Terms of Service & Shared Responsibility Agreement

Version 1.0 · 13 July 2026

Welcome to CVD Portal (the "Platform"), operated by Porta Regulus B.V., a private limited company registered in the Netherlands (KvK 42062307, VAT NL869534208B01), with its registered office at WTC Amsterdam, Strawinskylaan 1, 1077 XW Amsterdam, Netherlands ("we", "us", the "Provider"). By registering an account, configuring a workspace, or using any part of the Platform, you ("Tenant", "Manufacturer") explicitly agree to the following Terms of Service governing your Coordinated Vulnerability Disclosure (CVD) workflows.

1. Regulatory Compliance (EU Cyber Resilience Act)

The CVD Portal is specifically engineered to assist organizations in meeting the strict reporting and disclosure requirements mandated by the EU Cyber Resilience Act (Regulation EU 2024/2847). However, the Platform acts strictly as a data-processing utility. Ultimate regulatory liability rests with the Tenant.

1.1 Platform Capabilities (Our Responsibilities)

We provide the software architecture to facilitate compliance, including:

  • Intake & Timing: Maintaining a secure reporting pipeline (SPOC) and generating immutable audit logs to track the strict 48-hour acknowledgment regulatory clocks.
  • Data Export: Generating standard OASIS CSAF 2.0 (Common Security Advisory Framework) JSON advisories for resolved reports.
  • Threat Intelligence: Correlating your uploaded component lists automatically against the NVD (National Vulnerability Database).
  • Escalation Routing: Formatting 24-hour National CSIRT/ENISA immediate notification payloads for vulnerabilities you mark as Critical/High.

1.2 Tenant Obligations (Your Responsibilities)

By using the Platform, you acknowledge that you remain legally and operationally responsible for fulfilling the following engineering duties under the CRA:

  • SBOM & Hardware Tracking (PRE-7, PRE-8): You must actively maintain, generate (via your CI/CD pipelines), and upload accurate SPDX/CycloneDX Software Bill of Materials and Hardware Asset lists to the platform's registry.
  • Triage & Risk Assessment (VRF-1, VRF-2): You must technically reproduce incoming reports, determine their severity, and appropriately trigger the "Critical" escalation tools within the platform when societal risk exists.
  • Patch Development (RMD-2, PRE-10): You must write the actual software patches, test their efficacy, and securely host the compiled binaries or patches on your own infrastructure.
  • Active Monitoring (RCP-1): You must actively monitor the platform's alerts and your Single Point of Contact (SPOC) to ensure reports are acknowledged before deadlines expire.

2. Operations & Security

All vulnerability data is encrypted in transit and at rest. If your operations require End-to-End Encryption (E2EE) for sensitive payload exchange, you are responsible for safely generating and managing your own PGP asymmetric key pairs within the Platform's Security Settings.

3. Warranties and Limitation of Liability

The Platform is provided "AS-IS" and "AS AVAILABLE". To the extent permitted by law, we disclaim implied warranties of merchantability and fitness for a particular purpose. Reliance on the automated threat-intelligence mapping does not constitute an exhaustive penetration test of your internal systems. We shall not be held liable for regulatory fines, legal penalties, or security breaches resulting from a Tenant's failure to acknowledge active vulnerability reports, accurately configure their components, or deploy protective patches.

Subject to the following paragraph, our total aggregate liability arising out of or in connection with these Terms, whether in contract, tort (including negligence), or otherwise, is limited to the total fees you paid to us for the Platform in the twelve (12) months immediately preceding the event giving rise to the claim. We are not liable for indirect, incidental, or consequential loss, or for loss of profit, revenue, goodwill, or data.

Nothing in these Terms excludes or limits any liability that cannot be excluded or limited under Dutch law, including liability for intent (opzet) or gross negligence (bewuste roekeloosheid) within the meaning of Book 6 of the Dutch Civil Code (including art. 6:248 BW), for death or personal injury caused by our negligence, or for fraud.

4. Intellectual Property and Licence

All intellectual property rights in the Platform, including its software, design, and documentation, remain the exclusive property of Porta Regulus B.V. and its licensors. We grant you a limited, non-exclusive, non-transferable, revocable licence to access and use the Platform for your internal CVD and CRA-compliance purposes for the duration of your account. You retain all rights in the data you and your researchers upload; you grant us only the licence necessary to host, process, and display that data to operate the service.

5. Acceptable Use

You agree not to use the Platform to, and not to permit anyone to:

  • Use the Platform for any unlawful purpose or in breach of any applicable law or regulation.
  • Access, probe, or interfere with another tenant's workspace, data, or portal.
  • Attempt to circumvent authentication, rate limiting, tenant isolation, or the tamper-evident audit log.
  • Upload malware, or content that is unlawful, infringing, or that you have no right to submit.
  • Resell, sublicense, or provide the Platform to third parties except under a separate written partner agreement with us.
  • Scrape, overload, or disrupt the Platform, or use it to send unsolicited communications.

We may suspend or terminate access for a material or repeated breach of this section, where feasible after notice.

6. Data Retention and Account Termination

You can export all data your account has provided (HTML, CSV, or JSON) at any time, on any plan, from Settings, for as long as your account exists. This right is your safeguard against the deletion described below.

If your subscription or trial ends and your account has no active subscription, we retain your data for a grace period of at least 90 days during which export remains available. After that grace period, and after at least 30 days' prior notice sent to your account email, we may permanently delete the account and its data. Deletion is irreversible.

Two categories of records survive deletion because a legal obligation requires it. Records forming your CRA Article 14 evidence chain are retained in pseudonymised form, with personal identifiers removed, as described in our Data Processing Agreement. Billing and tax records are retained for the period required by law. No other data is kept.

7. Governing Law and Jurisdiction

These Terms and any dispute or claim arising out of or in connection with them (including non-contractual disputes) are governed by the laws of the Netherlands. The competent court in Amsterdam, the Netherlands, has exclusive jurisdiction, without prejudice to any mandatory consumer-protection rights you may have to bring proceedings in your country of residence.

By registering, you confirm that you have read, understood, and will abide by this Shared Responsibility Agreement.