Terms of Service
Effective date: August 16, 2026 · Last updated: August 16, 2026
These Terms govern your use of the Secontinuum website and of Vynnn, our cloud-hosted SIEM and SOC automation platform. In short: you must be an authorized representative of a business to open an account; you own your data and are responsible for having the right to send it to us; we own the platform; AI output is assistive and needs human review before you act on it; fees are set in your Order Form; our liability is capped; and either side can end the relationship as described below.
This summary is for convenience only — the full Terms below are what applies.
1.Agreement and acceptance
These Terms of Service (the “Terms”) are an agreement between Secontinuum Private Limited, a company incorporated under the laws of India with its registered office at B-1204, Block B, 12th Floor, Aparna Cyberlife, Lingampalli, Serilingampally, K.V. Rangareddy, Telangana, India – 500019 (“Secontinuum”, “we”, “us”), and the organization that accepts them (“Customer”, “you”). Vynnn is a product of Secontinuum.
These Terms cover both (a) visitors to our public websites, including www.secontinuum.com and vynnn.com, and (b) customers and users of the Vynnn service. If you and Secontinuum have signed a separate written agreement covering the Service, that agreement prevails over these Terms to the extent of any conflict.
By creating an account, signing an Order Form, or using the Service, you confirm that you are acting on behalf of an organization, that you are authorized to bind that organization, and that you are at least 18 years old. The Service is offered to businesses and their authorized security staff only; it is not a consumer service, and we do not offer accounts to children.
2.Definitions
- “Service”
- Vynnn, the multi-tenant, cloud-hosted SIEM and SOC automation platform operated by Secontinuum, including its consoles, ingest endpoints, host agents, connectors, APIs, and documentation.
- “Customer Data”
- Data that Customer or its Users submit to the Service or authorize the Service to collect, including security logs and telemetry, detections, investigation content, custom detection rules, and related configuration.
- “Account Data”
- Data relating to the Customer relationship itself, such as account registration details, User profile information, billing records, and support communications.
- “Tenant”
- The logically isolated environment provisioned for a Customer within the Service.
- “User”
- An individual authorized by Customer to access the Service under Customer’s Tenant, such as a security analyst or administrator.
- “Subprocessor”
- A third party engaged by Secontinuum to process data in connection with providing the Service.
- “Order Form”
- An ordering document or online purchase flow agreed between Customer and Secontinuum that specifies the Service plan, fees, and any special terms.
3.The Service, accounts, and tenants
Vynnn ingests security telemetry that Customer chooses to send — for example AWS CloudTrail events, Linux and Windows host logs collected by our agents, Microsoft Defender and Microsoft 365 signals, and events forwarded from Splunk — evaluates it against detection rules in near real time, and runs an AI agent pipeline that verifies, investigates, and can propose or assist remediation of security incidents. Supported sources evolve over time.
Accounts and credentials
Users sign in with individual credentials. Customer is responsible for maintaining the confidentiality of all credentials, API keys, agent enrollment tokens, and cloud connector roles associated with its Tenant, and for all activity under them. Customer must notify us promptly at contact@secontinuum.com of any suspected unauthorized use of its account.
Tenant administration
Customer designates administrators who control its Tenant: they invite and remove Users, assign roles and permissions (including who may view raw logs and export data), configure connectors and retention options, and manage API keys and webhooks. Customer is responsible for its administrators’ and Users’ actions in the Service.
4.Orders, fees, taxes, and trials
Fees, billing periods, usage limits, and any free trial terms are as set out in the applicable Order Form or otherwise agreed with us in writing. Unless the Order Form says otherwise: fees are payable in advance, payment obligations are non-cancellable, and fees are non-refundable except where required by law or expressly agreed.
Fees are exclusive of taxes. Customer is responsible for all applicable taxes, levies, and duties (including GST and any withholding taxes), other than taxes on our income. If Customer fails to pay undisputed fees when due, we may suspend the Service after written notice and a reasonable opportunity to pay, and may charge interest as permitted by law.
5.Acceptable use and prohibited activities
Customer Data warranty
Customer warrants that it has all rights, consents, and lawful bases needed to collect the telemetry it sends to the Service — including telemetry about its employees, contractors, and systems — and to have us process it as described in these Terms and our Privacy Statement. Customer must not upload data it has no right to process, and must comply with its own employment, privacy, and sector-specific laws.
Prohibited activities
Customer and its Users must not:
- use the Service to attack, scan, or monitor third-party systems without authorization, or otherwise to commit or facilitate unlawful activity;
- attempt to probe, bypass, or break tenant isolation or any other security control of the Service;
- reverse engineer, decompile, or disassemble the Service except to the extent such restriction is prohibited by applicable law;
- resell, sublicense, or provide the Service to third parties except under a partner agreement with us;
- use the Service or its outputs to develop a competing product or to train a competing model by systematically extracting outputs;
- intentionally overload the ingest pipeline or interfere with the integrity or performance of the Service;
- use the Service to distribute malware to third-party systems. Analyzing malware samples within Customer’s own lab environments and telemetry for detection purposes is permitted.
6.Agents, cloud roles, and third-party consents
The Service receives data through customer-installed host agents, cloud connectors (for example AWS IAM role assumption), Microsoft admin-consent OAuth, authenticated HTTP ingest, and forwarders that Customer configures. By installing an agent, granting a role, approving an OAuth consent, or configuring a forwarder, Customer authorizes us to pull or receive data from those systems on its behalf for the purpose of providing the Service, and confirms it is entitled to grant that authorization.
Customer is responsible for the scope of access it grants and may revoke it at any time through the relevant system (for example by removing the agent, role, or consent). Customer is also responsible for the destinations it configures, such as outbound webhook URLs it chooses to receive detections and alerts.
7.AI features and human review
The Service includes AI-driven SOC agents that analyze telemetry and detections, produce verdicts and investigation summaries, and recommend or assist remediation. To provide these features, relevant Customer Data — such as telemetry excerpts, detections, and analyst context — may be processed by our third-party AI model provider as a Subprocessor.
AI output is assistive. It may be incomplete or incorrect, and it is not professional, legal, or forensic advice. Customer remains responsible for reviewing AI-generated analyses and recommendations before acting on them, and for all remediation actions taken in its environment. We do not use the Service to make solely automated decisions with legal or similarly significant effects about individuals.
We do not use Customer Data — security logs, telemetry, detections, or investigation content — to train AI models. We may use operational data about our own agents’ behavior (actions taken, playbook outcomes, performance and feedback signals) to improve the Service.
8.Confidentiality
Each party may receive confidential information of the other in connection with the Service. The receiving party must use it only to perform under these Terms, protect it with at least reasonable care, and not disclose it except to employees, advisors, and Subprocessors who need it and are bound by confidentiality obligations. These obligations do not apply to information that is or becomes public without breach, was lawfully known before disclosure, is independently developed, or must be disclosed by law (with notice to the other party where legally permitted).
9.Security and incident notice
We maintain administrative, technical, and organizational safeguards designed to protect Customer Data, including multi-tenant isolation, encryption in transit (TLS), role-based access control, audit logging of privileged actions, secrets management, and least-privilege access within our infrastructure. Platform staff may access Tenants only for operations, support, and abuse or security response.
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Customer Data, we will notify Customer without undue delay and provide information reasonably available to us to help Customer meet its own notification obligations.
We do not currently hold SOC 2, ISO 27001, or similar certifications. We are actively working toward SOC 2 and other compliance certifications.
10.Data protection and roles
For Customer Data, Customer is typically the controller and Secontinuum acts as a processor on Customer’s documented instructions. For Account Data, Secontinuum is the controller. Details are in our Privacy Statement. A Data Processing Agreement (DPA) is available on request at contact@secontinuum.com; where a DPA is executed, it forms part of the agreement and prevails over these Terms for data-protection matters.
11.Intellectual property and licenses
What we own
Secontinuum and its licensors own the Service and all related intellectual property, including the platform software, the detection rule packs we ship, our models, prompts, and agent designs, and the content of our websites. No rights are granted except as expressly stated in these Terms.
What you own
Customer owns Customer Data, including its custom detection rules. Customer grants us a limited, non-exclusive license to host, process, transmit, back up, and display Customer Data as needed to provide the Service and to maintain and improve its reliability and security. We do not use Customer Data to train AI models, as stated in Section 7.
Feedback
If Customer or its Users provide feedback or suggestions, we may use them without restriction or obligation, without identifying the source.
12.Third-party services
The Service interoperates with third-party platforms and providers, including our cloud hosting and AI model providers, Microsoft, Splunk, and customer-configured destinations such as webhooks. Those providers’ services are governed by their own terms, and we are not responsible for their acts, omissions, or outages. Connecting a third-party system to the Service is Customer’s choice and is subject to Customer’s agreements with that provider.
13.Availability, maintenance, and beta features
We work to keep the Service available, but do not commit to a specific uptime level unless one is stated in an Order Form or SLA. We may perform maintenance, and will aim to schedule planned maintenance to minimize disruption.
We may offer beta, preview, or early-access features, which are provided as is, may change or be withdrawn at any time, and may be subject to additional terms. Beta features are excluded from any availability or support commitments.
14.Warranties and disclaimers
Each party warrants that it has the authority to enter into these Terms. EXCEPT AS EXPRESSLY STATED IN THESE TERMS OR AN ORDER FORM, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE”, AND WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL DETECT EVERY THREAT, THAT AI OUTPUT WILL BE ACCURATE OR COMPLETE, OR THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.
15.Indemnification
By Customer
Customer will defend and indemnify Secontinuum against third-party claims arising from Customer Data, Customer’s use of the Service in breach of these Terms, or Customer’s violation of law, and will pay damages finally awarded or agreed in settlement for such claims.
By Secontinuum
We will defend and indemnify Customer against third-party claims that the unmodified Service, used as permitted, infringes that third party’s intellectual property rights, and will pay damages finally awarded or agreed in settlement. If such a claim arises, we may modify the Service, procure rights, or — if neither is reasonable — terminate the affected Service and refund prepaid unused fees. This is Customer’s exclusive remedy for infringement claims.
The indemnified party must give prompt notice, allow the indemnifying party to control the defense, and reasonably cooperate.
16.Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, OR DATA; AND (B) EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS IS LIMITED TO THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM.
These limits do not apply to: a party’s willful misconduct or fraud; Customer’s payment obligations; our indemnification obligations under Section 15; a party’s breach of confidentiality obligations; or data-protection breaches caused by us.
17.Suspension, term, and termination
These Terms apply from Customer’s first acceptance and continue while Customer has an active account or Order Form. Customer may close its account at any time. Either party may terminate for material breach not cured within 30 days of written notice.
We may suspend or restrict the Service (in whole or for a Tenant) where reasonably necessary due to non-payment, a breach of the acceptable-use rules, legal risk, or a security threat to the Service or other customers. We will give notice and limit the scope and duration of a suspension where practicable.
On termination or expiry, Customer’s access ends and we will delete or, where requested and technically feasible, return Customer Data within a reasonable period after termination, except for backups (which expire on their normal cycle) and data we must retain for legal reasons. Sections that by their nature should survive — including confidentiality, IP, liability limits, and governing law — survive termination.
18.Export controls and sanctions
Customer must comply with applicable export control and sanctions laws, and warrants that it is not located in, and will not permit the Service to be accessed from, embargoed jurisdictions or by sanctioned or denied parties, except as permitted by law.
19.Publicity
We may identify Customer by name and logo as a customer of the Service in our marketing materials. Customer may opt out at any time by emailing contact@secontinuum.com, and we will stop new uses within a reasonable period. Any case study or detailed reference requires Customer’s prior consent.
20.Changes to these Terms
We may update these Terms from time to time. For material changes we will give notice via the website and/or email before the new version takes effect. Continued use of the Service after the effective date constitutes acceptance. If Customer objects to a material adverse change, it may terminate the affected Service by notice before the change takes effect and receive a pro-rata refund of prepaid unused fees.
21.General provisions
- Assignment. Neither party may assign these Terms without the other’s consent, except to an affiliate or in connection with a merger, acquisition, or sale of substantially all assets, with notice.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, other than payment obligations.
- Entire agreement. These Terms, together with any Order Forms, the Privacy Statement, and an executed DPA, are the entire agreement about the Service and supersede prior discussions.
- Severability; waiver. If a provision is unenforceable, the rest remains in effect. A failure to enforce is not a waiver.
- Notices. Legal notices to us go to contact@secontinuum.com or our registered office; notices to Customer go to the account owner’s email on file.
- Relationship. The parties are independent contractors; these Terms create no partnership, agency, or joint venture.
22.Governing law and disputes
These Terms are governed by the laws of India, without regard to conflict-of-laws rules. Subject to any mandatory law to the contrary, the courts at Hyderabad, Telangana, India have exclusive jurisdiction over disputes arising out of or relating to these Terms or the Service. The parties will first attempt in good faith to resolve any dispute informally.
23.Contact
Secontinuum Private Limited
B-1204, Block B, 12th Floor, Aparna Cyberlife,
Lingampalli, Serilingampally, K.V. Rangareddy,
Telangana, India – 500019
Support, privacy, and legal: contact@secontinuum.com