SecurityRing
PlatformHow it worksSecurityPricingPlay the game
Book a Demo
PlatformHow it worksSecurityPricingPlay the game
Legal

Terms of Service

These Terms govern organizational access to SecurityRing’s human-risk management, security-awareness, simulation, training, and reporting services.

Effective:
July 13, 2026
Last updated:
July 13, 2026
On this page
1. Agreement and scope2. Definitions and priority3. Eligibility and accounts4. The service5. Customer responsibilities6. Acceptable use7. Simulations and email delivery8. AI and synthetic media9. Content and intellectual property10. Data, security, and confidentiality11. Orders and fees12. Suspension13. Term and termination14. Warranties and disclaimers15. Indemnities16. Limitation of liability17. Governing law and disputes18. Changes and notices19. General terms and contact

On this page

1. Agreement and scope2. Definitions and priority3. Eligibility and accounts4. The service5. Customer responsibilities6. Acceptable use7. Simulations and email delivery8. AI and synthetic media9. Content and intellectual property10. Data, security, and confidentiality11. Orders and fees12. Suspension13. Term and termination14. Warranties and disclaimers15. Indemnities16. Limitation of liability17. Governing law and disputes18. Changes and notices19. General terms and contact

Important — authorized business use only

SecurityRing is a business-to-business security-awareness service. It may be used only for controlled, lawful exercises approved by the organization responsible for the people and systems involved. It must not be used for real phishing, credential theft, malware delivery, unauthorized surveillance, or public deception.

1. Agreement and scope

These Terms of Service (the “Terms”) form a binding agreement between 9DSEMBER SOFTWARE PRIVATE LIMITED, a private limited company incorporated in India that operates the SecurityRing service (“SecurityRing,” “we,” “us,” or “our”), and the customer that accesses or uses the Service (“Customer,” “you,” or “your”). An applicable Order Form may include additional contracting details but does not change the identity of SecurityRing unless it expressly names another contracting entity.

By accepting an Order Form, creating or using an administrative account, or otherwise using the Service on behalf of an organization, you agree to these Terms and represent that you have authority to bind that organization. If you lack that authority or do not agree, do not use the Service. The Service is offered for organizational use and not as a consumer service.

Individuals who receive a Customer-authorized simulation or training experience are not required to create a SecurityRing account. Our handling of their personal data is described in the Privacy Policy; the Customer’s own workforce or privacy notices may also apply.

2. Definitions and priority

Key definitions

  • “Authorized User” means a Customer employee, contractor, or representative whom Customer permits to use an administrative account.
  • “Customer Content” means rosters, campaign content, prompts, templates, brands, files, configurations, and other material submitted to the Service by or for Customer.
  • “Documentation” means current user guides, technical instructions, and in-product guidance supplied by SecurityRing.
  • “Order Form” means an ordering document, statement of work, online order, or other written commercial agreement referencing these Terms.
  • “Recipient” means a person included in a Customer-authorized simulation, assessment, notification, or training activity.
  • “Service” means SecurityRing’s websites, applications, APIs, simulation and training pages, email and domain workflows, AI-assisted features, reports, and related support covered by an Order Form or trial authorization.

Order of priority

If documents conflict, the following order applies unless the documents expressly state otherwise: (1) a signed Data Processing Agreement (“DPA”) for personal-data matters; (2) the applicable Order Form; (3) these Terms; and (4) the Documentation. A Customer purchase order does not modify the agreement, and its additional terms are rejected unless SecurityRing expressly accepts them in writing.

3. Eligibility and accounts

  • Authorized Users must be at least 18 years old and legally able to enter contracts for Customer.
  • Customer must provide accurate account and workspace information, keep it current, and promptly remove access for anyone who is no longer authorized.
  • Customer is responsible for activity under its accounts and for protecting authentication sessions, devices, API credentials, sender credentials, and integration secrets. Credentials may not be shared between users.
  • Customer must promptly notify SecurityRing at neha@securityring.ai of suspected unauthorized access or misuse.
  • SecurityRing may rely on Customer’s identity provider and workspace-domain controls. Customer is responsible for enforcing appropriate multi-factor authentication and access policies in that identity provider.

4. The service

Subject to the agreement, SecurityRing grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable subscription or evaluation period to access and use the Service for Customer’s internal security-awareness, training, testing, risk-management, and compliance purposes.

The Service may allow Customer to:

  • import and manage authorized workforce records and organizational attributes;
  • create, approve, schedule, pace, and deliver controlled security simulations;
  • use email, landing pages, quizzes, training videos, attachments, QR codes, OAuth-consent or device-code scenarios, and other supported educational interactions;
  • generate or edit campaign content and recommendations with AI-assisted tools;
  • request or configure sender, landing, tracking, mailbox, and domain resources;
  • measure delivery and Recipient interactions and produce reports or remediation recommendations; and
  • send operational notifications, test messages, approvals, reminders, and periodic reports.

Specific functionality, limits, support, regions, providers, and service levels may vary by Order Form, configuration, deployment stage, and third-party availability. SecurityRing may improve the Service and may replace functionality with materially equivalent functionality. Material reductions to purchased core functionality will not take effect during a paid subscription without reasonable notice, except where required for security, law, or third-party-provider changes.

5. Customer responsibilities

Customer determines the purpose, scope, audience, timing, lawful basis, and employment context of each simulation. Customer is solely responsible for obtaining and maintaining the organizational approvals and legal authority necessary for its use of the Service.

Before using the Service, and throughout use, Customer must:

  1. ensure that it has a lawful basis and all rights needed to provide Customer Content and Recipient data to SecurityRing and to instruct the processing described in the agreement;
  2. provide all notices and obtain all consents or authorizations required by privacy, employment, labor, electronic-communications, monitoring, anti-spam, intellectual-property, and other applicable laws;
  3. consult workers, representatives, works councils, unions, data protection officers, or regulators where required, and complete any required legitimate-interest assessment or data protection impact assessment;
  4. limit campaigns to Recipients with whom Customer has an appropriate relationship and to systems, domains, brands, and infrastructure that Customer owns or is authorized to test;
  5. configure targeting, sender identities, domains, allowlisting, pacing, approvals, training, and reporting in a proportionate manner that minimizes harm and unnecessary collection;
  6. conduct human review of campaign content, AI Output, risk indicators, and reports before launch or use;
  7. maintain a process for Recipient questions, complaints, accommodations, and privacy requests; and
  8. ensure that simulation results are used for security education and proportionate risk management, not as the sole basis for termination, discipline, compensation, promotion, hiring, or another decision producing legal or similarly significant effects.

Customer remains responsible for Authorized Users, Customer Content, Recipient selection, and instructions provided to SecurityRing, including actions performed through integrations or administrator-approved workflows.

6. Acceptable use

Customer and Authorized Users must not use or enable use of the Service to:

  • conduct real phishing, fraud, extortion, identity theft, credential theft, or unauthorized impersonation;
  • collect, retain, transmit, or solicit actual passwords, authentication codes, private keys, financial account details, government identifiers, health data, or other unnecessary sensitive information;
  • deliver malware, executable payloads, destructive files, unauthorized tracking technology, or code intended to compromise, disrupt, or gain access to a device, account, network, or service;
  • send unsolicited commercial messages, purchased-list campaigns, cold outreach, or messages to the public or to people outside Customer’s authorized scope;
  • evade suppression lists, provider restrictions, rate limits, security controls, sender-verification controls, abuse detection, or campaign approval gates;
  • harass, discriminate against, shame, threaten, or target a person based on a protected characteristic or vulnerability, or create unreasonable risk of physical, psychological, financial, or reputational harm;
  • misrepresent a simulation as an instruction from law enforcement, emergency services, a regulator, or a financial institution in a way that is unlawful or likely to harm a third party;
  • infringe intellectual-property, privacy, publicity, confidentiality, contractual, or other rights, including by using a person’s voice, face, likeness, or identity without sufficient authorization;
  • reverse engineer, probe, scan, copy, resell, sublicense, benchmark for competitive publication, or interfere with the Service except to the extent a restriction is prohibited by law; or
  • use the Service in violation of sanctions, export controls, court orders, or applicable law.

Customer may conduct good-faith security testing of its own configured experience only with SecurityRing’s written authorization and within an agreed test scope. Reports of suspected misuse may be sent to abuse@securityring.ai.

7. Simulations and email delivery

Controlled simulation requirements

Simulation messages may intentionally resemble workplace communications, but Customer must ensure each campaign is approved, scoped, proportionate, and connected to a legitimate training objective. Customer must not direct Recipients to send money, disclose real secrets, install software, or take actions that create actual operational, legal, or financial consequences.

A simulated form may record that a Recipient submitted the form. SecurityRing is designed not to intentionally retain the contents typed into simulated credential fields. Customer must not modify or use the Service to capture real credentials or other sensitive field contents.

Sender and domain controls

Customer may use a verified Customer-controlled sender, a provider-authorized sender, or a SecurityRing resource approved for the campaign. Customer represents that it has the right to use each requested display name, mailbox, domain, logo, and brand reference. Customer must maintain accurate DNS and authentication records where applicable and may not use lookalike domains to deceive anyone outside the approved exercise.

Delivery and suppression

Delivery depends on Customer configuration and third-party email, DNS, registrar, mailbox, filtering, and internet services. SecurityRing does not guarantee inbox placement, exact delivery time, open detection, or that security scanners will not interact with a message. Addresses associated with complaints, hard bounces, or repeated soft bounces may be suppressed. Customer must not bypass a suppression or re-add a suppressed address without documented lawful justification and SecurityRing approval.

8. AI and synthetic media

AI-assisted features

The Service may use third-party or SecurityRing-operated artificial-intelligence systems to generate campaign briefs, emails, pages, quizzes, videos, recommendations, classifications, summaries, or other output (“AI Output”). AI Output may be incomplete, inaccurate, biased, non-unique, or inappropriate for Customer’s context. It is provided as a draft and not as legal, employment, compliance, or security advice.

  • Customer must review, test, and approve AI Output before use.
  • Customer must not submit secrets or personal data to an AI feature unless necessary, authorized, and permitted by the applicable Order Form and DPA.
  • Customer must not represent AI Output as authentic evidence, a real third-party communication, or a human statement outside the controlled simulation context.
  • SecurityRing does not use Customer workforce data to train general-purpose AI models. Service providers may process inputs and outputs only to provide contracted functionality, subject to applicable provider terms and SecurityRing’s agreements with them.

Synthetic voice, image, and video

Customer may use synthetic or manipulated media only when it has documented permission for every person’s voice, face, likeness, performance, and other protected material involved. Customer must apply disclosures, provenance labels, watermarking, or notices required by law, and must disclose the simulated or synthetic nature of the experience at an appropriate point in the training flow. Customer must not create sexually explicit content, exploit vulnerable persons, impersonate public officials unlawfully, or publish synthetic media beyond the approved exercise.

9. Content and intellectual property

Customer Content

As between the parties, Customer retains its rights in Customer Content. Customer grants SecurityRing and its subprocessors a worldwide, limited, non-exclusive right to host, copy, transmit, transform, display, and otherwise process Customer Content only to provide, secure, support, and improve the operation of the Service, comply with law, and carry out Customer’s documented instructions.

Customer represents and warrants that it has all rights and lawful authority needed for Customer Content and its use, including for employee records, imported attributes, brands, trademarks, copyrighted material, uploaded files, sender identities, domains, personal likenesses, and instructions supplied to AI or media providers.

SecurityRing materials

SecurityRing and its licensors retain all rights in the Service, software, Documentation, templates, interfaces, methods, models, designs, and aggregated service know-how, excluding Customer Content. No rights are granted except those expressly stated in the agreement. If Customer provides feedback, Customer grants SecurityRing a perpetual, irrevocable, worldwide, royalty-free right to use it without identifying Customer or disclosing Customer Confidential Information.

Generated output

Subject to applicable law, provider terms, and third-party rights, Customer may use AI Output generated specifically for Customer during the subscription for Customer’s authorized internal purposes. SecurityRing does not warrant that AI Output is protectable, exclusive, non-infringing, or unlike output generated for others.

10. Data, security, and confidentiality

Data roles and instructions

For Customer-provided workforce data and Recipient interaction data, Customer generally acts as controller, business, or data fiduciary and SecurityRing acts as processor, service provider, or data processor on Customer’s behalf. The applicable DPA governs that processing. SecurityRing acts independently for account, security, billing, abuse-prevention, and website data it determines how and why to process, as described in the Privacy Policy.

Security

SecurityRing will maintain reasonable administrative, technical, and organizational safeguards appropriate to the Service and the data processed. Customer is responsible for secure configuration, Authorized User access, identity-provider controls, integrations, devices, and copies of data exported from the Service. Customer acknowledges that no system or transmission is completely secure.

Confidentiality

“Confidential Information” means non-public information disclosed by one party (“Discloser”) to the other (“Recipient”) that is marked confidential or reasonably should be understood as confidential. Customer Content is Customer Confidential Information; non-public Service technology and pricing are SecurityRing Confidential Information. Confidential Information excludes information the Recipient can document was lawfully known without restriction, independently developed, publicly available without breach, or lawfully received from a third party.

Recipient will use Confidential Information only to perform or exercise rights under the agreement, protect it with at least reasonable care, and disclose it only to personnel and service providers who need to know it and are bound by confidentiality obligations. A legally compelled disclosure is permitted if Recipient gives advance notice where lawful and reasonable assistance at Discloser’s expense.

11. Orders and fees

Subscription scope, usage limits, fees, currency, taxes, invoicing, and payment terms are stated in the Order Form. Except as expressly stated, fees are non-cancellable and non-refundable. Customer must pay undisputed invoices when due and notify SecurityRing of a good-faith dispute before the due date. Overdue undisputed amounts may accrue the lesser of 1.5% per month or the maximum lawful rate, plus reasonable collection costs.

Fees exclude taxes. Customer is responsible for applicable sales, use, goods and services, value-added, withholding, and similar taxes, excluding taxes based on SecurityRing’s net income. If Customer must withhold, it will provide valid documentation and cooperate to reduce withholding lawfully.

Trials, previews, betas, or evaluations are provided for the period and limits stated by SecurityRing and may be modified or ended at any time. Unless an Order Form states otherwise, they are provided without service levels, warranties, indemnities, or support commitments.

12. Suspension

SecurityRing may immediately suspend or limit access, a campaign, sender, domain, integration, or other resource when reasonably necessary to:

  • stop suspected fraud, phishing, abuse, unlawful monitoring, or other prohibited activity;
  • protect Recipients, third parties, the Service, sending reputation, or provider infrastructure;
  • respond to a complaint, legal demand, provider directive, security incident, or credible rights claim;
  • prevent material harm, unauthorized access, or excessive load; or
  • address undisputed fees more than 15 days overdue after notice.

Where practicable, SecurityRing will give notice and an opportunity to cure and will limit the suspension to the affected activity. SecurityRing may preserve relevant records where reasonably necessary for investigation, legal compliance, or dispute resolution.

13. Term and termination

These Terms begin when Customer first accepts them or uses the Service and continue while any Order Form or authorized use remains active. Subscription renewal and notice periods are stated in the Order Form.

Either party may terminate an Order Form for an uncured material breach if the breaching party does not cure within 30 days after written notice, or within 10 days for non-payment. Either party may terminate immediately if the other becomes insolvent, ceases business without a successor, or enters a proceeding not dismissed within 60 days. SecurityRing may terminate immediately for material or repeated Acceptable Use violations where cure is impossible or continued access presents material risk.

On termination, Customer’s access ends and Customer must stop using Service materials except exported reports lawfully retained. At Customer’s written request made before termination or within 30 days after it, SecurityRing will provide a reasonable export of available Customer data where technically feasible. SecurityRing will delete or return Customer personal data as required by the DPA, subject to legal retention, security records, and backups that remain protected and are deleted through normal cycles.

Accrued payment obligations and provisions that by their nature should survive—including confidentiality, intellectual property, disclaimers, indemnities, liability limits, disputes, and general terms—survive termination.

14. Warranties and disclaimers

Each party warrants that it has authority to enter the agreement. SecurityRing warrants that paid Service will materially conform to applicable Documentation under normal authorized use and that it will provide the Service with reasonable skill and care. Customer’s exclusive remedy for breach of this warranty is correction or re-performance; if SecurityRing cannot materially cure within a reasonable period, Customer may terminate the affected Order Form and receive a pro-rata refund of prepaid unused fees for the terminated portion.

EXCEPT FOR THE EXPRESS WARRANTIES ABOVE AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE, AI OUTPUT, TEMPLATES, RECOMMENDATIONS, REPORTS, TRIALS, AND THIRD-PARTY SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” SECURITYRING DISCLAIMS ALL IMPLIED OR STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE.

SECURITYRING DOES NOT WARRANT UNINTERRUPTED OR ERROR-FREE OPERATION, INBOX PLACEMENT, DETECTION OF EVERY HUMAN OR AUTOMATED INTERACTION, PREVENTION OF SECURITY INCIDENTS, OR ANY PARTICULAR COMPLIANCE, EMPLOYEE-BEHAVIOR, OR RISK OUTCOME. THE SERVICE SUPPORTS—BUT DOES NOT REPLACE—CUSTOMER’S LEGAL, EMPLOYMENT, SECURITY, AND HUMAN REVIEW.

15. Indemnities

Customer indemnity

Customer will defend SecurityRing and its personnel against third-party claims arising from Customer Content, Customer’s instructions, an unauthorized or unlawful campaign, Customer’s breach of Sections 5–8, or Customer’s violation of a Recipient’s or third party’s rights, and will pay resulting damages, settlements, and reasonable legal fees finally awarded or approved by Customer.

SecurityRing intellectual-property indemnity

For a paid subscription, SecurityRing will defend Customer against a third-party claim that Customer’s authorized use of SecurityRing’s unmodified Service infringes that third party’s patent, copyright, or trademark, and will pay resulting damages, settlements, and reasonable legal fees finally awarded or approved by SecurityRing. This does not cover Customer Content, AI Output, third-party services, combinations not supplied by SecurityRing, continued use after notice, or use contrary to the agreement. SecurityRing may modify or replace the affected Service, obtain rights for continued use, or terminate the affected feature and refund prepaid unused fees for it. This paragraph states Customer’s exclusive remedy for such claims.

Process

The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation at the indemnifying party’s expense, and allow it sole control of defense and settlement. Delay relieves obligations only to the extent materially prejudicial. No settlement may admit fault by or impose non-monetary obligations on the indemnified party without its written consent, not to be unreasonably withheld.

16. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THEIR POSSIBILITY.

EXCEPT FOR THE EXCLUSIONS BELOW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE GIVING RISE TO THE CLAIM DURING THE 12 MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY. FOR FREE OR EVALUATION SERVICE, SECURITYRING’S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED USD 100.

The exclusions and cap do not limit Customer’s payment obligations; either party’s fraud, willful misconduct, or liability that cannot lawfully be limited; Customer’s breach of Acceptable Use; or a party’s indemnity obligations. Liability for breach of confidentiality or data-protection obligations is capped at two times the general cap, except where a signed DPA or Order Form states a different cap.

These allocations apply regardless of the theory of liability and even if a remedy fails its essential purpose. Some jurisdictions do not allow certain limitations, so they apply only to the extent lawful.

17. Governing law and disputes

The governing law and forum stated in the applicable Order Form control. If the Order Form is silent, the agreement is governed by the laws of India, without regard to conflict-of-laws rules, and the courts located in Gurugram, Haryana, India have exclusive jurisdiction. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

Before filing a claim, each party will give written notice describing the dispute and allow senior representatives at least 30 days to attempt good-faith resolution. Either party may seek urgent injunctive or equitable relief to protect security, Confidential Information, intellectual property, or prevent unlawful use. Mandatory statutory rights and forums that cannot be waived remain unaffected.

18. Changes and notices

Changes to these Terms

SecurityRing may update these Terms to reflect legal, security, provider, or Service changes. The updated date will appear above. Material changes will be notified through the Service, by email, or through an Order Form contact at least 30 days before taking effect, unless a shorter period is required by law or to address urgent security or abuse risks. Changes will not retroactively reduce rights for an existing paid subscription. Continued use after the effective date constitutes acceptance; if Customer objects to a material change, it must stop using the affected Service and notify SecurityRing before that date.

Contractual notices

Notices to SecurityRing must be sent to neha@securityring.ai and are effective when received. SecurityRing may send notices to the account, billing, security, or legal contact in the Order Form or workspace. Routine operational messages may be delivered in-product. A party must keep its notice contacts current.

19. General terms and contact

  • Assignment. Neither party may assign the agreement without the other’s consent, except to an affiliate or in connection with a merger, reorganization, or sale of substantially all relevant assets, provided the assignee assumes the obligations and is not a direct competitor of the non-assigning party. Unauthorized assignments are void.
  • Subcontractors. SecurityRing may use subprocessors and subcontractors but remains responsible for their performance to the extent required by the agreement.
  • Force majeure. Neither party is liable for delay caused by events beyond reasonable control, excluding payment obligations. The affected party will use reasonable efforts to mitigate and resume performance.
  • Independent parties. The parties are independent contractors. The agreement creates no partnership, agency, fiduciary, employment, or franchise relationship.
  • No third-party beneficiaries. The agreement benefits only the parties and permitted successors, except indemnified parties solely for applicable indemnity rights.
  • Severability and waiver. An unenforceable provision will be modified to the minimum extent necessary and the remainder stays effective. Waiver must be in writing and is not a continuing waiver.
  • Entire agreement. The agreement is the complete agreement about the Service and supersedes prior or contemporaneous discussions on that subject. Headings are for convenience; “including” means “including without limitation.” Electronic acceptance and signatures are valid.

Questions about these Terms

Contact SecurityRing at neha@securityring.ai or at the address below.

9DSEMBER SOFTWARE PRIVATE LIMITED
Operator of SecurityRing
4th Floor, C1-614, Choma (62), Carterpuri Road
Palam Vihar Extension, Gurugram, Haryana 122017, India
GSTIN: 06AADCZ0579R1ZJ
Udyam Registration No.: UDYAM-HR-05-0196052
SecurityRing

Security awareness training, phishing simulation and human risk management for CISOs and GRC teams. Build continuous preparedness with relevant simulations, timely learning, and measurable progress.

Book a Demoneha@securityring.ai

Product

Platform overviewWhatsApp simulation (beta)RecommendationsDeepfake trainingEmail simulationsAI builderShort lessonsRisk dashboardReports

Company

Real or Fake? ChallengeCustomer storiesHow it worksSecurity & privacyPricingLoginContact us

Legal

Privacy policyTerms of serviceCookie policy
© 2026 SecurityRing. All rights reserved.Prepare. Protect. Repeat.