Legal
Terms of Service
The terms on which KROMSE is made available, and the limits of what it claims to do.
Draft pending legal review
This document was drafted by the KROMSE team from the behaviour of the running product. It has not yet been reviewed by a qualified lawyer and is published so that design partners can read what actually happens to their data before they connect a repository. Fields KROMSE cannot answer today are left as explicitly marked blanks rather than filled with a commitment the product does not keep.
- Drafted on
- 2026-08-29
- Reviewing counsel
- [ TO BE COMPLETED — name and firm of the reviewing lawyer ]
- Review completed on
- [ TO BE COMPLETED — date of legal review ]
1. What KROMSE is, and what it is not
KROMSE is workflow software. It scans connected repository code, uploaded SBOMs and firmware, and selected container images. It collects security evidence and helps your team organize it into drafts a human reviews.
KROMSE does not do the following, and no part of these terms should be read as saying otherwise:
- KROMSE supports evidence and human review; it does not certify legal compliance.
- KROMSE is not a filing channel. Drafts require human approval and are never submitted automatically to a CSIRT, to ENISA, to a supervisory authority, or to any other external recipient.
- KROMSE does not provide legal advice. Its output is an operational signal, not an opinion on your obligations under the Cyber Resilience Act, NIS2, the AI Act, or anything else.
- KROMSE does not guarantee that a scan finds every vulnerability in your code, or that a finding it reports is genuine. Scanner output requires human judgement.
A conclusion about your regulatory position, and any decision to notify anyone of anything, remains yours and your advisers'.
2. Who these terms are between
Kromse S.L.
Proposed company name. Company registration is pending. The legal operator and registration details remain to be confirmed.
Contact: info@kromse.com
"You" means the organization whose workspace is being used. If you accept these terms while using a company email address or on behalf of a workspace, you confirm you are authorized to bind that organization.
3. Access during the design partner phase
KROMSE is currently made available to invited design partners. Access is granted per workspace and may be withdrawn. The product is under active development: features change, and behaviour you rely on today may change with little notice.
Commercial terms — fees, billing, invoicing, and what happens at the end of the design partner phase — are [ TO BE COMPLETED BY KROMSE — not established today ]. Where a separate order form or design partner agreement is signed, it should be stated here whether that document or these terms prevail on conflict, which is [ TO BE CONFIRMED BY LEGAL COUNSEL — KROMSE cannot determine this ].
4. Your account and your workspace
Authentication is handled by our authentication provider. You are responsible for the accounts you invite into your workspace, for the roles you grant them, and for removing people who should no longer have access. Actions taken in your workspace are recorded in a tamper-evident audit trail attributed to the user who took them.
5. What you authorize KROMSE to do
By attaching an input and starting a scan, you instruct KROMSE to:
- Read repository code at the selected commit through your approved GitHub App installation or the Git source you attach, including public Git repositories.
- Read the SBOM or firmware you upload, or retrieve the container image reference you select from its registry. An SBOM scan covers the components it lists, not an independent inspection of the whole product.
- Run scanners in temporary working directories and remove those working copies when processing finishes. Uploaded firmware is also retained as a product input, as described in the Privacy Policy.
- Store the resulting scan evidence, encrypted, for the retention period of your plan.
- Send supported component and advisory identifiers to vulnerability-data services for lookup and enrichment, including during deterministic scans, as detailed in the Privacy Policy.
- Send a bounded, secret-redacted selection of your code to an AI provider — but only for a scan where you have explicitly selected an AI model for that purpose.
You are responsible for the rights needed to provide each repository, SBOM, firmware file or container image, including any third-party content it contains.
The Privacy Policy describes precisely what is received, stored, and transmitted. Read it before connecting anything.
6. Optional AI review, chat and document reading
Scans default to deterministic analysis with no repository source code sent to an AI provider. Optional code review requires selecting an AI option for that scan. Sending a chat message sends that message and bounded workspace context to the selected provider: OpenAI for Auto, High and Extra high, or Mistral for the explicitly selected 🇪🇺 KROMSE option. Optional document OCR uses Mistral after a separate confirmation before transmission.
These actions have different inputs, described in the Privacy Policy. Provider retention and other data controls depend on the applicable account configuration and provider terms; this draft makes no fixed retention or whole-product EU-only processing promise.
AI output is a hypothesis for a human to check. It is presented as such in the product and should be treated as such.
7. Acceptable use
- Scan only code you are entitled to scan.
- Do not use KROMSE to attack, probe, or test systems you do not own or have written permission to test.
- Do not attempt to reach another customer's workspace, or to circumvent the scoping that keeps workspaces separate.
- Do not upload malware for distribution, or use KROMSE to develop or stage an attack.
- Do not present KROMSE output as a certification, an audit, or legal advice — to a regulator, a customer, or anyone else.
8. Ownership
Your code, your evidence, and everything your team writes into the workspace remain yours. KROMSE claims no ownership over them and uses them to operate the service for you.
KROMSE does not use your source code or your workspace content to train machine learning models, and does not sell it. Where an optional AI provider is used, that provider's own terms govern what it does with the request; the Privacy Policy names each provider and the retention position KROMSE has been able to confirm.
The software, interface, and documentation remain KROMSE's.
9. Availability
[ TO BE COMPLETED BY KROMSE — not established today ]. There is no uptime commitment, no support response time, and no maintenance window policy today. KROMSE is provided on an as-available basis during the design partner phase. Do not write an availability figure here until one is measured and can be honoured.
10. Ending the arrangement
You may stop using KROMSE and disconnect your repositories at any time. Disconnecting a GitHub App installation revokes access through that installation. It does not remove separately attached Git sources or make public repositories inaccessible at their host.
KROMSE may suspend or end access for a breach of section 7, or at the end of the design partner phase.
What happens to your data when access ends: [ TO BE COMPLETED BY KROMSE — not established today ]. Evidence expires on the schedule described in the Privacy Policy, but there is no implemented export-on-exit and no committed deletion turnaround. Both need to exist in the product before either is promised here.
11. Warranties, liability, and governing law
[ TO BE CONFIRMED BY LEGAL COUNSEL — KROMSE cannot determine this ]. Warranty disclaimers, the limitation and exclusion of liability, indemnities, the governing law, and the forum for disputes are the clauses where a badly drafted document does the most damage, and where a non-lawyer draft is worth least. They are deliberately left empty rather than filled with plausible-looking boilerplate. This document must not be presented to a customer as a contract until counsel has written them.
One point is not a placeholder and should survive review in substance: because KROMSE does not certify compliance and does not submit anything on your behalf, nothing in the product is a substitute for your own legal determination, and reliance on scan output as though it were is not a use KROMSE can stand behind.
12. Changes to these terms
These terms are versioned. The current version is shown at the foot of this page. When the text changes materially the version is raised, and you are asked to accept the new version — the record of what you accepted before is kept rather than being overwritten.
Advance notice before a change takes effect: [ TO BE COMPLETED BY KROMSE — not established today ]. Re-acceptance is requested at next use; there is no advance notification mechanism today.
13. Contact
For questions about these terms, contact info@kromse.com.
The other documents
KROMSE provides workflow software, not legal advice, certification, or automatic regulatory submission.
Version 2026-09-09