Welcome to Trident. These Terms of Service (the “Terms”) are the agreement between you and Esprit Labs Inc., a Delaware corporation that builds and operates the Trident security platform (“Trident,” “we,” “us”). “You” means the organization using Trident, and the person accepting these Terms confirms they are authorized to do so on that organization’s behalf.
For paid customers, a separate signed Master Subscription Agreement (“MSA”) supersedes these Terms to the extent of any conflict.
1. Using Trident
Trident is a tool for businesses to test and secure their own systems. You may use it only for that purpose, and only against systems, applications, and assets that you own and control or are otherwise clearly authorized to test — never against anything else. By creating an account, signing up, or using the platform, you accept these Terms.
The Services covered by these Terms include the Trident platform and everything we make available through it: our AI-driven and automated penetration testing, cloud security and misconfiguration analysis, application and API testing, source-code and pull-request scanning, dashboards, APIs, findings, and reports (together, the “Services”).
Subject to these Terms and your payment of applicable fees, Esprit Labs grants you a limited, non-exclusive, non-transferable, revocable right to access and use the Services during the term.
3. What you agree to
You agree to give us accurate scope and contact details, keep your account credentials secure, and cooperate on re-testing. You’re responsible for everything that happens under your account.
You agree not to:
- use Trident against anything you don’t own or aren’t authorized to test;
- resell or provide the Services to others except as we permit;
- reverse engineer or try to extract our models, prompts, or methods (except where the law says you may);
- use Trident to build or benchmark a competing product without our written okay;
- interfere with the platform or try to break into it; or
- upload anything that infringes someone’s rights or breaks the law.
4. Accounts and suspension
You’re accountable for activity under your account, so tell us right away at contact@tridentsecurity.io if you think it’s been compromised. We may suspend your access — in whole or in part, and with notice where we reasonably can — if your use creates a security, legal, or operational risk, if we need to protect the platform or other customers, or if you materially breach these Terms. We’ll restore access once the issue is resolved.
5. Fees and free access
If you’re on a paid plan, the price, billing cycle, and renewal terms are set when you subscribe or in your order form. Fees are billed in advance, are non-refundable except where these Terms or the law say otherwise, and don’t include taxes (which are your responsibility, except taxes on our income). Undisputed late amounts may accrue interest at the lower of 1.5% per month or the legal maximum, and we may suspend a paid account that stays past due after notice.
Free and trial access. Some access to Trident is free, including trials and self-serve scans. Everything we promise in section 7 applies to it in full — we don’t store your code and we don’t train on your data, whether you pay us or not. What differs is the license you give us over the findings themselves.
What free access doesn’t include is any commitment about the results. Findings from free and trial use may be available in the product while that access lasts; exporting them, archiving them, and continued access to them are paid features. We may change, limit, or withdraw free access at any time, and we make no commitment to retain, delete, or continue to make available findings produced under it.
The license you grant on free access. For findings produced under free and trial access, you grant us a non-exclusive, worldwide, royalty-free license to retain them and to use them to operate, secure, support, and improve the Services, and to create aggregated, irreversibly de-identified vulnerability research from them. We may license that research commercially. That license is limited to those purposes and does not extend to any other use. Section 7still applies without exception: we don’t train models on them, and we don’t store the code, credentials, or cloud contents behind them. Free access is provided “as is,” without service levels or support commitments, and no Data Processing Addendum applies to it.
6. Who owns what
Your data stays yours. You keep all rights to your Customer Data — the code, configurations, credentials, request/response data, and other materials you submit or that we capture during authorized testing, along with the findings about your systems. You give us a limited license to use that data only to run, secure, support, and maintain the Services for you, to follow your instructions, and to meet our legal obligations. Findings produced under free and trial access carry a broader license — see section 5.
Our platform stays ours. We keep all rights to Trident itself — the software, models, agents, prompts, methodologies, dashboards, documentation, and any improvements.
Findings are yours to use. We grant you a perpetual, worldwide license to use the findings we deliver for your own security and compliance work, including sharing them with your auditors, regulators, and customers under reasonable confidentiality. We may use information derived from findings to improve the Services only after it’s been aggregated or irreversibly de-identified so it can’t be traced back to you, an individual, or your systems — and we don’t keep identifiable data, credentials, or evidence for that. Findings produced under free and trial access may also be used to create aggregated, irreversibly de-identified research that we may license as described in section 5. For all other Customer Data, the purpose remains limited to improving the Services.
Feedback. If you send us ideas or suggestions, we can use them freely without owing you anything.
7. How we handle your data
We never store your code. We process your source code, repository and GitHub contents, credentials, and other sensitive materials transiently — in memory or a short-lived, encrypted workspace — only as needed to run a test and deliver results, and we let those working copies go promptly afterward. We do not persistently store your source code, repository or cloud contents, credentials, access tokens, or personal data on our servers. You don’t need to send us personal data to use Trident; if we encounter it by accident, we won’t retain it.
Findings are the exception. We do store the findings we produce for you, because that is the product — you need to be able to open them, track them, share them, and retest. They are held encrypted, available to your account, and deleted on the schedule in section 12; free and trial use is covered by section 5. Separately from your own findings, what we keep for ourselves is non-identifying vulnerability information (type, severity, counts), once anything that could link it back to you, an individual, or your systems has been removed. For free and trial use, that non-identifying information may be licensed for security research and industry reporting as described in section 5; for all other use, it is used only to improve the Services.
No training on your data. We don’t use your code, cloud or repository contents, credentials, personal data, or identifiable findings to train AI models, to benchmark, or to build anything for our own independent purposes.
AI providers. Trident’s testing agents run on third-party foundation models from OpenAI and Anthropic. Anything we send them is transient and covered by confidentiality and retention terms we negotiate — including zero-retention configurations where required — and neither is permitted to train their general-purpose models on it.
Security and subprocessors. We maintain administrative, technical, and physical safeguards, including encryption in transit and at rest, access controls, and logging, and we review our vendors. A current list of the subprocessors that handle Customer Data is available on request at contact@tridentsecurity.io. Our handling of personal data is described in our Privacy Policy, and, where a Data Processing Addendum applies, that DPA governs.
8. Confidentiality
Each party may receive Confidential Information from the other. Confidential Information will be used only to perform under these Terms, protected with at least the same degree of care the receiving party uses for its own confidential information of like importance (and not less than reasonable care), and not disclosed except to personnel and contractors with a need to know under written obligations of confidentiality.
9. Warranties and disclaimers
Each party represents that it has the authority to enter into these Terms. EXCEPT AS EXPRESSLY STATED, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE,” AND ESPRIT LABS DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. SECURITY TESTING CANNOT IDENTIFY EVERY VULNERABILITY, AND WE DO NOT WARRANT THAT THE SERVICES WILL FIND ALL ISSUES IN YOUR TARGETS OR THAT YOUR SYSTEMS WILL BE SECURE.
10. Indemnification
Each party will defend the other against third-party claims to the extent caused by its breach of these Terms or its violation of applicable law, and will pay damages and costs finally awarded against the indemnified party or agreed in a settlement approved in writing by the indemnifying party.
You will additionally defend and indemnify Esprit Labs against any claim arising from a Target you designated without holding the authorization these Terms require, including claims brought by an owner, hosting provider, or cloud provider of that Target.
11. Limitation of liability
EXCEPT FOR EACH PARTY’S INDEMNIFICATION OBLIGATIONS AND BREACH OF CONFIDENTIALITY, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL. EACH PARTY’S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY YOU TO ESPRIT LABS IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
12. Term and termination
These Terms apply while you use the Services. Either party may terminate for material breach if not cured within thirty (30) days of written notice. On termination, your right to access the Services ends and we will delete Customer Data in accordance with the schedule described in your applicable order form or, absent one, within ninety (90) days. Sections intended to survive termination will survive.
Free and trial access ends when the trial period ends or when we withdraw it, and access to findings from that use ends with it. See section 5.
13. General
These Terms are governed by the laws of the State of Delaware, without regard to conflict of laws principles. Each party submits to the exclusive jurisdiction of the state and federal courts located in Delaware. If any provision is found unenforceable, the remaining provisions will remain in effect. These Terms do not create any agency, partnership, joint venture, or employment relationship. We may update these Terms as the Services change; the date at the top shows the current version, and we’ll flag anything material to active customers.
14. Contact
Esprit Labs Inc. (Trident)San Francisco, California, USA
contact@tridentsecurity.io
tridentsecurity.io