Last updated: December 16, 2025
1. Acceptance of Terms
By accessing or using Vigilbase's website, services, or products (collectively, the "Services"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Services on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms.
If you do not agree to these Terms, you may not access or use the Services. We reserve the right to modify these Terms at any time. We will notify you of material changes at least 30 days in advance via email or through the Services. Your continued use of the Services after any changes constitutes acceptance of the modified Terms.
2. Definitions
For the purposes of these Terms, the following definitions apply:
- "Customer" or "You" means the individual or entity accessing or using the Services
- "Customer Content" means any data, information, or materials you submit, upload, or transmit through the Services
- "Personal Data" means any information relating to an identified or identifiable natural person as defined under applicable data protection laws
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion
- "Data Controller" means the entity that determines the purposes and means of Processing Personal Data
- "Data Processor" means the entity that Processes Personal Data on behalf of a Data Controller
- "Sub-processor" means any third party engaged by Vigilbase to Process Personal Data
- "Data Subject" means an identified or identifiable natural person whose Personal Data is Processed
- "Supervisory Authority" means an independent public authority responsible for monitoring the application of data protection laws
3. Description of Services
Current engagements may include the following, only where specified in the applicable service agreement or order form:
- The Vigilbase Platform, the cybersecurity operating system, with supported integrations, investigations, authorized actions, and verification
- Cloudflare Enterprise licensing and guided deployment
- Vigilbase Shield managed website protection, a pre-Enterprise plan on Cloudflare, within the purchased scope
- Managed Cloudflare operations within the agreed controls, permissions, support coverage, and escalation responsibilities
- Security consulting and incident work expressly included in the engagement
The specific services provided to you will be outlined in your service agreement or order form. Services may be modified, updated, or discontinued at our discretion with reasonable notice.
4. Account Registration and Security
To access certain Services, you may be required to create an account. You agree to:
- Provide accurate, current, and complete information during registration
- Maintain and promptly update your account information
- Keep your login credentials secure and confidential
- Implement appropriate access controls and authentication measures
- Notify us immediately of any unauthorized access or security breach
- Accept responsibility for all activities that occur under your account
- Not share account credentials with unauthorized individuals
5. Acceptable Use
You agree to use the Services only for lawful purposes and in accordance with these Terms. You agree not to:
- Use the Services for any illegal or unauthorized purpose
- Violate any applicable laws, regulations, or third-party rights
- Process Personal Data in violation of applicable data protection laws
- Attempt to gain unauthorized access to any systems or networks
- Interfere with or disrupt the integrity or performance of the Services
- Transmit any malware, viruses, or other harmful code
- Reverse engineer, decompile, or disassemble any part of the Services
- Use the Services to conduct any form of attack against third parties
- Resell or redistribute the Services without our written consent
- Use the Services to store or transmit content that violates third-party intellectual property rights
- Engage in any activity that could damage, disable, or impair the Services
6. Payment Terms
For paid Services, the following terms apply:
- Fees are as specified in your order form or service agreement
- Payment is due according to the billing cycle specified in your agreement
- All fees are non-refundable unless otherwise stated in your agreement
- We may suspend Services for overdue payments after providing 14 days' notice
- You are responsible for all applicable taxes, duties, and levies
- Prices may be adjusted with 30 days' notice before your next renewal
- Disputed charges must be raised within 30 days of the invoice date
7. Intellectual Property
All intellectual property rights in the Services, including software, documentation, trademarks, trade secrets, methodologies, and content, remain the exclusive property of Vigilbase or our licensors. These Terms do not grant you any rights to use our trademarks, logos, or brand features without prior written consent.
You retain ownership of any data or content you submit through the Services ("Customer Content"). By using the Services, you grant us a limited, non-exclusive license to use, process, and store your Customer Content solely to provide the Services to you and as necessary to comply with applicable laws.
8. Confidentiality
Both parties agree to maintain the confidentiality of any proprietary or sensitive information exchanged during the course of the service relationship. Our Confidentiality Policy provides additional details on how we handle confidential information.
9. Data Protection and Privacy
We are committed to protecting your privacy and Personal Data. Our collection, use, and protection of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference.
9.1 Roles and Responsibilities
With respect to Personal Data processed in connection with the Services:
- Where you determine the purposes and means of Processing, you act as the Data Controller and Vigilbase acts as the Data Processor
- Where Vigilbase determines the purposes and means of Processing (e.g., for our own business operations), Vigilbase acts as the Data Controller
- Each party shall comply with its respective obligations under applicable data protection laws
9.2 Data Processing Agreement
Where Vigilbase processes Personal Data on your behalf, the parties agree that:
- Vigilbase will Process Personal Data only on your documented instructions, unless required by applicable law
- Vigilbase will ensure that personnel authorized to Process Personal Data have committed to confidentiality obligations
- Vigilbase will implement appropriate technical and organizational security measures
- Vigilbase will assist you in responding to Data Subject requests and compliance obligations
- Upon termination, Vigilbase will delete or return all Personal Data as directed, unless retention is required by law
- Vigilbase will make available all information necessary to demonstrate compliance and allow for audits
9.3 Sub-processors
You authorize Vigilbase to engage Sub-processors to Process Personal Data, subject to the following conditions:
- Vigilbase will maintain an up-to-date list of Sub-processors, available at our Trust Center
- Vigilbase will notify you of any intended changes to Sub-processors at least 30 days in advance
- You may object to the appointment of a new Sub-processor on reasonable grounds within 14 days of notification
- Vigilbase will impose data protection obligations on Sub-processors that are no less protective than those in these Terms
- Vigilbase remains fully liable for the acts and omissions of its Sub-processors
10. GDPR Compliance
Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to the Processing of Personal Data, the following provisions shall apply:
10.1 Lawful Basis for Processing
Vigilbase processes Personal Data based on one or more of the following lawful bases:
- Contract Performance: Processing necessary for the performance of our Services
- Legitimate Interests: Processing necessary for our legitimate business interests, where not overridden by your rights
- Legal Obligation: Processing necessary for compliance with legal obligations
- Consent: Where you have given explicit consent for specific Processing activities
10.2 Data Subject Rights
We respect and facilitate the exercise of Data Subject rights under GDPR, including:
- Right of Access: The right to obtain confirmation of Processing and access to Personal Data
- Right to Rectification: The right to correct inaccurate or incomplete Personal Data
- Right to Erasure: The right to request deletion of Personal Data ("right to be forgotten")
- Right to Restriction: The right to restrict Processing in certain circumstances
- Right to Data Portability: The right to receive Personal Data in a structured, machine-readable format
- Right to Object: The right to object to Processing based on legitimate interests or for direct marketing
- Rights Related to Automated Decision-Making: The right not to be subject to solely automated decisions with legal or significant effects
- Right to Withdraw Consent: The right to withdraw consent at any time, without affecting the lawfulness of prior Processing
To exercise these rights, please contact us at legal+dpo@vigilbase.com. We will respond to requests within 30 days, or as required by applicable law.
10.3 Data Protection Impact Assessments
Where required under GDPR Article 35, Vigilbase will assist you in conducting Data Protection Impact Assessments (DPIAs) by providing relevant information about our Processing activities and security measures.
10.4 Data Breach Notification
In the event of a Personal Data breach affecting your data:
- Vigilbase will notify you without undue delay, and in any event within 72 hours of becoming aware of the breach
- Notification will include the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed
- Vigilbase will cooperate with you and provide reasonable assistance for any required notifications to Supervisory Authorities or Data Subjects
- Vigilbase will document all breaches, including facts, effects, and remedial actions taken
10.5 Records of Processing Activities
Vigilbase maintains records of Processing activities as required under GDPR Article 30, including:
- Categories of Processing carried out on behalf of each Customer
- International transfers and safeguards in place
- General description of technical and organizational security measures
11. International Data Transfers
Vigilbase may transfer Personal Data internationally in connection with the Services. We ensure that all international transfers comply with applicable data protection laws through the following mechanisms:
11.1 Transfer Mechanisms
- Standard Contractual Clauses (SCCs): We utilize EU Commission-approved Standard Contractual Clauses for transfers from the EEA to third countries
- UK International Data Transfer Agreement (IDTA): For transfers from the UK, we implement the UK IDTA or UK Addendum to the EU SCCs
- Adequacy Decisions: We may transfer data to countries deemed adequate by relevant authorities
- Supplementary Measures: Where necessary, we implement additional technical, organizational, and contractual safeguards
11.2 Transfer Impact Assessments
Vigilbase conducts Transfer Impact Assessments to evaluate the laws and practices of destination countries and implements supplementary measures where necessary to ensure an essentially equivalent level of protection.
12. Additional Compliance Frameworks
Vigilbase is committed to compliance with multiple regulatory frameworks. The following provisions apply where relevant:
12.1 California Consumer Privacy Act (CCPA/CPRA)
For California residents, Vigilbase complies with the California Consumer Privacy Act and California Privacy Rights Act:
- We do not sell Personal Information as defined under CCPA
- We do not share Personal Information for cross-context behavioral advertising
- California residents have the right to know, delete, correct, and opt-out of certain Processing
- We honor Global Privacy Control (GPC) signals
- Where Vigilbase is a "Service Provider" under CCPA, we Process Personal Information only for the purposes specified in our agreement
12.2 Other US State Privacy Laws
Vigilbase complies with applicable state privacy laws including:
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Utah Consumer Privacy Act (UCPA)
- Other state laws as they become effective
12.3 UK GDPR and Data Protection Act 2018
For Processing subject to UK data protection law, Vigilbase complies with the UK GDPR and Data Protection Act 2018, including specific provisions for law enforcement processing and intelligence services processing where applicable.
12.4 Swiss Data Protection
For Processing subject to Swiss data protection law, Vigilbase complies with the Swiss Federal Act on Data Protection (FADP) and implements appropriate transfer mechanisms for international transfers.
12.5 Brazil LGPD
For Processing subject to Brazil's Lei Geral de Proteção de Dados (LGPD), Vigilbase ensures compliance with applicable requirements, including Data Subject rights and international transfer provisions.
12.6 South Africa POPIA
For Processing subject to South Africa's Protection of Personal Information Act (POPIA), Vigilbase complies with applicable requirements as both a responsible party and operator.
12.7 Industry-Specific Compliance
Vigilbase supports compliance with various industry-specific regulations and maintains relevant certifications. Our current certifications, audit reports, and compliance documentation are kept up to date and available at our Trust Center.
13. Security Measures
Vigilbase implements comprehensive technical and organizational security measures to protect Personal Data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication and role-based access controls
- Regular security assessments and penetration testing
- 24/7 security monitoring and incident response capabilities
- Employee security awareness training and background checks
- Physical security controls at data centers
- Business continuity and disaster recovery procedures
- Vendor security assessment program
- Regular security audits and certifications
Details of our security practices are available at our Trust Center.
14. Service Level and Support
We strive to provide reliable, high-quality Services. Specific service levels, uptime commitments, and support terms may be outlined in your service agreement. We will use commercially reasonable efforts to:
- Maintain the availability and performance of the Services
- Provide timely support and assistance
- Notify you of planned maintenance at least 48 hours in advance
- Respond promptly to security incidents
- Maintain service availability of at least 99.9% (excluding scheduled maintenance)
15. Disclaimer of Warranties
THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
While we implement industry-standard security measures, we do not warrant that the Services will be uninterrupted, error-free, or completely secure. No security solution can guarantee absolute protection against all threats.
THIS DISCLAIMER DOES NOT AFFECT ANY WARRANTIES THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW, INCLUDING CONSUMER PROTECTION LAWS.
16. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, VIGILBASE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR BUSINESS OPPORTUNITIES ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES.
OUR TOTAL LIABILITY FOR ANY CLAIMS ARISING UNDER THESE TERMS SHALL NOT EXCEED THE GREATER OF (A) THE FEES PAID BY YOU TO VIGILBASE IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED US DOLLARS ($100).
NOTHING IN THESE TERMS SHALL LIMIT OR EXCLUDE LIABILITY FOR: (A) DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE; (B) FRAUD OR FRAUDULENT MISREPRESENTATION; (C) BREACH OF DATA PROTECTION OBLIGATIONS WHERE SUCH LIABILITY CANNOT BE LIMITED BY LAW; OR (D) ANY OTHER LIABILITY THAT CANNOT BE LIMITED OR EXCLUDED BY APPLICABLE LAW.
17. Indemnification
You agree to indemnify, defend, and hold harmless Vigilbase and its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in any way connected with:
- Your use of the Services
- Your violation of these Terms
- Your violation of any applicable laws, including data protection laws
- Your violation of any third-party rights
- Your Customer Content
- Any claim that your use of the Services infringes third-party intellectual property rights
Vigilbase will indemnify you against claims that the Services infringe third-party intellectual property rights, subject to the limitations in these Terms.
18. Term and Termination
These Terms remain in effect until terminated. Either party may terminate the service relationship according to the terms of your service agreement. We may suspend or terminate your access to the Services immediately if:
- You materially breach these Terms
- Your use of the Services poses a security risk to us or others
- Required by law, regulation, or legal process
- Your account is overdue for more than 30 days
- You become insolvent or subject to bankruptcy proceedings
18.1 Effects of Termination
Upon termination:
- Your right to use the Services ceases immediately
- You must pay all outstanding fees within 30 days
- We will provide you with a reasonable period (typically 30 days) to retrieve your Customer Content
- After the retrieval period, we will delete your Customer Content unless retention is required by law
- Personal Data will be handled in accordance with Section 9.2
18.2 Survival
The following provisions shall survive termination: Definitions, Intellectual Property, Confidentiality, Data Protection (to the extent applicable to retained data), Limitation of Liability, Indemnification, Governing Law, and General Provisions.
19. Governing Law and Dispute Resolution
These Terms shall be governed by and construed in accordance with the laws of the State of Wyoming, United States, without regard to its conflict of law provisions.
19.1 Dispute Resolution
Any disputes arising out of or relating to these Terms shall first be attempted to be resolved through good-faith negotiations between the parties. If the dispute cannot be resolved through negotiations within 30 days, either party may pursue resolution through the courts.
19.2 Jurisdiction
For disputes that proceed to litigation, the parties consent to the exclusive jurisdiction of the state and federal courts located in Wyoming.
19.3 European Union Customers
If you are a consumer in the European Union, you may also be entitled to bring proceedings in the courts of your country of residence. Nothing in these Terms affects your rights as a consumer under mandatory applicable laws.
20. General Provisions
Entire Agreement: These Terms, together with your service agreement, any Data Processing Agreement, and our policies, constitute the entire agreement between you and Vigilbase regarding the Services and supersede all prior agreements.
Severability: If any provision of these Terms is held to be unenforceable, the remaining provisions shall continue in full force and effect. The unenforceable provision shall be modified to the minimum extent necessary to make it enforceable.
Waiver: Our failure to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision.
Assignment: You may not assign or transfer these Terms without our prior written consent. We may assign our rights and obligations under these Terms in connection with a merger, acquisition, or sale of assets, or to an affiliate.
Force Majeure: Neither party shall be liable for any failure or delay in performance due to circumstances beyond its reasonable control, including natural disasters, war, terrorism, riots, pandemics, government actions, or failures of third-party services.
Notices: All notices under these Terms shall be in writing and sent to the addresses specified in your service agreement. Notices may be sent by email for operational matters.
Independent Contractors: The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.
Third-Party Beneficiaries: These Terms do not confer any rights on third parties, except that our Sub-processors may enforce provisions related to limitation of liability.
21. Contact Information
If you have any questions about these Terms of Service, please contact us at:
EMAIL: legal@vigilbase.com
PHONE: +1 (855) 458-4445
ADDRESS: Vigilbase LLC
Legal Department
1908 Thomes Ave #12112
Cheyenne, WY 82001
United States
Data Protection Inquiries: For questions related to data protection and privacy, contact our Data Protection team at legal+dpo@vigilbase.com.
EU Representative: For inquiries from EEA Data Subjects regarding GDPR compliance, please contact us at legal+gdpr@vigilbase.com.