AA-sec logo AA-sec

General Terms and Conditions

Version dated 15 July 2026

1. Provider and contact details

The services described in these General Terms and Conditions are provided by:

AA Security Platform Austria GmbH
Registered address: [REGISTERED ADDRESS]
Company registration number: [COMPANY REGISTRATION NUMBER]
Registration court: [REGISTRATION COURT]
VAT identification number: [VAT ID]
Managing director: [MANAGING DIRECTOR]
Email: contact@double-a-sec.com

In these General Terms and Conditions, AA Security Platform Austria GmbH is referred to as “AA-sec”, “we”, “us”, or the “Provider”.

2. Scope and eligible customers

These General Terms and Conditions govern the provision and use of the AA-sec Cyber Resilience Platform, related application programming interfaces, optional on-premises components, professional services, manual assessments, evaluations, trials, early-access programmes, support services, and related deliverables.

These General Terms and Conditions apply only to business customers. A sole trader or self-employed individual acting for business or professional purposes is considered a business customer and not a consumer for the purposes of these General Terms and Conditions.

AA-sec may, at its discretion, agree separate terms with an individual or entity that does not fall within the standard eligible-customer categories. No such exception applies unless it is expressly documented in a written agreement signed by both parties.

The Services may be offered to customers in the European Union, the European Economic Area, the United Kingdom, and Switzerland, as well as to customers in other jurisdictions that operate under applicable European requirements or intend to place products on the European market. The Customer remains responsible for determining whether the Services may lawfully be procured and used in the Customer’s jurisdiction.

3. Definitions

For the purposes of these General Terms and Conditions:

4. Nature of the Services

AA-sec provides a Cyber Resilience Platform designed to help product teams manage security evidence, software bills of materials, vulnerabilities, and compliance workflows in one connected lifecycle.

The Services may include:

The exact functionality, scope, deployment model, usage limits, professional services, support level, and deliverables are determined by the individual Agreement or applicable Service Description.

5. Informational and advisory character

Except where Independent Audit Services or another expressly scoped professional service is agreed, the Platform and the general Services primarily provide informational and advisory support. Information and recommendations provided by AA-sec are based on the agreed scope, the information made available to AA-sec, applicable legal and regulatory materials, relevant technical standards, generally recognised cybersecurity practices, and the professional experience of qualified personnel.

Where relevant to the agreed Services, AA-sec seeks to take account of applicable European cybersecurity requirements, including requirements connected with the EU Cyber Resilience Act. References to laws, regulatory requirements, standards, or recognised practices do not constitute a guarantee of conformity, certification, or legal compliance.

The Platform does not make final business, legal, technical, compliance, certification, vulnerability-management, product-release, or risk-acceptance decisions on behalf of the Customer. Decisions recorded in the Platform are made by authorised users of the Customer.

Unless expressly agreed otherwise in writing, AA-sec:

The Customer remains responsible for reviewing the Outputs and for obtaining any legal, regulatory, safety, certification, or specialist advice required for its products, operations, or intended use.

Outputs must be independently reviewed before being relied upon in production environments, safety-related systems, regulated product releases, certification proceedings, regulatory submissions, or other circumstances in which an inaccurate or incomplete result could create material risk.

5.1 Independent Audit Services

Where Independent Audit Services are agreed, the individual Agreement will define the audit subject, scope, criteria, evidence requirements, methodology, limitations, auditor responsibilities, independence safeguards, deliverables, and permitted reliance on the audit report.

AA-sec will not describe an engagement as independent where a material conflict of interest would prevent an objective assessment. Any relevant prior advisory, implementation, operational, or Platform-related involvement will be assessed and, where necessary, disclosed and addressed through appropriate safeguards, separation of responsibilities, or limitations of scope.

6. Website enquiries and contract formation

Information presented on an AA-sec website, landing page, product page, presentation, or marketing material does not constitute a binding offer unless it is expressly identified as such.

Sending a contact form, requesting a demonstration, joining a waiting list, requesting a quotation, or otherwise contacting AA-sec:

A binding Agreement arises only after the scope, price, term, applicable contractual documents, and any trial or evaluation conditions have been agreed and expressly accepted by both parties, including through a signed Order Form, an accepted quotation, or another electronic acceptance mechanism expressly designated by AA-sec for the relevant Service.

Access to the paid Services is normally provided after conclusion of the Agreement and receipt of any payment due before activation. Where a trial or evaluation has been agreed, access may be provided before payment in accordance with the agreed trial or evaluation conditions.

Merely creating an account, providing technical access, or beginning preparatory work does not constitute silent acceptance of customer purchasing terms or other documents not expressly accepted by AA-sec.

7. Contract documents and order of precedence

The individual Agreement signed or otherwise expressly accepted by both parties takes precedence over these General Terms and Conditions.

Unless the individual Agreement provides otherwise, the following order of precedence applies in the event of a conflict:

  1. the individual written agreement or Order Form;
  2. any individually agreed amendments;
  3. the Data Processing Agreement, for personal-data processing matters;
  4. any applicable Service Level Agreement;
  5. the applicable Service Description;
  6. these General Terms and Conditions; and
  7. other documents expressly incorporated into the Agreement.

Customer purchasing terms, standard terms, or procurement conditions apply only to the extent expressly accepted by AA-sec in writing. AA-sec may agree to customer-specific terms following individual review and negotiation.

8. Customer Organisation and user administration

AA-sec creates the Customer Organisation and provides initial organisation-administrator rights to a representative designated by the Customer.

Following initial activation, the Customer is responsible for:

Multi-factor authentication may be provided or recommended but is not mandatory unless stated in the individual Agreement, Service Description, or applicable security requirements.

If the Customer suspects that an account or credential used to access the Services has been compromised, or that unauthorised access may affect the Services, Customer Data, or other users, the Customer must notify AA-sec without undue delay and take reasonable steps to contain the incident. Incidents that do not affect the Services remain subject to the Customer’s internal policies and applicable law.

9. Customer responsibilities

The Customer is responsible for its use of the Services and for all decisions made by its users in or on the basis of the Services.

The Customer must:

The Customer must not deliberately use the Services outside their intended purpose in a manner that compromises security, materially interferes with the Services, unlawfully infringes the rights of another person, or violates applicable law.

AA-sec is not required to monitor all Customer Data or activities within a Customer Organisation. The absence of monitoring or intervention by AA-sec does not constitute approval of any Customer activity.

10. Customer Data and ownership

AA-sec does not acquire ownership of Customer Data.

Ownership and other rights in Customer Data remain with the Customer or the relevant third-party rights holder. Nothing in the Agreement transfers such ownership or rights to AA-sec.

The Customer grants AA-sec a limited, non-exclusive right to process Customer Data solely to the extent necessary to:

AA-sec will not sell Customer Data or use Customer Data for unrelated independent commercial purposes.

11. Data access, encryption, and pseudonymisation

Customer Data within a Customer Organisation is accessible only to users authorised by the Customer and to any other persons to whom the Customer has granted access through the Platform.

As part of ordinary service operations, AA-sec does not access Customer Content unless such access:

Where the applicable technical configuration provides customer-side encryption or customer-controlled decryption, AA-sec cannot decrypt the corresponding protected information. Sensitive information may be stored in encrypted form and represented in documents in pseudonymised form.

The exact encryption, key-management, pseudonymisation, recovery, and access-control mechanisms applicable to a particular deployment are described in the applicable security documentation, Service Description, or individual Agreement.

The Customer acknowledges that AA-sec may be unable to validate the legality, accuracy, completeness, or purpose of information that is encrypted, pseudonymised, or otherwise not accessible to AA-sec.

12. Personal data and privacy

Each party must comply with the data-protection laws applicable to it, including the General Data Protection Regulation where applicable.

Where AA-sec processes personal data on behalf of the Customer, the applicable Data Processing Agreement forms part of the Agreement and governs that processing.

The Data Processing Agreement identifies, where applicable:

The Customer must not submit information whose processing through the Services is unlawful. Additional restrictions for particular categories of data may be specified in the individual Agreement, Service Description, or Data Processing Agreement.

After becoming aware of a Security Incident affecting Customer Data, AA-sec will notify the affected Customer without undue delay and will provide information reasonably available to support the Customer’s assessment and response. Any more specific notification timelines, cooperation duties, and procedures stated in the applicable Data Processing Agreement or security documentation take precedence.

12.1 Product Platform

Production Customer Data processed through the hosted Platform is intended to be hosted and processed on infrastructure located within the European Union, subject to the applicable Service Description and Data Processing Agreement.

Technical traffic-routing, content-delivery, network-security, or access-protection providers may be used to provide secure access to the Platform without acting as the primary host of the Platform’s production database. Applicable subprocessors and their roles are identified in the Data Processing Agreement or applicable subprocessor information.

12.2 Public website and landing pages

AA-sec’s public website and landing pages are technically separate from the production Platform.

Public website and landing-page content may be delivered through Cloudflare or comparable website, content-delivery, security, or hosting infrastructure. Such infrastructure may process technical website data outside the European Union where permitted by applicable law and subject to appropriate safeguards.

The public website may use Google Analytics or similar analytics services where disclosed in the applicable Privacy Policy and permitted by the visitor’s consent preferences and applicable law.

The processing of website visitor information, cookies, analytics data, and contact-form information is governed by the applicable website Privacy Policy and cookie information, not by the provisions governing production Customer Data within the Platform.

13. No AI or LLM training

AA-sec does not use Customer Data to train artificial-intelligence models, large language models, or comparable general-purpose machine-learning models.

AA-sec does not submit Customer Data to an external AI or LLM service unless this has been expressly agreed with the Customer for a specified purpose and is permitted under the applicable Data Processing Agreement.

If AA-sec intends to introduce functionality that uses Customer Data for AI-model training or improvement, AA-sec will provide advance information about the intended processing. Such use will require a separate, affirmative opt-in by the Customer. Refusal to opt in will not by itself authorise AA-sec to use existing Customer Data for such purposes.

14. Outputs and intellectual property

AA-sec and its licensors retain all rights in the Platform, software, APIs, documentation, templates, methods, workflows, generic structures, technical concepts, know-how, and other technology used to provide the Services.

Subject to payment of applicable fees, customer-specific Outputs created for the Customer may be used, reproduced, modified, distributed, submitted, and commercially exploited by the Customer.

The Customer may share Outputs with employees, affiliated companies, professional advisers, auditors, customers, prospective customers, certification bodies, notified bodies, authorities, and other third parties selected by the Customer.

Reports and other Outputs may be resold or incorporated into the Customer’s own commercial services. Access to the Platform itself may not be resold, sublicensed, or provided as a service to third parties without AA-sec’s prior written consent or a separate reseller or partner agreement.

Unless otherwise agreed in writing, customer-specific Outputs generated by the Platform must retain a proportionate attribution identifying AA-sec. The attribution may appear in a document footer, metadata field, acknowledgement section, cover page, or another technically appropriate location.

The standard attribution may state: “Generated using the AA-sec Cyber Resilience Platform.” Existing AA-sec attribution notices must not be removed unless AA-sec has agreed otherwise in writing.

The attribution requirement applies to reports, evidence packages, and other documents generated in an AA-sec format or using AA-sec templates. It does not apply to raw Customer Data, customer-provided materials, unbranded machine-readable exports, or ordinary API responses that do not contain AA-sec-branded analysis or documentation, unless otherwise agreed.

AA-sec may waive, modify, minimise, or replace the attribution requirement in an individual Agreement, including for confidential, white-label, embedded, technically restricted, or other agreed uses.

Where an Output has been materially modified after generation, any retained attribution must not imply that AA-sec reviewed, approved, certified, or endorsed the modifications.

The Customer may provide comments, suggestions, corrections, and other feedback concerning the Services. AA-sec may use such feedback without payment or other compensation, provided that doing so does not disclose Customer Confidential Information or identify the Customer without permission.

14.1 Third-party materials

Certain website elements, icons, libraries, or other third-party materials may be subject to separate licences or attribution requirements. Information concerning such materials may be provided below or in separate notices:

Website icons

15. Trials, evaluations, and Early Access

AA-sec may offer free trials, paid evaluations, demonstrations, proofs of concept, beta functionality, or Early Access services.

Unless otherwise agreed, an evaluation period may last up to one month. The exact duration, scope, users, functionality, data limits, and usage restrictions are determined in the individual Agreement or evaluation confirmation.

Trial and evaluation access is provided for review and assessment only and must not be used for production operations, regulatory reliance, or safety-critical decision-making unless expressly agreed in writing.

Early Access, preview, beta, demonstration, and evaluation functionality may:

Support for trials and Early Access is provided within the scope specified by AA-sec or the individual Agreement.

Early Access pricing may differ from future standard pricing. AA-sec does not guarantee that a particular discount, price, or relationship to future standard pricing will continue after the Early Access period.

After an evaluation ends, AA-sec may retain evaluation data for up to twelve months solely to enable a final export, an agreed reactivation, or continuation of the evaluation relationship, unless a different period is agreed or required by law.

The Customer may request deletion without an export at any time during this period. If the Customer requests an export, AA-sec will delete the corresponding active evaluation data after the export has been completed and delivered, unless continued retention has been expressly agreed or is required by applicable law.

Archived evaluation data will not be used for unrelated purposes.

16. Fees, invoicing, and payment

The commercial model may include:

Fees, usage limits, included services, billing periods, and payment conditions are specified in the individual Agreement.

Unless otherwise stated, prices are denominated in euros and exclude value-added tax and other applicable taxes, charges, or duties.

Unless the individual Agreement specifies another payment period, invoices are payable within fourteen calendar days from the invoice date without deduction.

If the Customer requires additional time to pay, it must request an extension in writing before the invoice becomes overdue. AA-sec is not obliged to grant an extension.

In the event of late payment, AA-sec may charge statutory default interest and reasonable recovery costs in accordance with applicable Austrian law.

Before suspending access solely because of a payment default, AA-sec will normally provide a reasonable additional payment period. AA-sec may suspend access or terminate the Agreement if the outstanding amount is not paid within that additional period.

Any refund of prepaid fees is subject to the individual Agreement and applicable law. If a prepaid price included a volume, term, or comparable commitment discount, AA-sec may reasonably take that discount into account when calculating any refundable amount.

17. Price changes

AA-sec may change prices by providing reasonable advance notice to the Customer. Unless a shorter period is required by law or expressly agreed, notice of a material price increase will be provided at least two months before the change takes effect.

A price change does not retroactively change fees already paid or unconditionally due for a completed billing period.

If a material price increase applies during an agreed fixed term and is not caused by an increase in scope, usage, taxes, third-party charges expressly passed through under the Agreement, or a customer-requested change, the Customer may terminate the affected Service before the increase takes effect.

18. Availability and support

AA-sec will use commercially reasonable efforts to maintain the availability of the hosted Platform. Any availability target or binding availability commitment applies only where it is specified in the applicable Service Description or Service Level Agreement.

Any binding calculation method, service credits, severity levels, and response or restoration targets must be specified in an applicable Service Level Agreement.

Unless otherwise agreed, availability calculations may exclude:

Standard support is available by email on Austrian business days. Applicable support hours, communication channels, response targets, telephone support, and any extended-support arrangements are specified in the applicable Service Description or individual Agreement.

Extended support, dedicated communication channels, telephone support, shorter response targets, and 24-hour support may be purchased or agreed separately.

19. Changes to the Services

AA-sec may maintain, update, improve, replace, or modify the Services to address security, legal, regulatory, technical, operational, or product-development requirements.

AA-sec will provide at least two months’ advance notice of a material change that significantly reduces core paid functionality, unless:

If a notified change materially reduces the primary functionality purchased by the Customer, and AA-sec cannot provide a reasonable alternative, the Customer may terminate the affected Service before the change takes effect.

In that case, AA-sec will refund prepaid fees attributable to unused full months following the effective date of termination. A month is considered started and used if more than five Austrian business days of that month have elapsed.

20. On-premises deployments

Where an on-premises deployment is agreed, the Customer is responsible for the infrastructure under its control, including:

AA-sec is responsible for the AA-sec software and professional services within the scope expressly agreed in the individual Agreement.

Hosted-service availability targets do not apply to an on-premises environment. Updates, maintenance, supported versions, deployment services, and support conditions for an on-premises installation are specified in the individual Agreement.

21. Confidentiality

Each party must protect the other party’s Confidential Information using at least reasonable care and no less care than it uses to protect its own confidential information of a comparable nature.

Confidential Information may be used only for performing, receiving, administering, or enforcing the Agreement and may be disclosed only to personnel, professional advisers, contractors, or subprocessors who need the information for that purpose and are subject to appropriate confidentiality obligations.

Confidential Information does not include information that the receiving party can demonstrate:

A party may disclose Confidential Information where required by law, a court, or a competent authority. Where legally permitted, the receiving party will give reasonable advance notice to the disclosing party.

Confidentiality obligations apply during the Agreement and for five years after its termination.

Trade secrets remain protected for as long as they retain their status as trade secrets. Personal data remains protected in accordance with applicable data-protection law and the Data Processing Agreement. Security-vulnerability information remains protected for as long as unauthorised disclosure could reasonably create a security risk.

Confidential Information may be disclosed or used beyond these restrictions where the disclosing party has given express permission.

22. Data export, retention, and deletion

During an active subscription, the Customer may use available export functionality to export Customer Data in the formats supported by the Services.

Following termination, the Customer may request one final export of Customer Data within a post-termination period of up to twelve months, unless:

During the post-termination export period, AA-sec retains the relevant Customer Data solely for the purpose of enabling the Customer’s final export or a lawful reactivation expressly agreed by the parties.

AA-sec may require reasonable identity, authority, and security verification before providing a final export.

Following the first completed and delivered final export, AA-sec will delete the relevant active Customer Data without undue delay, unless the Customer has expressly requested continued retention or retention is required by applicable law. Deletion remains subject to the Data Processing Agreement, technical backup rotation, and applicable legal retention obligations.

The Customer may request deletion without an export at any time during the post-termination period.

Where no final export is requested within the applicable period, AA-sec may delete the data after that period expires.

Residual copies in protected backups may remain until overwritten in the ordinary backup cycle. Such residual copies will remain protected and will not be restored except for legitimate disaster-recovery, security, or legal purposes.

23. Business continuity and provider cessation

AA-sec recognises the importance of Customer Data continuity and will design and operate the Services with the objective of preventing avoidable loss of Customer Data.

If AA-sec decides to discontinue the Platform, cease the relevant business activity, wind down operations, or permanently stop providing the Services, AA-sec will, to the extent legally and technically possible:

AA-sec will maintain reasonable backup, recovery, and continuity measures appropriate to the nature of the relevant Service.

Where a customer requires continuity protection beyond the standard export and backup arrangements, the parties may agree additional measures, including:

In the event of insolvency, legal restrictions or decisions of a court-appointed insolvency administrator may affect AA-sec’s ability to perform contractual obligations. AA-sec will, within the limits of applicable law and its remaining technical and legal authority, take reasonable measures to preserve the Customer’s ability to retrieve its Customer Data.

This section does not transfer ownership of Customer Data to AA-sec. Customer Data remains the property of the Customer or the relevant rights holder and must not knowingly be treated by AA-sec as an asset available for sale independently of the Services.

24. Suspension

AA-sec may temporarily suspend all or part of the Services where reasonably necessary to:

Where reasonably possible, AA-sec will notify the Customer before suspension and limit the suspension to the affected functionality or users.

25. Term and termination

The Agreement begins and continues for the term specified in the individual Agreement or as otherwise provided by applicable law.

Subscriptions do not renew automatically unless automatic renewal is expressly agreed in the individual Agreement.

Ordinary termination rights and notice periods are determined by the individual Agreement. Unless otherwise agreed, the intended standard notice period is two months.

Either party may terminate the Agreement for material breach if the other party fails to remedy the breach within ten Austrian business days after receiving written notice specifying the breach.

Immediate termination remains available where:

Termination does not affect rights, payment obligations, or claims accrued before the effective termination date.

Provisions concerning Customer Data, export, deletion, confidentiality, intellectual property, liability, payment, dispute resolution, and obligations intended by their nature to survive will continue to apply after termination.

26. Warranties

AA-sec will provide the Services with reasonable professional care and in material accordance with the applicable Agreement.

AA-sec does not warrant that the Services will be uninterrupted, completely error-free, or suitable for every customer-specific purpose.

AA-sec does not warrant the completeness or accuracy of Customer Data, third-party data, public vulnerability information, third-party standards, external databases, or information supplied by the Customer.

Recommendations and Outputs may depend on assumptions, configuration, available evidence, data quality, and the scope agreed with the Customer.

27. Liability

To the maximum extent permitted by applicable law, AA-sec’s aggregate liability arising out of or in connection with an Agreement is limited to the net fees paid or payable by the Customer for the affected Services during the twelve months preceding the event giving rise to the claim.

To the maximum extent permitted by applicable law, AA-sec is not liable for:

AA-sec does not accept responsibility for the Customer’s decision to release a product, accept a vulnerability, classify a risk, claim regulatory conformity, submit documentation, or rely on an Output without the review required by applicable law, professional practice, or the Customer’s internal procedures.

In the event of loss or corruption of Customer Data caused by AA-sec, AA-sec’s liability is limited to the reasonable and documented cost of restoring the affected data from the most recent available backup maintained by AA-sec under the applicable Service Description. Such liability remains subject to the overall liability cap stated above.

Nothing in the Agreement excludes or limits liability to the extent that exclusion or limitation is prohibited by mandatory applicable law. This includes liability that cannot lawfully be limited due to intentional misconduct, personal injury, or other mandatory statutory grounds.

The Customer must take reasonable steps to prevent and mitigate loss and must notify AA-sec of a potential claim without undue delay after becoming aware of the relevant circumstances.

28. Force majeure

Neither party is liable for delay or failure to perform an obligation, other than an obligation to pay an amount already due, to the extent caused by circumstances beyond its reasonable control.

Such circumstances may include natural disasters, widespread telecommunications failures, power-grid failures, war, terrorism, civil disturbance, epidemic measures, government action, labour disputes not limited to the affected party, and major failures of external infrastructure that could not reasonably have been prevented.

29. Changes to these General Terms and Conditions

AA-sec may amend these General Terms and Conditions to reflect legal, regulatory, security, technical, operational, or reasonable commercial changes.

AA-sec will notify affected Customers of material changes at least two months before they take effect, unless a shorter period is required by law or necessary to address an urgent security or legal issue.

If a material amendment significantly disadvantages the Customer, the Customer may object before the effective date. If the parties cannot resolve the objection, the Customer may terminate the affected Service before the amendment takes effect.

An amendment to these General Terms and Conditions does not override an inconsistent provision in an individual Agreement signed by both parties.

30. Governing law and jurisdiction

The Agreement is governed by the laws of the Republic of Austria, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.

Mandatory provisions of European Union law and any other mandatorily applicable law remain unaffected.

The courts having subject-matter jurisdiction for the registered office of AA Security Platform Austria GmbH have exclusive jurisdiction, to the extent such agreement on jurisdiction is legally permitted.

31. Language

These General Terms and Conditions may be made available in English and German. In the event of any inconsistency between the language versions, the English version prevails.

If an individual Agreement expressly specifies another prevailing language, that provision applies. In all cases, an individual Agreement expressly accepted by both parties takes precedence over conflicting provisions in these General Terms and Conditions.

32. Assignment

The Customer may not assign or transfer the Agreement or access to the Platform without AA-sec’s prior written consent, which must not be unreasonably withheld where the transfer does not create material legal, security, or commercial risk.

AA-sec may transfer the Agreement to an affiliated company or as part of a merger, reorganisation, financing, or transfer of the relevant business, provided that the transfer does not materially reduce the Customer’s contractual rights and remains subject to applicable data-protection law.

33. Notices

Contractual notices may be sent by email to the addresses specified in the Agreement or through an agreed customer portal.

Notices concerning termination, material breach, material changes, or legal claims must be sent in a form that permits the sender to retain evidence of delivery.

Each party is responsible for keeping its contact details current.

34. General provisions

The Agreement constitutes the entire agreement between the parties concerning its subject matter and replaces prior representations or understandings concerning that same subject matter.

Amendments and waivers are effective only if agreed in the form required by the individual Agreement or applicable law.

A failure or delay in exercising a right does not waive that right.

If a provision of the Agreement is invalid or unenforceable, the remaining provisions remain effective. The parties will replace the affected provision with a lawful provision that most closely reflects its intended commercial purpose.

The parties are independent contractors. The Agreement does not create a partnership, agency, employment relationship, fiduciary relationship, or joint venture.

35. Contact

Questions concerning these General Terms and Conditions may be sent to: contact@double-a-sec.com.