1.Agreement, contracting entity, and order of precedence
These Terms of Service (“Terms”) are a legally binding agreement between the customer identified on an Order Form or, if you are only browsing the website, you as an individual visitor (“Customer”, “you”), and Remote Fort B.V., trading as Remote Fort, Keizersgracht 123, 1015 CJ Amsterdam, The Netherlands (“Remote Fort”, “we”, “us”).
The Service is offered to organisations for professional use. If you accept these Terms on behalf of a company or other legal entity, you represent that you have authority to bind that entity. If you lack that authority, you must not accept and must not use the Service.
The complete agreement (the “Agreement”) consists of: (a) the Order Form (including any statement of work or quote that references these Terms); (b) the Data Processing Addendum (“DPA”), where executed or incorporated; (c) these Terms; (d) any acceptable-use or product-specific addenda we publish and incorporate by reference; and (e) the Privacy Policy, which describes controller privacy practices and does not itself vary the DPA. Documentation and Trust Center pages are descriptive unless an Order Form expressly makes them contractual.
By accessing, browsing, or using the public website, you agree to the website-use provisions of these Terms (acceptable use, IP, disclaimers, liability, governing law) and to the Privacy Policy. Creating a tenant, paying a subscription, or signing an Order Form constitutes acceptance of the full Agreement.
Previous versions of these Terms are available on request from legal@remotefort.com.
2.Definitions
- Authorised User: an individual Customer permits to access the Service, including employees, contractors, and auditors Customer invites.
- Confidential Information: non-public information disclosed by a party that is marked confidential or that a reasonable person would understand to be confidential, including Customer Content, product non-public features, pricing, and security documentation released under NDA.
- Customer Content: data, files, evidence, configurations, prompts, outputs stored in a tenant, and other material submitted to or collected into the Service by or for Customer, including personal data therein.
- Documentation: user guides, API docs, and in-product help we provide.
- Malicious Code: viruses, worms, time bombs, droppers, or other code intended to harm or unauthorisedly access systems or data.
- Order Form: an order form, quote, SOW, or similar document that references these Terms and states the subscribed services, fees, and term.
- Professional Services: onboarding, control mapping, evidence coaching, questionnaire support, implementation of Remote Fort or a third-party GRC tool, or other human services described in an Order Form or SOW.
- Service: the Remote Fort hosted platform, related APIs, website, Trust Center, support, and Professional Services.
- Subscription Term: the period stated on the Order Form, including renewals.
- Usage Data: technical logs, security telemetry, and aggregated or de-identified metrics about how the Service is used, excluding the substance of Customer Content except as incidentally present in logs.
3.Eligibility, accounts, and Authorised Users
You must be at least 18 years old and legally able to form a contract. The Service is intended for business customers, not for consumers acting for purposes outside their trade or profession. If mandatory consumer law nevertheless applies, nothing in these Terms limits rights that cannot be waived.
Customer is responsible for Authorised Users, for the accuracy of registration data, and for all activity under its accounts. Customer must keep credentials confidential, use MFA where offered, and promptly revoke access when a person leaves or no longer needs it. Customer will notify us without undue delay of suspected unauthorised access.
We may refuse, suspend, or reclaim usernames that are misleading, infringing, or reserved. Seats, user caps, and SSO/SCIM features follow the Order Form (for example Launch plans include a stated user cap; Enterprise may include SSO/SCIM).
Customer represents that Authorised Users are authorised to access any systems Customer connects to the Service and that Customer Content is collected and used in accordance with applicable law, including employment, works-council, and vendor-privacy notices where required.
4.The Service
Remote Fort provides a security and compliance workspace. Depending on the SKU, this may include control libraries and mapping across frameworks such as SOC 2, ISO/IEC 27001, GDPR, AWS security, and VAPT-related workflows; continuous evidence collection from integrations Customer enables; vendor risk and security-questionnaire workflows; AI-assisted drafting; reporting; and related support.
We may also provide Professional Services, including help connecting systems, organising evidence, and coordinating with auditors or testers. We may introduce independent third-party auditors, penetration testers, or specialists. Unless the Order Form says we are the attesting auditor, those third parties contract separately and we are not responsible for their opinions, reports, or certifications.
We may modify the Service, provided we do not materially reduce core purchased functionality during a paid Subscription Term without a reasonable alternative or a right for Customer to terminate the affected unused portion. Beta, preview, or free features may be changed or withdrawn at any time and are provided “as is”.
We grant Customer a limited, non-exclusive, non-transferable, non-sublicensable right, during the Subscription Term, to access and use the Service solely for Customer’s internal business purposes, in accordance with the Agreement, Documentation, and applicable user limits.
5.Website, demos, and trials
The public website and Trust Center are provided for information. Submitting a demo request does not create a paid subscription. Trial or proof-of-concept tenants, if offered, are governed by these Terms and any trial length or data-wipe rules stated when the trial is provisioned. Trial data may be deleted when the trial ends unless converted to a paid Order Form.
Marketing statements, pricing pages, and case studies are illustrations, not warranties. List prices (including Launch and Scale annual figures published on the site) may change and are confirmed only on an Order Form.
6.Fees, invoicing, taxes, and payment
Fees, currency, billing frequency, and the Subscription Term are set out in the Order Form. Unless the Order Form states otherwise:
- Subscriptions are billed in advance for the Term (typically annually).
- Invoices are due within 30 days of the invoice date.
- Fees are exclusive of VAT, sales tax, and similar levies. Customer is responsible for taxes other than taxes on our net income. If we are required to collect tax, we will add it to the invoice.
- Payments may be made by invoice/bank transfer or, where offered, by card via Stripe. Card details are processed by Stripe, not stored by us as full PAN/CVC.
- Late amounts may accrue interest at the statutory commercial rate under Dutch law (wettelijke handelsrente) or 1% per month, whichever we are permitted to apply, plus reasonable collection costs.
- Fees are non-cancellable and non-refundable except as expressly stated in the Agreement or required by mandatory law.
- If Customer reasonably disputes an invoice in good faith before the due date, the undisputed portion remains payable; the parties will work in good faith on the disputed portion.
We may suspend the Service for overdue amounts after notice, except for amounts disputed in good faith. Suspension does not relieve payment obligations.
Overages (extra seats, extra frameworks, or usage beyond the Order Form) may be billed at then-current rates or the rates in the Order Form.
7.Term, renewal, and termination
The Agreement starts on the Order Form effective date (or the date you first use the Service, if earlier for website use) and continues for the Subscription Term.
Unless the Order Form states otherwise, subscriptions renew automatically for successive periods equal to the initial Term (or one year, if the initial Term is longer and the Order Form is silent) at then-current list price or the renewal price stated on the Order Form. Either party may prevent renewal by written notice at least 30 days before the end of the then-current Term.
Either party may terminate the Agreement for material breach if the breach is not cured within 30 days after written notice (or immediately if the breach is incapable of cure). We may terminate immediately if Customer infringes our IP, introduces Malicious Code, or uses the Service in a way that creates urgent security or legal risk.
Customer may terminate for convenience only if the Order Form expressly allows it. Otherwise, the Subscription Term is committed.
On termination or expiry: (a) access rights end; (b) Customer will stop using the Service and delete our Confidential Information except copies required by law or reasonable archives; (c) outstanding fees become due; (d) provisions that by nature should survive (including IP, confidentiality, disclaimers, liability, indemnities, governing law, and this survival sentence) survive.
8.Data export and deletion at the end of the Term
During the Subscription Term, Customer may export Customer Content using product export features or by requesting reasonable assistance from support (which may be billable if it exceeds standard self-serve export).
After termination or expiry, we will delete Customer Content from production systems in accordance with the DPA and our retention schedule. Backups then age out on their rolling window. Confirm the production-deletion date with support@remotefort.com. We may retain Usage Data and legally required billing records.
We have no obligation to retain Customer Content after the deletion window, and we are not a Customer’s system of record for archival compliance beyond what the product stores during the Term.
9.Acceptable use and restrictions
Customer shall not, and shall not permit others to:
- Use the Service in violation of applicable law, including export, sanctions, privacy, employment, and cybercrime law.
- Reverse engineer, decompile, disassemble, or attempt to derive source code or underlying models from the Service, except to the extent mandatory law (including EU software-directive interoperability rights) prohibits this restriction.
- Probe, scan, or load-test the Service or shared infrastructure without our prior written authorisation; run unauthenticated vulnerability scans against other customers’ tenants; or bypass technical access controls. Vulnerability reports must follow the Trust Center disclosure process (security@remotefort.com).
- Interfere with or disrupt the Service, or introduce Malicious Code.
- Resell, sublicense, lease, or provide the Service to third parties as a standalone offering, or use it to build a competing GRC product, except as an Order Form expressly allows (for example a managed-service partner schedule).
- Share login credentials, or exceed contracted seat or capacity limits.
- Misrepresent output of the Service as an independent audit opinion, certification, or legal advice issued by Remote Fort.
- Upload special category personal data or payment-card PAN/CVC except as a written DPA instruction allows; or upload content that is unlawful, infringing, or that Customer has no right to process.
- Use AI features to generate content that Customer then presents as solely human-authored where disclosure is legally required, or to attempt to identify individuals in a way that is unlawful.
- Use the website or Service to send unsolicited bulk communications, or to scrape the site in a way that impairs its operation (reasonable indexing by public search engines is allowed).
We may suspend access to the extent reasonably necessary to address a violation, a security emergency, or a legal demand, and will restore access promptly when the issue is resolved. Where practicable we will give notice.
10.Customer Content and licences
As between the parties, Customer retains all rights to Customer Content. Customer grants Remote Fort and its subprocessors a worldwide, non-exclusive licence to host, copy, process, transmit, display, and create derivative works of Customer Content solely as needed to provide, secure, maintain, and support the Service, to prevent or address service or security issues, and to comply with law.
Customer is responsible for Customer Content and represents that it has all rights and lawful bases needed to submit it and to grant the licence above. Customer is the controller of personal data in Customer Content; we are the processor, as described in the Privacy Policy and DPA.
We may generate Usage Data and aggregated or de-identified statistics that do not identify Customer or individuals, and we own those statistics. We will not use Customer Content to train general-purpose foundation models.
11.Data protection
The Privacy Policy explains our controller practices for the website, sales, and accounts. Processing of Customer Content is governed by the DPA. If Customer is established in the EEA/UK or Customer Content includes personal data of EEA/UK individuals, Customer shall execute our DPA (available on request from the Trust Center). Upon execution, the DPA is incorporated into the Agreement.
If the parties have not yet signed a DPA but Customer uses the Service to process personal data, these Terms incorporate the following processor terms until a DPA is signed: we will process Customer Content only on Customer’s documented instructions (the Agreement, product configuration, and support tickets from Authorised Users); we will ensure persons authorised to process are under confidentiality; we will implement the security measures described in the Trust Center and Section 12; we will flow down equivalent obligations to subprocessors; we will assist with data-subject requests and DPIAs that relate to the Service, at Customer’s cost if the assistance is disproportionate; we will notify personal-data breaches without undue delay; and we will delete or return Customer Content at the end of the Term as in Section 8. The public subprocessor list applies, with 30 days’ notice of material additions except where a shorter window is required to contain an incident.
Customer instructs us to process personal data as needed to provide the Service, including transfers to listed subprocessors and to AWS eu-central-1.
12.Security
Each party will maintain reasonable administrative, technical, and organisational safeguards appropriate to the nature of the data it processes under the Agreement. Our current control posture — including EU regional hosting, encryption in transit and at rest, access control, logging, and testing — is described in the Trust Center. Formal SOC 2, ISO, TISAX, and pentest evidence is released under NDA to customers and qualified prospects and is not a warranty that the Service is error-free or invulnerable.
Customer is responsible for securing its own endpoints, identity provider, integration credentials, and the systems it connects; for classifying Customer Content; and for configuring the Service, including user permissions.
Security reports: email security@remotefort.com. Do not access data that is not yours, and do not publicly disclose a vulnerability until we have had a reasonable chance to investigate. We do not offer a cash bounty by default.
13.Integrations and third-party products
The Service may interoperate with third-party products Customer chooses (identity providers, cloud accounts, device management, ticketing, other GRC tools). Those products are not part of the Service. Customer’s use of them is governed by Customer’s contract with the third party. We are not responsible for third-party unavailability, APIs, or data the third party sends or withholds.
By enabling an integration, Customer authorises us to access the third-party product as configured and to process resulting data as Customer Content. Customer must use least-privilege credentials and disable integrations it no longer needs.
If Customer asks us to implement or operate a third-party GRC platform instead of or alongside Remote Fort, Professional Services fees and that vendor’s terms apply. We do not warrant third-party platforms.
14.AI features
Certain features use machine-learning or large-language models to suggest control mappings, draft questionnaire answers, summarise evidence, or similar. Outputs may be wrong, incomplete, outdated, or unrepresentative of Customer’s actual environment. Customer must review and approve all outputs before relying on them internally or sending them to auditors, customers, or regulators.
Customer must not use AI features to process data in violation of law or of Section 9. Prompts and outputs stored in the tenant are Customer Content. We do not use Customer Content to train general-purpose foundation models.
AI features may be optional, metered, or limited by plan. We may change models or vendors that power AI features, provided we remain bound by the DPA and these Terms.
15.Professional Services
Professional Services are provided as described in the Order Form or SOW. Unless stated otherwise they are billed as packaged onboarding or on a time-and-materials basis, during business hours in the Netherlands or as agreed, and do not include a dedicated named resource except on Enterprise or SOW terms.
Customer will provide timely access, accurate information, and reasonably competent counterparts. Delays caused by Customer may shift timelines without liability for us.
Deliverables we create in the course of Professional Services (playbooks, mappings, templates) are licensed to Customer for internal use with the Service. We retain ownership of our pre-existing materials, tools, and generic know-how. Customer retains ownership of Customer Content incorporated into deliverables.
Unless an Order Form states that we will issue an independent attestation, Professional Services do not include acting as Customer’s external auditor or as a certified public accountant or advocaat providing regulated opinions.
16.Support, availability, and maintenance
Support channels and hours follow the plan on the Order Form (email and chat on Launch; premium onboarding and quarterly strategy on Scale; dedicated CSM on Enterprise, where purchased). We will use commercially reasonable efforts to respond to support requests and to make the production Service available, excluding: (a) scheduled maintenance of which we give reasonable notice; (b) emergency maintenance; (c) force majeure; (d) failures of Customer or third-party systems; (e) trial, beta, or sandbox environments.
Unless an Order Form includes a separate service-level agreement with credits, this Section is the entire availability commitment and no service credits are owed.
We may perform planned maintenance. We will aim to avoid peak European business hours where practicable.
17.Confidentiality
Each party (the “Recipient”) will use the other party’s Confidential Information only to perform the Agreement, will protect it with at least reasonable care, and will not disclose it to third parties except to personnel, advisers, and subprocessors who need it and are bound to confidentiality at least as protective as this Section. Customer Content is Customer’s Confidential Information. The Service, non-public pricing, and NDA evidence packs are our Confidential Information.
Confidentiality obligations do not apply to information that: (a) is or becomes public other than by Recipient’s breach; (b) was rightfully known without duty of confidentiality; (c) is independently developed without use of the discloser’s Confidential Information; or (d) is rightfully received from a third party without a confidentiality duty.
Recipient may disclose Confidential Information if required by law or a competent authority, after giving the discloser reasonable notice (if legally permitted) so the discloser may seek a protective order. NDA document packs requested via the Trust Center remain subject to this Section and any additional NDA Customer signs.
18.Intellectual property and feedback
We and our licensors own the Service, Documentation, control libraries, software, models, visual design, trademarks (including Remote Fort), and all related intellectual property. No rights are granted except as expressly stated. Customer must not remove proprietary notices.
If Customer provides suggestions, ideas, or error reports (“Feedback”), Customer grants us a perpetual, irrevocable, worldwide, royalty-free licence to use Feedback without restriction and without obligation to Customer. Feedback is not Customer Confidential Information.
19.Publicity
We will not use Customer’s name or logo in public customer lists, the website, or case studies without Customer’s prior consent (email is enough), except that we may identify Customer as a customer in confidential sales discussions. Either party may issue a press release if both approve the text in writing. Customer may not imply that Remote Fort certified, audited, or legally advised Customer without our written permission.
20.Warranties and disclaimers
Each party represents that it has the legal power to enter into the Agreement. We warrant that during a paid Subscription Term we will provide the Service in a professional manner substantially in accordance with the Documentation. Customer’s exclusive remedy for a breach of this warranty is, at our option, re-performance or a pro-rata refund of prepaid fees for the materially non-conforming portion of the Service.
Customer warrants that it will use the Service in accordance with the Agreement and law, and that Customer Content does not infringe third-party rights.
21.Indemnification
Remote Fort will defend Customer against third-party claims alleging that the Service, as provided by us and used in accordance with the Agreement, directly infringes a copyright, trademark, or EU/US patent, and will pay damages and reasonable costs finally awarded (or agreed in settlement we approve). We have no obligation for claims arising from: (a) Customer Content or Customer integrations; (b) combination of the Service with items we did not supply, if the claim would not have arisen without the combination; (c) modification by anyone other than us; (d) use after we notified Customer to stop because of an IP claim; or (e) trial, beta, or free services. If such a claim appears likely, we may procure the right to continue, modify the Service, or terminate the affected Service and refund prepaid unused fees for that portion.
Customer will defend Remote Fort and our directors, employees, and subprocessors against third-party claims arising from Customer Content, Customer’s use of the Service in breach of the Agreement or law, Customer’s integrations, or Authorised Users’ conduct, and will pay damages and reasonable costs finally awarded (or agreed in settlement Customer approves, not to be unreasonably withheld).
The indemnified party must give prompt notice (delay excuses the indemnifying party only to the extent it is prejudiced), reasonable cooperation, and sole control of the defence and settlement (no settlement that admits fault or imposes obligations on the indemnified party without consent, not to be unreasonably withheld).
22.Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, GOODWILL, DATA, OR BUSINESS OPPORTUNITY, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY.
EXCEPT FOR THE EXCLUSIONS BELOW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE AGREEMENT WILL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY CUSTOMER TO REMOTE FORT FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM (OR, IF THE CLAIM ARISES DURING A FREE TRIAL, ONE THOUSAND EUROS).
The following are not limited by the cap above except where mandatory law requires otherwise: (a) Customer’s payment obligations; (b) a party’s infringement or misappropriation of the other party’s intellectual property; (c) a party’s breach of confidentiality (excluding claims relating solely to personal-data incidents, which are addressed in (d)); (d) a party’s liability for a personal-data breach caused by that party’s failure to meet the DPA or Section 12, which is capped at two times (2×) the fees in the twelve months before the event; (e) Customer’s indemnification obligations; (f) fraud, wilful misconduct, or liability that cannot be limited under Dutch law (including liability for death or personal injury caused by negligence, where such a rule applies).
The limitations apply to the fullest extent permitted even if a remedy fails of its essential purpose. Multiple claims will not enlarge the cap. Nothing in these Terms excludes liability that cannot be excluded.
23.Force majeure
Neither party is liable for delay or failure to perform (except payment) due to events beyond its reasonable control, including acts of God, epidemic, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, strikes, shortages, failures of utilities or public internet, or widespread cloud-region outages at the infrastructure provider, provided the affected party uses reasonable efforts to mitigate and resume. If such an event continues more than 60 days, either party may terminate the affected unused portion of the Service on notice, with a refund of prepaid unused fees for that portion.
24.Export, sanctions, and anti-bribery
The Service may be subject to EU, UK, US, and other export-control and sanctions laws. Customer represents that it is not a sanctioned person, is not located in a comprehensively sanctioned jurisdiction, and will not use the Service for prohibited end uses (including unauthorised military or weapons purposes). Customer will not permit access from such jurisdictions or persons.
Each party will comply with applicable anti-bribery and anti-corruption laws, including the Dutch Criminal Code provisions on bribery and, where applicable, the UK Bribery Act and US FCPA. Neither party will offer anything of value to improperly influence a government official or counterparty.
25.Government and regulated customers
If Customer is a public body, additional procurement terms may be attached to the Order Form. The Service is a commercial offering. Unless an Order Form states a specific accreditation, we do not represent that the Service meets a particular government authorisation beyond what is described in the Trust Center.
Customer remains responsible for its own sectoral duties (for example financial, health, or automotive supply-chain obligations). TISAX or other marks we hold describe Remote Fort’s own assessment, not Customer’s.
26.Changes to these Terms
We may update these Terms. We will post the new version on this page and update the date. For Customers on a paid Subscription Term, material adverse changes will take effect at the next renewal unless we give at least 30 days’ notice and Customer objects in writing before the effective date, in which case the prior Terms continue until the end of the then-current Term (and we may choose not to renew). Changes required by law or that apply only to new features may take effect sooner.
Website visitors are bound by the Terms posted at the time of use. Continued browsing after an update constitutes acceptance of website-use terms.
27.Notices
Legal notices to Remote Fort must be sent to legal@remotefort.com and by post to Keizersgracht 123, 1015 CJ Amsterdam, The Netherlands, for the attention of Legal. Notices to Customer may be sent to the billing or admin email on the Order Form, or to an in-product admin notification. Email notice is deemed given on the first business day in Amsterdam after sending, unless the sender receives an immediate bounce.
28.Governing law and disputes
The Agreement is governed by the laws of the Netherlands, without regard to conflict-of-laws rules and without application of the UN Convention on Contracts for the International Sale of Goods.
The parties will first attempt to resolve disputes in good faith through discussion between commercial contacts, then (if needed) between a director-level representative, for at least 15 days after written notice of the dispute (injunctions for IP or data misuse may be sought immediately).
Exclusive jurisdiction lies with the competent courts of Amsterdam, the Netherlands, except that either party may still seek interim relief in any court of competent jurisdiction. If mandatory law gives Customer a right to sue in another forum, these Terms do not override that right.
The English language version of the Agreement controls. Translations are for convenience only.
29.Miscellaneous
- Entire agreement. The Agreement is the entire agreement and supersedes prior proposals and discussions relating to its subject. Website marketing is not incorporated except as expressly stated.
- Amendments. Except as Section 26 allows, amendments must be in writing (including agreed e-signature or an updated Order Form).
- Waiver. A failure to enforce is not a waiver. Waivers must be in writing.
- Severability. If a provision is unenforceable, it will be modified to the minimum extent necessary, and the rest remains in effect.
- Assignment. Customer may not assign the Agreement without our prior written consent, except to an affiliate or successor in connection with a merger or sale of substantially all assets, provided the assignee is not a competitor and is not sanctioned. We may assign to an affiliate or successor. Any other attempted assignment is void.
- Independent contractors. The parties are independent contractors. The Agreement does not create a partnership, joint venture, or employment relationship, and does not make us Customer’s auditor, advocaat, or Data Protection Officer unless an Order Form expressly appoints that role.
- No third-party beneficiaries. There are none, except indemnified persons under Section 21.
- Counterparts. Order Forms may be executed in counterparts and by electronic signature.
- Interpretation. “Including” means “including without limitation”. Headings are for convenience. “Written” includes email.
- Open source. The Service may include open-source components licensed under their own terms, which prevail for those components.
30.Contact
Questions about these Terms:
- Remote Fort B.V.
- Keizersgracht 123
- 1015 CJ Amsterdam
- The Netherlands
- Legal: legal@remotefort.com
- Privacy: privacy@remotefort.com
- Support: support@remotefort.com
- Sales: sales@remotefort.com
