New: export PCI DSS v4 evidence from real browser traffic.

Legal

Terms of Service - CentralCSP

Last updated: July 9, 2026

Preamble: Acceptance of Terms

These Terms of Service, including all documents, policies, and addenda incorporated by reference (collectively, the "Agreement" or "Terms"), form a legally binding contract between CentralCSP ("CentralCSP", "we", "us", "our") and the entity or individual creating an account or using the Services ("Customer", "you", "your").

By accessing the CentralCSP website, creating an account, clicking a button or checkbox indicating acceptance (for example "I Agree"), or using any part of the Service, you confirm that you have read, understood, and agree to be bound by this Agreement in its entirety. If you do not agree to all of its terms, you must not access or use the Service.

If you accept this Agreement on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "Customer", "you", and "your" refer to that entity. If you lack such authority, you must not accept this Agreement or use the Service.

This Agreement expressly incorporates by reference the CentralCSP Privacy Policy and the CentralCSP Data Processing Agreement (DPA), each of which is an integral part of these Terms.

1. Definitions

2. The Service

2.1. License grant

Subject to the Customer's compliance with this Agreement and payment of all applicable fees, CentralCSP grants the Customer a limited, personal, non-exclusive, non-transferable, and non-sublicensable right to access and use the Service(s) and Documentation during the subscription term, solely for the Customer's internal business purposes and in accordance with any applicable Order Form. This Agreement grants a right to access and use the Service; it is not a sale of software or any underlying Intellectual Property Rights.

2.2. Acceptable use

The Customer shall not, and shall not permit any Authorized User or third party to:

2.3. Service modifications and updates

CentralCSP may modify, enhance, update, or discontinue the Service(s) or any feature at its discretion. We will make commercially reasonable efforts to ensure that such changes do not materially decrease the core functionality of the Service(s) purchased by the Customer during an active subscription term.

2.4. Customer's implementation

The Customer is solely responsible for the actions required to use the Service. This includes correctly configuring the reporting endpoint on its web properties and correctly deploying any Content Security Policies generated by the Service to its servers, headers, or infrastructure. CentralCSP provides tools and recommendations, but responsibility for implementation, testing, and validation rests with the Customer. CentralCSP is not responsible for damage arising from the Customer's incorrect or incomplete implementation of a policy.

2.5. Free trials and free tools

CentralCSP may offer free trials or free tools (such as the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool). Any Service provided on a free basis is offered "AS IS", without warranty, support, or indemnification of any kind. Data you enter during a free trial is retained under our standard retention policy: browser reports are deleted after a rolling 90-day period, scan results are kept until you delete the corresponding website or workspace, and all other account data is kept until you delete your account. See the Privacy Policy and DPA for details.

2.6. Suspension

CentralCSP may suspend the Customer's or an Authorized User's access to the Service, in whole or in part, with notice where practicable, if: (a) the Customer materially breaches Section 2.2 (Acceptable Use); (b) the use poses a security risk to the Service, to CentralCSP's systems, or to others; (c) the use is unlawful or exposes CentralCSP to liability; or (d) an invoiced amount is overdue as described in Section 4.3. CentralCSP will limit any suspension in scope and duration to what is reasonably necessary and will restore access promptly once the cause is resolved. A suspension under this Section does not relieve the Customer of its payment obligations.

3. Customer Obligations

3.1. Account security

The Customer is responsible for all activity under its account(s) and for keeping its passwords and credentials confidential and secure. The Customer shall notify CentralCSP promptly of any unauthorized use of its account or any known or suspected security breach.

3.2. Authorized Users

The Customer is responsible and liable for the acts and omissions of its Authorized Users. Any breach of this Agreement by an Authorized User is deemed a breach by the Customer.

3.3. Customer Data accuracy and legality

The Customer represents and warrants that it has obtained all rights, consents, and permissions required to provide and use the Customer Data with the Service, and that the Customer Data and its use will not violate any law or infringe any third-party rights. This warranty is directly linked to the acceptable-use restriction on unauthorized scanning.

3.4. Compliance with laws

The Customer shall use the Service in compliance with all applicable laws and regulations, including those relating to data privacy and the transmission of technical or personal data.

4. Fees, Payment, and Subscription

4.1. Plans and fees

The Customer shall pay all fees in the applicable Order Form or as stated on the CentralCSP website. Fees are based on the plan purchased, not on actual usage. Except as otherwise specified, payment obligations are non-cancelable and fees paid are non-refundable.

4.2. Billing

Fees are invoiced in advance in accordance with the Order Form. The Customer is responsible for providing complete and accurate billing information. All fees are exclusive of taxes, which the Customer is responsible for paying. Payments are processed by our third-party payment processor; we do not store full card details.

4.3. Late payments

If an invoiced amount is overdue, without limiting our other remedies, it may accrue interest at 1.5% of the outstanding balance per month, or the maximum permitted by law, whichever is lower, and we may suspend access to the Service until payment is made.

4.4. Auto-renewal

Unless otherwise specified in an Order Form, the subscription renews automatically for successive periods equal to the expiring term, unless either party gives written notice of non-renewal at least thirty (30) days before the end of the term. Renewal pricing is CentralCSP's then-current pricing unless otherwise agreed in writing.

5. Intellectual Property and Data Rights

5.1. CentralCSP's intellectual property

CentralCSP and its licensors retain all right, title, and interest, including all Intellectual Property Rights, in the Service, the underlying technology, the Documentation, and any modifications or derivative works. This Agreement conveys no ownership in the Service. The CentralCSP name, logo, and product names are trademarks of CentralCSP or third parties; no right to use them is granted.

5.2. Customer's intellectual property

As between the parties, the Customer owns all right, title, and interest in the Customer Data, including the Customer's website content and the data generated by it (all types of reports collected and the various policies generated).

5.3. License to provide the Service

The Customer grants CentralCSP a worldwide, non-exclusive, royalty-free, limited-term license to host, copy, transmit, display, and otherwise use Customer Data as reasonably necessary to provide, maintain, and support the Service for the Customer.

5.4. License for service improvement

The Customer grants CentralCSP a perpetual, irrevocable, worldwide, royalty-free, non-exclusive license to use, copy, modify, and create derivative works of Customer Data in aggregated and de-identified (anonymized) form, for the purposes of improving the Service, developing new features, and conducting research and industry reporting (for example our periodic "State of the Web" report). This clause supports the continuous improvement of the platform while preserving the Customer's ownership of its identifiable data. CentralCSP exercises this license consistently with the DPA; in particular, where a browser report incidentally contains personal data, that data is never used for public research reporting, and any conflict between this Section and the DPA is resolved in favour of the DPA. For the avoidance of doubt, CentralCSP does not use Customer Data to train, fine-tune, or develop artificial intelligence or machine-learning models, and does not share Customer Data with any third-party AI service.

5.5. Feedback

If the Customer or an Authorized User provides feedback, comments, or suggestions about the Service ("Feedback"), such Feedback is given voluntarily, and CentralCSP may use, disclose, and exploit it without obligation or restriction.

5.6. Publicity

The Customer grants CentralCSP the right to use and display the Customer's name and logo to identify the Customer as a customer of CentralCSP, on CentralCSP's website and in its marketing materials, presentations, and customer lists. CentralCSP will use the logo in accordance with any reasonable trademark usage guidelines the Customer provides, and this right does not otherwise transfer any ownership of the Customer's trademarks. The Customer may opt out at any time by written notice to the contact details in Section 12, after which CentralCSP will cease new use of the Customer's name and logo within a reasonable period.

6. Confidentiality, Privacy, and Security

6.1. Confidentiality

The Receiving Party shall protect the Disclosing Party's Confidential Information with at least the same degree of care it uses for its own confidential information of like kind (and no less than reasonable care), shall not use it outside the scope of this Agreement, and shall not disclose it to any third party except as authorized in writing.

6.2. Privacy Policy

CentralCSP collects, uses, and discloses Personal Data in accordance with its Privacy Policy, which is incorporated by reference and describes how we handle the information you provide when you use the Service.

6.3. Data Processing Agreement (DPA)

To the extent CentralCSP processes Personal Data contained in Customer Data on the Customer's behalf, and such processing is subject to data protection laws such as the GDPR, the parties are bound by the CentralCSP Data Processing Agreement, which is incorporated by reference. The DPA sets out the roles and obligations of the parties as required by regulations such as the GDPR and provides the contractual assurances Customers need for their own compliance. The DPA covers the following details of processing:

Processing detailDescription
Subject-matter of the processingCollection and analysis of browser-generated security telemetry and website security data to monitor and enhance the security of the Customer's web properties.
Duration of the processingFor the term of the Customer's subscription, and as specified in the data retention section of the DPA (a rolling 90-day maximum for browser reports; scan results are kept until the Customer deletes the corresponding website or workspace).
Nature and purpose of the processingTo provide the Services, including collecting and analysing all supported browser Reporting-API report types, generating event-based alerts, maintaining a script inventory and detecting vulnerabilities (CVEs), producing PCI DSS evidence, scanning and evaluating website security, and generating recommended CSP policies. To use aggregated, anonymized data for service improvement.
Type of Personal Data processedAccount data: name, email, company, password (hashed). Report and scan data: IP addresses, user-agent strings, URLs, and other technical data incidentally contained in browser reports and scan results. No special categories of data and no cardholder data.
Categories of Data SubjectsThe Customer's Authorized Users, and End-Users of the Customer's websites whose browsers submit reports.
Obligations and rights of the ControllerThe Customer's obligations and rights as data controller are set out in this Agreement and the DPA.

6.4. Security measures

CentralCSP maintains appropriate administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data against unauthorized access, use, modification, or disclosure. These are based on industry standards and include data encryption, access controls, and secure development practices, as further described in the DPA. All Customer Data is hosted within the European Union.

7. Warranties and Disclaimers

7.1. Mutual warranties

Each party represents and warrants that it has the legal power and authority to enter into this Agreement.

7.2. Disclaimer of warranties

Except as expressly provided, the Service(s) and all related components and information are provided on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind. CentralCSP disclaims all warranties, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.

Except as expressly set out in the SLA (which applies to Enterprise plans), CentralCSP does not warrant that the Service will be uninterrupted, timely, secure, or error-free, or that defects will be corrected. CentralCSP makes no guarantee regarding the results obtained from the Service, the accuracy of any security or compliance scores, or the effectiveness of any generated Content Security Policies. The Customer acknowledges that no security tool provides absolute protection, and CentralCSP does not guarantee that use of the Service will prevent all security vulnerabilities (such as XSS, click-jacking, or data injection) or that generated policies will be perfectly optimized or compliant in all circumstances. The Service is a tool to aid security efforts, not a guarantee of security.

8. Limitation of Liability

8.1. Cap on direct damages

In no event shall either party's total aggregate liability arising out of or related to this Agreement exceed the total amount paid by the Customer to CentralCSP in the twelve (12) months preceding the event giving rise to the claim. This limitation applies whether the claim is in contract or tort and regardless of the theory of liability.

8.2. Exclusion of indirect damages

Under no legal theory shall either party be liable for any indirect, special, incidental, exemplary, punitive, or consequential damages, including lost profits, losses, or expenses, whether or not the party was advised of the possibility of such damage.

9. Indemnification

You agree to indemnify and hold CentralCSP and its affiliates, officers, directors, agents, partners, and employees harmless from any claim or demand, including reasonable attorneys' fees, made by any third party arising out of your use of the Service or any act or omission by you (including the entity on whose behalf you enter into this Agreement). This obligation survives termination of this Agreement. The limitations of liability in Section 8 do not apply to this indemnity.

10. Term and Termination

10.1. Term

This Agreement begins on the date the Customer first accepts it and continues for the initial subscription term in the applicable Order Form. The term renews automatically as described in Section 4.4.

10.2. Termination for cause

Either party may terminate this Agreement for cause if the other materially breaches it and fails to cure the breach within thirty (30) days of written notice. If the Customer terminates for cause under this Section, CentralCSP will refund any prepaid fees covering the remainder of the subscription term following the effective date of termination.

10.3. Termination for convenience

The Customer may terminate its subscription at any time using the cancellation procedures within the Service. Such termination takes effect at the end of the then-current billing period, and the Customer is not entitled to a refund of prepaid fees.

10.4. Effect of termination

On termination or expiration, all rights granted to the Customer immediately cease. CentralCSP has no obligation to maintain Customer Data and may delete it, subject to the data-handling provisions of the DPA and applicable law (including the storage-limitation principle under the GDPR).

10.5. Survival

The following survive termination or expiration: Section 1 (Definitions), Section 4 (Fees) for fees owed, Section 5 (Intellectual Property and Data Rights), Section 6.1 (Confidentiality), Section 7 (Warranties and Disclaimers), Section 8 (Limitation of Liability), Section 9 (Indemnification), Section 10.4 (Effect of Termination), Section 10.5 (Survival), and Section 11 (General Provisions).

11. General Provisions

11.1. Governing law and jurisdiction

This Agreement is governed by and construed in accordance with the laws of France. Any dispute arising under or in connection with it is subject to the exclusive jurisdiction of the courts of France, subject to Section 11.2.

11.2. Dispute resolution

The parties shall first attempt to resolve any dispute through good-faith negotiation. If it is not resolved within a reasonable time, it shall be finally settled under the Rules of Arbitration of the International Chamber of Commerce (ICC) by one or more arbitrators appointed under those Rules. This clause does not prevent either party from seeking injunctive relief or litigating intellectual-property matters in a competent court.

11.3. Notices

Legal notices must be in writing and are deemed given on (i) personal delivery; (ii) the second business day after mailing; or (iii) the first business day after sending by email. Notices to CentralCSP are sent to the address in Section 12; notices to the Customer are sent to the email associated with its account.

11.4. Assignment

Neither party may assign its rights or obligations without the other's prior written consent, except that either party may assign this Agreement in its entirety in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets.

11.5. Force majeure

Neither party is liable for any failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control and occurring without its fault or negligence.

11.6. Entire agreement and order of precedence

This Agreement, including the Privacy Policy, the DPA, the SLA, and all Order Forms, is the entire agreement between the parties and supersedes all prior agreements concerning its subject matter. In the event of any conflict among these documents, the order of precedence is: (1) the Data Processing Agreement, (2) the applicable Order Form, (3) the SLA, and (4) these Terms of Service.

11.7. Modifications to these Terms

CentralCSP may modify these Terms at its discretion. For material changes we will provide notice through the Service's interface, by email to the address associated with your account, or by other reasonable means. Your continued use of the Service after the effective date of any change constitutes acceptance of the modified Terms.

11.8. Language

These Terms are drafted in English, which is the authoritative and legally binding version. Any translation (for example the French version) is provided for convenience only. In the event of any conflict, ambiguity, or divergence between the English version and a translated version, the English version prevails and governs.

12. Contact Information

For questions about these Terms or for legal notices, contact us at: