Article 1
Purpose
These General Terms of Use (hereinafter the “Terms of Use”) set out the terms of access to and use of the website techwatchalert.com and of the SaaS application available at app.techwatchalert.com (hereinafter collectively the “Service”), published and operated by the company TechWatchAlert (hereinafter “TechWatchAlert”).
Accessing and using the Service constitutes full, complete and unreserved acceptance of these Terms. If the User does not accept these terms, they must refrain from accessing or using the Service.
These Terms are supplemented, where applicable, by the General Terms of Sale for paid subscriptions, and by the Privacy policy for the processing of personal data.
Article 2
Definitions
- “Service”: the entire TechWatchAlert platform, including the public website, the web application, the REST API, the CVE search, stack monitoring, automated alerting and report generation features, and any other feature made available.
- “User”: any natural person accessing the Service, whether an Account holder or a visitor to the public website.
- “Account”: the personal space created by the User on the platform, giving access to the features of their plan.
- “User Content”: any data, information or configuration entered by the User into the Service (lists of monitored technologies, alert settings, webhook configurations, etc.).
- “CVE Data”: information on software vulnerabilities (Common Vulnerabilities and Exposures) obtained from third-party public sources, including the NVD, CISA KEV, CVEList and PoC-in-GitHub.
- “API”: the application programming interface provided by TechWatchAlert that allows programmatic access to the Service under the terms of the subscribed plan.
- “Credentials”: the email address and password, or any other authentication mechanism (TOTP, OAuth), that allow the User to access their Account.
Article 3
Access to the Service and Account creation
3.1 Open access
Access to the public website techwatchalert.com is open and free of charge. No registration is required to view the public pages (Service overview, public documentation, pricing, legal notice).
3.2 Access to the application
Access to the application app.techwatchalert.com and its features requires an Account. Creating an Account is subject to acceptance of these Terms and, for paid plans, of the Terms of Sale.
3.3 Account creation
The User creates their Account by providing the information requested during the registration process, including:
- A valid, working email address;
- A password that meets the security requirements set by the platform;
- Where applicable, information about their organization.
The email address provided serves as the primary identifier and as the communication channel for notifications related to the Account, CVE alerts and billing. The User agrees to provide a valid email address that they own.
3.4 Verification
A verification email is sent to the address provided at registration. Full activation of the Account requires confirmation of this email address. TechWatchAlert reserves the right to refuse or suspend the creation of an Account without having to give reasons.
Article 4
Registration requirements
4.1 Legal capacity
Access to the Service and the creation of an Account are restricted to natural persons who are of legal age and have full legal capacity. Minors are not permitted to create an Account or use the Service.
If the User creates an Account on behalf of a legal entity (company, non-profit, etc.), they represent that they have the capacity and authority to bind it contractually.
4.2 One Account per User
Each User may hold onlyone active Account per email address. Creating multiple accounts to circumvent a plan's limits, or for any other fraudulent purpose, is strictly prohibited and is grounds for immediate termination.
4.3 Accuracy of information
The User agrees to provide accurate, complete and up-to-date information. Any fraudulent or incorrect information may result in suspension or termination of the Account.
4.4 Professional use
The Service is designed and optimized for professional use in the field of cybersecurity. Personal use unrelated to IT security activities is permitted but is not the intended use of the Service.
Article 5
Account security and confidentiality of Credentials
5.1 Responsibility for Credentials
The User is solely responsible for the confidentiality of their Credentials and for all actions performed from their Account. TechWatchAlert cannot be held liable for the consequences of unauthorized access resulting from the User's negligence in protecting their Credentials.
5.2 Security requirements
The User agrees to:
- Choose a strong, unique password not used on other services;
- Never share their Credentials with a third party;
- Enable two-factor authentication (2FA/TOTP) where available, particularly for accounts with API access;
- Log out of the Service at the end of each session on a shared device;
- Not use an insecure password manager to store their Credentials.
5.3 Incident notification
If the User suspects the Account has been compromised (unauthorized access, stolen Credentials, abnormal activity), the User must immediately :
- Change their password and revoke active API tokens;
- Notify TechWatchAlert at [email protected] ;
- Enable or reset their two-factor authentication.
TechWatchAlert may, at its discretion, temporarily suspend an Account showing signs of abnormal activity, and will inform the User as soon as possible.
5.4 API tokens
API access tokens are Credentials in their own right. They must not be exposed publicly (code repositories, logs, unencrypted environment variables). If a token is compromised, the User must revoke it immediately from the Account interface.
Article 6
Acceptable use of the Service
The User agrees to use the Service fairly and for its intended purpose, in compliance with these Terms, applicable laws and regulations, and the rights of third parties.
6.1 Permitted uses
The Service is designed for the following uses:
- Monitoring and searching for CVE vulnerabilities affecting technologies used by the User or their clients;
- Setting up automated alerts to be notified of relevant new vulnerabilities;
- Analyzing and prioritizing vulnerabilities using CVSS and EPSS scores and the KEV indicator;
- Generating monitoring reports for security teams or management;
- Integrating the Service into CI/CD pipelines, SIEMs or DevSecOps tools via the REST API;
- Any lawful use aimed at improving the security posture of the User or their clients.
6.2 Use in the course of services to clients
A User may use the Service to deliver cybersecurity services on behalf of third-party clients, provided they stay within the limits of their plan and do not resell access to the Service as such.
Article 7
Prohibited uses
Any breach of this article may result in immediate suspension of the Account, without notice or refund, and, where applicable, legal action.
The User is strictly prohibited from the following:
7.1 Security and integrity violations
- Attempt to compromise, bypass or disable the platform's security measures;
- Perform penetration tests or vulnerability scans on TechWatchAlert's infrastructure without prior written authorization;
- Introduce malware, viruses, Trojan horses, injection scripts or any other harmful code;
- Attempt to access data belonging to other Users or unauthorized resources;
- Exploit vulnerabilities discovered in the Service without informing TechWatchAlert through the responsible disclosure process set out in Article 12.
7.2 Availability violations
- Generate an excessive volume of requests likely to degrade the performance of the Service for other Users (denial-of-service attack, unauthorized large-scale scraping);
- Circumvent the rate limits imposed by the API;
- Use bots, scripts or automated tools to access the web interface in a manner inconsistent with its intended use.
7.3 Unlawful or unethical uses
- Use vulnerability information provided by the Service to design, develop or deploy cyberattacks against third-party systems;
- Use the Service for industrial espionage, unauthorized intelligence gathering or attacks on third-party information systems;
- Share information obtained from the Service in a way that facilitates malicious activities.
7.4 Infringement of TechWatchAlert's rights
- Reproduce, copy, sell, rent or distribute all or part of the Service without prior written authorization;
- Reverse engineer, decompile or disassemble the platform's code;
- Remove or alter intellectual property notices or warnings in the Service;
- Use TechWatchAlert's trademarks, logos or names without authorization.
7.5 Circumventing plans
- Share their Credentials to let third parties not authorized under the subscribed plan access the Service;
- Create multiple Accounts to obtain the benefits of the free plan beyond its stated limits.
Article 8
User content
8.1 Nature of User Content
User Content includes all data entered by the User into the Service: lists of monitored technologies (stack), alert settings, webhook configurations, integrations (Slack, Discord, email), notification preferences and any other configuration setting.
8.2 Ownership and license
The User retainsfull ownership of their User Content. By using the Service, the User grants TechWatchAlert a limited, non-exclusive, non-transferable license to use the User Content solely for the purposes of:
- Providing the Service in accordance with the Terms of Use and the Terms of Sale;
- Improving the performance and relevance of the Service (based on aggregated, anonymized data);
- Complying with applicable legal obligations.
8.3 Responsibility for Content
The User is solely responsible for the accuracy, lawfulness and relevance of the User Content they enter into the Service. TechWatchAlert does not review User Content and cannot be held liable for its content or the consequences of its use.
8.4 Data export
The User may export their User Content from the Service interface at any time during their Subscription. Upon termination, a 30-day period is granted for export, in accordance with Article 8 of the Terms of Sale.
Article 9
Intellectual property
9.1 TechWatchAlert's rights
All elements making up the Service are the exclusive property of TechWatchAlert or are licensed to TechWatchAlert, including in particular:
- The source code, algorithms, technical architecture and databases;
- The graphical interface, mockups, designs, icons and visual elements;
- Trademarks, logos, trade names and domain names;
- Texts, editorial content, technical documentation and methodologies;
- The structuring, enrichment and organization of CVE Data performed by TechWatchAlert (computed scores, correlations, indexing).
These elements are protected by French and international laws on intellectual property, copyright, trademarks and databases.
9.2 Public CVE data
Raw CVE data from the NVD, CISA, MITRE and other public sources is freely accessible data subject to its own reuse terms. TechWatchAlert claims no exclusive rights over this raw data. TechWatchAlert's added value lies in indexing, enriching and correlating it, and making it available through an optimized interface.
9.3 License to use
Taking out a Subscription grants the User a personal, non-exclusive, non-assignable, non-sublicensable and non-transferable right to use the Service, limited to the term of the Subscription and to the features of the subscribed plan. This right does not constitute a transfer of ownership.
9.4 Feedback and suggestions
If the User sends TechWatchAlert suggestions, improvement ideas or feedback, TechWatchAlert may freely use them to improve the Service, with no obligation of compensation, confidentiality or attribution.
Article 10
Personal data and cookies
10.1 Data controller
TechWatchAlert processes Users' personal data as data controller within the meaning of the GDPR (Regulation (EU) 2016/679) and the amended French Data Protection Act (loi Informatique et Libertés).
10.2 Data collected
In connection with the use of the Service, TechWatchAlert collects the following data:
- Identification data: last name, first name, email address, password (hashed);
- Account data: settings, preferences, stack configuration, alert history;
- Billing data: payment information (processed by the payment provider), billing address;
- Technical data: IP address, user agent, login logs, API access tokens;
- Usage data: searches performed, alerts viewed, features used (to improve the Service).
10.3 Purposes and legal bases
- Account management and provision of the Service: performance of a contract ;
- Sending CVE alerts and notifications: performance of a contract ;
- Billing and accounting: legal obligation ;
- Security and fraud prevention: legitimate interest ;
- Service improvement (aggregated data): legitimate interest ;
- Marketing communications (with consent): consent.
10.4 Users' rights
Under the GDPR, the User has the following rights, which may be exercised by writing to [email protected] :
- Access: obtain a copy of the data concerning them;
- Rectification: correct inaccurate or incomplete data;
- Erasure: request the deletion of their data (“right to be forgotten”), subject to legal retention obligations;
- Portability: receive their data in a structured, machine-readable format;
- Restriction: restrict processing in certain cases provided for by the GDPR;
- Objection: object to processing based on legitimate interest or carried out for direct marketing purposes.
The User may also lodge a complaint with the CNIL (www.cnil.fr).
10.5 Retention period
Data is retained for the duration of the Subscription, then for 3 years for purposes of contractual evidence, before deletion or anonymization. Billing data is retained for 10 years in accordance with accounting obligations.
10.6 Cookies
The Service uses cookies and similar technologies for:
- Essential cookies: session persistence, CSRF protection; no consent required;
- Analytics cookies: anonymized audience measurement; subject to consent;
- Preference cookies: language, interface theme; no consent required.
The User can manage their cookie preferences via the consent banner or their browser settings.
Article 11
Availability and maintenance
11.1 Availability target
TechWatchAlert undertakes to keep the Service available with an availability target of 99.5% per calendar month, excluding scheduled maintenance periods and force majeure events. This target is not a contractual guarantee, except for Customers with a formal SLA in their Enterprise contract.
11.2 Scheduled maintenance
TechWatchAlert reserves the right to carry out maintenance, updates or technical work necessary for the proper operation of the Service. Where possible, this work is scheduled outside peak hours and announced by email or in-app notification with a notice period of at least 48 hours.
11.3 Unplanned incidents
In the event of an incident affecting the availability of the Service, TechWatchAlert will endeavor to:
- Communicate about the incident as soon as possible through the available channels (email, status page);
- Restore the Service as quickly as possible;
- Provide a post-incident report for significant outages.
11.4 Service updates
TechWatchAlert may change the Service at any time, including by adding, modifying or removing features. Significant changes are communicated to Users through the release notes (changelog) available in the application.
Article 12
Platform security
12.1 Security measures
TechWatchAlert implements appropriate technical and organizational security measures to protect the Service and Users' data, including:
- Encryption of data in transit (TLS 1.2+) and at rest;
- Password hashing with a configurable-cost algorithm (bcrypt or Argon2);
- Access logging and anomaly detection;
- Two-factor authentication available for all Accounts;
- Regular security testing of the infrastructure.
12.2 Responsible vulnerability disclosure
TechWatchAlert encourages the responsible disclosure of security vulnerabilities discovered in its Service. Any vulnerability identified must be reported to [email protected] before any public disclosure, allowing a reasonable period for a fix.
TechWatchAlert undertakes to acknowledge receipt of any report within 5 business days, to handle vulnerabilities diligently, and not to take legal action against any researcher who has acted in good faith as part of responsible disclosure.
12.3 User responsibility
The User agrees not to perform security testing (scans, fuzzing, injection) on TechWatchAlert's infrastructure without prior written authorization. Any action likely to compromise the security or availability of the Service is prohibited and constitutes a criminal offense that may be prosecuted under the Godfrain Act (Article 323-1 et seq. of the French Criminal Code).
Article 13
Hyperlinks and third-party services
13.1 Links from the Service
The Service may contain links to third-party websites (CVE sources, external documentation, security resources). TechWatchAlert has no control over these sites and disclaims all liability for their content, availability or personal data practices.
13.2 Third-party data sources
The CVE Data displayed in the Service comes from third-party public sources (NVD/NIST, CISA, MITRE, GitHub). TechWatchAlert does not guarantee the completeness, point-in-time accuracy or continuous availability of these sources. If a source is unavailable, data updates may be delayed.
13.3 Third-party integrations
The Service allows integration with third-party services (Slack, Discord, webhooks, etc.). Use of these integrations is subject to the terms and conditions of the relevant third-party services. TechWatchAlert cannot be held liable for the operation or availability of these third-party services, or for changes they make.
Article 14
Account suspension and termination
14.1 Temporary suspension
TechWatchAlert may temporarily suspend a User's access to the Service, with or without notice depending on severity, in the event of:
- Suspected or actual breach of these Terms;
- Abnormal or suspicious activity on the Account (attempted compromise, API abuse);
- Non-payment of an overdue invoice (for paid plans, in accordance with the Terms of Sale);
- A request from a competent authority.
The User is notified of the suspension by email as soon as possible, unless such notification is likely to increase the identified risk.
14.2 Termination by TechWatchAlert
TechWatchAlert may permanently terminate an Account in the event of:
- Serious or repeated breach of these Terms, in particular of Article 7 (prohibited uses);
- Provision of clearly false information at registration;
- Use of the Service for unlawful purposes or purposes contrary to public order;
- Continued non-payment beyond the period set out in the Terms of Sale.
14.3 Termination by the User
The User may delete their Account at any time from the Account settings or by contacting [email protected]. Deleting the Account terminates the Subscription under the conditions set out in the Terms of Sale.
14.4 Effects of termination
Upon termination of the Account, for whatever reason:
- Access to the Service is removed, immediately or gradually;
- User Content is kept for 30 days to allow export, then deleted;
- The rights of use granted under the Terms end immediately;
- Provisions of the Terms intended to survive termination (intellectual property, limitation of liability, governing law) remain in effect.
Article 15
Limitation of liability
15.1 General exclusions
TechWatchAlert cannot be held liable for damages resulting from:
- Temporary interruption of the Service for maintenance or a technical incident;
- Inaccuracies or delays in CVE Data obtained from third-party sources;
- Decisions made by the User or their clients based on information provided by the Service;
- Use of the Service that does not comply with these Terms;
- Unauthorized access to the Account resulting from the User's negligence;
- The failure of third-party services integrated into the Service;
- A force majeure event within the meaning of Article 15 of the Terms of Sale.
15.2 Indirect damages
Under no circumstances shall TechWatchAlert be liable for indirect, consequential, incidental, special or punitive damages, including loss of data, loss of revenue, loss of customers, reputational harm or loss of profit, even if TechWatchAlert has been advised of the possibility of such damages.
15.3 Liability cap
For Customers with a paid Subscription, TechWatchAlert's total liability is limited in accordance with Article 14 of the Terms of Sale. For Users of the free Service (Basic plan), TechWatchAlert's liability is expressly excluded to the fullest extent permitted by applicable law.
Important reminder: TechWatchAlert is a cybersecurity decision-support tool. It is not a substitute for professional security expertise. The User remains responsible for the remediation actions taken on their infrastructure based on information from the Service.
Article 16
Warranties and nature of the Service
16.1 Provision “as is”
The Service is provided “as is” and “as available”. TechWatchAlert does not warrant that the Service will be error-free, uninterrupted, or fit for any particular purpose of the User beyond the features described.
16.2 Accuracy of CVE data
TechWatchAlert applies rigorous indexing and enrichment processes to ensure the quality of CVE Data. However, given the nature of the sources (third-party public databases updated asynchronously), TechWatchAlert does not guarantee:
- The completeness of the index at all times;
- The absence of errors or inaccuracies in metadata (CVSS scores, affected versions, etc.);
- Real-time availability of all published vulnerabilities at the same moment as their official disclosure.
16.3 Informational nature of the data
The information provided by the Service (scores, risk indicators, confirmed exploitation, etc.) is informational and indicative only. It does not constitute legal advice, certified security recommendations or compliance audits. Any security decision must be validated by a qualified professional.
Article 17
Changes to the Service and the Terms
17.1 Changes to the Service
TechWatchAlert reserves the right to modify, improve or discontinue all or part of the Service's features at its sole discretion. Significant changes are communicated to Users through the release notes and, for material changes affecting paid plans, by email with reasonable notice.
17.2 Changes to the Terms
TechWatchAlert may amend these Terms at any time, in particular to reflect changes in the Service, legislation or industry practices. Any material change is notified to Account holders by email at least 15 days before it takes effect.
Continued use of the Service after the effective date of the new Terms constitutes acceptance of them. If the User does not accept the new Terms, they must stop using the Service and may close their Account in accordance with Article 14.3.
The current version of the Terms is available at all times at techwatchalert.com/cgu along with the date of the last update.
Article 18
Miscellaneous
18.1 Entire agreement
These Terms, read together with the Terms of Sale (for paid subscriptions) and the Privacy Policy, constitute the entire agreement between TechWatchAlert and the User regarding the use of the Service, and supersede any prior agreement.
18.2 Severability
If any provision of these Terms is held void, unlawful or unenforceable by a competent court, the remaining provisions remain in full force. The void provision is replaced by a valid provision that comes as close as possible to the parties' original intent.
18.3 No waiver
TechWatchAlert's failure at any time to enforce any provision of these Terms shall not be construed as a waiver of its right to enforce it later.
18.4 Assignment
The User may not assign, transfer or delegate their rights and obligations under these Terms without TechWatchAlert's prior written consent. TechWatchAlert may assign these Terms in connection with a merger, acquisition or sale of all or part of its business, provided that it informs the User.
18.5 Communications
All official communications from TechWatchAlert to the User are sent by email to the address associated with the Account, or through in-app notifications. The User is responsible for keeping their email address valid and accessible.
Article 19
Governing law and jurisdiction
These Terms are governed by and construed in accordance with French law, to the exclusion of any other law and of conflict-of-laws rules.
For business Users: any dispute relating to the formation, interpretation, performance or termination of these Terms shall, after an attempt at amicable resolution within 30 days, be submitted to the exclusive jurisdiction of the competent courts for the place of TechWatchAlert's registered office.
For Consumer Users: the Consumer User may bring proceedings before the court of their place of residence or any court with jurisdiction under the ordinary rules. The mandatory provisions of the Consumer User's country of residence remain applicable to the full extent provided by applicable regulations.
For Consumer disputes, recourse to mediation is provided for in Article 17 of the Terms of Sale.
Contact
Contact details
For any question about these Terms, your Account or the use of the Service: