Last updated: 10 July 2026
These Terms govern your use of TCSR (Talivio Cyber Security Report), operated by Talivio Technology OÜ (registry code 16991406, Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia — "Talivio", "we"). By creating an account or using the service you agree to them.
TCSR scans domains and generates security assessment reports, optionally with continuous monitoring, a public trust badge, internal collector agents and one-off forensic investigations. Reports are provided "as is" and are informational only: they reflect what our modules could observe at a single point in time and detect only a subset of possible security issues. A passing scan, a good grade or a "clean" verdict does not mean your site is secure — it is not a security guarantee, an audit opinion or a certification, and it does not establish the absence of vulnerabilities or compromise. New vulnerabilities, misconfigurations or intrusions may exist that our modules did not or could not detect, and the security posture of any asset can change at any time after a scan.
You may only scan, probe or investigate systems you own or are expressly authorized in writing to test. By initiating any scan, collector run or forensic investigation, you represent and warrant that you own the target asset or hold a valid, current written authorization from its owner sufficient to permit the testing you initiate, and that such testing does not violate any law or any agreement binding on you. Unauthorized scanning or probing of third-party systems may be a criminal offence in many jurisdictions (for example under computer-misuse and anti-hacking laws) and may give rise to civil liability. You are solely responsible for verifying you have this right before every scan.
Passive versus active testing. The scope of authorization required depends on how intrusive the testing is:
Indemnity. You will defend, indemnify and hold harmless Talivio, its officers, employees and contractors from and against any and all claims, demands, proceedings, losses, damages, fines, penalties, regulatory or law-enforcement investigations, and costs and expenses (including reasonable legal fees) arising out of or relating to any scan, probe, collector run or forensic investigation you initiate without the required authority, or otherwise in breach of this section or applicable law. This obligation survives termination of your account and of these Terms.
Paid plans are billed monthly or yearly in advance via Stripe; you can cancel anytime and access continues until the end of the paid period. One-off products (such as forensic investigations and cleanup verifications) are sold as single purchases via Stripe and are consumed when you start the investigation. Fees are non-refundable except where required by law.
Each report carries a reference and SHA-256 fingerprint that third parties can check on our public verification page. The optional trust badge and public status page reflect the result of the most recent successful scan and automatically degrade to a neutral state when that result becomes stale; they are a statement that a scan took place and what it found, not a certification of security. You are responsible for how you distribute and act upon reports, badges and verdicts. Raw forensic evidence is retained only for a limited period after delivery, as described in the Privacy Policy.
We aim to keep the service available but provide it "as is" and "as available", without warranty of uninterrupted or error-free operation. The service depends on third-party systems we do not control (including Stripe, our AI provider and public data sources) and we are not responsible for their availability or decisions.
To the maximum extent permitted by law, the service is provided "as is" and "as available" and Talivio disclaims all implied warranties, including merchantability, fitness for a particular purpose and non-infringement. This disclaimer does not affect the statutory conformity rights that consumers have under Directive (EU) 2019/770 and applicable national law, which remain unaffected.
To the maximum extent permitted by law, Talivio is not liable for indirect, incidental or consequential damages, loss of profits or data, or for damage resulting from a security incident affecting an asset we scanned, from reliance on a report, or from scans you were not authorized to run. Our total aggregate liability under these Terms is limited to the fees you paid us in the twelve months before the event giving rise to the claim or, if you have paid no fees, to EUR 100.
Nothing in these Terms excludes or limits liability that cannot be excluded or limited under mandatory law, including liability for intent (wilful misconduct) or gross negligence, for death or personal injury, or under mandatory consumer-protection law.
You may stop using the service and close your account at any time. We may suspend or terminate accounts that violate these Terms or applicable law — including any unauthorized scanning.
These Terms are governed by the laws of Estonia, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG). The courts of Estonia, and in particular Harju Maakohus (Harju County Court) in Tallinn, have exclusive jurisdiction over disputes arising out of or in connection with these Terms. Nothing in this clause deprives you of the protection of mandatory provisions of the law of your country of habitual residence or establishment that cannot be derogated from by agreement.
Consumers. The service is intended for business and professional use. If you nonetheless use it as a consumer, the mandatory consumer-protection provisions of your country of habitual residence apply, and the Governing Law, Limitation of Liability and Warranty Disclaimer sections apply only to the extent that mandatory law permits. Mandatory data-protection law of your country of residence, where applicable, is not excluded by our choice of GDPR-based data practices described in our Privacy Policy.
Where we process personal data on your behalf (see section 4 of our Privacy Policy), we will, on request, enter into a GDPR Article 28 data processing agreement with business customers; our standard DPA is available from [email protected].
Questions: [email protected].