Terms of Service
Last updated: 26 September 2026
1. Introduction
These Terms of Service ("Terms") govern the use of Tveir, Venor's AI-assisted security operations service (the "Service"). The Service is provided by Venor AB (org. nr 559116-3695), Stockholm, Sweden ("Venor", "we", "us"). These Terms apply to the organisation that has been given access to the Service (the "Customer") and to every person the Customer allows to use it ("Users").
The Service is provided to businesses only. It is not offered to consumers.
If the Customer and Venor have signed a separate agreement for the Service, that agreement takes precedence over these Terms where the two conflict. If there is no signed agreement, these Terms are the agreement. By using the Service, the Customer and its Users accept these Terms.
2. The Service
The Service connects to security products the Customer authorises, such as endpoint detection and response or identity protection platforms, receives their alerts, and triages them. For each alert it produces an assessment, such as a classification, a severity, the findings behind them and recommended next steps.
Depending on the settings the Customer chooses, the Service may also:
- close alerts it assesses as not requiring action;
- escalate alerts to destinations the Customer configures, such as chat, ticketing or on-call tools;
- write its assessment back to the source platform as a comment and update the alert's status there.
To assess an alert, the Service may query the Customer's connected platforms for related information. It may also run public web searches using details from the alert, such as file names, domains and hashes, and in some cases names of people that appear in it.
Venor sets up each Customer's environment. Venor may change, improve or remove features of the Service. It will give at least 30 days' notice of changes that materially reduce the Service's functionality.
3. Accounts and sign-in
Users sign in with an existing Google or Microsoft account through Venor's sign-in service, or with a password. The Customer decides who may access its environment and is responsible for:
- keeping its list of Users current;
- the accounts and identity systems its Users sign in with;
- all activity carried out under its Users' accounts.
The Customer must tell Venor without undue delay if it suspects unauthorised access to its environment.
4. The Customer's responsibilities
The Customer is responsible for:
- having the legal right to connect every system it connects to the Service, and to let Venor process the data those systems contain on its behalf;
- the credentials it provides for connected systems, including limiting them to the access the Service needs;
- the settings it chooses, including which alerts are closed automatically, what is written back to its platforms, and where alerts are escalated;
- keeping its own security processes. The Service supports the Customer's security operations; it does not replace the Customer's responsibility for them.
5. AI-generated output
The Service's assessments are produced by AI models and automated analysis. They can be incomplete or wrong, and the same alert can be assessed differently at different times. Assessments are decision support. The Customer remains responsible for security decisions made using the Service, including decisions carried out automatically under settings the Customer has enabled.
The Customer should review assessments with the care their consequences warrant, particularly before relying on an automatic closure.
6. Acceptable use
The Customer and its Users must not:
- use the Service unlawfully, or to process data they have no right to process;
- connect systems or accounts they are not authorised to connect;
- try to get around the Service's security or access controls, or probe or test its vulnerabilities without Venor's written permission;
- reverse engineer the Service, except as far as the law allows despite this restriction;
- use the Service, or its output, to build a competing product or to develop or train AI models;
- resell the Service or give third parties access to it, except as agreed with Venor in writing;
- use the Service in a way that breaks the usage policies of the AI providers it relies on. Venor will provide these on request.
7. Customer Data
"Customer Data" means the data the Service receives from the Customer's connected systems and Users, and the assessments it produces from that data. As between the parties, Customer Data belongs to the Customer. The Customer gives Venor the right to process Customer Data to provide, secure and support the Service.
Venor does not sell Customer Data, and does not use it to train AI models. Customer Data is stored in the European Union, unless the Customer and Venor agree in writing on another region.
Venor's access. Venor personnel can access the Customer's environment, including Customer Data, to operate, maintain, support and secure the Service and to investigate incidents. Venor limits this access to personnel who need it, bound by confidentiality.
Security. Venor implements appropriate technical and organisational measures to protect Customer Data. The Customer's systems and credentials remain the Customer's responsibility.
8. Data protection
This section is the parties' data processing agreement under Article 28 of the GDPR, unless they have signed a separate one.
Scope. Venor processes personal data in Customer Data on the Customer's behalf, for the term of the agreement, to triage the Customer's security alerts.
- Personal data involved: the identifiers found in security data, such as names, user names, email addresses, device names, IP addresses, file paths and command lines.
- People it concerns: the Customer's employees, contractors and others whose activity appears in the Customer's security data.
The Customer is the controller and Venor is the processor.
Venor will:
- Process the personal data only on the Customer's documented instructions. These Terms and the settings the Customer chooses in the Service are those instructions. Venor will tell the Customer if it believes an instruction breaks data protection law.
- Ensure that everyone authorised to process the data is bound by confidentiality.
- Implement the security measures required by Article 32 of the GDPR.
- Use subprocessors only as set out below.
- Help the Customer, taking into account the nature of the processing, to respond to requests from data subjects. It will likewise help with security, breach notification, data protection impact assessments and prior consultation (Articles 32–36 of the GDPR).
- Notify the Customer without undue delay, and no later than 48 hours after becoming aware of it, of a personal data breach affecting Customer Data.
- Delete the personal data when the agreement ends, as described in section 18, and give the Customer a copy first if it asks.
- Make available the information needed to demonstrate compliance with this section. It will also allow audits, requested in writing with 30 days' notice, at most once a year, carried out at the Customer's cost and under confidentiality.
Subprocessors. The Customer authorises Venor to use these subprocessors:
- Google: hosting and infrastructure (Google Cloud), AI analysis (Gemini) and sign-in
- Anthropic: AI analysis
- Microsoft: sign-in
- SerpApi: public web search
Venor will give at least 30 days' notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty. Venor imposes data protection obligations on each subprocessor equivalent to those in this section, and remains responsible for them.
Transfers. Some subprocessors process data outside the EU/EEA. Where they do, the transfer relies on the European Commission's Standard Contractual Clauses or, where the provider is certified under it, the EU–U.S. Data Privacy Framework.
Venor as controller. For Users' account and sign-in data, Venor is the controller, as described in its Privacy Policy at https://venor.se/privacy.
9. Trials and demonstrations
Venor may provide the Service on a trial or demonstration basis. Trials are free unless otherwise agreed, last for the period Venor states, and are provided "as is" without any commitment on availability or support. When a trial ends without a paid subscription, Venor may end access and delete the trial environment and its data.
10. Fees
Fees are set out in the Customer's agreement or order with Venor. Unless otherwise agreed, fees are invoiced in advance for each billing period, payable within 30 days of the invoice date, and exclude VAT. Late payments carry interest under the Swedish Interest Act (räntelagen). Venor may suspend the Service if undisputed fees remain unpaid 30 days after written notice.
11. Availability and support
Venor works to keep the Service available and to fix problems promptly, but does not promise uninterrupted or error-free operation. No service level applies unless one is agreed in writing. Support is provided by email at firstcontact@venor.se on Swedish business days, 08:00–17:00 Swedish time.
12. Suspension
Venor may suspend all or part of the Customer's access, with notice where reasonably possible, if:
- this is needed to prevent a security risk to the Service, to Venor or to other customers;
- the Customer or its Users materially breach these Terms;
- the law requires it.
Venor will restore access once the reason for the suspension no longer applies.
13. Intellectual property
Venor and its licensors own the Service, including its software, models, playbooks and documentation. These Terms give the Customer a right to use the Service during the term; they do not transfer ownership of anything. If the Customer gives Venor feedback, Venor may use it without obligation.
14. Confidentiality
Each party will keep the other party's non-public information confidential, and use it only for the purposes of these Terms. This applies to information disclosed in any form. It does not apply to information that is or becomes public without breach, that the receiving party already had, or that it developed independently. A party may disclose information when the law requires it, giving the other party notice where permitted. These obligations continue for three years after the agreement ends.
15. Warranties
Venor will provide the Service with reasonable skill and care. Beyond that, and to the extent the law permits, the Service is provided without warranties of any kind, express or implied. This includes warranties that it will detect every threat, that every assessment is correct, or that it is fit for a particular purpose.
16. Limitation of liability
Neither party is liable for indirect or consequential loss, including loss of profit, revenue, data or goodwill, or for loss arising from a security incident the Service did not detect or correctly assess.
Each party's total liability under these Terms is limited to the fees the Customer paid for the Service during the 12 months before the event giving rise to the claim. For free trials the limit is SEK 10,000.
These limits do not apply to liability for gross negligence or wilful misconduct, to the Customer's obligation to pay fees, or to the extent the law does not allow liability to be limited.
17. Customer indemnity
The Customer will hold Venor harmless from third-party claims arising from systems or data the Customer connected to the Service without the right to do so, or from the Customer's breach of section 6.
18. Term and termination
These Terms apply from the Customer's first use of the Service until its agreement or subscription ends. Either party may terminate the agreement on written notice if the other party materially breaches it and has not remedied the breach within 30 days of being told.
When the agreement ends, the Customer's access ends. Within 30 days, Venor deletes the Customer's environment, including the Customer Data, accounts and logs stored in it. Venor's infrastructure provider then completes permanent deletion under its own deletion process. Venor keeps only what it needs for its own accounting and legal obligations, such as the Customer's name and billing records.
If the Customer asks before the agreement ends, Venor will first provide a copy of the Customer's triage records in a machine-readable format, such as JSON.
19. Changes to these Terms
Venor may update these Terms. It will give at least 30 days' notice of material changes by email or in the Service. Continued use after that date means acceptance of the updated Terms. If the Customer does not accept a material change, it may terminate before the change takes effect.
20. Governing law and disputes
These Terms are governed by Swedish law, without regard to its conflict-of-law rules. Disputes will be settled by Swedish courts, with Stockholm District Court (Stockholms tingsrätt) as the court of first instance.
21. Contact
Venor AB
Org. nr 559116-3695
Stockholm, Sweden
+46 (0) 8 38 88 67