Terms of Service

Effective 25 June 2026

These terms are a contract between you and Nomad Crow s.r.o. ("we", "us") and govern your use of Normproof (the "Service"). By creating an account or using the Service, you agree to them.

1. The Service

Normproof helps software manufacturers prepare and maintain a conformity package for the EU Cyber Resilience Act (Regulation (EU) 2024/2847): a software bill of materials (SBOM), vulnerability handling, technical documentation, and a draft EU Declaration of Conformity. The Service generates these artefacts from the information and source/build data you connect.

2. Not legal advice; you self-declare conformity

Normproof is a tool, not a law firm, a notified body, or a conformity-assessment body. We do not provide legal advice and we do not certify your products. Under the CRA default category (Annex VIII, Module A) the manufacturer assesses and declares conformity on its own responsibility. The documents the Service produces are drafts and evidence to support your assessment; you are responsible for reviewing them, supplying accurate inputs, completing any items marked “needs input”, and deciding whether to sign and rely on the Declaration of Conformity. Nothing in the Service shifts that responsibility to us.

Outputs are generated from the inputs you provide and the current rules library and may contain errors, omissions, or outdated information — for example where a regulatory change has not yet been reflected in the rules library, or where your inputs are incomplete. Generated outputs reflect what was known at the time they were generated: a new vulnerability in one of your components, a dependency change, or a legal or regulatory development can all affect their accuracy afterwards without a document being automatically regenerated. Review every generated document independently — and regenerate it if your product or its dependencies have changed — before relying on it, filing it, or making a regulatory statement based on it.

3. Accounts

You must provide accurate registration details and keep your credentials secure. You are responsible for activity under your account and your organisation’s workspace. Roles (Owner, Admin, Editor, Viewer) determine what each member may do. Notify us promptly of any unauthorised access.

4. Acceptable use

You agree not to:

  • access another customer’s organisation or data, or attempt to defeat tenant isolation;
  • conduct security testing, scanning, or load-testing against the Service itself without our prior written authorisation, except through features we provide for testing your own data;
  • reverse engineer, decompile, or disassemble the Service, except to the extent applicable law makes this restriction unenforceable;
  • scrape or harvest data from the Service by automated means outside the features we provide;
  • consume shared computing resources in a way designed to degrade the Service for other customers, or otherwise make excessive automated use of it;
  • upload unlawful content, malware, or other malicious code, or material you have no right to submit;
  • resell or provide the Service to third parties except as expressly permitted;
  • use the Service to build a competing product; or
  • misuse the free, public CRA readiness checker (it is rate-limited and for genuine evaluation).

5. Your data and our intellectual property

You retain all rights in the data you submit (“Customer Data”), including source and build metadata, SBOMs, findings, audit-trail records of activity in your organisation, and the generated dossiers. You grant us a limited, non-exclusive licence to host, copy, process, analyse, and transform Customer Data, and to generate outputs from it (such as SBOMs, findings, and dossiers), solely to provide, secure, and support the Service for you. Audit-trail records are available to you through dossier export bundles, and — like the rest of your organisation’s Customer Data — are deleted if you delete your organisation.

We and our licensors own the Service itself — the Normproof platform, software, the rules engine, document templates, and all associated trademarks and branding. Except for the limited right to use the Service under these terms, nothing here grants you any rights in our intellectual property. Software we make available under an open-source licence (for example the free SBOM/scan CLI) remains governed by that licence’s own terms, and third-party open-source components the Service identifies or incorporates (for example in a generated SBOM) remain subject to their own licences; we make no warranty regarding them.

Where Customer Data includes personal data (for example, names or email addresses of people in your organisation or your own end users), you act as the data controller and we act as processor, handling it only on your documented instructions. That processing is governed by our Data Processing Addendum, which forms part of these terms. How we handle personal data more broadly is described in our Privacy Policy.

6. Your representations and warranties

You represent and warrant that:

  • you have the authority to connect and upload the repositories, builds, and documents you submit;
  • you own, or are licensed to provide, all Customer Data you submit;
  • your Customer Data does not infringe a third party’s intellectual property rights;
  • your use of the Service, including any Customer Data you submit, complies with applicable export-control and sanctions laws; and
  • where Customer Data contains personal data, you have an appropriate legal basis and any required consents for including it.

7. Plans, billing and trials

The public readiness checker and the open-source SBOM/scan CLI are free. Paid plans (documents, monitoring, and audit trail) are billed through our payment processor, Stripe. Fees are stated at checkout, charged in advance for the billing period, and exclusive of taxes unless stated. Subscriptions renew automatically until cancelled; you can cancel anytime and retain access through the end of the paid period. Except where required by law, fees are non-refundable.

8. Availability and changes

We aim to keep the Service available but do not guarantee uninterrupted operation. Maintenance, outages, and third-party failures (including at our own sub-processors) may affect availability; unless we have agreed a specific service level with you in writing, we do not promise a specific uptime figure. We may update features, the rules library, and document templates; material changes that affect your dossiers are versioned so prior outputs remain reproducible.

9. Third-party services and integrations

The Service relies on sub-processors (for example cloud hosting in the EU, Stripe for payments, and an email provider) and draws on public vulnerability data sources such as NVD, OSV, GHSA, and the EUVD. We are not responsible for the accuracy, completeness, availability, or timeliness of these third-party services or data sources — a delay or inaccuracy in one of them can affect the completeness of a scan or dossier.

Where you connect a third-party integration (for example GitHub, GitLab, or Azure DevOps), that integration depends on the relevant provider’s API; a change to that API may affect functionality, and you are responsible for maintaining the credentials and permissions the integration needs.

10. Beta and experimental features

We may offer features labelled beta, preview, or experimental. These are provided without warranty, without a specific support commitment, and without guaranteed availability, and we may change or withdraw them at any time.

11. Warranties and disclaimer

The Service is provided “as is” and “as available”. To the maximum extent permitted by law, we disclaim all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that use of the Service will result in regulatory compliance or a successful conformity assessment.

We implement technical and organisational security measures appropriate to the risk of processing your data, as described in our Privacy Policy; we do not promise a specific security standard or certification unless agreed separately in writing.

We are not liable for regulatory penalties, fines, enforcement actions, market-surveillance findings, market-withdrawal orders, or notified-body or certification decisions concerning your product. Those outcomes depend on your product, your own compliance work, and the accuracy and completeness of the inputs you provide — not on the Service.

12. Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, or consequential damages. Our aggregate liability arising out of the Service is limited to the fees you paid in the twelve months before the event giving rise to the claim. Nothing limits liability that cannot be limited by law.

13. Indemnification

You agree to indemnify and hold us harmless from third-party claims, damages, and reasonable legal costs arising from: your unlawful use of the Service; Customer Data that infringes a third party’s rights or violates applicable law; or a Declaration of Conformity, CE marking decision, or other regulatory statement you make in reliance on the Service’s outputs. This does not extend to claims arising from our own breach of these terms or applicable law.

14. Confidentiality

Each party may receive confidential, non-public information from the other. For us, this includes your Customer Data, account information, and your compliance documentation; for you, this may include our non-public technical documentation, pricing, security information, and unpublished product information. Each party will protect the other’s confidential information with at least the same care it uses for its own, and use it only to perform under these terms, except where disclosure is required by law.

15. Export control and sanctions

You may not access or use the Service in violation of applicable EU, UN, or other trade-control or sanctions laws, including from a sanctioned territory or on behalf of a person or entity subject to sanctions. You represent that you are not subject to such restrictions.

16. Force majeure

Neither party is liable for delay or failure to perform caused by events reasonably beyond its control, including cloud-provider or internet outages, war, government action, sanctions, or cyberattacks, for as long as that event continues.

17. Suspension and termination

You may stop using the Service and close your account at any time; deleting your organisation through the Service deletes its Customer Data, including audit-trail records, immediately.

We may suspend or terminate your access for material breach of these terms. We may also suspend access, without treating it as termination, where we reasonably suspect a security incident, abuse of shared computing resources, excessive automated use, an attempt to circumvent security or tenant isolation, or where a legal or regulatory request requires us to — restoring access once the issue is resolved.

If we terminate your access for breach, you may export your Customer Data for a reasonable period beforehand where practicable, after which we may delete it in line with the Privacy Policy. Backups are retained only for the limited window described there and are not a substitute for exporting your own data.

18. Governing law

These terms are governed by the laws of the Slovak Republic, and the courts of that jurisdiction have exclusive jurisdiction, without prejudice to mandatory consumer-protection rights you may have where you live.

19. Changes to these terms

We may update these terms. We will post the new version here and update the effective date; material changes will be notified to account holders. Continued use after changes take effect means you accept them.

20. General provisions

You may not assign these terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. If a provision is found unenforceable, the rest remains in effect, and an unenforceable provision is replaced with one that most closely reflects its intent. These terms, the Privacy Policy, and the Data Processing Addendum are the entire agreement between us on this subject and supersede prior discussions on it. A failure to enforce a provision is not a waiver of it. Provisions that by their nature should survive termination — including intellectual property, confidentiality, indemnification, warranties, and limitation of liability — do. If you send us feedback or suggestions about the Service, we may use them without obligation or compensation to you; this does not give us any rights in your confidential information beyond the feedback itself. We may communicate with you electronically, including by email, and you consent to that as a way of receiving notices under these terms.

21. Contact

Nomad Crow s.r.o., Astrová 43, 900 41 Rovinka, Slovakia (company no. 51320304, VAT SK2120677383). Questions about these terms: legal@normproof.com.

Questions? See the Privacy Policy and Terms of Service, or contact support@normproof.com.