// Terms of Service — content mirrors vantuz-platform/.planning/legal/TERMS-OF-SERVICE.md

const TERMS_SECTIONS = [
  { h: '1. The service', blocks: [
    'Vantuz provides intrusion detection by deception: you deploy decoy assets ("honeytokens") across your own environment, and Vantuz alerts, investigates and (on supported plans) helps contain access to them. Features and limits depend on your plan, as described at vantuz.co/pricing.',
  ] },
  { h: '2. Accounts and eligibility', blocks: [
    'The service is for business use by organisations and the professionals acting for them. You are responsible for your account, your users, and keeping credentials secure. We strongly recommend enabling two-factor authentication.',
  ] },
  { h: '3. Acceptable use', blocks: [
    'You agree to deploy honeytokens **only in environments you own or are authorised to protect**. You must not:',
    { ul: [
      'deploy decoys in systems you do not control or have no authorisation to monitor;',
      'use the service to entrap, surveil, or unlawfully process data about individuals outside a genuine security purpose;',
      "attempt to breach the service, other customers' data, or our infrastructure;",
      'use the service in violation of applicable law (including computer-misuse, privacy and export laws).',
    ] },
    'You are responsible for the lawfulness of your deployment, including any required notices or assessments in your jurisdiction.',
  ] },
  { h: '4. Containment actions', blocks: [
    'On supported plans, Vantuz can take automated containment actions against your own connected provider accounts (e.g. revoke a key, block an IP). You authorise these actions by connecting an integration and configuring thresholds. You are responsible for the configuration; Vantuz acts on your instruction and is not liable for the consequences of containment you enabled, except as set out in Section 8.',
  ] },
  { h: '5. Customer data and privacy', blocks: [
    'Our processing of personal data is described in the Privacy Policy. Where Vantuz processes personal data on your behalf, our Data Processing Agreement applies and forms part of these Terms.',
  ] },
  { h: '6. Fees', blocks: [
    'Paid plans are billed in advance per the pricing in effect. Fees are non-refundable except as required by law or expressly stated. We may change pricing with reasonable notice; changes apply at your next renewal.',
  ] },
  { h: '7. Availability', blocks: [
    'We aim for high availability but do not guarantee uninterrupted service unless a separate SLA is agreed in writing. We may perform maintenance and will use reasonable efforts to minimise disruption.',
  ] },
  { h: '8. Warranties, scope of protection, and liability', blocks: [
    { h3: '8.1 No guarantee of protection' },
    'Vantuz is a detection-by-deception and response-assistance tool. It is **one layer** of security, not a complete or comprehensive security solution, and it does not protect your entire infrastructure. Vantuz makes **no representation, warranty or guarantee** that it will detect, identify, prevent, block, contain, or remediate any or all attacks, intrusions, compromises, or unauthorised access, or that your systems, data or accounts will be or remain secure. Security is inherently probabilistic; no product can guarantee protection against a determined, novel, or sophisticated adversary.',
    { h3: '8.2 What is outside the service' },
    'The service only observes activity that interacts with the decoys you deploy and the integrations you connect. It does not, and is not intended to, detect, prevent or respond to attacks or compromise that do not interact with a deployed decoy, including (without limitation): social engineering and phishing; theft or misuse of legitimate credentials; insider threats; vulnerabilities, misconfigurations, or malware in systems where no decoy is deployed; zero-day or previously unknown techniques; supply-chain compromise; denial-of-service; physical attacks; or any activity in environments, accounts, or assets you have not connected to or covered with Vantuz. Coverage is limited to what you choose to deploy and configure, and gaps in coverage are your responsibility.',
    'You alone decide where, how many, and in what configuration to place decoys within your environment. Vantuz does not deploy decoys into your systems and cannot know, verify, or assess whether your placement, quantity, or distribution is appropriate or sufficient for your risk. The effectiveness of the service depends directly on these choices, which are yours.',
    { h3: '8.3 Customer responsibility' },
    'You are solely responsible for your overall security posture. This includes deploying adequate decoys and controls, configuring containment thresholds, maintaining your own defences (patching, access management, backups, logging, monitoring, and staff training), and all decisions and actions taken in response to Vantuz alerts, scores, narratives and recommendations, which are **advisory only** — you make the final decision on any action. You remain responsible for your own incident response and for any breach-notification or regulatory obligations that apply to you.',
    'Alerts, notifications and reports are a best-effort signal. Vantuz does not guarantee that any alert will be generated, delivered, delivered on time, or seen, and is **not responsible for whether or when you read, acknowledge, or act on an alert**, nor for any loss arising from a delayed, missed, undelivered, or unread alert (including where email or other delivery fails for reasons outside Vantuz’s control). You are responsible for monitoring for alerts and for responding within a timeframe appropriate to your own risk.',
    { h3: '8.4 "As is" and limitation of liability' },
    'The service is provided **"as is"** and **"as available"**. To the maximum extent permitted by law, Vantuz disclaims all implied warranties, including merchantability, fitness for a particular purpose, and any warranty that the service will be uninterrupted, error-free, or secure.',
    'Nothing in these Terms excludes or limits any liability that cannot lawfully be excluded or limited, including for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.',
    'Subject to the paragraph above, and to the maximum extent permitted by law:',
    { ul: [
      "Vantuz is **not liable** for any security breach, intrusion, unauthorised access, data loss or exfiltration, ransomware, malware, fraud, business interruption, downtime, or for any loss or damage resulting from such events — **whether or not** Vantuz detected, alerted on, scored, or attempted to contain the underlying activity, and whether or not the activity was within the service’s scope;",
      'Vantuz is **not liable** for any indirect, special, incidental, or consequential loss, or for loss of profit, revenue, data, goodwill, business, or anticipated savings, for regulatory fines or penalties, or for third-party claims; and',
      "Vantuz’s **total aggregate liability** arising out of or related to the service, on any basis (contract, tort including negligence, statute, or otherwise), is **limited to the fees you paid to Vantuz in the 12 months** before the event giving rise to the claim.",
    ] },
    'You acknowledge that the fees reflect this allocation of risk, and that Vantuz would not provide the service on these terms without these limitations. These limitations survive termination of these Terms.',
  ] },
  { h: '9. Suspension and termination', blocks: [
    'We may suspend or terminate access for breach of these Terms, non-payment, or unlawful use. You may cancel at any time; cancellation stops future billing. On termination we will delete or return your data per the Privacy Policy and DPA.',
  ] },
  { h: '10. Changes', blocks: [
    'We may update these Terms with reasonable notice. Continued use after changes take effect constitutes acceptance.',
  ] },
  { h: '11. Governing law', blocks: [
    'These Terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to mandatory consumer/data-protection rights in your jurisdiction.',
  ] },
];

function TermsPage() {
  return (
    <LegalDoc
      eyebrow="LEGAL · TERMS OF SERVICE"
      title="Terms of Service"
      effective="Effective date: 9 June 2026"
      intro={[
        'These Terms govern use of the Vantuz platform provided by Vantuz Ltd ("Vantuz", "we"), a company registered in England and Wales (company no. 17270048), 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. By creating an account or using the service you ("Customer") agree to these Terms.',
      ]}
      sections={TERMS_SECTIONS}
      contact="Contact: legal@vantuz.co"
    />
  );
}

ReactDOM.createRoot(document.getElementById('root')).render(<TermsPage />);
