Terms of Service
Last updated: 2026 · GuardianX Technologies Pvt. Ltd.
These Terms of Service ("Terms") govern your use of the GuardianX platform (the "Service") operated by GuardianX Technologies Pvt. Ltd. ("GuardianX", "we", "us"). By creating an account or using the Service, you agree to these Terms. If you do not agree, you may not use the Service.
1. Definitions
- • "Customer", "you" — the entity or individual that has created a GuardianX account.
- • "Service" — the GuardianX SaaS platform including the web app, API, and CLI.
- • "User Data" — data you upload to or generate via the Service.
- • "MSA" — the Master Subscription Agreement signed by Enterprise customers; in case of conflict, the MSA governs.
- • "DPA" — the Data Processing Agreement (see DPDPA-COMPLIANCE.md §8).
2. Eligibility & Accounts
- • You must be at least 18 years old and able to form a legally binding contract under Indian law.
- • You must provide accurate information at signup and keep it current.
- • You are responsible for keeping your password and 2FA secret confidential and for all activity under your account.
- • New accounts require admin approval before accessing the Service. GuardianX may refuse or terminate accounts at its discretion.
- • One account per person; sharing accounts is prohibited. Service accounts must be clearly labeled.
3. Acceptable Use Policy
You may use the Service only for lawful security testing on systems you own or are explicitly authorized to test. The following activities are permitted and prohibited:
| Status | Activity |
|---|---|
| Allowed | Use GuardianX to scan codebases and targets you own or have written authorization to test. |
| Allowed | Use generated patches and findings in your internal security workflows. |
| Allowed | Participate in the GuardianX bug bounty program in good faith. |
| Prohibited | Scanning third-party systems without explicit written authorization from their owner. |
| Prohibited | Using GuardianX to attack, exploit, or compromise systems you do not own. |
| Prohibited | Uploading malware, ransomware, or other malicious code with intent to deploy (vs. analyze). |
| Prohibited | Attempting to access other users' data, credentials, or audit logs. |
| Prohibited | Reverse-engineering, decompiling, or circumventing the GuardianX application or its licensing. |
| Prohibited | Reselling, sublicensing, or white-labeling the GuardianX service without written agreement. |
| Prohibited | Running high-volume automated scans against GuardianX infrastructure itself (use the bug bounty program instead). |
| Prohibited | Spam, phishing, or any illegal activity through the platform's email or webhook features. |
| Prohibited | Uploading personal data of third parties without their consent (e.g. customer PII belonging to your end users). |
| Prohibited | Using GuardianX to train competing AI models on aggregated scan data without written consent. |
Violations may result in immediate account suspension, data deletion, and referral to law enforcement under the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023.
4. Service Level Expectations
GuardianX offers three service tiers. Uptime is measured monthly excluding scheduled maintenance (announced ≥ 48h in advance) and force-majeure events.
| Tier | Uptime | Support | Response time |
|---|---|---|---|
| Free / Trial | Best-effort | Community only | Best-effort |
| Pro | 99.5% | Email, business hours IST | ≤ 24h (Critical); ≤ 72h (High) |
| Enterprise | 99.9% with SLA credits | Dedicated CSM + Slack channel, 24×7 | ≤ 1h (Critical); ≤ 4h (High) |
Enterprise customers with custom SLAs are governed by their MSA. SLA credits are issued as service extensions, not cash refunds, and must be claimed within 30 days of the incident.
5. Your Data & Privacy
- • You retain all right, title, and interest in your User Data.
- • GuardianX processes User Data as a Data Processor for B2B customers per the DPA (incorporated by reference).
- • We will not access your User Data except to provide the Service, prevent/ address security or technical issues, or comply with legal process.
- • See our Privacy Policy for what personal data we collect and your DPDPA rights.
- • You are responsible for ensuring you have all necessary rights and consents to upload User Data (including source code and credentials) to GuardianX.
- • Upon account termination, we delete User Data within 30 days except where retention is required by law (see Privacy Policy §5).
6. Intellectual Property
- • GuardianX IP. The Service, including the GuardianX name, logo, software, documentation, and underlying AI models, is the exclusive property of GuardianX Technologies Pvt. Ltd. and is protected by Indian and international IP laws.
- • User Data. You retain all IP rights in your User Data, including uploaded source code and generated findings/patches. Granting GuardianX a limited, non-exclusive, worldwide license to process User Data solely to deliver the Service.
- • Generated findings & patches. Vulnerability findings and AI-generated patches derived from your User Data belong to you. GuardianX may use aggregated, de-identified statistics (e.g. "X% of codebases had SQL injection") to improve the Service, but never in a way that re-identifies you or your clients.
- • Open-source components. The Service uses open-source components under their respective licenses. A list is available on request.
- • Feedback. If you provide feedback or suggestions about the Service, GuardianX may use them without restriction or compensation.
- • Trademarks. "GuardianX", the GuardianX logo, and related marks are trademarks of GuardianX Technologies Pvt. Ltd. You may not use them without written permission.
7. Fees & Payment
- • Fees are described on our Pricing page or in your MSA.
- • Paid plans are billed in advance, monthly or annually as you select.
- • We use Stripe/Razorpay — your card data never touches GuardianX servers.
- • All fees are exclusive of applicable taxes (GST, etc.) which are added at checkout.
- • Refunds: annual plans are refundable on a pro-rata basis for the unused portion within the first 30 days; monthly plans are non-refundable.
- • We may change fees with 30 days' notice; existing subscribers keep the current rate until renewal.
8. Limitation of Liability
To the maximum extent permitted by law:
- • The Service is provided "as is" and "as available" without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, or non-infringement.
- • GuardianX does not warrant that the Service will find every vulnerability, that generated patches will be free of defects, or that the Service will be uninterrupted or error-free.
- • You are responsible for independently verifying all findings and patches before applying them.
- • In no event will GuardianX be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost data, or business interruption.
- • GuardianX's aggregate liability under these Terms is capped as follows:
| Tier | Liability cap |
|---|---|
| Free / Trial | ₹0 (service provided as-is) |
| Pro | Aggregate liability capped at fees paid in the 6 months preceding the claim. |
| Enterprise | Aggregate liability capped at fees paid in the 12 months preceding the claim, or ₹50,00,000 (₹50 lakh), whichever is higher. |
These caps do not apply to liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) breach of confidentiality obligations; or (d) any liability that cannot be excluded under Indian law.
9. Indemnification
You will indemnify, defend, and hold harmless GuardianX, its officers, directors, employees, and agents from any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your User Data; (b) your violation of these Terms or the Acceptable Use Policy; (c) your violation of applicable law or third-party rights (including IP rights); or (d) your unauthorized scanning of third-party systems.
10. Termination
- • By you. You may terminate your account at any time via Settings → Account → Delete. No refunds for partial billing periods on monthly plans; pro-rata refund for annual plans within 30 days of renewal.
- • By GuardianX — for cause. We may suspend or terminate your account immediately for: (a) breach of the Acceptable Use Policy; (b) non-payment after 15 days' notice; (c) violation of applicable law; (d) your insolvency or bankruptcy.
- • By GuardianX — for convenience. We may discontinue the Service or a tier with 90 days' notice, with a pro-rata refund of any prepaid fees.
- • Effect of termination. Your right to use the Service ceases. We will delete your User Data within 30 days except where retention is required by law. Sections that by their nature should survive (IP, liability, indemnification, governing law) will survive termination.
- • Account recovery. If your admin is locked out and email recovery is unavailable, see our Break-Glass Recovery runbook.
11. Disclaimers & Dispute Resolution
- • No security guarantee. GuardianX is a security-testing tool, not a security guarantee. Use of the Service does not ensure that your systems are free from vulnerabilities.
- • Independent verification. You are responsible for independently verifying all findings and patches before applying them. GuardianX is not liable for damages caused by applying an AI-generated patch.
- • Negotiation. Any dispute will first be addressed by good-faith negotiation for 30 days.
- • Arbitration. Unresolved disputes will be settled by binding arbitration administered by the Mumbai Centre for International Arbitration (MCIA), seated in Bengaluru. One arbitrator, English language, Indian law.
- • Injunctive relief. Notwithstanding the above, GuardianX may seek injunctive relief in any court of competent jurisdiction for IP violations or breach of confidentiality.
12. Governing Law & Jurisdiction
- • These Terms are governed by the laws of the Republic of India, without regard to conflict-of-law principles.
- • Subject to the arbitration clause in §11, the courts at Bengaluru, Karnataka have exclusive jurisdiction over any dispute.
- • The Information Technology Act, 2000; the Digital Personal Data Protection Act, 2023; the Bharatiya Nyaya Sanhita, 2023; and the Consumer Protection Act, 2019 apply to your use of the Service.
- • The United Nations Convention on Contracts for the International Sale of Goods (CISG) does not apply.
13. Changes to These Terms
We may update these Terms. Material changes (fees, liability, AUP, governing law) will be announced 30 days before taking effect via email + dashboard banner. Non-material changes (typographical, clarifications) take effect on publication. Continued use after the effective date constitutes acceptance. If you do not agree with material changes, you may terminate your account before the effective date for a pro-rata refund.
14. General Provisions
- • Entire agreement. These Terms + the Privacy Policy + any signed MSA/DPA constitute the entire agreement between you and GuardianX.
- • Severability. If any provision is held unenforceable, the rest remain in effect.
- • No waiver. Failure to enforce a provision is not a waiver of that provision.
- • Assignment. You may not assign these Terms without GuardianX's written consent; GuardianX may assign freely in connection with a merger, acquisition, or asset sale.
- • Force majeure. GuardianX is not liable for delays caused by acts of God, war, terrorism, pandemic, government action, or major infrastructure outage beyond our control.
- • Notices. Legal notices to GuardianX: legal@guardianx.in or by registered post to our registered office.
- • Export control. You represent that you are not located in a country subject to Indian export sanctions and will not use the Service in violation of such sanctions.
15. Contact
- • General: hello@guardianx.in
- • Legal: legal@guardianx.in
- • Privacy / DPDPA: privacy@guardianx.in
- • Security / bug bounty: security@guardianx.in (PGP — see security.txt)
- • Registered office: GuardianX Technologies Pvt. Ltd., Bengaluru, Karnataka, India.
See also: Privacy Policy · Bug Bounty Program · DPDPA Compliance