Last updated: 2026 · Operator: ROL PORTAL SERVICES SRL, Romania · VAT RO 36837313 · Reg. J2016016379403 · [email protected].
"Service" = the CYBER3.AI platform (Ask CYBER3, CYBER3 Global Scan, AI-assisted SOC analysis). "Credit" = the billing unit. "Client" = the individual/entity using the Service. "Client Content" = the Client's data, questions and scanned assets.
CYBER3.AI provides EXCLUSIVELY defensive cybersecurity AI assistance: answers grounded in proprietary threat-intel, authorized vulnerability scanning, and human-in-the-loop decision support. The Service does not replace the Client's professional judgment.
Paid access requires an account. The Client is responsible for safeguarding credentials/API keys and for all activity under the account. The Service is intended for professionals and organizations.
Actions are debited in Credits per the rate card shown BEFORE each action. 1 Credit = €0.10 (fixed published rate). Credits are pre-purchased. Payment: direct invoice (30-day terms), card or cloud marketplace, per the order. For card and global (app / online) purchases, Paddle.com Market Ltd acts as the Merchant of Record: Paddle is the seller of record for those transactions, processes payment, issues the invoice, collects applicable sales tax/VAT and provides buyer support. Direct B2B invoices in Romania are issued by the Operator.
For purchases where Paddle is the Merchant of Record (card and global purchases), you may request a full refund within 14 days of purchase, with NO exceptions, in line with the Paddle Buyer Terms (paddle.com/legal/checkout-buyer-terms). Refunds are processed by Paddle. To request a refund, contact [email protected] or Paddle buyer support. Statutory consumer rights (including the EU 14-day right of withdrawal) remain unaffected. For direct B2B invoices issued by the Operator in Romania, mandatory statutory rules apply.
The Service is for DEFENSIVE use only. PROHIBITED: developing malware/exploits, attacks, offensive evasion, any illegal activity. External scanning is performed ONLY on Client-owned assets with verified ownership and authorization. Violations lead to suspension. By requesting an external scan you attest (click-wrap) that you own or are authorized for the target, and for domains you confirm ownership (DNS/.well-known); unauthorized scanning is illegal (e.g., US CFAA, EU Directive 2013/40, RO Law 161/2003). The scan supports your own risk management (NIS2, EU Dir. 2022/2555). Analysis is AI-assisted, defensive, with human oversight (EU Reg. 2024/1689 — AI Act).
CYBER3.AI, the engine, models, threat-intel database and interfaces remain the Operator's property. The Client retains rights to Client Content. The Client receives a limited, non-exclusive license to use the Service.
Account and usage data are hosted in the European Union. We process data strictly to provide the Service. The Client has GDPR rights (access, rectification, erasure, portability, objection). Organizational clients sign a dedicated DPA.
We treat Client Content as strictly confidential. We NEVER display or use a client's data (IP ranges, structure, results) in demos, materials or toward other clients. Discretion is a core principle of the Service.
The Service is provided "as is", without implied warranties. To the extent permitted by law, the Operator's liability is limited to amounts paid in the last 12 months. The Operator is not liable for indirect damages.
We may suspend/terminate access for breach or non-payment. We may amend these Terms with notice; continued use means acceptance.
Romanian law applies; disputes are settled by the competent courts in Romania. Contact: [email protected].