These Terms of Service ("Terms") govern your access to and use of all products and services provided by AFTRDRK, LLC (collectively, the "Services").
The Services include the following, which may be purchased separately or in any combination:
- DRK Web Surveillance – consisting of Dark Web and Attack Surface Monitoring;
- DRKCACHE – conversational cyber threat intelligence platform that enables users to ask questions of AFTRDRK's collected corpus of data, generate reports, retrieve target packs, and conduct investigations (available only in certain subscription tiers);
- MATTR (Material Attribution) – AFTRDRK's proprietary attribution methodology and the finished attribution reports delivered under it, sold as report credits and drawn down against individual cases;
- AFTRDRK TI – subscription threat intelligence bundles, including Requests for Information at the volumes set forth in the applicable Order Form;
- Threat Actor Engagement – negotiation services provided as a standalone 30-day engagement.
- Professional Intelligence Services – including Requests for Information (RFIs), that generate deliverables including: targeted research, dark web intelligence collection, and other custom intelligence services.
Engagements involving MATTR, Threat Actor Engagement or Professional Intelligence Services may also involve tri-party execution with the Customer's legal counsel, as documented in the applicable Statement of Work and Order Form.
By accessing or using any of our Services — including through click-wrap acceptance on our website — you agree to be bound by these Terms. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have the authority to bind that entity to these Terms.
1. Definitions
- "Services" means the DRK Web Surveillance (Dark Web Monitoring and Attack Surface Monitoring), DRKCACHE (conversational cyber threat intelligence features), MATTR, AFTRDRK TI, Professional Intelligence Services, and optional Threat Actor Engagement services, together with any other product or service offered by AFTRDRK from time to time.
- "Customer", "you", or "your" means the individual or entity using the Services.
- "Intelligence" means all alerts, reports, insights, data, and other outputs generated or delivered through the Services, including all Deliverables.
- "A-GIR" means AFTRDRK's Attribution General Intelligence Requirements framework, comprising the structured set of correlated indicators through which the MATTR methodology constructs an attribution assessment.
- "MATTR" or "Material Attribution" means AFTRDRK's proprietary attribution methodology — including the A-GIR framework, AFTRDRK's indicator correlation, enrichment, and analytical processes, its source composition and collection architecture, and all associated tooling — together with the finished attribution reports produced by application of that methodology.
- "Deliverable" means any report, target package, assessment, briefing, or other finished work product delivered to Customer under an Order Form or Statement of Work, including MATTR reports.
- "AFTRDRK Methodology" means, collectively, MATTR, the A-GIR framework, and any other analytical method, framework, correlation logic, enrichment technique, scoring approach, source composition, or process used by AFTRDRK to produce Intelligence, whether or not disclosed to Customer.
- "Data" means any information you provide to us, including watchlist items, domains, emails, IPs, usernames, keywords, or other indicators you choose to monitor through the Services.
2. License and Access
We grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Services during your active subscription term solely for your internal business security purposes, subject to the restrictions set forth in Section 8. DRKCACHE features are available only in qualifying higher-tier subscriptions. You may not resell, sublicense, rent, lease, or make the Services available to third parties except as explicitly permitted in a separate written agreement.
3. Subscriptions, Free Trial, and Threat Actor Engagement
- Platform Subscription: The DRK Web Surveillance (Dark Web Monitoring and Attack Surface Monitoring) automatically renews unless properly canceled.
- DRKCACHE: Access to conversational features is available only in qualifying higher subscription tiers.
- MATTR: MATTR report credits are purchased in blocks under an Order Form and drawn down against individual cases. Credits are non-refundable, expire per the term set forth in the applicable Order Form, and do not roll over or carry forward in most cases. Credit blocks do not automatically renew.
- Threat Actor Engagement: This is an optional 30-day service that does not automatically renew.
- Free Trial: All customers receive a 30-day free trial of DRK Web Surveillance upon signup. Activation of Threat Actor Engagement automatically initiates the 30-day trial if you do not already have an active subscription or trial.
- Some purchases of DRK Web Surveillance are completed via click-wrap acceptance on our website and are billed automatically at signup or upon expiration of the free trial.
4. User Responsibilities and Acceptable Use
You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account. You must ensure the accuracy, legality, and appropriateness of any Data (including watchlist items, domains, emails, IPs, usernames, keywords, or other indicators) you upload or configure in the Services.
When requesting Professional Intelligence Services (including Requests for Information ("RFIs"), targeted research, dark web intelligence collection, or any other custom intelligence work), you expressly authorize AFTRDRK to perform such services on your behalf. You acknowledge and agree that:
- These services may involve accessing, searching, or interacting with underground, illicit, or closed-source environments.
- AFTRDRK will perform reasonable due diligence and sanctions screening, but you remain solely responsible for any legal, regulatory, or sanctions-related consequences.
- You will not request AFTRDRK to perform any activity that is illegal, violates applicable sanctions or export control laws, or could reasonably be expected to expose AFTRDRK to legal or regulatory risk.
- AFTRDRK reserves the right to decline or immediately terminate any RFI or custom intelligence request if, in our sole discretion, it presents a compliance, legal, or reputational risk.
4.1 Case Handling
As part of Threat Actor Engagement and Professional Intelligence Services, AFTRDRK maintains internal records and systems to manage cases, track communications, and coordinate with authorized partners (such as legal counsel, forensics firms, or cryptocurrency specialists). The Customer authorizes AFTRDRK to collect, store, and process relevant case information necessary to deliver these services. Access to these internal systems is strictly limited to authorized AFTRDRK personnel and approved partners.
You agree not to:
- Attempt to reverse engineer, decompile, scrape, or otherwise interfere with the Services, or to take any action restricted by Section 8.
- Use the Services to engage in or facilitate any illegal activity.
- Upload or submit any Data that is unlawful, infringing, or harmful.
4.2 Data Retention and Legal Holds
We retain Customer Data for the duration of the active subscription plus up to twelve (12) months after termination for operational, security, billing, and compliance purposes.
Notwithstanding the foregoing, AFTRDRK may retain case records, work product, Deliverables, and derived intelligence for a longer period where required or reasonably necessary for AFTRDRK's internal governance, professional, insurance, or legal obligations, or to establish, exercise, or defend legal claims. Retention under this paragraph is subject to Section 8.4.
If AFTRDRK receives a valid legal hold request, subpoena, court order, or formal notice from the Customer or their authorized legal counsel regarding a tenant's data, we will preserve all relevant Data indefinitely until the legal hold is officially lifted. The Customer is responsible for notifying us promptly of any legal hold. After the hold is lifted, we will retain the data for an additional ninety (90) days before resuming our standard deletion schedule.
5. Sanctions, Export Controls, and Compliance
You represent, warrant, and covenant that:
(a) neither you nor any of your users is a sanctioned person or entity under U.S. sanctions laws (including OFAC); and
(b) your use of the Services, including any watchlist items and activation of Threat Actor Engagement, will not cause AFTRDRK to violate any sanctions or export control laws.
We perform reasonable sanctions screening before providing Threat Actor Engagement. We reserve the right to immediately decline, suspend, or terminate any Service or engagement without liability to you if we determine, in our sole discretion, that there is a sanctions or export control risk. You acknowledge that certain Services or Intelligence may be subject to U.S. export control laws, and you agree to comply with all applicable export and re-export restrictions.
AFTRDRK may, at its sole discretion, facilitate the purchase of data, credentials, or access on your behalf as part of Professional Intelligence Services. However, you remain solely and exclusively responsible for any and all legal, financial, regulatory, sanctions-related, or other consequences arising from your use of the Services, any requests you make, or any decisions related to ransom payments or purchased materials. You agree to promptly reimburse AFTRDRK for all costs incurred in connection with any such purchases.
6. Intelligence Sharing and Cooperation with Authorities
We may share aggregated, anonymized, or de-identified threat intelligence derived from the Services with law enforcement, government agencies, cybersecurity organizations, or industry partners when we believe in good faith that such sharing is necessary to prevent or mitigate cyber threats, protect public safety, or fulfill our legal obligations.
We may also disclose your Data or Intelligence to the extent required by applicable law, regulation, court order, or government authority (including valid subpoenas or law enforcement requests). Where permitted by law and reasonably practicable, we will notify you in advance of any such disclosure so that you may seek appropriate protective measures.
You acknowledge and agree that AFTRDRK has no obligation to notify you or obtain your consent prior to sharing information when prohibited by law or when we determine that immediate disclosure is necessary to prevent imminent harm.
7. Use of Artificial Intelligence
Portions of the Services, including DRKCACHE, may utilize artificial intelligence and machine learning technologies for fuzzy matching, confidence scoring, alert prioritization, content summarization, and other functions. AI-generated outputs are assistive only and may contain inaccuracies or omissions. You agree not to rely solely on AI outputs for critical security or business decisions and must apply independent human review and verification.
8. Intellectual Property
All technology, platforms, methodologies, frameworks, Intelligence, Deliverables, and related materials are owned by AFTRDRK or its licensors. This includes, without limitation, the AFTRDRK Methodology, MATTR, the A-GIR framework, and AFTRDRK's collection, correlation, enrichment, and analytical processes and underlying tooling. You receive no ownership rights in the Services, in any Intelligence or Deliverable, or in any AFTRDRK Methodology.
8.1 Permitted Use
You may use Intelligence and Deliverables internally for your own security, risk-management, and incident-response purposes, and may distribute them to the extent expressly permitted in the applicable Statement of Work. All internal use is subject to the restrictions in Sections 8.2 and 8.3. You may not redistribute, republish, or commercially exploit Intelligence or any Deliverable without our prior written consent.
8.2 No Derivative Works
You may not create, or assist or enable any third party to create, any derivative work, database, index, model, product, or service that is based on, derived from, trained on, or that incorporates Intelligence or any Deliverable, in whole or in part. Without limiting the foregoing, you may not use Intelligence or Deliverables — individually or in aggregate across multiple deliverables or over time — to develop, train, benchmark, validate, evaluate, or improve any attribution, threat intelligence, analytical, or scoring capability, whether for your own use, for the use of any affiliate, or for the benefit of any third party. The internal use permitted under Section 8.1 does not extend to any use described in this Section 8.2.
8.3 No Reverse Engineering of Methodology
You may not reverse engineer, decompile, deconstruct, or otherwise attempt to derive, reconstruct, replicate, or approximate any AFTRDRK Methodology — including MATTR, the A-GIR framework, AFTRDRK's correlation logic, enrichment techniques, confidence and scoring approaches, or source composition — whether from the Services, from any Intelligence or Deliverable, from the structure or sequence of deliverables received over time, or from any combination thereof. This restriction is independent of, and supplements, the restrictions in Section 4.1, and applies regardless of whether the AFTRDRK Methodology was expressly disclosed to you.
8.4 Derived Intelligence and Corpus Rights
AFTRDRK may retain, process, and derive intelligence from materials submitted by you and from work performed in connection with the Services, and may incorporate such derived intelligence into AFTRDRK's internal intelligence corpus for the purposes of delivering, maintaining, and improving the Services and AFTRDRK Methodology. Such derived intelligence is and remains the exclusive property of AFTRDRK. AFTRDRK will not disclose your identity, your Data, or case-identifying details to any third party except as permitted under Section 6 or as otherwise expressly agreed in writing.
8.5 Survival
The restrictions in this Section 8 survive termination or expiration of these Terms and of any Order Form or Statement of Work: indefinitely with respect to AFTRDRK trade secrets, and for five (5) years with respect to all other Intelligence, Deliverables, and materials.
9. Data Privacy and Security
We handle your Data in accordance with our Privacy Policy. We use commercially reasonable efforts to protect your Data. However, no security measures are perfect, and we do not guarantee that the Services will be free from unauthorized access, breaches, or other cybersecurity events. You retain ownership of your Data.
10. Confidentiality
Both parties agree to protect the other's Confidential Information and use it only as necessary to perform under these Terms.
"Confidential Information" means any non-public information disclosed by one party to the other, whether or not marked confidential, that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. AFTRDRK's Confidential Information includes, without limitation, the AFTRDRK Methodology, MATTR, the A-GIR framework, AFTRDRK's source composition and collection architecture, its analytical and enrichment processes, and all Intelligence and Deliverables. Confidential Information does not include information that is or becomes publicly available through no fault of the receiving party, was rightfully known to the receiving party without obligation of confidence prior to disclosure, or is independently developed without reference to the disclosing party's Confidential Information.
Each party will protect the other's Confidential Information using no less than reasonable care, will limit access to those of its personnel and advisors with a need to know who are bound by obligations no less protective than these, and will not use it for any purpose outside performance under these Terms. These obligations survive termination for five (5) years, and indefinitely with respect to information constituting a trade secret. Nothing in this Section limits the restrictions in Section 8, which apply independently.
11. Warranties and Disclaimers
THE SERVICES ARE PROVIDED STRICTLY "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, AFTRDRK DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICES OR INTELLIGENCE WILL BE ACCURATE, COMPLETE, UNINTERRUPTED, OR ERROR-FREE.
We do not warrant that:
- The Services or Intelligence will detect or prevent all threats; or
- Any Threat Actor Engagement will succeed, result in reduced ransom demands, prevent data disclosure, or achieve any specific outcome.
Threat Actor Engagement Specific Disclaimer: When you activate this optional service, we act solely as your limited authorized agent for communication with threat actors. We make absolutely no guarantees regarding any outcome, success, timing, reduction in demands, prevention of data leaks, or any other result. You remain fully responsible for all decisions, ransom payments, and any legal or regulatory consequences. We do not provide legal, financial, insurance, or recovery advice.
MATTR Specific Disclaimer: MATTR is a probabilistic attribution methodology based on correlated indicators and does not constitute definitive proof of any individual's or entity's identity or involvement. Attribution conclusions reflect AFTRDRK's professional assessment as of the date of the report and may be incomplete, later superseded, or subject to revision. AFTRDRK makes no guarantee that any conclusion will be accepted by any court, regulator, insurer, or other third party, or that it will withstand adversarial challenge. Additional MATTR-specific terms are set forth in the applicable Statement of Work.
Dark Web / CTI Disclaimer: Intelligence is derived from inherently unreliable, adversarial, and illicit sources. We cannot and do not guarantee the completeness, accuracy, or timeliness of any Intelligence.
12. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY DELAWARE LAW, AFTRDRK'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED THE AMOUNT YOU PAID TO AFTRDRK IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
This limitation applies even in cases of negligence or gross negligence (to the extent permitted by law) and is an essential element of the bargain between the parties. The Services would not be offered without this limitation. IN NO EVENT SHALL AFTRDRK BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES (INCLUDING LOST PROFITS, DATA LOSS, OR BUSINESS INTERRUPTION), EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
The foregoing limitation does not apply to Customer's breach of Section 8 (Intellectual Property) or Section 10 (Confidentiality).
13. Indemnification
You agree to indemnify, defend, and hold harmless AFTRDRK and its officers, directors, employees, and agents from any claims, losses, damages, liabilities, and expenses (including reasonable attorneys' fees) arising from:
- Your misuse of the Services or Intelligence;
- Any Data you provide;
- Any actions you take (or fail to take) based on the Services;
- Any claims related to your watchlist items or instructions regarding Threat Actor Engagement; or
- Any violation of sanctions or export control laws related to your use of the Services.
14. Termination
We may suspend or terminate your access to the Services immediately for breach of these Terms or if continued provision would create legal or regulatory risk. Upon termination, your right to use the Services and any Intelligence ceases immediately. Platform subscriptions that automatically renew will continue until properly canceled; Threat Actor Engagement ends after its 30-day period and does not automatically renew.
Sections 4 (User Responsibilities and Acceptable Use), 5 (Sanctions), 6 (Intelligence Sharing), 8 (Intellectual Property), 10 (Confidentiality), 12 (Limitation of Liability), 13 (Indemnification), and 17 (Governing Law) shall survive termination or expiration. Any provision of an Order Form or Statement of Work expressly stated to survive shall also survive in accordance with its terms.
15. Force Majeure
Neither party shall be liable for any delay or failure to perform its obligations under these Terms (except for payment obligations) to the extent such delay or failure is caused by events beyond its reasonable control, including but not limited to cyber attacks, acts of God, war, terrorism, pandemics, government actions, or failures of third-party infrastructure.
16. Assignment
You may not assign or transfer these Terms or any rights or obligations hereunder without our prior written consent. We may assign these Terms without your consent in connection with a merger, acquisition, corporate reorganization, or sale of assets.
17. Governing Law
These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws principles. Any legal action or proceeding arising under these Terms shall be brought exclusively in the state or federal courts located in Wilmington, Delaware, and you hereby consent to the personal jurisdiction of such courts.
18. Miscellaneous
- These Terms may be updated by us from time to time. Continued use of the Services after changes constitutes acceptance of the new Terms. Where an Order Form or Statement of Work has been executed by both parties, the Terms in effect as of its Effective Date govern that engagement unless the parties agree otherwise in writing.
- Order of Precedence. These Terms, together with any executed Order Form and Statement of Work, constitute the entire agreement between you and AFTRDRK regarding the Services and supersede all prior understandings or representations. In the event of a conflict, the following order of precedence applies: (1) the Order Form; (2) the applicable Statement of Work; (3) these Terms. A provision of an Order Form or Statement of Work that imposes additional or more restrictive obligations on Customer than these Terms shall be given full effect and shall not be treated as a conflict.
- If any provision is held invalid, the remaining provisions remain in full force and effect.
- Notices must be sent in writing to the email addresses provided by each party.
- No waiver of any breach shall constitute a waiver of any other breach.
Contact
If you have any questions about these Terms, please contact us at [email protected].
By using our Services, you acknowledge that you have read, understood, and agree to be bound by these Terms.