Oksa Security
Last updated: 22 September 2026 · Effective upon subscription
Oksa Security provides an external attack surface management (ASM) platform ("Service"). The Service continuously monitors the publicly visible digital perimeter of the domains you register, including subdomains, open network ports, TLS certificates, DNS security records, public cloud storage, and public source code repositories.
The Service is strictly passive and read-only. We collect only information that is already publicly accessible on the internet. We do not attempt authentication, exploit vulnerabilities, execute payloads, or modify any customer or third-party systems.
The Service is a monitoring and awareness tool. It identifies publicly visible indicators that may represent security risk. The Service does not guarantee that your systems are secure, that all vulnerabilities will be detected, or that your organisation will not experience a security incident, data breach, or cyberattack.
Factors outside the scope of the Service include, but are not limited to:
The Customer is solely responsible for evaluating findings, prioritising remediation, and implementing security controls. Use of the Service does not relieve the Customer of any security obligations under law, regulation, or contract.
To the maximum extent permitted by applicable law, Oksa Security shall not be liable for any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to:
This limitation applies regardless of the theory of liability (contract, tort, negligence, strict liability, or otherwise) and even if Oksa Security has been advised of the possibility of such damages.
Where liability cannot be excluded by law, Oksa Security's total aggregate liability for all claims under or related to this agreement shall not exceed the total subscription fees paid by the Customer in the three (3) months immediately preceding the event giving rise to the claim.
The Customer agrees to:
Subject to payment of the applicable subscription fee and compliance with these Terms, Oksa Security grants the Customer a non-exclusive, non-transferable, revocable license to access and use the Service solely for the Customer's internal security monitoring purposes during the subscription period.
The Customer may not sub-license, resell, or provide access to the Service to third parties without prior written consent from Oksa Security.
All software, algorithms, data models, and visual designs comprising the Service are the exclusive property of Oksa Security. Nothing in these Terms transfers any intellectual property rights to the Customer.
Scan results generated from the Customer's registered domains are owned by the Customer. Oksa Security may use aggregated, anonymised findings to improve the Service.
Processing of personal data related to your use of the Service is governed by our Privacy Policy. For organisations subject to GDPR, a Data Processing Agreement (DPA) is available on request.
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND. OKSA SECURITY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
OKSA SECURITY DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR THAT ALL SECURITY FINDINGS AFFECTING THE CUSTOMER'S ASSETS WILL BE IDENTIFIED.
The Customer agrees to indemnify, defend, and hold harmless Oksa Security from any claims, losses, damages, liabilities, costs, and expenses (including reasonable legal fees) arising from: (a) the Customer's use of the Service in violation of these Terms; (b) the Customer's monitoring of domains without authorisation; or (c) any breach by the Customer of applicable law.
These Terms are governed by the laws of Finland. Any dispute arising from or related to these Terms that cannot be resolved amicably shall be submitted to the exclusive jurisdiction of the Helsinki District Court (Helsingin käräjäoikeus).
Oksa Security may update these Terms from time to time. Material changes will be notified by email at least 30 days in advance. Continued use of the Service after the effective date constitutes acceptance of the updated Terms. If you do not accept updated Terms, you may cancel your subscription before the effective date.
Questions regarding these Terms: oksasecurity@gmail.com