Terms of Service

SITEY terms of service: what a license grants and limits, monthly and lifetime billing, authorized-scanning rules, liability, and Türkiye governing law.

Last updated: [DATE]

These terms of service (the “Terms”) govern your purchase and use of SITEY, the autonomous vulnerability management platform sold at siteyvm.com. SITEY is sold self-service: you buy online, you download the installer, and you deploy and operate the software in your own infrastructure. Read these Terms before you buy. They contain limits on what a license allows, rules about which systems you are permitted to scan, and a cap on our liability.

1. Acceptance

You accept these Terms when you do any of the following: create an account on siteyvm.com, complete a purchase, activate a license key, or install or run the software. If you accept on behalf of a company or other organisation, you confirm that you are authorised to bind it, and “you” means that organisation.

If you do not accept these Terms, do not create an account, do not purchase a license, and do not install the software.

These Terms apply together with our Privacy Policy and the prices published on the pricing page. If we have signed a separate written agreement with you, that agreement controls where it conflicts with these Terms.

2. Definitions

  • SITEY, we, us: [LEGAL ENTITY NAME], registered in Türkiye, [TRADE REGISTRY NUMBER], [REGISTERED ADDRESS], [TAX OFFICE AND TAX NUMBER].
  • You, Customer: the person or organisation that creates the account and pays for the license.
  • Software: the SITEY installer, server components, database schema, endpoint agents, scan and remediation engine, web interface, APIs and documentation, in any form we make available to you.
  • Engine feed: the detection content, scanner integrations, remediation knowledge base, risk-scoring data and model instructions that we publish as updates to the Software.
  • Deployment: one production installation of the Software operating against a single primary database, including the agents reporting into it.
  • Agent: the component you install on your own hosts so the Deployment can inventory, scan, patch and retest them.
  • License key: the credential issued to your account that permits a Deployment to run.
  • Activation: the process by which a License key is bound to a specific Deployment and machine fingerprint.
  • Target system: any host, network, application, container, repository, cloud account or device that you point the Software at.

3. How SITEY is delivered

SITEY is self-service software, not a managed service and not a consulting engagement. In practice that means:

  • You purchase online with a credit card. An account is required, because the account holds your license key and your download entitlements.
  • You download the installer and deploy it yourself, in infrastructure you control.
  • You roll out the Agents to your own hosts yourself, with your own credentials and your own change process.
  • We do not connect to, log into, or administer your environment. We have no remote access to your Deployment. We do not ship a backdoor, a support tunnel or a telemetry channel that carries your scan results.
  • Your database, findings, asset inventory, credentials, tickets and reports stay on your servers. Licence activation and update checks communicate with us. Optional integrations you enable, such as an AI provider or vulnerability databases, communicate directly with those third parties, as described in section 7.

The Software automates an eight-phase loop: discovery and scanning, collection and deduplication, AI validation and triage, risk scoring, assignment, remediation planning, automated patching, and retest and closure. Two of those phases act on your systems rather than only reading them. Section 8 sets out what that means for you.

4. License models and fees

We sell two license models. Both cover the same product and the same platform modules and scanner integrations. All prices are in US dollars and exclusive of VAT, KDV, withholding or any other tax, which is added at checkout or invoiced where applicable.

License Price Term Updates and support
Monthly subscription 599 USD per month Recurring. Renews every month on the purchase date until you cancel. Product updates and engine feed for as long as the subscription is active. Standard support.
Lifetime 5,999 USD one time Perpetual. The license does not expire and does not renew. One year of product updates and engine feed from the purchase date. Priority support.

The Lifetime price equals ten months of the monthly price. From month eleven onward it costs you nothing further to keep running.

After the first year, a Lifetime license continues to work perpetually with the content you hold at that point. Updates and engine feed stop unless you renew them at the then-current renewal price, [ANNUAL RENEWAL PRICE] per year. Renewal is optional. We will not disable a Lifetime Deployment because its update term has lapsed.

Payments are processed by Stripe. Your card details are handled by Stripe and are never stored by us. You are responsible for keeping a valid payment method on file for a Monthly subscription.

5. What your license grants

Subject to payment and to these Terms, we grant you a non-exclusive, non-transferable, non-sublicensable right to:

  • install and run one production Deployment of the Software per license, in infrastructure you own or lawfully control;
  • install and run Agents on Target systems you own or are authorised to test, with no separate per-agent fee;
  • run one non-production Deployment for staging, testing or disaster recovery, provided it is not used to scan production systems in parallel with your production Deployment;
  • use the outputs of the Software, including findings, reports, remediation plans and exported data, for any lawful purpose, including sharing them with your auditors, regulators, customers and insurers.

Findings, reports and all other data produced inside your Deployment are yours. We claim no ownership over them and no right to use them.

If you need more than one production Deployment, a Deployment operated on behalf of a third party, or use in a managed security service you resell, contact us at /contact/ first. We will quote it. Do not assume it is covered.

6. License restrictions

You may not:

  • run more production Deployments than the number of licenses you hold;
  • share, publish, mirror, torrent or otherwise distribute the installer, the Agents, the engine, the engine feed, or any part of the Software;
  • resell, rent, lease, sublicense, or operate the Software as a service for third parties, unless we have agreed that in writing;
  • transfer or assign your license key to another organisation without our written consent;
  • reverse engineer, decompile or disassemble the Software, or attempt to derive its source code, engine logic, model prompts or detection content, except to the extent that this restriction is unenforceable under mandatory applicable law, and then only within the limits that law allows;
  • circumvent, patch, emulate, proxy or tamper with license activation, license validation or update integrity checks, or use a key you did not obtain from us;
  • remove or alter copyright, license or attribution notices.

We do not restrict you from evaluating the product and publishing what you find. You may benchmark SITEY against other tools and publish the results, including results that are unfavourable to us. We ask only that you state the version and configuration you tested.

7. Activation and license checks

A Deployment must activate its license key against our license service before it will run, and it re-validates periodically thereafter. Activation binds the key to that Deployment’s machine fingerprint.

The license service receives only what it needs to do that: the license key, a derived machine fingerprint, the Software version, and a timestamp. It does not receive your scan results, your asset inventory, your findings, your credentials, your host names or your users’ personal data. See the Privacy Policy for detail.

You may move a Deployment to new hardware. Contact us to release the old binding. We do not charge for hardware migrations or for rebuilds after a disaster. [NUMBER] self-service reactivations per year are available from your account, after which we ask you to open a support request so we can confirm the reason.

Loss of connectivity to our license service does not immediately stop a running Deployment. A grace period of [GRACE PERIOD] applies, after which the Deployment will stop starting new scans until it can re-validate.

8. Your responsibilities as operator

You deploy it, you configure it, you run it. Specifically, you are responsible for:

  • the security, patching, backup and access control of the servers you install the Software on, and of its database;
  • the credentials you give the Software, including scan credentials, patching credentials and integration tokens, and for scoping them to least privilege;
  • who you grant access to inside the Software, and for reviewing that access;
  • your change control. The automated patching phase can install packages, apply configuration changes and restart services on your Target systems. The Software ships with approval gates, scheduling windows and scope limits. It is your decision how far to open them, and that decision is yours to test in a non-production environment first;
  • maintaining working, tested backups and rollback procedures before you enable automated remediation on any production system;
  • reviewing AI-generated validation, triage decisions, risk scores and remediation plans before acting on them in environments where a wrong action is costly. The Software is an automation tool operated by you, not a substitute for your judgement or for a human change approver.

9. Acceptable use and authorization to scan

This is the section we enforce most strictly.

You may only use SITEY against systems that you own, or that you have documented authorisation to scan, test and modify. The authorisation must cover scanning, exploitation checks used for validation, and automated remediation where you enable it.

You must not use the Software:

  • against any system you do not own and are not authorised in writing to test, including shared infrastructure, third-party SaaS, or a hosting provider’s network where the provider’s terms forbid it;
  • to launch, stage or support an attack, a denial of service, data theft, extortion or unauthorised access;
  • to test another party’s systems as a service unless both they and we have agreed to it in writing;
  • in breach of applicable law, including Turkish Penal Code provisions on unauthorised access to information systems and Law No. 6698 (KVKK), or of applicable export control and sanctions rules;
  • to develop a competing vulnerability management product, or to extract our detection content or engine feed for use in another product.

You are solely responsible for obtaining authorisation and for proving it if challenged. We have no visibility into what you scan, and we cannot obtain that authorisation for you. If we receive a credible abuse report, we may ask you for evidence of authorisation and may suspend the license under section 13 while we do.

10. Your data and your environment

Scan data, findings, evidence, credentials, reports and user accounts created inside your Deployment live in your database, on your infrastructure. We do not collect them, cannot read them, and hold no copy.

Because of that, we cannot restore your data, recover a lost database, or retrieve findings for you. Backup is entirely yours.

Data we do hold is limited to your account: name, work email, company, billing record, license keys, activation records and support correspondence. Our handling of that data is described in the Privacy Policy.

11. Billing, renewal and taxes

  • Monthly: charged in advance on the day of purchase and on the same day each month, until cancelled. The price for an active subscription is fixed for at least [PRICE NOTICE PERIOD] from any change we announce; we will email you before a price change takes effect, and you can cancel before it does.
  • Lifetime: charged once, in advance. There is no recurring charge. Optional update renewal after year one is charged only if you choose it.
  • If a payment fails, we will retry and notify you. If it remains unpaid after [DUNNING PERIOD], the license may be suspended under section 13. A suspended Monthly Deployment reactivates once payment succeeds.
  • Prices exclude taxes. Where we are required to collect VAT, KDV or a similar tax, it is added. Where you are required to apply withholding, you gross up so that we receive the listed amount.
  • Invoices are issued to the billing details in your account. Keep them accurate.

12. Cancellation and refunds

You can cancel a Monthly subscription at any time from your account. No call, no retention process, no notice period. Cancellation stops the next charge. Your Deployment keeps running until the end of the period you already paid for, and then license validation stops and the Deployment stops starting new scans. Your database and your data remain yours and untouched; you can export before the period ends.

We do not refund partial months on a Monthly subscription.

For a Lifetime license, you may request a refund within [REFUND WINDOW] days of purchase if you have not been able to get the product working in your environment. On refund, the license key is revoked and you must uninstall the Software and delete the installer. Outside that window, Lifetime purchases are final, as the product is delivered digitally and in full at purchase.

Refund requests go to /contact/ or info@siteyvm.com.

13. Suspension and termination

We may suspend or terminate a license if:

  • payment for a Monthly subscription fails and remains unresolved after notice;
  • we have credible evidence of piracy: a shared, cracked, emulated or resold key, a tampered activation check, or distribution of the installer or engine;
  • we have credible evidence that the Software is being used against systems you are not authorised to test, or for an attack;
  • you materially breach these Terms and do not fix the breach within 15 days of written notice, where the breach can be fixed.

For piracy or unauthorised scanning we may suspend immediately and investigate afterwards, because the harm is immediate. We will tell you why, in writing, and will restore the license if the report is wrong.

On termination you must stop using the Software, uninstall every Deployment and Agent, and delete the installer. Sections 6, 9, 16, 17, 18, 19, 20 and 21 survive termination. Termination for your breach does not entitle you to a refund.

You can terminate at any time by cancelling and uninstalling.

14. Support, updates and the engine feed

Support is delivered by email at info@siteyvm.com and through your account. Standard support applies to Monthly subscriptions; priority support applies to Lifetime licenses. Target first response times are [STANDARD RESPONSE TARGET] and [PRIORITY RESPONSE TARGET] on business days, Türkiye time. These are targets, not a contractual SLA, unless we have signed one with you separately.

Support covers installation, configuration, defects, scanner integration issues and license administration. It does not cover remediation of your vulnerabilities, operation of your environment, or writing your policies for you. We do not log into your systems.

Updates are delivered as new installer versions and engine feed content that you apply yourself, on your schedule. We do not push updates into your Deployment. We do not guarantee any specific feature, integration or release date, and roadmap statements are not commitments.

15. Third-party scanners and components

SITEY orchestrates third-party scanners and includes open-source components. Two consequences:

  • Commercial scanners we integrate with, such as Nessus and Acunetix, require your own license from their vendor. Your SITEY license does not include them, and we do not resell them. Open-source scanners such as OpenVAS, Nmap, Nuclei, ZAP, Trivy, MobSF and Semgrep are used under their own licenses.
  • Open-source components bundled with the Software are licensed to you under their own terms, which are listed in the documentation shipped with the installer. Where those terms conflict with these Terms for that component, they control for that component.

We are not responsible for the availability, accuracy, licensing or behaviour of third-party scanners, feeds or ticketing systems you connect.

16. Compliance mapping is not certification

The Software maps findings and controls to ISO 27001, PCI DSS, SOC 2, GDPR, KVKK and BDDK requirements, and produces reports against those mappings. Read that literally. We map to those standards. We are not certified against them on your behalf, we are not your auditor, and a SITEY report is not an audit opinion, a certification, a legal opinion or a regulatory filing. Your auditor decides what satisfies your obligations.

17. Warranty disclaimer

The Software is provided “as is”. To the fullest extent permitted by law, we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement.

Specifically, and with no hedging: no vulnerability scanner finds every vulnerability. We do not warrant that the Software will detect every vulnerability present in your environment, that its AI validation and triage will be correct in every case, that it will produce no false positives or false negatives, that automated remediation will succeed on every host, or that it will operate without interruption or error. Statements about closing critical vulnerabilities in 72 hours describe what the automated loop is designed to do in a properly deployed environment. They are a design target, not a warranty of outcome in yours.

Use of the Software does not make you secure, compliant or breach-proof, and it does not transfer responsibility for your security to us.

18. Limitation of liability

To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data, business interruption or reputational harm, even if advised such damages were possible.

Our total aggregate liability arising out of or relating to these Terms or the Software is limited to the amounts you actually paid us for the license in the twelve months before the event giving rise to the claim.

We are not liable for outages, data loss, failed changes or service disruption on your Target systems caused by scans, credentialed checks or automated remediation that you configured, scheduled or approved. Those actions run in your environment, under your control, with your credentials, within scopes and approval gates you set.

Nothing in these Terms excludes liability that cannot lawfully be excluded, including liability for death or personal injury caused by negligence, or for fraud or wilful misconduct.

19. Your indemnity

You will defend and indemnify us against third-party claims, regulatory actions, fines, losses and reasonable legal costs arising from your use of the Software in breach of section 9, including scanning, testing, exploiting or modifying systems you were not authorised to touch, and from your breach of section 6.

20. Governing law and disputes

These Terms are governed by the laws of the Republic of Türkiye, without regard to conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

The parties will first try to resolve any dispute in good faith, by written notice to info@siteyvm.com, within 30 days. If that fails, the [CITY] Courts and Enforcement Offices of Türkiye have exclusive jurisdiction.

If you are a consumer resident in a jurisdiction whose mandatory consumer protection law gives you a different forum or additional rights, that law applies to the extent it is mandatory. SITEY is sold for business use; consumer purchases are not our intended market.

21. General terms

  • Assignment: you may not assign these Terms or your license without our written consent, except to a successor of your whole business, with notice to us. We may assign on a merger or sale of our business.
  • Force majeure: neither party is liable for delay or failure caused by events beyond its reasonable control.
  • Severability: if a provision is held unenforceable, the rest remains in force and the provision is limited to the minimum extent necessary.
  • No waiver: not enforcing a provision once does not waive it.
  • Notices: we write to the email on your account. You write to info@siteyvm.com. Keep your account email current.
  • Entire agreement: these Terms, the Privacy Policy and your order confirmation are the whole agreement between us on this subject, and replace any prior statement, proposal or marketing claim.
  • Language: the English version of these Terms is the operative version. Any translation is provided for convenience. [CONFIRM: a Turkish version may be required for Turkish counterparties.]

22. Changes to these Terms

We may update these Terms. The “Last updated” date at the top always reflects the current version.

For material changes, we will email the address on your account at least [CHANGE NOTICE PERIOD] days before they take effect. For a Monthly subscription, continuing to pay after that date means you accept the new Terms; if you do not accept them, cancel before they take effect. For a Lifetime license, changes do not retroactively reduce the license rights you already paid for under section 5. They may apply to optional update renewals you buy afterwards.

23. Contact

Questions about these Terms, license scope, authorised use, or a refund: info@siteyvm.com, or the form at /contact/. Pricing detail is on the pricing page, and what the platform actually does is on the features page.

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], Türkiye. Trade registry [NUMBER]. Tax office [OFFICE], tax number [NUMBER].