# Terms of Use for Tachyonik Website and Products

*Last updated: June 2026*

## 1. Scope and Applicability

1.1 These Terms of Use ("Terms") govern the use of (a) the website of Tachyonik GmbH ("Tachyonik", "we", "us") (the "Website") and (b) the Tachyonik CSM application software — where "CSM" stands for Cyber-Security-Management — (the "Application"), whether the Application is operated as a software-as-a-service platform ("SaaS") or installed on the customer's own infrastructure as an on-premise appliance ("Appliance"). The Website and the Application are together referred to as the "Services".

1.2 By accessing or using the Website or the Application, you ("User", "you") agree to be bound by these Terms. If you do not agree, you must not use the Services.

1.3 These Terms apply in addition to any separate agreements between you and Tachyonik, including but not limited to service level agreements, data processing agreements, or individual licensing contracts. In the event of a conflict, the more specific agreement shall prevail.

1.4 The Terms apply to all user types: Anonymous Users, Registered Users, and Professional Users (as defined in Section 4).

## 2. The Website

2.1 The Website serves informational purposes about Tachyonik GmbH and its products. Tachyonik reserves the right to modify, supplement, or delete the content of the Website at any time without prior notice, or to temporarily or permanently cease publication.

2.2 Use of the Website is permitted exclusively for lawful purposes. Any use that violates applicable laws, infringes the rights of third parties, or impairs the functionality of the Website is prohibited. In particular, any automated retrieval of content (scraping, crawling) without prior written consent is not permitted.

2.3 The Website may contain links to external websites over which Tachyonik has no control. Tachyonik assumes no responsibility for the content of linked websites. The respective provider or operator of the linked pages is solely responsible for their content.

## 3. Description of the Application

3.1 The Tachyonik CSM Application is a cybersecurity platform that provides automated vulnerability detection, asset management, tool orchestration, and AI-assisted analysis capabilities. The Application is made available under a dual-licensing model (see Section 5) and connects to the Tachyonik Feed (see Section 6).

3.2 The Application may integrate third-party components, open-source software, and AI services. The availability and functionality of such components may vary and are subject to the respective third-party terms.

3.3 Tachyonik reserves the right to modify, extend, or discontinue features of the Application at any time. For Professional Users, such changes are subject to the terms of the applicable service level agreement.

## 4. User Types and Registration

4.1 Anonymous Users may access limited functionality of the Application without registration. Anonymous sessions are temporary and may be terminated at any time without notice.

4.2 Registered Users create an account by providing a valid email address and choosing a password. Registration is free of charge. Registered Users gain access to extended functionality as determined by Tachyonik.

4.3 Professional Users are Registered Users who have entered into a paid subscription or licensing agreement with Tachyonik. Professional Users receive additional features, support, and service commitments as defined in the applicable service level agreement.

4.4 Users must be natural persons of at least 18 years of age or legal entities represented by an authorised person. By registering, you represent and warrant that the information provided is accurate and complete.

4.5 Each user account is personal and non-transferable. You are responsible for maintaining the confidentiality of your login credentials and for all activities that occur under your account.

## 5. Software Licensing (Dual Licensing)

5.1 **Dual-licensing model.** Tachyonik makes the Tachyonik CSM Application available under a dual-licensing model. The same software is offered under two alternative sets of terms, and the terms that apply to you depend on how you obtain the software:

- (a) **Source code under the AGPL.** The source code of the Application is published as open-source software under the GNU Affero General Public License, version 3 or (at your option) any later version ("AGPL"). If you obtain the software in source form, your rights to use, study, modify, and distribute it are governed exclusively by the AGPL.
- (b) **Binary installers and SaaS under these Terms (proprietary licence).** The binary installers distributed by Tachyonik and the SaaS platform operated by Tachyonik are offered under a separate, proprietary licence on these Terms. If you obtain the software by downloading a Tachyonik binary installer or by accessing the SaaS platform, you do so under these Terms and not under the AGPL.

5.2 **AGPL rights over the source code are not restricted.** Nothing in these Terms restricts, limits, or adds conditions to the rights granted to you under the AGPL with respect to source code obtained under Section 5.1(a). In the event of any conflict between these Terms and the AGPL as regards such source code, the AGPL prevails. You remain free, at all times, to obtain the source code, to build the Application yourself, and to use and distribute your own builds under the AGPL, independently of Tachyonik's binary installers and SaaS platform.

5.3 **Proprietary licence for Tachyonik binaries and SaaS.** Subject to these Terms, Tachyonik grants you a limited, non-exclusive, non-transferable, revocable licence to install and use the Tachyonik binary installers and to access the SaaS platform for their intended purpose. Under this proprietary licence, and except where mandatory law provides otherwise, you shall not redistribute, publish, sell, sublicense, rent, lease, or otherwise make the Tachyonik binary installers available to third parties, nor make the SaaS platform available to third parties as your own offering. This restriction applies to the Tachyonik binary installers and the SaaS platform as licensed under these Terms; it does not apply to, and does not diminish, your separate rights to obtain and distribute the source code under the AGPL pursuant to Section 5.1(a).

5.4 **Relationship between the two licences.** The two licences are alternatives. Choosing to use a Tachyonik binary installer or the SaaS platform under these Terms does not waive your right to obtain and use the source code under the AGPL, and exercising your AGPL rights over the source code does not entitle you to use the Tachyonik binary installers or SaaS platform other than under these Terms.

5.5 **Trademarks.** Neither licence grants any right to use the name, logo, or trademarks of Tachyonik. The AGPL does not grant trademark rights. Any use of Tachyonik's trademarks remains subject to Section 8 and applicable trademark law.

5.6 **Feed content.** The Application connects to the Tachyonik Feed, the licensing of which is set out in Section 6. The Tachyonik Feed is not part of the AGPL-licensed source code, is not licensed under the AGPL, and is provided solely under these Terms regardless of which licence applies to the software itself.

## 6. The Tachyonik Feed

6.1 The Application may connect to the "Tachyonik Feed", a data feed provided by Tachyonik that contains curated content, including security intelligence, detection logic, and related materials ("Feed Content"). Feed Content constitutes the intellectual property of Tachyonik or its licensors and is not licensed under the AGPL. Use of Feed Content is governed by these Terms, including where you access the Feed from an Application built from source under the AGPL.

6.2 **Tachyonik Community Feed.** The Tachyonik Community Feed is available free of charge. Subject to these Terms, Tachyonik grants you a limited, non-exclusive, non-transferable, revocable right to access and use the Tachyonik Community Feed solely in connection with, and for the intended operation of, the Tachyonik CSM Application. You shall not:

- (a) redistribute, publish, sell, sublicense, or otherwise make the Tachyonik Community Feed (in whole or in part) available to third parties; or
- (b) use the Tachyonik Community Feed with, or integrate it into, any application or system other than the Tachyonik CSM Application.

6.3 **Tachyonik Enterprise Feed.** The Tachyonik Enterprise Feed is available only to Professional Users. Access to and use of the Tachyonik Enterprise Feed are subject to the applicable service level agreement and any further licensing terms agreed therein. In the absence of conflicting provisions in that agreement, the restrictions in Section 6.2 apply equally to the Tachyonik Enterprise Feed.

6.4 The restrictions in this Section 6 apply independently of the AGPL licensing of the source code under Section 5.1(a) and survive any use of the Application built from source. The Tachyonik Feed is licensed separately from the software, and obtaining the software under the AGPL confers no right to access or use the Tachyonik Feed.

## 7. Permitted Use

7.1 The Services may be used exclusively for lawful purposes and in accordance with these Terms.

7.2 You shall not:

- (a) use the Application to conduct unauthorised attacks, scans, or intrusions against systems you do not own or have explicit authorisation to test;
- (b) use the Application to develop, distribute, or deploy malware, ransomware, or other malicious software;
- (c) circumvent, disable, or interfere with security features, access controls, or usage limitations of the SaaS platform, the binary installers, or the Tachyonik Feed (this does not affect your rights under the AGPL with respect to the source code pursuant to Section 5.1(a));
- (d) use the Services in a manner that violates applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG);
- (e) resell, rent, lease, or otherwise make the SaaS platform or the binary installers available to third parties as a commercial offering without prior written consent from Tachyonik (this does not affect your rights to distribute the source code under the AGPL pursuant to Section 5.1(a), nor your rights under the AGPL generally);
- (f) use automated means (bots, scrapers, crawlers) to access the Services beyond their intended interfaces (APIs);
- (g) transmit content that is unlawful, harmful, threatening, abusive, defamatory, or otherwise objectionable through the Services;
- (h) use the Tachyonik Feed in violation of Section 6.

7.3 For Appliance deployments, the customer is solely responsible for ensuring that the infrastructure, network configuration, and access controls meet the requirements specified in the applicable documentation. Tachyonik bears no liability for security incidents, data loss, or service disruptions caused by inadequate on-premise infrastructure or configuration.

## 8. Intellectual Property

8.1 All content on the Website (texts, graphics, logos, icons, images, and software), the binary installers, the Tachyonik Feed, the documentation, and the Tachyonik trademarks are the property of Tachyonik GmbH or its licensors and are protected by German and international copyright, trademark, and other intellectual property laws. Any reproduction, distribution, modification, or use of Website content beyond the scope of copyright law requires the prior written consent of Tachyonik. The source code of the Application is licensed under the AGPL as set out in Section 5.1(a); this Section 8 does not limit the rights granted to you under the AGPL with respect to the source code.

8.2 Subject to these Terms, Tachyonik grants you a limited, non-exclusive, non-transferable, revocable right to use the binary installers and the SaaS platform for their intended purpose. This right does not constitute a transfer of ownership and is without prejudice to your rights in the source code under the AGPL.

8.3 Data you upload, create, or generate through the Application ("User Data") remains your property. You grant Tachyonik a limited right to process User Data solely for the purpose of providing and improving the Application's services. For details on data processing, please refer to our Privacy Policy and, where applicable, the Data Processing Agreement.

8.4 Feedback, suggestions, or improvement proposals you provide regarding the Services may be used by Tachyonik without restriction or obligation to compensate.

## 9. AI-Generated Content

9.1 The Application may utilise artificial intelligence to generate analyses, recommendations, code, and other outputs ("AI-Generated Content").

9.2 AI-Generated Content is provided on an "as-is" basis. Tachyonik does not guarantee the accuracy, completeness, suitability, or reliability of AI-Generated Content. You are solely responsible for reviewing and validating any AI-Generated Content before relying on it or acting upon it.

9.3 AI-Generated Content may be processed by third-party AI service providers. By using AI features, you acknowledge that data may be transmitted to such providers in accordance with our Privacy Policy.

## 10. Availability and Maintenance

10.1 **SaaS:** Tachyonik endeavours to maintain reasonable availability of the Application but does not guarantee uninterrupted or error-free access. Scheduled maintenance windows will be announced in advance where practicable.

10.2 **Appliance:** For on-premise deployments, the customer is responsible for the operation, maintenance, backup, and availability of the Application on its own infrastructure, unless a separate maintenance agreement is in place.

10.3 **Website:** The content of the Website has been created with care. However, Tachyonik may temporarily or permanently restrict or cease access to the Website and does not guarantee uninterrupted availability.

10.4 For Professional Users, availability commitments are governed by the applicable service level agreement.

## 11. Warranty and Liability

11.1 **For Anonymous and Registered Users, and for use of the Website:**

- (a) The Services are provided "as is" and "as available" without warranties of any kind, whether express or implied, to the maximum extent permitted by law. In particular, Tachyonik assumes no liability for the accuracy, completeness, or timeliness of the content provided on the Website.
- (b) Tachyonik's liability is limited to cases of intent (Vorsatz) and gross negligence (grobe Fahrlässigkeit) as required by mandatory German law. This does not affect liability for damages resulting from injury to life, body, or health (Section 309 No. 7a BGB), or liability under the German Product Liability Act (Produkthaftungsgesetz).
- (c) In the event of a negligent breach of a material contractual obligation (wesentliche Vertragspflicht/Kardinalpflicht), liability is limited to the foreseeable, contract-typical damage.

11.2 **For Professional Users:**

- (a) Warranty and liability for Professional Users are governed by the applicable subscription or licensing agreement and, where applicable, the service level agreement.
- (b) In the absence of specific provisions in such agreements, the limitations set forth in Section 11.1 shall apply.

11.3 Tachyonik shall not be liable for:

- (a) damages caused by force majeure, including but not limited to natural disasters, pandemics, war, government actions, power failures, or internet outages;
- (b) damages resulting from the User's failure to maintain adequate security measures, backups, or access controls;
- (c) damages resulting from unauthorised modifications to the Application or its configuration by the User;
- (d) indirect, incidental, or consequential damages, including lost profits, lost data, or business interruption, except where such exclusion is prohibited by mandatory law.

## 12. Data Protection

12.1 Tachyonik processes personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Digital Services Act (DDG), and the German Telecommunications-Telemedia Data Protection Act (TDDDG).

12.2 Details regarding the collection, processing, and use of personal data are set out in our Privacy Policy, which is available on the Website and within the Application.

12.3 Where Tachyonik processes personal data on behalf of the User (in particular in SaaS deployments), the parties shall enter into a Data Processing Agreement (Auftragsverarbeitungsvertrag) pursuant to Article 28 GDPR.

12.4 For Appliance deployments, the customer acts as the data controller. Tachyonik's role is limited to providing the software and, where applicable, support services.

## 13. Term and Termination

13.1 For Anonymous Users, access may be terminated at any time without notice by either party.

13.2 For Registered Users, the account may be terminated by the User at any time by deleting the account through the Application. Tachyonik may terminate a Registered User's account with 30 days' notice, or immediately for cause (in particular for violation of these Terms).

13.3 For Professional Users, the term and termination provisions of the applicable subscription or licensing agreement shall prevail.

13.4 Upon termination:

- (a) the User's right to access the Application ceases immediately;
- (b) Tachyonik may delete User Data after a retention period of 30 days following termination, unless longer retention is required by law or agreed upon separately;
- (c) for Professional Users, data export options are available as defined in the applicable agreement.

## 14. Appliance-Specific Provisions

14.1 Where the Application is deployed as an Appliance on the customer's infrastructure, the customer is responsible for:

- (a) providing and maintaining adequate hardware, operating systems, and network infrastructure in accordance with the system requirements specified in the documentation;
- (b) ensuring physical and logical security of the systems on which the Application operates;
- (c) performing regular backups of all data processed by the Application;
- (d) applying security updates and patches provided by Tachyonik in a timely manner.

14.2 Tachyonik grants the customer a limited licence to install and operate the Application on the agreed number of systems for the duration of the licence term.

14.3 The customer shall not modify, adapt, or create derivative works of the binary installers without prior written consent, except to the extent expressly permitted by mandatory law. This restriction does not apply to the source code, which the customer may modify and distribute in accordance with the AGPL as set out in Section 5.1(a).

## 15. SaaS-Specific Provisions

15.1 In SaaS deployments, Tachyonik hosts and operates the Application on its own or third-party infrastructure.

15.2 Tachyonik implements appropriate technical and organisational measures to protect the security, integrity, and availability of the Application and User Data in accordance with the state of the art (Stand der Technik).

15.3 Tachyonik may engage sub-processors for the operation of the SaaS platform. A list of sub-processors is available upon request and, where required, in the Data Processing Agreement.

## 16. Export Control

16.1 The Application may be subject to export control regulations of the Federal Republic of Germany, the European Union, and other jurisdictions. You agree to comply with all applicable export control and sanctions laws and regulations. You shall not use, export, or re-export the Application in violation of such laws.

## 17. Miscellaneous

17.1 **Amendments:** Tachyonik reserves the right to amend these Terms at any time. For the Application, Users will be notified of material changes through the Application or by email (for Registered and Professional Users), and continued use after notification constitutes acceptance of the amended Terms. For the Website, the amended version will be published on the Website, and continued use after publication constitutes acceptance. If you do not agree to the amended Terms, you must cease using the affected Service and, if applicable, terminate your account.

17.2 **Severability:** If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. The invalid provision shall be replaced by a valid provision that most closely reflects the economic purpose of the invalid provision.

17.3 **Entire Agreement:** These Terms, together with any applicable service level agreement, data processing agreement, and subscription or licensing agreement, constitute the entire agreement between you and Tachyonik regarding the use of the Services.

17.4 **No Waiver:** Failure by Tachyonik to enforce any provision of these Terms shall not constitute a waiver of that provision or the right to enforce it at a later time.

## 18. Governing Law and Jurisdiction

18.1 These Terms are governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and conflict-of-law rules.

18.2 For Users who are merchants (Kaufleute), legal entities under public law, or public-law special funds, the exclusive place of jurisdiction for all disputes arising from or in connection with these Terms is the registered office of Tachyonik GmbH.

18.3 For consumers within the European Union, the provisions regarding jurisdiction under Regulation (EU) No 1215/2012 (Brussels Ia) remain unaffected. The European Commission provides an online dispute resolution platform at https://ec.europa.eu/consumers/odr.

## 19. Contact

For questions regarding these Terms, please contact:

**Tachyonik GmbH**
Albert-Einstein-Str. 1, 49076 Osnabrück
info@tachyonik.com
