Terms of Service

Effective 26 August 2026. Last updated 26 August 2026. These terms apply to all use of the Tasirio service from that date.

1. Who these terms are with

These Terms of Service are an agreement between you — the organisation using Tasirio ("you", "Customer") — and Smartware Holdings, Inc., a Wyoming corporation doing business as "Tasirio", 4637 Indian Rock Drive, Fort Worth, TX 76244, United States ("Tasirio", "we", "us").

You accept these terms by using Tasirio — by signing in, connecting a system, or letting your people do either. If you are accepting for an organisation, you confirm you are authorised to bind it.

2. Who may use Tasirio

3. Your account and your users

4. What the service reads

Tasirio is a governance and accountability service. You connect the systems you want governed. We read their security and permission configuration, analyse it, and report exposures with guidance on how to fix them.

We readExamples
Who exists and what they can reachUsers, groups and membership, roles and role assignments, app registrations and the permissions granted to them, conditional-access and authorisation policy settings, sign-in timestamps
How sharing and access are configuredSite and drive inventory, sharing links, permission grants, sensitivity-label catalogues, channel membership, installed apps. Item and site names — never the contents of an item
Schema shape and reachabilityWhich tables and columns exist, which regulated data classes they hold, how many rows, and whether our read-only credential can select them
Supplier and payment master data — accounts-payable connector onlySupplier name, supplier ID, tax or company registration number, address, telephone, contact email, and a bank-account identifier. See below.
Network usage records — only if you deploy the shadow-AI agentA device IP address and the AI service hostname it looked up, aggregated to device, service and count. A device IP is personal data in many places, which is why it is listed here rather than left implicit.
The people you nominate for alertsName, work email and, if you enter one, mobile number of your own colleagues

We do not read the contents of documents, files, mailboxes, chat or Teams messages, calendar entries, notebooks or attachments. We do not download file bytes.

Two connectors read business record fields, deliberately, and we would rather say so than hide behind the word "metadata".

On our Microsoft 365 connector, the "no content" rule is enforced by the code and not only by policy: every request goes through a single choke point that pins the method to GET, refuses any host other than Microsoft Graph, rejects a fixed list of content paths (messages, mail folders, calendar, chat, contacts, attachments, photos, thumbnails, versions, notebooks and raw-value paths), and then requires what is left to match an explicit list of permission and inventory endpoints. That specific mechanism is the Microsoft 365 connector's. Other connectors reach their vendors through their own read paths and read-only credentials. The commitment not to read content applies to all of them; the structural enforcement described here does not, and we will not imply that it does.

5. What the service is not

6. Connecting your systems

6.1 You must have authority to connect

You may only connect a system your organisation owns or is authorised to administer, using access you are authorised to grant. You are also responsible for having a lawful basis for the processing and for giving your people any notice their law requires. We cannot verify any of this for you.

6.2 We do not write to the systems we govern

Tasirio does not create, modify, or delete data in the systems it reads. Our connectors issue read calls. Where a vendor's read operation requires an HTTP POST — an OAuth token exchange, a query API that takes a request body — we use it for that read and nothing else. We compute who can reach what from your permission model; we never test access by probing or by escalating our own privileges.

6.3 Outbound integrations you configure — where we do write

This is the honest exception, and it belongs on the same page as the promise above.

If you configure an outbound ticketing integration, Tasirio creates and updates records in that destination, using credentials you supply, at your instruction. Concretely: we create issues in Jira, incidents in ServiceNow, and tickets in Zendesk and Syncro; we update their status when a finding's status changes; and we add comments or work notes explaining a re-verification outcome. We also post to Slack and to generic webhooks you nominate.

Two of those destinations — ServiceNow and Zendesk — can also be connected as systems we govern. When the same system is both governed and used as your ticket destination, we read it under section 6.2 and write to it under this section. That is not a contradiction, but it is exactly the kind of thing a contract should say plainly rather than leave to be discovered.

6.4 How we authenticate

Most connectors use a credential issued directly to Tasirio. A few vendors only expose the data we need through delegation: for Google Workspace we sign as a service account and act as an administrator you designate in your own domain, using read-only scopes; DocuSign uses a similar impersonation grant. You choose the account we act as, and you can revoke it. We disclose this because "we never act as one of your users" would not be true, even though we never do it in order to test access.

6.5 Permissions with write-sounding names

Some vendors put read-only data behind a permission whose name implies write access, and publish no narrower alternative. Reading SharePoint site permission grants is the clearest example. We do not silently decline these — declining is not free, and quietly collecting less is not the same as looking and finding nothing.

Before such a permission is granted we show you: what it is for, what it unlocks, why no read-only version exists, what is still not collected even with it, and what stays invisible if you decline. You must acknowledge it explicitly, and that acknowledgement is recorded. Consent is never inferred from the grant merely existing. For every connector that holds such a permission, a build check fails our deployment if that connector's code could issue any non-GET call, and the connector must pin its HTTP method at a single fetch choke point.

The limit, stated plainly: that build check covers the connectors that declare a write-named permission, and it scans connector code only. The others are protected because the credential you issue is read-only — a write would be refused by the vendor rather than by our code. No connector contains a mutating call to a vendor today, but that is a measured state, not a compiled guarantee. We will not claim "the build fails if any connector stops being read-only".

6.6 The one thing we write outside our own systems

The only thing Tasirio writes anywhere outside its own database is the credential you give us, into a key vault — ours, or your own — so it never sits in a database. That is separate from the outbound integrations in section 6.3, which write into destinations you chose and control.

6.7 Software you run on your premises

Some systems sit inside your network. For those we provide a collector agent you install and run. It makes read-only queries against the system you point it at and one outbound HTTPS call to us. Nothing inbound; no firewall change on your side. You are responsible for the host it runs on and for the read-only database account you create for it. We grant you a non-exclusive, non-transferable licence to run the agent during the term, solely to send data to your own Tasirio tenant. The agent is an early-access capability and section 16 applies to it.

6.8 Where we can and cannot verify the address you type

Where a system has a vendor-owned domain, the address you type is locked to that vendor's own registrable domain, so a credential cannot be sent to a look-alike host. Some systems are genuinely yours — an on-premises SQL Server, a self-hosted ERP, an on-premises Oracle endpoint. For those there is no vendor domain to anchor to, and the only guarantee available is that the address is not one of ours. We check that on every sync rather than only when you save it, because a name that resolves publicly today can be re-pointed tomorrow. In those cases the address you type is the address we dial, and getting it right is a shared responsibility.

7. Credentials and keys

8. Your data, and who owns what

8.1 You own your data

You own everything you connect and everything we derive from it for you: the configuration and permission metadata we collect, the findings, the evidence and the reports. We claim no ownership. You grant us the limited right to read, store, process and display that data to operate the service for you, for your users and for the people you share reports with. We do not sell it, and we do not use it to train any machine-learning model. That right ends when this agreement ends, except as sections 8.3 and 15.3 describe.

8.2 We own the software

Tasirio owns the platform: the software, the connectors, the detection logic, the reports and their templates, and all related intellectual property. Nothing here transfers any of it. You get a non-exclusive, non-transferable right to use the service for your own organisation during the term. If you send us feedback or suggestions we may use them without obligation, and will not identify you as the source without your permission.

8.3 Aggregate statistics

We keep a separate, deliberately narrow record of finding activity: the type of finding, the connector it came from, its severity, and when it was first seen and when it was resolved. That record carries no resource name, no description, no account and no user — those columns do not exist in it. Issues are linked over time by a one-way keyed identifier that cannot be reversed into the underlying resource.

We use it for three things, and we list all three because enumerating two would make the omission of the third a misstatement:

  1. Our own product analytics — which detections fire, which are resolved, where the product is weak.
  2. Peer benchmarking — described below.
  3. Aggregate outcome statistics we publish about the product, of the form "N findings on a real customer estate". These never name a customer and never identify one.

Benchmarking, stated precisely. The product contains two different comparisons and they must not be confused. One is a modelled reference distribution built from our own configuration; every response it produces is labelled as such in the product, and it is not real peer data. The other is a genuine peer comparison computed from the record above, and it will only ever return a figure when the cohort contains at least five organisations other than you, so no single peer can be identified. Only aggregates and your own position leave that system — never another customer's identity or numbers. Today the peer comparison rarely meets that floor, so what you are most likely to see is the modelled reference, labelled.

These records are durable. They are designed to survive the deletion of an account so historical totals are not retroactively rewritten. They contain nothing that identifies you or your systems, but they are not deleted when your account is.

9. Acceptable use

You may not, and may not permit anyone else to:

If you breach this section we may suspend access immediately and without notice. We will tell you why as soon as we reasonably can.

10. Fees and billing

11. Trials and pilots

12. The Exposure Assessment

The Assessment is a one-time engagement, not a subscription. If you buy one, this section applies in addition to the rest of these terms.

13. Availability, maintenance and changes to the service

These terms contain no service level agreement. We do not commit to an uptime percentage, to a recovery time, or to any availability target, and you should not rely on one. We aim to keep the service running and to give reasonable notice of planned maintenance. That is the whole of the commitment.

We may change, add to, or remove features. If we remove something you depend on, or make a change that materially reduces the service, we will give you reasonable notice; and if the change materially reduces the service for the remainder of your term, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees for the unused period.

We may suspend the service, in whole or in part, where we reasonably need to in order to protect the platform, our other customers, or you.

14. Security and privacy

How we handle personal information is described in our Privacy Policy. Where we process personal data on your behalf, our Data Processing Addendum governs — including the sub-processor list, international transfers, and how we notify you of changes.

What we can say about our security posture, precisely:

15. Term, termination, and what happens to your data

15.1 Term

These terms apply from when you first use the service until your subscription ends and your account is closed.

15.2 Termination

15.3 Your data on termination

On termination, and on your written request, we will return or delete your data within 30 days. Some categories behave differently, and all of them are listed here rather than summarised:

DataWhat happens
Findings, permission records, scan history, connector settings, your tenant and user recordsDeleted within 30 days of termination or your written request.
Connector credentialsDeleted from the key vault within 30 days. The vault keeps a recoverable soft-deleted copy for 90 days and then purges it. Under bring-your-own-vault there is nothing for us to delete — you revoke our access. In every case you can revoke the credential in your own system immediately, without us.
Evidence packsHeld under a 365-day write-once retention policy. While that policy stands they cannot be deleted or overwritten, which is what makes them usable as evidence. The policy is in an unlocked state, so we retain the technical ability to lift it where the law requires erasure. It is therefore not impossible to erase them, but it is not automatic either.
The activity logCannot be edited or purged during the term — the database refuses the operation, and deleting entries would break the tamper-evidence that is the point of it. It is deleted together with your tenant record on termination.
BackupsDeleted data may persist in a point-in-time database backup for up to 35 days before it ages out. Backups are restored only for disaster recovery, never to retrieve data that was deleted on request.
Aggregate statistics (section 8.3)Retained. They carry no resource, account or user identifiers.
Billing and tax recordsRetained as required by law. These are our own records, not your data.

While your account is active you can export your data yourself. Ask us before termination if you want a final export; we will provide your findings and reports within 30 days in the formats the service supports at the time.

15.4 What survives

Sections 7 (your right to revoke), 8.1 (final sentence), 8.2, 8.3, 15.3, 15.4, 16, 17, 18, 19, 20, 22, 23 and 24 survive termination, together with any payment obligation already accrued.

16. Warranties and disclaimers

We will perform the service with reasonable skill and care. That is the only warranty we give.

Subject to that, the service is provided "as is" and "as available". To the fullest extent the law allows we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, title and non-infringement.

In particular, we do not warrant that:

Descriptions are not warranties. Sections 4, 5, 6 and 14 describe how the service works so you can make an informed decision. They are accurate as at the effective date and we will not change them to be less accurate without notice, but they are descriptions of software behaviour, not performance warranties, and the disclaimer above applies to them.

Early-access features. Some capabilities are built but not yet proven in a customer environment — at the date of these terms that includes the own-cloud key-vault integrations, export to a customer's security-monitoring platform, and the on-premises collector agent. Where we identify a feature as early access, beta or preview, it is provided as-is, is excluded from the warranty in the first paragraph of this section, and is excluded from our indemnity in section 18.

You remain responsible for your own security decisions. Findings are input to your judgement, not a replacement for it.

17. Limitation of liability

Neither party is liable to the other for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, however caused and regardless of the theory of liability, even if told such damages were possible.

Each party's total aggregate liability arising out of or relating to this agreement is limited to the fees you paid or owed to us in the twelve months before the event giving rise to the claim. Where the service has been provided without charge — a pilot, a trial or a design-partner arrangement — that cap is one thousand United States dollars (US$1,000).

These limits do not apply to:

18. Indemnity

You will defend and indemnify us against third-party claims arising from: (a) your connecting a system you did not own or were not authorised to administer, or using a credential you were not authorised to issue; (b) your use of the service in breach of section 9; (c) your own acts or omissions in acting on the findings and reports we produce, except to the extent the claim arises from our own negligence, wilful misconduct or breach of this agreement; or (d) your violation of law.

We will defend and indemnify you against third-party claims that the Tasirio platform, used as permitted by these terms, infringes that party's intellectual property rights. This does not apply where the claim arises from your data, from your combining the service with something else, from an early-access feature under section 16, or from your use in breach of these terms. If the service becomes subject to such a claim we may modify it, obtain a licence, or terminate the affected part and refund fees for the unused period.

The indemnified party must notify the other promptly, allow it to control the defence, and cooperate reasonably. Neither party may settle in a way that admits liability for the other without consent.

19. Confidentiality

Each party will protect the other's confidential information with at least the care it uses for its own, will use it only to perform this agreement, and will disclose it only to people who need it and are bound to keep it confidential. This does not cover information that is public, already known, independently developed, or lawfully received from someone else. Either party may disclose where legally compelled, after giving the other notice where it is lawful to do so.

Your findings, reports and connected-system data are your confidential information.

20. Security incidents

If we become aware of a security incident affecting your data in our systems, we will notify you without undue delay, and in any event no later than 72 hours after we become aware. This applies whether or not the data involved is personal data — the schema inventories, supplier records and stored credentials we hold on your behalf are not obviously personal data and we do not want a scope argument standing between you and a notice. Where the incident involves personal data, section 12 of the Data Processing Addendum also applies.

Our notice will describe what we know at the time and will be followed by updates as facts are established. We will not delay a first notice in order to complete an investigation. A notice is not an admission of fault or liability.

21. Changes to these terms

We may update these terms. If a change materially affects your rights we will give you at least 30 days' notice by email to your account contact and by posting the updated terms with a new effective date. If you do not agree you may terminate before the change takes effect and we will refund fees for the unused portion of your term. Changes that are not material — corrections, clarifications, and changes required by law — take effect when posted.

22. Publicity

Neither party will name the other, or use its logo, in marketing without prior written consent. Consent for one use is not consent for another. This does not restrict the aggregate, non-identifying statistics described in section 8.3.

23. Governing law and disputes

These terms are governed by the laws of the State of Texas, without regard to its conflict-of-laws rules, and the United Nations Convention on Contracts for the International Sale of Goods does not apply. The parties submit to the exclusive jurisdiction of the state and federal courts located in Tarrant County, Texas, and each party consents to venue there.

Before filing, the parties will try in good faith for 30 days to resolve a dispute through their named contacts. Either party may seek injunctive relief at any time to protect its confidential information or intellectual property.

Where the European Commission's Standard Contractual Clauses apply to the processing of personal data, the governing law and forum for those clauses are as stated in our Data Processing Addendum, and they prevail over this section for that processing.

24. General

Questions

Commercial questions: your account contact. Privacy: privacy@tasirio.com. Security: security@tasirio.com. Legal notices: legal@tasirio.com.

Related: Privacy Policy · Terms of Service · Data Processing Addendum · Sub-processors · Security & Trust