors. Osto may use Sub-processors to provide the Platform. Osto will maintain a current list of Sub-processors and comply with the applicable notice and objection requirements set out in the DPA.
11.4 Security Incidents. Osto will notify Customer without undue delay, and in any event within seventy-two (72) hours after confirming its Security Incident affecting Customer Data. Osto will investigate, contain, mitigate, and remediate the Security Incident and provide Customer with information reasonably available to Osto concerning the incident. Failed attempts and events that do not compromise Customer Data will not constitute Security Incidents.
11.5 Customer Security Responsibilities. Customer must maintain appropriate security controls, protect access credentials, securely configure integrations, and promptly install critical updates for Osto agents and software. Security incidents arising from Customer's systems, credentials, Users, configurations, instructions, or third-party services remain Customer's responsibility.
11.6 Privacy Policy. Personal information collected by Osto outside Customer Data, including information relating to accounts, billing, marketing, and use of Osto's website, is governed by Osto's Privacy Policy.
12. Third-Party Dependencies and AI Features
12.1 Third-Party Integrations. Customer may connect the Platform to third-party products and services. Doing so authorizes Osto to exchange Customer Data with those products as required for the integration. Customer is responsible for having the right to connect them and complying with their applicable terms. Osto does not control third-party products and is not responsible for their availability, security, changes, or performance. A third-party product is not part of the Platform unless an Order Form expressly states otherwise.
12.2 Cyber Insurance. Where offered, Osto may facilitate access to cyber insurance through an insurance web aggregator, broker, insurer, or other insurance partner. Osto is a facilitator and does not own, underwrite, issue, guarantee, or determine the terms of any insurance policy unless expressly stated in an Order Form and permitted by applicable law. The applicable insurance provider or intermediary determines eligibility, underwriting, pricing, coverage, exclusions, policy terms, claims, renewal, cancellation, and refunds. Customer is responsible for reviewing and accepting the applicable third-party terms before purchasing coverage. Osto is not responsible for the acts, omissions, decisions, availability, pricing, coverage, claims handling, or performance of any insurer, broker, web aggregator, or other insurance partner.
12.3 AI Features. AI Features may generate summaries, classifications, findings, recommendations, scores, and other outputs. AI Output is probabilistic and may be incomplete, inaccurate, outdated, or non-unique. Customer must review and validate AI Output before relying on it. AI Output is not professional advice, a certification, or an independent decision.
12.4 Customer Data and Model Training. Osto will not use Customer Data to train, fine-tune, or develop artificial-intelligence or machine-learning models, whether its own or those of a third party, unless Customer expressly opts in. Osto may route Customer Data through approved model providers solely to generate AI Output, subject to appropriate contractual restrictions. Osto may use Feedback and Aggregated Data as permitted under these Terms.
12.5 AI Use. Where the Platform provides an administrator control to disable an AI Feature, Customer may use that control. Customer must not use AI Features for unlawful, infringing, deceptive, discriminatory, malicious, or harmful purposes, including to facilitate malware, ransomware, phishing, credential theft, social engineering, unauthorized surveillance, or other prohibited activity.
12.6 AI Regulatory Responsibilities. Where applicable law assigns provider or deployer responsibilities to either party, each party will comply with its respective obligations. Customer remains responsible for its use case, required human oversight, transparency obligations, and decisions based on AI Output.
13. Confidentiality
13.1 Confidential Information. Confidential Information means non-public information disclosed by one party to the other that is marked confidential or should reasonably be understood to be confidential given its nature and the circumstances of disclosure. Customer Data and Platform findings are Customer's Confidential Information. Osto Technology, Osto's non-public product and security information, pricing, and Order Form terms are Osto's Confidential Information.
13.2 Use and Disclosure. Each party will use the other's Confidential Information only to perform or receive the applicable Platform offering and related obligations, protect it with at least reasonable care, and disclose it only to personnel, Affiliates, contractors, and advisers who need to know and are subject to equivalent confidentiality obligations.
13.3 Exclusions. These obligations do not apply to information that becomes public without breach, was already lawfully known without restriction, is lawfully received from a third party without a duty of confidentiality, or is independently developed.
13.4 Required Disclosure and Incidents. A party may disclose Confidential Information where legally required, giving prompt notice where permitted and reasonable cooperation if the other party seeks protective relief. Each party will promptly notify the other of unauthorized access to or disclosure of the other's Confidential Information and reasonably assist with mitigation.
13.5 Duration. These obligations continue for five years after disclosure, except trade secrets and personal data remain protected for as long as applicable law requires.
14. Warranties and Disclaimers
14.1 Authority. Each party represents that it has authority to enter into and perform its obligations under these Terms.
14.2 Platform Warranty. During a paid Subscription Period, the Platform will perform materially as the Documentation describes when used as permitted. Customer must notify Osto within 30 days after discovering a material problem and provide sufficient detail for Osto to investigate. Osto will use commercially reasonable efforts to repair or replace the affected functionality. If Osto cannot do so within a reasonable time, Customer may terminate the affected Order Form and receive a pro rata refund of prepaid Fees for the unused portion of the affected Subscription Period. This is Customer's exclusive remedy for this warranty.
14.3 Security and Support. Osto will not knowingly introduce a virus, worm, back door, or time bomb into the Platform. Osto will perform Platform Support Activities using appropriately skilled personnel and reasonable care. This does not warrant the outcome of any security test, VAPT, assessment, recommendation, finding, compliance result, vCISO advisory, or AI Output.
14.4 No Guarantee of Security or Compliance. Customer acknowledges that no cybersecurity product, security assessment, VAPT, source code assessment, compliance program, vCISO advisory, or other security measure can guarantee the prevention or detection of every threat, vulnerability, attack, security incident, data breach, compromise, misconfiguration, or control failure. The Platform and related services are provided based on the scope, information, access, configurations, and conditions available at the relevant time. Osto is not responsible for any security incident, breach, attack, vulnerability, compromise, business interruption, loss, damage, reputational harm, regulatory action, or third-party claim arising despite Customer's use of the Platform or receipt of any Platform Support Activity, including VAPT, assessments, or vCISO advisory, except to the extent liability cannot lawfully be excluded or limited under these Terms.
14.5 Exclusions. The express warranties do not cover problems caused by Customer Data, Customer systems, third-party services, misuse, unauthorized modification, use outside these Terms or the Documentation, failure to apply an available fix, trials, free access, beta or experimental functionality, or matters outside Osto's reasonable control.
14.6 Disclaimer. Except for the express warranties in this Section 14, and to the maximum extent permitted by law, the Platform, website, Documentation, Platform Support Activities, and AI Output are provided as-is and as-available. Osto disclaims all other warranties, express, implied, or statutory, including merchantability, fitness for a particular purpose, title, non-infringement, and warranties arising from course of dealing or trade usage.
14.7 Third Parties. Osto is not responsible for third-party products, independent auditors, certification bodies, external assessors, insurers, insurance intermediaries, or decisions made by Customer's customers, regulators, auditors, certification bodies, or other third parties.
14.8 Customer Communications and Attribution. Customer must not represent or publicly state that Osto is responsible for Customer's security, compliance, regulatory obligations, or any security incident affecting Customer, or attribute any such incident to Osto, without Osto's prior written consent. This restriction does not prevent Customer from making any disclosure required by applicable law, regulation, court order, or competent governmental or regulatory authority.
15. Indemnification
15.1 Osto Intellectual Property Indemnity. Osto will defend Customer against any third-party claim alleging that Customer's permitted use of the paid Platform infringes or misappropriates such third party's patent, copyright, trademark, or trade secret. Osto will pay damages and reasonable legal fees finally awarded against Customer or agreed in a settlement approved by Osto.
15.2 Exclusions. Osto has no obligation under Section 15.1 to the extent a claim arises from Customer Data, Customer's specifications or instructions, modifications not made by Osto, combinations with products or technology not supplied or approved by Osto where the claim would not otherwise arise, use outside these Terms or the Documentation, continued use after Osto offers a non-infringing alternative or requests cessation, trials, betas or experimental functionality, third-party products or services, open-source software governed by its own license, or failure to use a current version made available by Osto without material additional charge.
15.3 Osto's Options. For a claim covered by Section 15.1, Osto may obtain the right for Customer to continue using the affected functionality, modify or replace it with a substantially equivalent non-infringing alternative, or terminate the affected portion of the applicable Order Form and refund prepaid Fees for the unused portion of the applicable Subscription Period. This Section 15 states Osto's entire liability and Customer's exclusive remedy for covered intellectual-property claims.
15.4 Customer Indemnity. Customer will defend and indemnify Osto, its Affiliates, and their respective officers, directors, employees, and representatives against third-party claims arising from Customer Data, Prohibited Uses, breach of these Terms or applicable law, Customer's systems, configurations, instructions or actions, third-party products or services used or connected by Customer, failure to provide required privacy, employment, monitoring or device notices or consents, unauthorized endpoint-agent deployment or security testing, Restricted Data submitted in violation of these Terms, deployment in a High-Risk Environment in violation of these Terms, or use of Platform findings or AI Output in violation of these Terms or the Documentation.
15.5 Indemnification Process. The indemnified party must promptly notify the indemnifying party of a covered claim, provide reasonable cooperation at the indemnifying party's expense, and allow the indemnifying party to control the defense and settlement. Neither party may settle a claim in a manner that admits fault by, imposes a non-monetary obligation on, or fails to fully release the indemnified party without its prior written consent, not unreasonably withheld or delayed.
16. Limitation of Liability
16.1 Exclusion of Certain Damages. To the maximum extent permitted by law, neither party, nor its Affiliates, licensors, or service providers, will be liable for indirect, incidental, special, exemplary, consequential, or punitive damages; lost profits, revenue, business, goodwill, or anticipated savings; business interruption; or lost or corrupted data, even if advised of the possibility.
16.2 General Liability Cap. Except as provided in Sections 16.3 and 16.4, each party's total aggregate liability arising out of or relating to these Terms or an Order Form will not exceed the Fees paid or payable for the applicable Platform offering during the 12 months before the first event giving rise to the liability.
16.3 Enhanced Liability Cap. For a breach of confidentiality, breach of data-protection obligations, or an indemnification obligation, each party's total aggregate liability will not exceed two times the cap in Section 16.2.
16.4 Exclusions from Liability Caps. The liability caps do not apply to Customer's payment obligations, Customer's infringement or misuse of Osto Technology, Customer's liability under authorized testing, Restricted Data, High-Risk Environment, or endpoint-agent obligations, or either party's fraud, wilful misconduct, or gross negligence.
16.5 Non-Excludable Liability. Nothing in these Terms limits liability that cannot lawfully be limited.
16.6 Application of Limitations. The limitations apply regardless of the legal theory of the claim and even if a limited remedy fails of its essential purpose. Liability across Osto and its Affiliates, licensors, and service providers is counted once and is not stacked.
17. Website Use and Copyright
17.1 Website Use. Customer may use osto.one and its content for its own business and informational purposes. Osto owns the website and its content. Customer must not copy, republish, sell, frame, mirror, or build upon the website content, remove Osto notices, imply Osto endorsement, damage or overload the site, attempt unauthorized access, scan or test the site without written permission, scrape except through an interface Osto provides, bypass security or rate limits, upload malicious code, or use the site to build or train a product that competes with Osto.
17.2 Submitted Content. Customer is responsible for content it submits through website forms, portals, blogs, or in-product features and must have the rights needed to submit it. Osto may remove content that violates these Terms or creates material risk.
17.3 Informational Content. Osto's website, blog, templates, reports, and AI Output are informational and do not constitute legal, regulatory, accounting, tax, investment, or other professional advice.
17.4 Security Reporting. Security vulnerabilities discovered in Osto's website or Platform should be reported confidentially to security@osto.one. Osto's published vulnerability disclosure practices apply where applicable.
18. Governing Law and Disputes
18.1 Dispute Discussion. Before commencing formal proceedings, a party must give written notice describing the dispute and the relief sought and allow 30 days of good-faith discussion between appropriate representatives. This does not prevent urgent injunctive or equitable relief.
18.2 Osto Cybersecurity Inc. For an Order Form with Osto Cybersecurity Inc., California law applies, without regard to conflict-of-law principles. Disputes will be finally resolved by binding arbitration before one JAMS arbitrator in San Francisco, California, under the JAMS Comprehensive Arbitration Rules, in English, with the Federal Arbitration Act governing the arbitration agreement.
18.3 Osto Cybersecurity Pvt. Ltd. For an Order Form with Osto Cybersecurity Pvt. Ltd., Indian law applies. Disputes will be finally resolved by arbitration under the Delhi International Arbitration Centre Rules and the Arbitration and Conciliation Act, 1996, before one arbitrator seated in New Delhi, in English.
18.4 Urgent Relief. Either party may seek urgent injunctive or equitable relief from a court of competent jurisdiction for intellectual property infringement, unauthorized access, misuse of the Platform, confidentiality breaches, or other matters requiring immediate relief.
18.5 Arbitration Opt-Out. Customer may opt out of arbitration by emailing legal@osto.one within 30 days after first accepting these Terms, identifying Customer and expressly stating that it opts out. If Customer opts out, disputes will be brought in the courts of San Francisco County, California for an Osto Cybersecurity Inc. Order Form, or New Delhi for an Osto Cybersecurity Pvt. Ltd. Order Form, and the parties consent to those courts' jurisdiction.
18.6 Individual Proceedings. To the extent permitted by law, disputes will proceed individually and not as a class, collective, consolidated, or representative action.
18.7 Trade Compliance. Each party will comply with applicable export-control, sanctions, and trade laws.
19. General
19.1 Documents Governing a Purchase. The applicable Order Form and these Terms govern the Customer's purchase. Where a Data Processing Addendum applies, it governs personal-data processing to the extent of any conflict. Any other document is incorporated only if the Order Form or these Terms expressly says so. There is no separate master services agreement required for a purchase governed by these Terms.
19.2 Order of Precedence. For a conflict concerning commercial or scope terms expressly stated in an Order Form, the Order Form controls. For personal-data processing, the DPA controls. Otherwise, these Terms control. Customer purchase orders, procurement portals, onboarding forms, and similar documents do not modify these Terms unless Osto expressly accepts the change in writing.
19.3 Changes to These Terms. Osto may update these Terms from time to time. Osto will generally provide at least 30 days' notice of a material change, and material commercial changes will normally take effect at the next renewal. A change may take effect during a Subscription Period where reasonably required by law, security risk, abuse prevention, or an upstream dependency, provided it does not materially reduce the core functionality or protections applicable to Customer without a reasonable remedy. Osto may archive prior versions.
19.4 Assignment. Neither party may assign an Order Form without the other's written consent, except either party may assign it on notice, without consent, to an Affiliate or in connection with a merger, acquisition, reorganization, or sale of substantially all relevant business or assets, provided the assignee agrees to be bound. Customer may not assign an Order Form to a direct competitor of Osto.
19.5 Anti-Corruption. Neither party will offer, give, seek, or accept a bribe, kickback, or improper payment in connection with the purchase or use of the Platform and each will comply with applicable anti-corruption laws.
19.6 Notices. Notices to Osto must be sent to legal@osto.one. Notices to Customer may be sent to the billing, administrator, or other business email address associated with the Account or Order Form. Email notice is effective on the next business day unless it bounces.
19.7 Force Majeure. Neither party is liable for delay or failure, other than payment obligations, caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, labor disputes, epidemics, utility or internet failures, government action, cyberattacks not caused by its own breach, or failure of essential third-party infrastructure.
19.8 Waiver and Severability. Failure to enforce a provision once does not waive it. If a provision is unenforceable, it will be limited to the minimum extent necessary and the remaining provisions remain effective.
19.9 Time Limit on Claims. To the extent permitted by law, a claim must be brought within one year after the claimant knew or reasonably should have known the facts giving rise to it, except claims for unpaid Fees, intellectual property infringement or misuse, fraud, and claims for which a longer period cannot lawfully be waived.
19.10 Independent Parties. The parties are independent contractors. These Terms do not create a partnership, agency, fiduciary relationship, employment relationship, or joint venture, and neither party may bind the other.
19.11 Affiliates and Subcontractors. Osto may use Affiliates and subcontractors to operate and support the Platform and remains responsible for them to the extent required by these Terms or applicable law.
19.12 No Third-Party Beneficiaries. No person other than the parties has rights under these Terms except where expressly stated.
19.13 Electronic Acceptance. Electronic signatures, electronic acceptance, and acceptance through an Order Form or Platform interface are effective and binding.
19.14 Entire Terms. The applicable Order Form and these Terms contain the complete terms governing the applicable purchase and supersede prior discussions or representations concerning that purchase, except for any written commercial term expressly incorporated into the Order Form.
20. Contact
Legal notices: legal@osto.one
Security reports: security@osto.one
For the contracting Osto entity and its registered office, refer to the entity identified in the applicable Order Form.