This is a convenience translation. In case of divergence, the Portuguese (pt-BR) version prevails.
Terms
Terms of Use
Last updated: August 28, 2026version 1.0
01Acceptance of the terms
Access to the site or the product, by any user of any client organization, implies acceptance of these Terms and of the Privacy Policy. Whoever accepts on behalf of an organization declares having the authority to bind it contractually.
02About this website
The content of this site is informational and commercial. Three limits apply to everything displayed here:
- Example figures are not measurements. Every exposure range, confidence percentage or simulation shown on the site is labeled as an example and exists to show the product's output format, never an actual measurement of any organization.
- The site's content does not constitute legal, regulatory, actuarial or investment advice.
- We may change the site's content at any time, without prior notice.
03Description of the service
The platform provides cyber risk exposure quantification (as a value range, never a single point), control maturity management, an evidence trail and an action plan, aimed at institutions subject to operational and cyber resilience regulation.
The product does not replace independent legal, actuarial or audit advice; it is a decision-support tool whose outputs depend on the quality of the data entered by the client organization itself.
04Registration and account
- Access is individual, tied to a corporate e-mail, authenticated by a one-time code (no password).
- Each user is responsible for keeping access to their own e-mail secure; it is the only authentication factor.
- Access roles (executive, audit, operations, administrator) define what each user sees and edits, and are assigned by the client organization's administrator.
- The client organization is responsible for keeping its list of authorized users up to date, revoking access of those who leave.
05License of use
We grant the client organization a limited, non-exclusive, non-transferable and revocable license to use the product for the duration of the commercial contract, exclusively for the purposes described in the service description section. Reverse engineering, resale, or use to build a competing product are expressly prohibited.
06Obligations of the client organization and its users
- Enter truthful evidence and data: the product quantifies risk from what is declared; false data invalidates the analysis and may constitute misuse.
- Do not share access credentials between people.
- Do not attempt to access another client organization's data, nor to circumvent the isolation between organizations.
- Use the product in compliance with the legislation applicable to your regulated sector.
07Intellectual property
All software, the Indene brand, the content of this site, the interface and the quantification methodology belong to INDENE SECURITY LTDA or its licensors. The data entered by the client organization (evidence, assessments, process data) remains the property of that organization; we use it solely to provide the contracted service.
08Isolation between organizations
Each client organization operates in a logically isolated environment, enforced by row-level access control in the database (row-level security), not merely by application rules. One organization's data never appears, even in aggregate, on another organization's screen, except where the organization itself grants explicit access to an external consultant.
09Availability and service level
We use commercially reasonable efforts to keep the site and the product available. Scheduled maintenance is announced in advance whenever possible by e-mail to client organization administrators. A formal Service Level Agreement (SLA), with availability metrics and credits for downtime, will be defined in each client organization's specific commercial contract. Operational questions: contato@indene.io.
10Limitation of liability
To the maximum extent permitted by law, the liability of INDENE SECURITY LTDA for damages arising from the use of the product is limited to the amount effectively paid by the client organization in the 12 months preceding the event. We are not liable for business decisions made on the basis of calculated exposure ranges where the client organization entered incomplete, outdated or incorrect data.
As to this website, we are not liable for decisions made on the basis of example figures, which exist solely to demonstrate the product's output format.
11Termination
Either party may end the relationship under the conditions of the signed commercial contract. Once ended, the client organization's data follows the retention policy described in the Privacy Policy.
12Changes to these terms
Material changes to these Terms are communicated at least 30 days in advance to client organization administrators. Continued use of the site or the product after a change takes effect constitutes acceptance of the new version.
13Governing law, venue and target certifications
These Terms are governed by Brazilian law. The courts of the judicial district where INDENE SECURITY LTDA has its seat are elected as venue for any dispute, to the exclusion of any other, however privileged.
Legislation observed (in force)
- LGPD (Lei 13.709/2018)
- Marco Civil da Internet (Lei 12.965/2014)
- CMN Resolução 4.893/2021
- BCB Resolução 85/2021
Target certifications (none obtained)
- ISO/IEC 27001
- ISO/IEC 27701
- SOC 2 Type II