Back to Theodolite
Theodolite by vCSO.ai

Terms of Service

Governing your use of the Theodolite platform
Effective: March 2026

1. Acceptance of Terms

These Terms of Service (“Terms”) constitute a legally binding agreement between you (“User,” “you,” or “your”) and vCSO.ai, Inc. (“Company,” “we,” “us,” or “our”) governing your access to and use of the Theodolite platform, accessible at app.theodolite.io, and any associated services, APIs, and documentation (collectively, the “Service”).

By creating an account, accessing, or using the Service, you agree to be bound by these Terms and our Privacy Policy. If you are accepting on behalf of an organization, you represent that you have the authority to bind that organization to these Terms.

If you do not agree to these Terms, do not access or use the Service.

2. Description of Service

Theodolite is a cybersecurity decision-making platform that provides:

  • Vulnerability scanning and risk quantification — Import vulnerability reports and receive FAIR-based risk analysis expressed in dollar-denominated terms (Annual Loss Expectancy, Value at Risk, breach cost estimates).
  • Sensitive data discovery — Scan connected cloud storage and filesystems to identify PII, PHI, financial data, credentials, and other sensitive information, with egress cost estimation.
  • Compliance assessment — Automated infrastructure scanning against SOC 2, ISO 27001, and NIST CSF frameworks, with questionnaire-based assessments and cross-framework compliance mapping.
  • Cloud security posture management — Connect AWS, Azure, and GCP accounts to auto-discover infrastructure and scan against security best practices.

The Service is designed for CISOs, security leaders, board members, and due diligence teams. It is a decision-support tool and does not replace professional cybersecurity judgment.

3. Beta Program

Current Status: Theodolite is currently in a closed beta program. Access is by invitation only. Additional terms in the Beta Participation Agreement apply to beta participants and supplement these Terms. In the event of a conflict, the Beta Participation Agreement controls during the beta period.

Beta features may be added, modified, or removed at any time without notice. We make no guarantees regarding the availability, performance, or continued existence of any features during the beta period. The Service may contain bugs, errors, and incomplete functionality.

When Theodolite transitions to general availability, these Terms will be updated. Existing users will be notified and asked to accept the updated Terms.

4. Accounts & Access

4.1 Account Registration

You must create an account to use the Service. You agree to provide accurate, current, and complete information and to keep your account information updated.

4.2 Account Security

You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account. You must notify us immediately at security@vcso.ai if you suspect unauthorized access. We are not liable for losses caused by unauthorized use of your account.

4.3 Account Eligibility

You must be at least 18 years old and have the legal authority to enter into these Terms. During the beta period, access is restricted to invited participants.

5. License & Restrictions

5.1 License Grant

Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Service for your internal business purposes.

5.2 Restrictions

You shall not:

  • Copy, modify, adapt, translate, reverse engineer, decompile, disassemble, or create derivative works of the Service or its underlying technology
  • Sublicense, lease, rent, loan, sell, distribute, or otherwise make the Service available to any unauthorized third party
  • Use the Service to build or enhance any product or service that competes with or is substantially similar to Theodolite
  • Remove, alter, or obscure any proprietary notices, labels, or marks
  • Access the Service through automated means (bots, scrapers, crawlers) except through our documented APIs
  • Attempt to bypass any security measures, rate limits, or access controls
  • Use the Service in any manner that violates applicable law or infringes the rights of others

5.3 Reservation of Rights

All right, title, and interest in the Service, including all intellectual property rights, patents, trademarks, trade secrets, and copyrights, are and remain the exclusive property of vCSO.ai, Inc. These Terms do not grant you any ownership interest in the Service.

6. Your Data

6.1 Ownership

You retain all ownership rights in the data you submit to or process through the Service (“Your Data”). We do not claim ownership of Your Data.

6.2 License to Process

You grant us a limited, non-exclusive license to access, process, store, and display Your Data solely to the extent necessary to provide, maintain, and improve the Service. This license terminates when you delete Your Data or when your account is terminated.

6.3 Your Responsibilities

You represent and warrant that:

  • You have all necessary rights, consents, and authorizations to submit Your Data to the Service and to grant us the license in Section 6.2
  • You will only connect cloud accounts, storage systems, and data sources that you are legally authorized to access and scan
  • You will comply with all applicable data protection laws and regulations, including obtaining any required consents from data subjects whose information may be processed through the Service
  • You will not submit data that you are prohibited by law, contract, or policy from sharing with third-party services

6.4 Data Handling

Our data collection, use, and protection practices are described in our Privacy Policy, which is incorporated into these Terms by reference. For sensitive data discovery, we process data to generate classifications and findings — we do not store the underlying sensitive data itself.

6.5 Data Portability & Deletion

You may export Your Data at any time using the Service's available export features. Upon termination of your account or upon written request, we will delete Your Data within 30 days, except where retention is required by law or for legitimate purposes (such as aggregated, de-identified analytics).

7. Confidentiality

7.1 Our Confidential Information

The Service, its features, underlying technology, documentation, non-public APIs, pricing, product roadmap, risk quantification methodologies, FAIR analysis frameworks, and any other non-public information disclosed to you constitute our Confidential Information. You agree to hold it in confidence, not disclose it to third parties, and use it solely for purposes permitted by these Terms.

7.2 Your Confidential Information

We treat Your Data and account information as confidential. Our handling of your information is governed by our Privacy Policy.

7.3 Exclusions

Confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was already known to the receiving party without restriction; (c) is received from a third party without restriction; or (d) is independently developed without reference to confidential information.

8. Feedback & Intellectual Property

If you provide suggestions, ideas, bug reports, feature requests, or other feedback about the Service (“Feedback”), you irrevocably assign to us all right, title, and interest in such Feedback. We may use, modify, and incorporate Feedback into the Service or any other product without restriction, attribution, or compensation. This assignment does not apply to Your Data.

9. Acceptable Use

You agree not to use the Service to:

  • Scan, assess, or access any system, network, or environment without proper legal authorization from the owner
  • Conduct unauthorized penetration testing, vulnerability exploitation, or security assessments against third parties
  • Store, process, or transmit any data that infringes intellectual property rights or violates applicable law
  • Transmit malware, viruses, or other harmful code through the Service
  • Interfere with the integrity or performance of the Service or other users' data
  • Harass, abuse, threaten, or impersonate other users
  • Violate any applicable local, state, national, or international law or regulation

We reserve the right to investigate and take appropriate action, including suspension or termination, for violations of this section.

10. Third-Party Integrations

The Service allows you to connect third-party services, including cloud providers (AWS, Azure, GCP), project management tools (Jira), dark web monitoring services, and vulnerability scanning tools (Nessus, OpenVAS). These integrations are initiated by you and governed by the third party's own terms and policies. We are not responsible for third-party services, their availability, data practices, or any losses arising from their use.

11. Disclaimers

THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. WE SPECIFICALLY DISCLAIM ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS.

Important: Security findings, risk quantification outputs (ALE, VaR, breach cost estimates), compliance scores, and all other assessments generated by the Service are provided for informational purposes only. They do not constitute professional cybersecurity advice, legal advice, insurance recommendations, or a guarantee of your security posture. The Service is a decision-support tool — not a substitute for professional judgment. You should not rely on the Service's outputs as the sole basis for any business, security, compliance, legal, or financial decisions.

12. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL vCSO.ai, Inc., ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR AFFILIATES BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO DAMAGES FOR LOSS OF PROFITS, GOODWILL, DATA, BUSINESS INTERRUPTION, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR IN CONNECTION WITH THESE TERMS OR YOUR USE OF THE SERVICE, REGARDLESS OF THE THEORY OF LIABILITY.

OUR TOTAL AGGREGATE LIABILITY UNDER THESE TERMS SHALL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS YOU HAVE PAID TO US IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED DOLLARS ($100.00 USD).

Some jurisdictions do not allow the exclusion or limitation of certain damages. In such jurisdictions, our liability shall be limited to the maximum extent permitted by law.

13. Indemnification

You agree to indemnify, defend, and hold harmless vCSO.ai, Inc. and its officers, directors, employees, agents, and affiliates from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to:

  • Your use of the Service in violation of these Terms
  • Your breach of any representation or warranty herein
  • Your violation of applicable law or regulation
  • Your unauthorized scanning or access of third-party systems, networks, or data
  • Any dispute between you and a third party arising from your use of the Service
  • Your Data, including any claim that Your Data infringes the rights of a third party

14. Termination

14.1 By You

You may terminate your account at any time by contacting us or using the account deletion feature in the Service. Upon termination, your right to access the Service ceases immediately.

14.2 By Us

We may suspend or terminate your access to the Service at any time, with or without cause, with or without notice. We will endeavor to provide reasonable notice where practicable, except where we believe immediate termination is necessary (such as for violations of Section 9 or a security incident).

14.3 Effect of Termination

Upon termination: (a) your license to use the Service terminates immediately; (b) you must cease all use of the Service; (c) you must delete or destroy all copies of Confidential Information in your possession; (d) we will delete Your Data in accordance with Section 6.5 and our Privacy Policy.

14.4 Survival

Sections 5.3 (Reservation of Rights), 7 (Confidentiality), 8 (Feedback & IP), 11 (Disclaimers), 12 (Limitation of Liability), 13 (Indemnification), 15 (Governing Law), and 16 (General Provisions) survive any termination or expiration of these Terms.

15. Governing Law & Dispute Resolution

15.1 Governing Law

These Terms shall be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of laws principles.

15.2 Dispute Resolution

Any dispute arising out of or relating to these Terms or the Service shall be resolved exclusively in the state or federal courts located in San Francisco County, California. You consent to the personal jurisdiction of such courts.

15.3 Equitable Relief

Nothing in this section shall prevent either party from seeking injunctive or other equitable relief in any court of competent jurisdiction to prevent irreparable harm pending resolution of a dispute.

16. General Provisions

16.1 Entire Agreement

These Terms, together with the Privacy Policy and any applicable Beta Participation Agreement, constitute the entire agreement between you and Company regarding the Service and supersede all prior agreements and understandings.

16.2 Amendments

We reserve the right to modify these Terms at any time. We will notify you of material changes by posting the updated Terms on this page, updating the “Effective” date, and providing notice through the Service or by email. Your continued use of the Service after the effective date of any changes constitutes acceptance. If you do not agree with the revised Terms, you must stop using the Service.

16.3 Severability

If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

16.4 Waiver

The failure of either party to enforce any provision of these Terms shall not constitute a waiver of that provision or the right to enforce it at a later time.

16.5 Assignment

You may not assign or transfer these Terms or any rights hereunder without our prior written consent. We may assign these Terms without restriction, including in connection with a merger, acquisition, or sale of assets.

16.6 Notices

We may provide notices to you through the Service, by email to the address associated with your account, or by posting on this page. You may provide notices to us at the contact information below.

16.7 Electronic Acceptance

You acknowledge that clicking “I Accept” or similar acknowledgment constitutes your electronic signature and is legally binding. Your acceptance is logged with a timestamp, agreement version, and device information to create an enforceable audit trail.

17. Contact

Questions about these Terms of Service should be directed to:

vCSO.ai, Inc.

Email: account@vcso.ai

Website: www.vcso.ai