Terms of Service
Last updated 18 July 2026
These terms govern your use of Vandorisk. They are written for business use. By creating an account or using the service, you agree to them. Where a separate order form or design-partner agreement is signed, that agreement prevails over these terms to the extent they conflict.
1. What Vandorisk is — and is not
Vandorisk is guided self-assessment software. It structures your assessment of your products against the EU Cyber Resilience Act (Regulation (EU) 2024/2847), stores your evidence, and generates document drafts — including technical documentation and EU Declaration of Conformity drafts — from your answers and your evidence.
Vandorisk is not a law firm, notified body, or conformity-assessment body, and does not provide legal advice. Using Vandorisk does not make your product compliant, and no output of Vandorisk is a certification or a substitute for a conformity assessment. You — the manufacturer — remain solely responsible for your products’ compliance, for the accuracy of everything you enter, for the correctness of any Declaration of Conformity you sign, and for your reporting obligations. Verify all outputs against the Regulation and your own circumstances, with professional advisers where appropriate.
2. Accounts and eligibility
The service is for business use only. If you accept these terms on behalf of an organization, you confirm you are authorized to bind it. Keep your credentials confidential; you are responsible for activity under your accounts.
3. Your data
You keep all rights in the content you enter or upload — product data, assessments, evidence, SBOMs, and generated documents (“Customer Data”). You grant us the licence needed to host, process, and display it in order to operate the service. We process personal data within Customer Data as your processor under our Data Processing Agreement. You are responsible for having the right to upload what you upload. For any question about how personal data is handled, email hello@vandorisk.com.
4. Acceptable use
- No unlawful use of the service.
- No reselling or service-bureau use without a separate agreement.
- No reverse engineering except to the extent the law mandates.
- No security testing without our written permission.
- No attempting to access other customers’ data.
5. Vulnerability screening
SBOM screening extracts the package names and versions from your SBOM and queries the public OSV.dev database, operated by Google LLC (USA); the SBOM file itself and your identity are not transmitted. Results reflect the contents of that public database at the time of the query. We do not warrant that screening identifies all vulnerabilities— an absence of findings is not an assurance of security.
6. Availability and support
We aim for high availability, but at this early stage of the service we do not commit to a numerical service-level agreement except where one is agreed in an order form. We may carry out maintenance, giving reasonable notice where practicable. Support is provided by email at hello@vandorisk.com.
7. Retention and export
During the term you can export your assessments, evidence, and generated documents at any time, including an archive that contains the documents you uploaded. After termination we retain Customer Data for a short export window and then delete it, unless you have instructed extended retention.
Important: the CRA requires youto retain technical documentation for 10 years, or the support period if longer. Make sure you export your documentation, or arrange extended retention, before the end of your term — avoiding deletion at term-end is your responsibility.
8. Warranties and disclaimers
To the maximum extent permitted by law for business contracts, the service is provided “as is”. We warrant that we will provide the service with reasonable skill and care. We do not warrant regulatory outcomes, the completeness of regulatory content, or that using the service satisfies any legal obligation. Section 1 applies at all times.
9. Limitation of liability
Neither party excludes liability that cannot lawfully be excluded. Subject to that:
- neither party is liable for indirect or consequential loss, loss of profit, or loss of data beyond the cost of restoration;
- our total aggregate liability in any 12-month period is capped at the fees you paid for the service in that period;
- we are not liable for regulatory penalties, enforcement action, or third-party claims arising from your products’ compliance status or from documents you signed.
10. Term and changes
Subscriptions run for the agreed term and renew unless cancelled in line with your order form. Either party may terminate for material breach that is not cured within a reasonable notice period. We may improve the service over time; material adverse changes to these terms take effect at your next renewal, with notice.
11. Who you are contracting with, and governing law
Vandorisk is operated by its founder, and the operating company is in the process of being incorporated in the European Union. Until that is complete the contracting party is the founder trading as Vandorisk, not a limited company. We would rather say that plainly than leave the question unanswered.
When the company is incorporated these terms will be updated to name the entity, its registration number and its registered address, and to name the member state whose law governs and whose courts have jurisdiction. Existing customers will be told before that happens, and nothing in this section reduces any right you already have.
If your procurement process needs a named legal counterparty, a registration number or a specific governing law before you can sign, write to hello@vandorisk.com and we will tell you where incorporation stands rather than leave you to guess. These terms do not affect any mandatory consumer or statutory rights that cannot be waived by agreement.
Contact
These terms describe how the service is offered today; they are not legal advice. Questions? Email hello@vandorisk.com.