Legal

Desktop licence agreement.

Effective 2026-07-30

These are the terms every CipherM Desktop Order Form incorporates. They are written to be read once, by a person who is not a lawyer, without anything hiding in them.

This Agreement takes effect on the Start Date of the Order Form referencing it, between Pierre Louis LLC, a Nevada limited liability company doing business as CipherM (“CipherM”), and the entity identified as Customer on that Order Form (“Customer”).

1Definitions

Software —the CipherM Desktop application, its evidence-pack generator, and the signed detection rule bundles supplied under this Agreement, together with any documentation.

Rule Bundle —a cryptographically signed set of detection rules published by CipherM and verified by the Software before use.

Licensed User —a natural person named on the Order Form, or (Enterprise) an employee or contractor of Customer operating within the Licensed Scope.

Licensed Scope —the business units, legal entities or applications listed on the Order Form. For an Assessor Seat, the Licensed Scope is unlimited as to Customer's clients and limited to the named Licensed User.

Evidence Pack —the set of artefacts the Software generates: a CycloneDX CBOM, an inventory export, a report, and a manifest.

2Licence grant

2.1Subject to payment and to this Agreement, CipherM grants Customer a non-exclusive, non-transferable, worldwide right during the Term to install and use the Software within the Licensed Scope, and to generate, retain, and deliver Evidence Packs to Customer's own clients and regulators.

2.2Assessor Seat. A seat licenses one named individual, not a workstation. That individual may install the Software on as many machines as they personally use, and may use it on behalf of any number of Customer's clients. Two assessors require two seats.

2.3Enterprise. Unlimited internal seats and unlimited scans within the Licensed Scope. Use outside that scope, including on behalf of third parties, requires a separate Order Form.

2.4Evidence Packs belong to Customer. CipherM claims no right in them. Customer may deliver them to clients, auditors, QSAs, and regulators, may publish them, and may retain them without limit of time. Expiry of this Agreement does not affect Evidence Packs already generated.

3What CipherM will not do

These are commitments, not descriptions, and Customer may rely on them.

3.1Nothing is ever sent to CipherM. The Software does not transmit source code, findings, file names, licence status, telemetry, usage data, crash reports, or any other information to CipherM or to any third party. There is no licence check-in, no rule fetch, no update check, and no analytics. Licence and rule bundle verification are performed entirely offline against Ed25519 public keys compiled into the binary. CipherM operates no service that an installed copy could contact, and could not add one without shipping Customer a new binary.

3.1.1The scanning and evidence path opens no sockets at all. scan, report, inventory, fips, explain, rules, version and selfcheck make no network connections of any kind. Your source code does not leave your network.

3.1.2Two verbs connect, only to hosts you name. cipherm certs and cipherm tls connect to an endpoint you supply on the command line, because probing a live endpoint is what they are for. They appear under a separate “network verbs” heading in the tool's own help, they run only when explicitly invoked with a target, and they contact nothing else. The optional local dashboard (scan --serve) binds a loopback listener and initiates no connection. You can confirm every word of this yourself in about ten minutes — the procedure is in the installation guide, and we would rather you did.

3.2No customer data. CipherM receives no Customer or Customer-client data through the Software and therefore cannot disclose, lose, or be compelled to produce it. A subpoena served on CipherM cannot reach Customer's scan results, because CipherM does not have them.

3.3No remote disablement. CipherM cannot disable, degrade, or limit an installed copy of the Software, and has built no mechanism capable of doing so. Entitlement is enforced only as described in section 5.

3.4No degradation by entitlement. No licence state causes the Software to detect less, scan fewer files, or withhold artefacts. An assessor working on an air-gapped network cannot renew a licence, and a tool that stops working there destroys the evidence chain it exists to produce.

4Customer obligations

4.1Customer will not sublicense, resell, rent, or provide the Software itself to a third party. Delivering Evidence Packs to clients is expressly permitted and is not a sublicence.

4.2Customer will not remove, disable, or circumvent the licence verification, the rule-bundle signature verification, the staleness controls, or any watermark the Software applies to its output.

4.3Self-certification in place of audit. CipherM has no technical means of verifying seat count or scope, because the Software makes no network calls — a deliberate product decision CipherM will not reverse, whose consequence is that CipherM cannot detect over-deployment. In place of an audit right, Customer will, on written request no more than once per Term, confirm in writing the number of Licensed Users and the Licensed Scope then in effect. A good-faith discrepancy is resolved by a true-up invoice at list price for the current Term, with no penalty and no retroactive charge.

4.4Customer is responsible for reviewing findings before relying on them. The Software detects by matching patterns against source text; it cannot determine whether a code path is reachable or whether a match sits in a comment, a test fixture, or a vendored dependency. Every finding requires human confirmation before being recorded as a deficiency, and the Software says so on every Evidence Pack it produces.

5Term, renewal, and what expiry actually does

5.1The Term is stated on the Order Form. This Agreement does not auto-renew. Renewal requires a new Order Form.

5.2On expiry, the Software continues to run and continues to report every finding it would have reported during the Term. Evidence Packs generated after expiry are watermarked as unlicensed output and record the licence state in their manifest. Rule Bundles published after expiry are not supplied, so detection reflects the last bundle received.

5.3Expiry does not affect Evidence Packs already generated, and CipherM will take no step to invalidate, revoke, or watermark them retroactively. An Evidence Pack delivered to a QSA in month three of an engagement must remain valid when that engagement is reviewed in month twenty, whatever has happened to the licence in between.

5.4Customer may terminate for CipherM's material breach on thirty (30) days' written notice, uncured. CipherM may terminate for non-payment on thirty (30) days' written notice, uncured. Fees paid are non-refundable except under 5.5.

5.5If CipherM ceases to publish Rule Bundles for more than ninety (90) consecutive days during the Term, Customer may terminate and receive a pro-rata refund of the unused portion of the annual fee.

6Rule bundles and freshness

6.1CipherM will publish Rule Bundles during the Term and supply each to Customer. CipherM does not commit to a fixed publication cadence.

6.2The Software refuses to generate an Evidence Pack from a Rule Bundle older than 120 days unless the operator passes an explicit acknowledgement flag, and that acknowledgement is recorded in the Evidence Pack manifest and printed in the report. Customer accepts that this is intended behaviour and not a defect.

7Warranty

7.1CipherM warrants that the Software will perform materially as described in its documentation, and that the binaries supplied are signed by CipherM and free of any intentionally harmful code.

7.2CipherM does not warrant that the Software identifies every cryptographic asset in any codebase, that its findings are free of false positives, or that its output satisfies any particular assessor, regulator, or standard. The Software is an inventory and evidence tool. It is not a compliance determination, and it is not a substitute for a qualified assessor's judgement.

7.3Except as stated in 7.1, the Software is provided “as is” and CipherM disclaims all other warranties, express or implied, including merchantability and fitness for a particular purpose, to the maximum extent permitted by law.

8Limitation of liability

8.1Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits or lost data, however caused.

8.2Each party's total aggregate liability arising out of or relating to this Agreement is limited to the fees paid by Customer under the applicable Order Form in the twelve (12) months preceding the event giving rise to the claim.

8.38.1 and 8.2 do not apply to Customer's payment obligations, to either party's breach of confidentiality, or to CipherM's indemnity under section 9.

9Indemnity

9.1CipherM will defend Customer against any third-party claim that the Software infringes a copyright, trade secret, or patent, and will pay damages finally awarded, provided Customer notifies CipherM promptly and allows CipherM to control the defence.

9.2If the Software becomes subject to such a claim, CipherM may procure the right for Customer to continue using it, modify it so it is non-infringing, or terminate and refund the unused portion of the annual fee.

9.3CipherM has no obligation under 9.1 to the extent a claim arises from modification of the Software by Customer or from use outside this Agreement.

10Confidentiality

10.1Each party will protect the other's confidential information with at least reasonable care and use it only to perform this Agreement. This survives termination by three (3) years.

10.2Customer's scan results, findings, and Evidence Packs are Customer's confidential information. CipherM does not receive them (see 3.2) and therefore holds no obligation with respect to material it never possesses.

10.3Neither party will name the other as a customer or supplier in marketing without prior written consent.

11General

11.1Governing law. This Agreement is governed by the laws of the State of Nevada, without regard to conflict of laws principles.

11.2Assignment. Neither party may assign this Agreement without the other's written consent, except to a successor in a merger or sale of substantially all assets, on written notice.

11.3Entire agreement. This Agreement and the Order Form are the entire agreement regarding the Software. Terms contained in a Customer purchase order, vendor portal, or click-through do not apply unless countersigned by CipherM.

11.4Order of precedence. Where the Order Form and this Agreement conflict, the Order Form controls for that order only.

11.5Amendment. Only in writing, signed by both parties.

11.6Severability. If a provision is held unenforceable, the rest remains in effect.

11.7Notices. In writing, to the addresses on the Order Form. Email to the billing and technical contacts is sufficient.

Pierre Louis LLC d/b/a CipherM · founder@cipherm.io · Questions about these terms before signing are welcome and get a straight answer.