Terms of Service
Effective 2026-05-02 · governing law: Israel.
1. Definitions
"Cybool" means the Cybool Platform operated by SymbioLab Ltd., a company incorporated in Israel. "Customer" (or "Partner" / "Client" depending on tenancy tier) means the legal entity that signs up to use the Platform. "Customer Data" means data the Customer or its end users submit to or generate within the Platform.
2. Service description
Cybool provides a multi-tenant SaaS for cyber posture management, threat intelligence, compliance readiness (NIS2, ISO 27001, NIST CSF 2.0, AI Act, DORA), third-party risk management, AI-assisted policy generation, and incident response. The Platform is hosted in the EU and operated under the architecture summarised at /trust.
3. Account & access
Cybool issues each Partner an isolated tenant. Partners may onboard their own Clients into their tenant. Customer is responsible for maintaining the confidentiality of credentials, enabling MFA on privileged accounts, and promptly disabling former-employee access.
4. Acceptable use
- No use of the Platform that violates applicable law or third-party rights.
- No reverse engineering of the Platform beyond the limits Israeli law permits.
- No automated bulk extraction of Cybool-curated reference data (NIS2 / ISO controls, scenario library, policy templates).
- No attempts to circumvent tenant isolation; report any cross-tenant defect via security@cybool.com.
5. Fees & billing
Subscriptions are billed monthly or annually per the SKU agreed at signup (Starter / Pro / Enterprise). Cybool currently invoices manually (no Stripe / Paddle integration). Fees are non-refundable except where Israeli consumer law requires.
6. Customer Data ownership
Customer Data is and remains the Customer's property. Cybool processes Customer Data solely as a data processor on behalf of the Customer to provide the Platform; the Data Processing Addendum governs that processing.
7. AI processing
The Platform uses Anthropic Claude and Mistral AI for AI features (summarisation, document extraction, embeddings, copilot). AI inference is performed on the EU-resident endpoints of those vendors. We do not allow our AI vendors to train on Customer Data. AI-generated outputs are advisory; Customer must review before acting on them.
8. Sub-processors
Current sub-processors are listed at /trust. Cybool gives Customer 30 days' notice before adding a new sub-processor that will process Customer Data.
9. Warranties & disclaimers
Cybool warrants that the Platform will materially perform as described in product documentation and the applicable Order Form. EXCEPT FOR THE FOREGOING, THE PLATFORM IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND. Cybool is a security-decision-support tool and does not guarantee detection or prevention of any specific threat.
10. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, CYBOOL'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE TERMS WILL NOT EXCEED THE FEES PAID BY CUSTOMER TO CYBOOL IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY. NEITHER PARTY IS LIABLE FOR INDIRECT, CONSEQUENTIAL, INCIDENTAL, OR PUNITIVE DAMAGES.
11. Term & termination
These Terms remain in effect while Customer has an active subscription. Either party may terminate for material breach uncured after 30 days' written notice. Cybool may suspend access without notice for actions that pose immediate security risk to other customers (cross-tenant attack attempts, etc.).
12. Governing law
These Terms are governed by the laws of Israel, without regard to conflict-of-laws principles. The competent courts of Tel Aviv-Jaffa have exclusive jurisdiction over any dispute, except that either party may seek injunctive relief in any court of competent jurisdiction.
13. Changes
Cybool may revise these Terms. Material changes are notified at least 30 days in advance via email and in-app banner. Continued use after the effective date constitutes acceptance.
Contact: legal@cybool.com · Effective date: 2026-05-02.