Skip to content

Terms of Service

The agreement between your organisation and the operator of CRA Sentinel. Sections 3, 4 and 12 matter most: they set out what this software does not do, and what remains your responsibility.

Effective date
2026-09-03
Provider
Enete Ebube Basil · 3534461-2 · VAT FI35344612
Business address
Taitoniekantie 9 R, 40740 Jyväskylä, Finland

1Parties, and who may use the service

These terms are an agreement between Enete Ebube Basil (“we”, “us”, “the operator”), a Finnish private trader trading as CRA Sentinel, Business ID 3534461-2, VAT number FI35344612, business address Taitoniekantie 9 R, 40740 Jyväskylä, Finland, and the organisation that creates or joins a CRA Sentinel account (“you”, “the customer”).

Business use only. CRA Sentinel is offered to businesses and professional users acting in the course of a trade or profession. It is not offered to consumers, and it is not intended for personal, family or household use.

By creating an account or using the service you represent that you are acting for an organisation and that you have authority to bind the organisation you create or join to these terms.

2What the service is

CRA Sentinel is a software tool. It supports your Cyber Resilience Act vulnerability-monitoring, triage, evidence and reporting workflows by providing:

  • an inventory of the products and supported product versions you record;
  • ingestion of software bills of materials, and a component inventory derived from them;
  • continuous monitoring of those components against third-party vulnerability sources;
  • awareness of vulnerabilities that those sources report as actively exploited;
  • a workflow in which a named person on your team makes technical triage decisions;
  • reporting cases, deadline tracking and preparation of notification content;
  • an append-only evidence history, with export; and
  • notifications about the above.

3What the service is not

The service does not provide, and we do not undertake to provide:

  • legal advice, or any other regulated professional advice;
  • regulatory representation, or communication with any authority on your behalf;
  • a determination of whether an event is legally reportable;
  • submission or filing of any report or notification to ENISA, to a CSIRT, or to any other authority;
  • a security guarantee, or assurance that your products or ours are free of vulnerabilities;
  • certification of any kind; or
  • a guarantee of compliance with the Cyber Resilience Act or any other law.

Using CRA Sentinel does not make your organisation legally compliant. Nothing in the product or on our website is legal advice.

4Your responsibilities

You remain responsible for:

  • determining your own legal and regulatory obligations;
  • the accuracy and completeness of the data you upload, including software bills of materials;
  • deciding whether a product version is technically affected by a vulnerability;
  • deciding what is reportable, and reporting it;
  • filing reports with competent authorities, and meeting legal deadlines;
  • maintaining your own security controls, independently of this service; and
  • reviewing the alerts and findings the service surfaces to you.

The service records and organises decisions. It does not make them, and it does not relieve you of them.

5Vulnerability data comes from third parties

The vulnerability and exploitation information in the service is derived from third-party sources and from the documents you supply. Those sources may contain errors, may be incomplete, may be delayed, and may change after publication.

We do not warrant that every vulnerability, or every actively exploited vulnerability, affecting your products will be detected or surfaced. The service cannot identify a vulnerability that no source has published, or a component that no bill of materials records. Where coverage is limited, the service reports the limit; that reporting is itself best-effort.

6Accounts and access

You are responsible for the accounts created under your organisation, for keeping credentials confidential, and for activity carried out through them. Tell us promptly at [email protected] if you believe an account has been compromised.

Roles carry different permissions. Only an owner may manage the subscription, and machine API keys are refused for the triage and reporting decisions the product attributes to a named person.

7Acceptable use

You agree not to:

  • use the service unlawfully, or to infringe anyone's rights;
  • attack, overload, probe, scan or load-test the service, or attempt to gain unauthorised access to it or to another customer's data;
  • reverse engineer, decompile or disassemble the software, except to the extent applicable law gives you a right to do so that cannot be excluded by agreement;
  • share, resell or transfer credentials, or allow access by anyone outside your organisation except as agreed with us in writing;
  • upload malicious content, or content you have no right to disclose to us; or
  • use the service to build a competing product.

8Fees, renewal and taxes

Access to paid functionality requires an active subscription. Subscriptions are priced per organisation and each plan covers a number of products: Starter at €79 per month or €790 per year, covering up to 5 products; and Growth at €199 per month or €1,990 per year, covering up to 25 products. Enterprise arrangements are agreed separately and are not purchasable through the service. Prices are stated in euro. Taxes may apply depending on your billing details and applicable law.

A product means one of the distinct products you record in the service. Versions, SBOMs, components, scans and evidence entries are not counted towards the number a plan covers. Where your organisation holds more products than your current plan covers, we do not delete, hide or restrict access to anything you have already recorded; creating an additional product is unavailable until the number you hold is within your plan.

Subscriptions are charged in advance for the interval chosen and renew automatically for successive intervals of the same length until cancelled. Payment is processed by our payment provider; we do not receive or store your card details.

We may change prices on at least 30 days’ notice by email before the change takes effect for your organisation. You may cancel before it does.

If a payment fails, we will retry it and notify you; paid functionality continues during that period. If the subscription then lapses, entitlement changes as described in the Refund & Cancellation Policy, which forms part of these terms.

9Your data, and our intellectual property

You retain all rights in the content you put into the service. We retain all rights in the CRA Sentinel software, its interfaces and its documentation. Nothing here transfers ownership of either.

You grant us a limited, non-exclusive right to host, store, process and display your content only so far as is necessary to provide, secure, support and maintain the service for you, and to comply with law. That right is subject to the Privacy Policy and to applicable data-protection law.

We do not use your content to train machine learning models, we do not sell it, and we do not disclose it for advertising.

You confirm that you are entitled to upload the content you provide and that doing so breaches no third party’s rights and no confidentiality obligation you owe.

10Third-party services

The service depends on third-party infrastructure and data providers — hosting, database and storage, content delivery, email delivery, payment processing, and vulnerability and advisory data sources. Their availability, correctness and continuity are outside our control.

We choose those providers with care and remain responsible to you for our own performance, but we do not warrant the performance of a third party, and an interruption originating with one is not a breach of these terms by us.

11Availability

We provide no service level agreement unless one is separately agreed with you in writing. The service may be affected by planned and unplanned maintenance, provider outages, internet and network failures, and interruption of third-party interfaces.

We do not promise that the service will be uninterrupted, timely, or free of errors. We will make reasonable efforts to restore availability and, where practical, to give advance notice of planned maintenance.

12No compliance warranty

We do not warrant that use of the service will result in, or contribute to:

  • compliance with the Cyber Resilience Act or any other law;
  • acceptance of any report or notification by any authority;
  • avoidance of any fine, penalty, sanction or enforcement action;
  • detection or avoidance of any vulnerability; or
  • any security certification or attestation.

13Disclaimer of warranties

To the maximum extent permitted by applicable law, the service is provided on an “as is” and “as available” basis, and we disclaim all implied warranties and conditions that may lawfully be disclaimed, including implied warranties of merchantability, satisfactory quality, fitness for a particular purpose and non-infringement.

We do not attempt to disclaim any warranty or condition that cannot lawfully be disclaimed. Where applicable law does not allow a disclaimer, it does not apply to you.

14Exclusion of indirect loss

To the maximum extent permitted by applicable law, and subject to section 16, neither party is liable for indirect, special, incidental or consequential loss, or for loss of profit, loss of revenue, loss of anticipated savings, loss of business opportunity, business interruption, or loss of goodwill, however arising.

This exclusion does not affect your rights under data-protection law, and it is not intended to limit any remedy available to you under that law in respect of personal data.

15Aggregate liability cap

Subject to section 16, and to the maximum extent permitted by applicable law, the operator’s total aggregate liability arising out of or relating to these terms or the service, whether in contract, tort (including negligence) or otherwise, is limited to the fees paid or payable by the customer to the operator during the twelve months immediately preceding the event giving rise to the claim.

CRA Sentinel does not guarantee compliance with the Cyber Resilience Act or any other law, and does not guarantee the avoidance of regulatory enforcement, fines or penalties. Responsibility for legal and reporting decisions, and for filings with any authority, remains with the customer.

16Liability that cannot be limited

Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited. That includes, without limitation, liability for death or personal injury caused by negligence, liability for fraud or fraudulent misrepresentation, liability arising from gross negligence or wilful misconduct where applicable law so provides, and liability under mandatory data-protection law.

Sections 13, 14 and 15 apply only so far as applicable law allows. Where a limitation in those sections is held unenforceable or is adjusted, the remainder continues to apply to the extent permitted.

Nothing in these terms restricts your right to bring a claim, to complain to a supervisory or regulatory authority, or to exercise a statutory right.

17Customer indemnity

You will indemnify us against third-party claims, and against reasonable legal costs directly resulting from them, to the extent the claim arises from:

  • your unlawful use of the service; or
  • content or material you supplied to the service that infringes a third party's rights, or that you had no right to provide to us.

This indemnity is limited to those two cases. It does not apply to the extent a claim arises from our own breach, negligence or unlawful act, and it does not apply where you were following our written instructions. It is not an indemnity for regulatory fines or penalties imposed on either party.

We will notify you promptly of any claim covered by this section, will not settle it without your consent (not to be unreasonably withheld), and will give you reasonable cooperation and control of its defence.

18Suspension and termination

We may suspend access, in whole or in part and proportionately to the problem, where reasonably necessary because of a security threat, unlawful use, a material breach of these terms, or non-payment as reflected in your billing entitlement. Where practical we will tell you first, and we will restore access as soon as the reason has been resolved.

Suspension for non-payment follows the product’s billing behaviour: paid capacity stops, and read access to your existing records and continued work on open compliance cases does not. We will not delete your evidence history because a payment failed.

Either party may terminate for material breach that is not remedied within 30 days of written notice, or immediately where the breach cannot be remedied or where the law requires it. You may cancel your subscription at any time as described in the Refund & Cancellation Policy.

After termination we retain your data for the periods set out in the Privacy Policy, so that you can request an export and so that records with their own retention basis are not destroyed as a side effect.

19Force majeure

Neither party is liable for failure or delay in performance caused by an event beyond its reasonable control, including natural events, war, civil unrest, industrial action to which it is not a party, failure of public telecommunications or power networks, and failure or interruption of a third-party infrastructure provider. The affected party will notify the other and will use reasonable efforts to resume performance. This does not excuse an obligation to pay amounts already due.

20Changes to these terms

We may change these terms. We will give at least 30 days’ notice by email of a change that materially affects your rights or obligations, and the effective date at the top of this page will be updated.

Changes apply from their effective date onward. We will not apply a change retroactively to rights or liabilities that have already accrued. If you do not accept a change, you may cancel before it takes effect.

21Governing law and venue

These terms are governed by the laws of Finland, excluding its conflict-of-law rules and excluding the United Nations Convention on Contracts for the International Sale of Goods.

Disputes arising out of or in connection with these terms will be submitted to the District Court of Central Finland (Keski-Suomen käräjäoikeus), Finland, unless mandatory applicable law requires otherwise.

Nothing in this clause limits either party’s right to seek urgent injunctive relief from any competent court, or your right to contact or complain to a competent supervisory or regulatory authority.

Please contact us at [email protected] first. Most disputes are resolved faster by conversation than by process.

22General

Entire agreement. These terms, together with the Privacy Policy and the Refund & Cancellation Policy, are the entire agreement between the parties about the service and replace any previous understanding about it. Nothing in this clause limits liability for fraudulent misrepresentation.

Severability. If a provision is held invalid or unenforceable, it is modified to the minimum extent necessary to make it enforceable, or severed if it cannot be, and the rest of these terms continue in force.

Waiver. A failure or delay in enforcing a right is not a waiver of it, and a single or partial exercise does not prevent a further one.

Assignment. You may not assign or transfer these terms without our written consent, not to be unreasonably withheld. We may assign them to a successor in connection with a merger, acquisition or sale of substantially all relevant assets, on notice to you.

Notices. We give notice to the email address registered for your organisation. You give notice to [email protected].

No partnership. Nothing here creates a partnership, joint venture, agency or employment relationship between the parties.