In plain language
- You connect your own data sources; we analyze permissions and data flows and explain every risk we find.
- Monitoring is read-only and limited to the scopes you approve. The platform changes something in your sources only if you turn on Auto-remediate — off by default — and then it only revokes or reduces access.
- Plans and prices are the ones on the pricing page — self-serve, no sales call.
- Security findings are information, not legal advice, and no tool catches everything.
- You're responsible for the policies, enforcement levels, and permissions you configure; we're responsible for carrying out exactly what you configured — nothing more.
- 8200.dev adds a layer of detection and enforcement on top of your own security program — it never replaces your controls, backups, monitoring, or judgment.
- We don't promise uninterrupted service; an outage, a missed detection, or a third party's failure isn't a breach of these Terms.
- Our liability is capped at what you paid us in the last 12 months — we don't limit liability for gross negligence, wilful misconduct, or breaches of data-protection law, and if you're an individual consumer covered by mandatory consumer law, these limits apply only as far as that law allows.
- You indemnify us against third-party claims arising from the policies, permissions, or data you connected.
1. The agreement
These Terms of Service ("Terms") are a binding agreement between Enterprise.Systems ("we", "us") and the organization or person using the 8200.dev platform ("you", the "Customer"). By creating an account, connecting a source, or otherwise using the platform, you accept these Terms. If you act on behalf of an organization, you represent that you have authority to bind it.
8200.dev is a business-to-business service. It is intended for use by organizations and professionals securing systems they own or administer.
2. The service
8200.dev is an autonomous data-security platform. You connect data sources your organization controls (for example, a Google Workspace tenant); the platform enumerates resources, permissions, and principals through the vendor APIs you authorize, evaluates them against security rules, and produces findings — each with a plain-language explanation and the evidence behind it.
The platform works at three levels, which you choose. At the Detect & Alert and Recommend & Guide levels it is read-only: it reads metadata and permissions through the scopes presented to you at connection time (the scope inventory for every connector is shown before you approve it), reports findings, and tells you how to fix them, without changing anything in your sources. The Auto-remediate level is optional and off by default. It acts only when (a) an owner or admin of your organization has turned on auto-remediation, (b) a policy for the relevant rule is armed, and (c) you have separately granted the connector the write scopes it needs — a second consent that you can revoke at any time without disconnecting monitoring. Auto-remediate only revokes or reduces access — for example, removing a public link or an external share, or revoking an unused API key; downgrading a role always needs a person’s click. It never deletes files, never changes or reads the contents of your files, and every action is recorded in your audit log. You decide whether to enable Auto-remediate and which policies to arm, and you remain responsible for those choices. We never exfiltrate the content of your sources.
3. Accounts and organizations
You must provide accurate registration information and keep your credentials confidential. Activity under your account is your responsibility. Accounts belong to an organization with roles (owner, admin, viewer); you are responsible for the access you grant your own members.
4. Plans, fees, and billing
Plans, features, and prices are as described on the pricing page at the time of purchase. Plans are self-serve: you can start, upgrade, downgrade, or cancel from the platform without a sales process. Fees for paid plans are billed in advance and are non-refundable except where required by law. Prices exclude applicable taxes.
We may change plans or prices prospectively with at least 30 days notice; changes never apply retroactively to a period you already paid for.
5. Your data
You retain all rights in the data accessible through your connected sources and in the findings generated for your organization ("Customer Data"). You grant us a limited license to process Customer Data solely to provide, secure, and improve the service for you. Where Customer Data includes personal data, the Data Processing Agreement applies.
You represent that you are authorized to connect each source — that it belongs to your organization or that you administer it with the owner’s consent. Connecting sources you are not authorized to monitor is a material breach of these Terms and of the Acceptable Use Policy.
6. Acceptable use
Your use of the platform is subject to the Acceptable Use Policy, which is part of these Terms. In short: defensive use of your own (or explicitly authorized) environments only.
7. AI-assisted analysis
Parts of the platform use large language models provided by Anthropic: the in-product support assistant, the executive-summary narratives you request, and translation of the interface into additional languages. AI output can be imperfect or incomplete. Findings are decision support — review them before taking consequential action. We do not permit our AI providers to train their models on your data.
8. Intellectual property
The platform, including its software, rule engines, models, and documentation, is owned by Enterprise.Systems and its licensors. We grant you a non-exclusive, non-transferable right to use it during your subscription. You may not copy, modify, reverse engineer, or resell the platform except as permitted by law. If you give us feedback, we may use it without restriction or obligation.
9. Confidentiality
Each party will protect the other’s non-public information with at least reasonable care and use it only to perform under these Terms. This obligation survives termination for three years; trade secrets are protected for as long as they remain trade secrets.
10. Warranties and disclaimers
For paid plans we warrant that the platform will materially conform to its documentation. Otherwise, the platform is provided "as is" and "as available", without warranties of any kind, express or implied.
Security findings are informational. No security tool detects every risk, and a clean dashboard is not a guarantee that your environment is secure or compliant. Nothing in the platform — including findings, explanations, and these legal pages — constitutes legal advice. Consult your own counsel for legal and compliance questions.
10.1 Allocation of responsibility
You are solely responsible for the security policies you define within the platform, for the enforcement level you assign to each policy (Detect & Alert, Recommend & Guide, or Auto-remediate), and for the permissions and write scopes you grant us. We are responsible for executing the action a policy calls for correctly — the action defined, on the target defined, and nothing beyond it. Any outcome of a policy you configured is your responsibility, including access that is revoked that you needed, and access that is left in place that you would have wanted removed.
10.2 Not a substitute for security controls
The platform is an additional detection and enforcement layer. It does not replace your own security controls, backups, monitoring, incident response, or human judgment. No security system detects every risk, our findings may be incomplete or delayed, and using the platform does not reduce your own responsibility for securing your environment.
10.3 Availability and failure
The platform is provided "as is" and "as available". We do not commit to uninterrupted availability. An interruption, malfunction, delayed or missed detection, or the failure of a third party we rely on (a cloud provider, an API provider, or other infrastructure) does not constitute a breach of these Terms and does not give rise to a claim — including an Auto-remediate action that did not execute because the platform was unavailable.
11. Limitation of liability
To the maximum extent permitted by law: (a) neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost business, lost goodwill, or lost or corrupted data; and (b) Enterprise.Systems’ total liability for any claim arising from or related to the service is capped at the amounts you actually paid us in the 12 months preceding the event giving rise to the claim, or USD 100 if you are on a free plan.
These limits do not apply to liability that cannot be limited under applicable law, including liability arising from willful misconduct, gross negligence, or breach of data-protection law by either party, your payment obligations, or your breach of Section 5 (authorization to connect sources) or the Acceptable Use Policy.
Consumer carve-out: if you are an individual consumer using the platform under the Personal Pro plan with your own personal GitHub account, and mandatory consumer-protection law of your jurisdiction applies to this agreement, the limitations in this Section 11 apply only to the extent that law permits, and the remainder of these Terms remains in full force.
12. Indemnification
You will defend and indemnify Enterprise.Systems against any third-party claim arising from the policies you configured, the permissions you granted, the data you connected, sources you connected without authorization, your violation of the Acceptable Use Policy, or your use of the platform or its findings in violation of law or these Terms.
13. Term, suspension, and termination
These Terms apply for as long as you use the platform. You may terminate at any time by deleting your account (Settings → Delete my account). We may suspend or terminate for material breach — including AUP violations — after notice where practicable, or immediately where the breach endangers the platform or third parties.
On termination, you can export your data via the self-serve export; after the deletion grace period, your data is purged as described in the Privacy Policy.
14. Changes to the service and these Terms
We improve the platform continuously and may change or retire features. We will not materially reduce the core security functionality of your paid plan during a paid period. We may update these Terms; an update takes effect on the effective date shown at the top of this page, and continued use after that date is acceptance.
15. Governing law and disputes
These Terms are governed by the laws of the State of Israel, without regard to conflict-of-law rules. The competent courts of Tel Aviv-Yafo have exclusive jurisdiction, except that either party may seek injunctive relief in any competent court. Mandatory rights you hold under the consumer-protection or data-protection law of your jurisdiction are unaffected.
16. Contact
Enterprise.Systems — [email protected]. Security reports: [email protected].