Pistos
Compliance Sentinel

Terms of Service

Effective date: August 10, 2026
← Back

These Terms of Service ("Terms") are a binding agreement between Pistos Information Protection LLC ("Pistos," "we," "us") and the organization and individuals who access the Pistos Compliance Sentinel platform ("PCS," the "Service"). By accessing or using the Service, you agree to these Terms. If you use the Service on behalf of an organization, you represent that you are authorized to bind that organization, and "you" refers to that organization.

1.The Service

PCS is a cybersecurity compliance management platform. It provides tools to build and maintain a security program, including risk assessments, evidence collection, written policies, security awareness training, technical assessment ("Scopein") tooling, incident-response and disaster-recovery planning, inventories, and reporting. The Service is made available to organizations and their authorized users as described in these Terms. We may add, change, or remove features over time.

2.Accounts and access

Accounts are provisioned by Pistos or by a client administrator. You agree to provide accurate account information, to keep it current, and to safeguard your credentials. You are responsible for all activity that occurs under your account. Each account is for a single, named individual and may not be shared. Where multi-factor authentication is required, you agree to enroll and maintain it. Notify us promptly at help@pistosip.com of any unauthorized use of your account or credentials.

3.Roles and permissions

The Service assigns each account a role — such as operator (vCISO), local administrator, end user, managed service provider, or read-only auditor — that determines what you may view and do. You agree to use only the access granted to your role and not to attempt to access data, agencies, or functions outside it.

4.Acceptable use

You agree not to, and not to permit anyone to:

5.Assessment and scanning tools

The Service includes assessment tools (including the Scopein family of scanners) that examine systems, cloud tenants, and endpoints to gather compliance evidence.

You are responsible for authorization to scan. You represent and warrant that you own, or are duly authorized to permit the assessment of, every system, account, network, and tenant you run these tools against, and that you will run them only against systems you are authorized to test. You are responsible for obtaining any consents required from third parties, personnel, or providers. Pistos is not responsible for scans you run against systems you were not authorized to assess.

6.Your data

"Customer Data" means the information you and your users submit to the Service — including evidence files, inventories, plans, assessment entries, notes, and personal information about your personnel. As between you and Pistos, you retain all rights to Customer Data. You grant Pistos a limited, non-exclusive license to host, store, process, and transmit Customer Data as necessary to provide, secure, maintain, and improve the Service, and as described in our Privacy Statement. You are responsible for the accuracy and legality of Customer Data and for having the right to provide it, including any personal information about your staff.

7.Privacy and security

We process personal information as described in our Privacy Statement. We apply administrative and technical safeguards designed to protect Customer Data, including encryption in transit and at rest, access controls, and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for the security of your own credentials, devices, and configurations.

8.Confidentiality

Each party may receive information from the other that is confidential. Each party agrees to use the other's confidential information only to exercise its rights and perform its obligations under these Terms, and to protect it with reasonable care. This does not apply to information that is public through no fault of the receiving party, already known to it, independently developed, or lawfully received from a third party.

9.Intellectual property

The Service, including its software, the Scopein assessment tools, methodologies, control templates, policy and training content, designs, and all related intellectual property, is owned by Pistos and its licensors and is protected by law. Subject to these Terms, Pistos grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Service for your internal compliance purposes during the term. No rights are granted except as expressly stated. You may export or download materials the Service makes available to you for your own compliance use; you may not redistribute Pistos templates or content as your own product.

10.Compliance disclaimer

PCS is a tool, not a guarantee of compliance, and not legal advice. PCS helps you build, document, and manage a cybersecurity compliance program. Using it does not guarantee that you comply with any law, regulation, or framework — including NY DFS 23 NYCRR 500, HIPAA, CMMC, the GLBA Safeguards Rule, PCI DSS, or NIST standards — and does not guarantee any particular result in an audit, examination, filing, or enforcement action. Scores, determinations, reports, and other outputs are decision aids, not legal or regulatory conclusions. You are solely responsible for your own compliance obligations and determinations, and should obtain independent legal advice where appropriate.

11.Availability and third-party services

We aim to keep the Service available and reliable, but we do not guarantee that it will be uninterrupted, timely, or error-free. We may perform maintenance, and we may modify or discontinue features. The Service relies on third-party providers (for example, hosting and email delivery); their availability is outside our control, and we are not responsible for third-party services or any sites they link to.

12.Disclaimer of warranties

The Service is provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranty regarding the accuracy, completeness, or results of the Service. Some jurisdictions do not allow the exclusion of certain warranties, so parts of this section may not apply to you.

13.Limitation of liability

To the maximum extent permitted by law, Pistos will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, or goodwill, arising out of or relating to the Service or these Terms, even if advised of the possibility. To the maximum extent permitted by law, Pistos's total aggregate liability arising out of or relating to the Service or these Terms will not exceed the greater of the amounts you paid to Pistos for the Service in the twelve months before the claim, or US$100.

14.Indemnification

You agree to defend, indemnify, and hold harmless Pistos and its officers, employees, and agents from and against any claims, damages, liabilities, and expenses (including reasonable legal fees) arising out of your use of the Service in violation of these Terms, your Customer Data, or your assessment or scanning of systems you were not authorized to test.

15.Suspension and termination

We may suspend or terminate your access if you breach these Terms, if your use poses a security or legal risk, or if required by law. You may stop using the Service at any time. On termination, your right to access the Service ends. You may request an export or deletion of your Customer Data by contacting us; after a reasonable period following termination, we may delete Customer Data in the ordinary course, subject to any legal retention obligations. Sections that by their nature should survive termination — including intellectual property, disclaimers, limitation of liability, indemnification, and governing law — will survive.

16.Changes to these Terms

We may update these Terms from time to time. When we do, we will revise the effective date above, and material changes will be reflected on this page. Your continued use of the Service after an update means you accept the revised Terms.

17.Governing law

These Terms are governed by the laws of the State of New York, without regard to its conflict-of-laws rules. The state and federal courts located in New York will have exclusive jurisdiction over any dispute arising out of or relating to these Terms or the Service, and the parties consent to venue there. Nothing in these Terms limits either party's ability to seek injunctive relief to protect its intellectual property or confidential information.

18.General

These Terms, together with the Privacy Statement and any separate written agreement between you and Pistos, are the entire agreement regarding the Service. If a separate signed agreement between you and Pistos conflicts with these Terms, that agreement controls. If any provision is found unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. Neither party is liable for delays or failures caused by events beyond its reasonable control.

19.Contact

Questions about these Terms:
Pistos Information Protection LLC
help@pistosip.com

Pistos Compliance Sentinel · Terms of Service · Effective August 10, 2026