Legal
Terms of Service - CentralCSP
Last updated: July 9, 2026
Preamble: Acceptance of Terms
These Terms of Service, including all documents, policies, and addenda incorporated by reference (collectively, the "Agreement" or "Terms"), form a legally binding contract between CentralCSP ("CentralCSP", "we", "us", "our") and the entity or individual creating an account or using the Services ("Customer", "you", "your").
By accessing the CentralCSP website, creating an account, clicking a button or checkbox indicating acceptance (for example "I Agree"), or using any part of the Service, you confirm that you have read, understood, and agree to be bound by this Agreement in its entirety. If you do not agree to all of its terms, you must not access or use the Service.
If you accept this Agreement on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "Customer", "you", and "your" refer to that entity. If you lack such authority, you must not accept this Agreement or use the Service.
This Agreement expressly incorporates by reference the CentralCSP Privacy Policy and the CentralCSP Data Processing Agreement (DPA), each of which is an integral part of these Terms.
1. Definitions
- Service(s) means the web security and compliance tools and services provided by CentralCSP. This includes, without limitation, the CSP Scanner, CSP Evaluator, CSP Builder, the reporting endpoint (which collects all supported browser Reporting-API report types), event-based alerting, script inventory and vulnerability (CVE) detection, PCI DSS evidence generation, on-demand website security scanning, the hash and Subresource Integrity (SRI) calculators, the security-header checker, the API and MCP integrations, and any related websites (including centralcsp.com), software, documentation, and support. The definition also covers all updates, modifications, and new features introduced from time to time.
- Customer Data means all electronic data submitted to or generated by the Service by or for the Customer. It comprises (a) data provided by the Customer, including website URLs, existing Content Security Policies, information entered into forms, and browser reports transmitted to the reporting endpoint; and (b) data generated for the Customer, such as analysis reports, security and compliance scores, script inventories, vulnerability assessments, alerts, PCI DSS evidence, and the recommended Content Security Policies produced by the CSP Builder.
- Personal Data means information that constitutes "personal data", "personal information", or a similar term under applicable data protection laws, including the GDPR. This may include Authorized User account information (for example name and email) and personal data incidentally contained in browser reports (for example IP addresses or identifiers embedded in URLs).
- Authorized User(s) means an individual (such as an employee, consultant, or contractor of the Customer) authorized by the Customer to use the Service under the rights granted to the Customer.
- Documentation means the official user guides, articles, and technical or functional documentation for the Service provided by CentralCSP.
- Intellectual Property Rights means all registered and unregistered rights under patent, copyright, trademark, trade secret, database, and other intellectual property laws anywhere in the world.
- Confidential Information means non-public information disclosed by one party (the "Disclosing Party") to the other (the "Receiving Party") that is designated as confidential or that should reasonably be understood to be confidential. CentralCSP's Confidential Information includes the non-public aspects of the Service; the Customer's Confidential Information includes Customer Data.
- Order Form means an ordering document or online order specifying the Service(s) to be provided, entered into between the Customer and CentralCSP, incorporating this Agreement by reference and detailing the subscription term, fees, and any usage parameters.
- SLA means the CentralCSP Service Level Agreement, which sets out the availability commitment for the Covered Services and is provided to Enterprise customers on request as an optional addition to their plan, incorporated into this Agreement by reference where agreed.
2. The Service
2.1. License grant
Subject to the Customer's compliance with this Agreement and payment of all applicable fees, CentralCSP grants the Customer a limited, personal, non-exclusive, non-transferable, and non-sublicensable right to access and use the Service(s) and Documentation during the subscription term, solely for the Customer's internal business purposes and in accordance with any applicable Order Form. This Agreement grants a right to access and use the Service; it is not a sale of software or any underlying Intellectual Property Rights.
2.2. Acceptable use
The Customer shall not, and shall not permit any Authorized User or third party to:
- Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, structure, or algorithms of the Service, except to the extent this restriction is prohibited by applicable law.
- Access or use the Service to monitor its availability or performance, or for benchmarking or competitive purposes, including to build a competing product or service.
- Use the Service's scanning or analysis tools (for example the CSP Scanner or Evaluator, or on-demand scanning) on any website or digital property for which the Customer does not have explicit, verifiable, and lawful authorization to conduct such security assessments. This is a critical obligation: the legal burden of authorization rests entirely with the Customer, and a breach is grounds for termination.
- Use the Service to store or transmit content that is infringing, libelous, or otherwise unlawful, or that violates third-party privacy rights.
- Use the Service to transmit any viruses, worms, malicious code, or software intended to damage or alter a system or data.
- Attempt to gain unauthorized access to the Service or to any accounts, systems, or networks connected to it.
- Submit false, misleading, or malicious data (including fabricated browser or violation reports) with the intent to disrupt or degrade the Service or its analytical capabilities.
2.3. Service modifications and updates
CentralCSP may modify, enhance, update, or discontinue the Service(s) or any feature at its discretion. We will make commercially reasonable efforts to ensure that such changes do not materially decrease the core functionality of the Service(s) purchased by the Customer during an active subscription term.
2.4. Customer's implementation
The Customer is solely responsible for the actions required to use the Service. This includes correctly configuring the reporting endpoint on its web properties and correctly deploying any Content Security Policies generated by the Service to its servers, headers, or infrastructure. CentralCSP provides tools and recommendations, but responsibility for implementation, testing, and validation rests with the Customer. CentralCSP is not responsible for damage arising from the Customer's incorrect or incomplete implementation of a policy.
2.5. Free trials and free tools
CentralCSP may offer free trials or free tools (such as the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool). Any Service provided on a free basis is offered "AS IS", without warranty, support, or indemnification of any kind. Data you enter during a free trial is retained under our standard retention policy: browser reports are deleted after a rolling 90-day period, scan results are kept until you delete the corresponding website or workspace, and all other account data is kept until you delete your account. See the Privacy Policy and DPA for details.
2.6. Suspension
CentralCSP may suspend the Customer's or an Authorized User's access to the Service, in whole or in part, with notice where practicable, if: (a) the Customer materially breaches Section 2.2 (Acceptable Use); (b) the use poses a security risk to the Service, to CentralCSP's systems, or to others; (c) the use is unlawful or exposes CentralCSP to liability; or (d) an invoiced amount is overdue as described in Section 4.3. CentralCSP will limit any suspension in scope and duration to what is reasonably necessary and will restore access promptly once the cause is resolved. A suspension under this Section does not relieve the Customer of its payment obligations.
3. Customer Obligations
3.1. Account security
The Customer is responsible for all activity under its account(s) and for keeping its passwords and credentials confidential and secure. The Customer shall notify CentralCSP promptly of any unauthorized use of its account or any known or suspected security breach.
3.2. Authorized Users
The Customer is responsible and liable for the acts and omissions of its Authorized Users. Any breach of this Agreement by an Authorized User is deemed a breach by the Customer.
3.3. Customer Data accuracy and legality
The Customer represents and warrants that it has obtained all rights, consents, and permissions required to provide and use the Customer Data with the Service, and that the Customer Data and its use will not violate any law or infringe any third-party rights. This warranty is directly linked to the acceptable-use restriction on unauthorized scanning.
3.4. Compliance with laws
The Customer shall use the Service in compliance with all applicable laws and regulations, including those relating to data privacy and the transmission of technical or personal data.
4. Fees, Payment, and Subscription
4.1. Plans and fees
The Customer shall pay all fees in the applicable Order Form or as stated on the CentralCSP website. Fees are based on the plan purchased, not on actual usage. Except as otherwise specified, payment obligations are non-cancelable and fees paid are non-refundable.
4.2. Billing
Fees are invoiced in advance in accordance with the Order Form. The Customer is responsible for providing complete and accurate billing information. All fees are exclusive of taxes, which the Customer is responsible for paying. Payments are processed by our third-party payment processor; we do not store full card details.
4.3. Late payments
If an invoiced amount is overdue, without limiting our other remedies, it may accrue interest at 1.5% of the outstanding balance per month, or the maximum permitted by law, whichever is lower, and we may suspend access to the Service until payment is made.
4.4. Auto-renewal
Unless otherwise specified in an Order Form, the subscription renews automatically for successive periods equal to the expiring term, unless either party gives written notice of non-renewal at least thirty (30) days before the end of the term. Renewal pricing is CentralCSP's then-current pricing unless otherwise agreed in writing.
5. Intellectual Property and Data Rights
5.1. CentralCSP's intellectual property
CentralCSP and its licensors retain all right, title, and interest, including all Intellectual Property Rights, in the Service, the underlying technology, the Documentation, and any modifications or derivative works. This Agreement conveys no ownership in the Service. The CentralCSP name, logo, and product names are trademarks of CentralCSP or third parties; no right to use them is granted.
5.2. Customer's intellectual property
As between the parties, the Customer owns all right, title, and interest in the Customer Data, including the Customer's website content and the data generated by it (all types of reports collected and the various policies generated).
5.3. License to provide the Service
The Customer grants CentralCSP a worldwide, non-exclusive, royalty-free, limited-term license to host, copy, transmit, display, and otherwise use Customer Data as reasonably necessary to provide, maintain, and support the Service for the Customer.
5.4. License for service improvement
The Customer grants CentralCSP a perpetual, irrevocable, worldwide, royalty-free, non-exclusive license to use, copy, modify, and create derivative works of Customer Data in aggregated and de-identified (anonymized) form, for the purposes of improving the Service, developing new features, and conducting research and industry reporting (for example our periodic "State of the Web" report). This clause supports the continuous improvement of the platform while preserving the Customer's ownership of its identifiable data. CentralCSP exercises this license consistently with the DPA; in particular, where a browser report incidentally contains personal data, that data is never used for public research reporting, and any conflict between this Section and the DPA is resolved in favour of the DPA. For the avoidance of doubt, CentralCSP does not use Customer Data to train, fine-tune, or develop artificial intelligence or machine-learning models, and does not share Customer Data with any third-party AI service.
5.5. Feedback
If the Customer or an Authorized User provides feedback, comments, or suggestions about the Service ("Feedback"), such Feedback is given voluntarily, and CentralCSP may use, disclose, and exploit it without obligation or restriction.
5.6. Publicity
The Customer grants CentralCSP the right to use and display the Customer's name and logo to identify the Customer as a customer of CentralCSP, on CentralCSP's website and in its marketing materials, presentations, and customer lists. CentralCSP will use the logo in accordance with any reasonable trademark usage guidelines the Customer provides, and this right does not otherwise transfer any ownership of the Customer's trademarks. The Customer may opt out at any time by written notice to the contact details in Section 12, after which CentralCSP will cease new use of the Customer's name and logo within a reasonable period.
6. Confidentiality, Privacy, and Security
6.1. Confidentiality
The Receiving Party shall protect the Disclosing Party's Confidential Information with at least the same degree of care it uses for its own confidential information of like kind (and no less than reasonable care), shall not use it outside the scope of this Agreement, and shall not disclose it to any third party except as authorized in writing.
6.2. Privacy Policy
CentralCSP collects, uses, and discloses Personal Data in accordance with its Privacy Policy, which is incorporated by reference and describes how we handle the information you provide when you use the Service.
6.3. Data Processing Agreement (DPA)
To the extent CentralCSP processes Personal Data contained in Customer Data on the Customer's behalf, and such processing is subject to data protection laws such as the GDPR, the parties are bound by the CentralCSP Data Processing Agreement, which is incorporated by reference. The DPA sets out the roles and obligations of the parties as required by regulations such as the GDPR and provides the contractual assurances Customers need for their own compliance. The DPA covers the following details of processing:
| Processing detail | Description |
|---|---|
| Subject-matter of the processing | Collection and analysis of browser-generated security telemetry and website security data to monitor and enhance the security of the Customer's web properties. |
| Duration of the processing | For the term of the Customer's subscription, and as specified in the data retention section of the DPA (a rolling 90-day maximum for browser reports; scan results are kept until the Customer deletes the corresponding website or workspace). |
| Nature and purpose of the processing | To provide the Services, including collecting and analysing all supported browser Reporting-API report types, generating event-based alerts, maintaining a script inventory and detecting vulnerabilities (CVEs), producing PCI DSS evidence, scanning and evaluating website security, and generating recommended CSP policies. To use aggregated, anonymized data for service improvement. |
| Type of Personal Data processed | Account data: name, email, company, password (hashed). Report and scan data: IP addresses, user-agent strings, URLs, and other technical data incidentally contained in browser reports and scan results. No special categories of data and no cardholder data. |
| Categories of Data Subjects | The Customer's Authorized Users, and End-Users of the Customer's websites whose browsers submit reports. |
| Obligations and rights of the Controller | The Customer's obligations and rights as data controller are set out in this Agreement and the DPA. |
6.4. Security measures
CentralCSP maintains appropriate administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data against unauthorized access, use, modification, or disclosure. These are based on industry standards and include data encryption, access controls, and secure development practices, as further described in the DPA. All Customer Data is hosted within the European Union.
7. Warranties and Disclaimers
7.1. Mutual warranties
Each party represents and warrants that it has the legal power and authority to enter into this Agreement.
7.2. Disclaimer of warranties
Except as expressly provided, the Service(s) and all related components and information are provided on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind. CentralCSP disclaims all warranties, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.
Except as expressly set out in the SLA (which applies to Enterprise plans), CentralCSP does not warrant that the Service will be uninterrupted, timely, secure, or error-free, or that defects will be corrected. CentralCSP makes no guarantee regarding the results obtained from the Service, the accuracy of any security or compliance scores, or the effectiveness of any generated Content Security Policies. The Customer acknowledges that no security tool provides absolute protection, and CentralCSP does not guarantee that use of the Service will prevent all security vulnerabilities (such as XSS, click-jacking, or data injection) or that generated policies will be perfectly optimized or compliant in all circumstances. The Service is a tool to aid security efforts, not a guarantee of security.
8. Limitation of Liability
8.1. Cap on direct damages
In no event shall either party's total aggregate liability arising out of or related to this Agreement exceed the total amount paid by the Customer to CentralCSP in the twelve (12) months preceding the event giving rise to the claim. This limitation applies whether the claim is in contract or tort and regardless of the theory of liability.
8.2. Exclusion of indirect damages
Under no legal theory shall either party be liable for any indirect, special, incidental, exemplary, punitive, or consequential damages, including lost profits, losses, or expenses, whether or not the party was advised of the possibility of such damage.
9. Indemnification
You agree to indemnify and hold CentralCSP and its affiliates, officers, directors, agents, partners, and employees harmless from any claim or demand, including reasonable attorneys' fees, made by any third party arising out of your use of the Service or any act or omission by you (including the entity on whose behalf you enter into this Agreement). This obligation survives termination of this Agreement. The limitations of liability in Section 8 do not apply to this indemnity.
10. Term and Termination
10.1. Term
This Agreement begins on the date the Customer first accepts it and continues for the initial subscription term in the applicable Order Form. The term renews automatically as described in Section 4.4.
10.2. Termination for cause
Either party may terminate this Agreement for cause if the other materially breaches it and fails to cure the breach within thirty (30) days of written notice. If the Customer terminates for cause under this Section, CentralCSP will refund any prepaid fees covering the remainder of the subscription term following the effective date of termination.
10.3. Termination for convenience
The Customer may terminate its subscription at any time using the cancellation procedures within the Service. Such termination takes effect at the end of the then-current billing period, and the Customer is not entitled to a refund of prepaid fees.
10.4. Effect of termination
On termination or expiration, all rights granted to the Customer immediately cease. CentralCSP has no obligation to maintain Customer Data and may delete it, subject to the data-handling provisions of the DPA and applicable law (including the storage-limitation principle under the GDPR).
10.5. Survival
The following survive termination or expiration: Section 1 (Definitions), Section 4 (Fees) for fees owed, Section 5 (Intellectual Property and Data Rights), Section 6.1 (Confidentiality), Section 7 (Warranties and Disclaimers), Section 8 (Limitation of Liability), Section 9 (Indemnification), Section 10.4 (Effect of Termination), Section 10.5 (Survival), and Section 11 (General Provisions).
11. General Provisions
11.1. Governing law and jurisdiction
This Agreement is governed by and construed in accordance with the laws of France. Any dispute arising under or in connection with it is subject to the exclusive jurisdiction of the courts of France, subject to Section 11.2.
11.2. Dispute resolution
The parties shall first attempt to resolve any dispute through good-faith negotiation. If it is not resolved within a reasonable time, it shall be finally settled under the Rules of Arbitration of the International Chamber of Commerce (ICC) by one or more arbitrators appointed under those Rules. This clause does not prevent either party from seeking injunctive relief or litigating intellectual-property matters in a competent court.
11.3. Notices
Legal notices must be in writing and are deemed given on (i) personal delivery; (ii) the second business day after mailing; or (iii) the first business day after sending by email. Notices to CentralCSP are sent to the address in Section 12; notices to the Customer are sent to the email associated with its account.
11.4. Assignment
Neither party may assign its rights or obligations without the other's prior written consent, except that either party may assign this Agreement in its entirety in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets.
11.5. Force majeure
Neither party is liable for any failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control and occurring without its fault or negligence.
11.6. Entire agreement and order of precedence
This Agreement, including the Privacy Policy, the DPA, the SLA, and all Order Forms, is the entire agreement between the parties and supersedes all prior agreements concerning its subject matter. In the event of any conflict among these documents, the order of precedence is: (1) the Data Processing Agreement, (2) the applicable Order Form, (3) the SLA, and (4) these Terms of Service.
11.7. Modifications to these Terms
CentralCSP may modify these Terms at its discretion. For material changes we will provide notice through the Service's interface, by email to the address associated with your account, or by other reasonable means. Your continued use of the Service after the effective date of any change constitutes acceptance of the modified Terms.
11.8. Language
These Terms are drafted in English, which is the authoritative and legally binding version. Any translation (for example the French version) is provided for convenience only. In the event of any conflict, ambiguity, or divergence between the English version and a translated version, the English version prevails and governs.
12. Contact Information
For questions about these Terms or for legal notices, contact us at:
- Company: CentralSaaS (operating the CentralCSP service)
- Address: 1 Allée des Frênes, 38240 Meylan, France
- SIRET: 927 890 756 00012
- VAT: FR36927890756
- Country: France
- Contact: contact@centralcsp.com
- Hosting provider: OVHcloud, 2 rue Kellermann, 59100 Roubaix, France