Terms of Service
These terms govern access to Sifr's identity governance workspace, related support, and public product surfaces.
1. Scope
These Terms of Service apply to your access to Sifr AI's hosted identity governance and compliance workspace, including public product pages, administrator features, evidence exports, and connected workflow tooling. By accessing or using Sifr, you agree to these terms.
If you are using Sifr on behalf of an organisation, you represent that you are authorised to bind that organisation to these terms. In that case, "you" refers to the organisation and its authorised users.
2. Product boundary
Sifr is a governance workspace for non-human identities such as service accounts, API keys, bots, workflows, contractors, and AI agents. External IAM, IGA, PAM, cloud, and AI platform systems remain the source of truth for live identity and access state.
Sifr stores the governance records it creates: ownership assignments, campaigns, certifications, audit history, discovery candidates, approval workflows, runtime activity records, connector settings, and evidence artefacts. You remain responsible for the underlying systems and access decisions enforced there.
3. Accounts and administrator authority
You must provide accurate account information and keep it current. You are responsible for activity conducted under your account and for maintaining the confidentiality of authentication credentials.
Workspace administrators may invite users, connect source systems, configure policies, and export evidence on behalf of their organisation. You are responsible for ensuring that your administrators have appropriate authority to take those actions.
4. Acceptable use
You may not use Sifr to:
- violate law, regulation, or third-party rights;
- probe, disrupt, or degrade the security or availability of the service;
- upload malicious code, credential dumps, or content that compromises other tenants or connected systems;
- misrepresent the source, ownership, or compliance status of identities or evidence records;
- reverse engineer the service except to the extent such restriction is prohibited by applicable law.
5. Customer data and privacy
You retain responsibility for the data you submit to Sifr, including identity metadata, workflow records, connector settings, and supporting evidence. You represent that you have the rights necessary to submit that data and instruct Sifr to process it.
Our handling of personal data is described in the Privacy Policy. You are responsible for providing any notices or obtaining any consents required for your use of the service.
6. Security and shared responsibilities
Sifr maintains technical and organisational controls appropriate for a governance workspace, including encrypted secrets storage, access-controlled infrastructure, and audit logging. Details of our current security posture are described in the Security & Trust Center.
You remain responsible for securing your identity providers, cloud environments, endpoint devices, local exports, and administrator accounts. You must promptly notify us at security@sifrhq.com if you suspect unauthorised access to your workspace.
7. Integrations and third-party services
Sifr may connect to third-party services such as identity providers, ticketing systems, and cloud platforms. Your use of those third-party services is governed by the applicable provider terms, and Sifr is not responsible for their availability, security, or changes in API behavior.
You are responsible for verifying that imported records and exported remediation actions match your operational intent before relying on them for production governance decisions.
8. Commercial terms
Pricing, payment, pilot scope, support commitments, and any service-level commitments are governed by the applicable order form, statement of work, or other commercial agreement between you and Sifr. If there is a conflict between these terms and an executed commercial agreement, the executed commercial agreement controls for that conflict.
9. Intellectual property and feedback
Sifr and its related software, documentation, branding, and product content remain our property and that of our licensors. Subject to these terms and any commercial agreement, we grant you a limited, non-exclusive, non-transferable right to access and use the service for your internal business purposes.
If you provide feedback, suggestions, or product requests, we may use them without restriction or obligation to you.
10. Confidentiality
Each party may receive non-public information from the other that should reasonably be understood as confidential. The receiving party will protect that information using reasonable care and use it only as needed to perform under these terms, except where disclosure is required by law.
11. Suspension and termination
We may suspend or terminate access if necessary to address security risk, prevent abuse, comply with law, or respond to your material breach of these terms. Where practical, we will provide notice before suspension.
You may stop using the service at any time. Upon termination, your right to access the service ends, but provisions that by their nature should survive termination will remain in effect.
12. Disclaimers and liability limits
Sifr is provided on an "as is" and "as available" basis, except as expressly stated in an executed commercial agreement. To the maximum extent permitted by law, we disclaim implied warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenues, goodwill, or data. Each party's aggregate liability arising out of or related to the service will not exceed the amounts paid or payable to Sifr under the applicable commercial agreement during the twelve months before the claim arose.
13. Changes to these terms
We may update these terms to reflect product, legal, or operational changes. If we make a material change, we will post the updated terms here and may notify active workspace administrators by email. Your continued use of the service after the effective date constitutes acceptance of the updated terms.
14. Contact
Questions about these terms can be sent to legal@sifrhq.com. Privacy questions should be sent to privacy@sifrhq.com, and security disclosures to security@sifrhq.com.