Terms & Conditions
- Home
- Terms & Conditions
Effective Date: May 17, 2026
Contents
- Acceptance of Terms
- Description of Service
- Account Registration
- Free Account & Plan Reports
- Acceptable Use
- Data Handling & Privacy
- AI Processing Disclosure
- CMMC & Compliance Content
- Intellectual Property
- Payment & Billing
- Disclaimer of Warranties
- Limitation of Liability
- Indemnification
- Termination
- Changes to These Terms
- Governing Law
- Contact
1Acceptance of Terms
These Terms & Conditions ("Terms") constitute a legally binding agreement between you ("User," "Customer," or "you") and KnightHawk Cybersecurity LLC ("KnightHawk," "we," "us," or "our"), a Colorado limited liability company, governing your access to and use of the Watchtower platform, the KnightHawk website at knighthawkcybersecurity.com, and the application at app.knighthawkcybersecurity.com (collectively, the "Service").
By creating an account, uploading a log file, accessing any report, or otherwise using the Service, you acknowledge that you have read, understood, and agree to be bound by these Terms. If you do not agree, you may not use the Service.
2Description of Service
KnightHawk provides Watchtower, an AI-KnightHawk provides Watchtower, an AI-assisted security log analysis and reporting platform that enables users to:
- Upload security log files (Windows Event, Linux syslog, macOS, firewall, web server, IDS/IPS, network capture, and other supported formats)
- Receive AI-assisted security assessments with MITRE ATT&CK framework mappings, investigation guidance, and remediation steps
- Generate CMMC Readiness & Evidence Reports with NIST 800-171 domain coverage analysis
- Produce Executive Summary Reports that summarize security and compliance posture for organizational leadership
- Interact with prior log sessions via natural-language Q&A
The Service is intended to support your organization's security awareness and compliance documentation efforts. It does not replace the advice of qualified cybersecurity professionals, legal counsel, or certified CMMC assessors.
3Account Registration
Access to the Watchtower platform requires account registration. You agree to:
- Provide accurate and complete information when creating your account
- Maintain the security of your account credentials and not share access with unauthorized individuals
- Notify us immediately at info@knighthawkcybersecurity.com if you believe your account has been compromised
- Accept responsibility for all activity that occurs under your account
You must be at least 18 years of age and have the authority to bind the organization you represent to these Terms. KnightHawk reserves the right to refuse or terminate accounts at its discretion.
4Free Account & Plan Reports
New accounts include one (1) complimentary report at no charge ("Free Scan"). No credit card is required to create a free account or use the Free Scan.
After the Free Scan is used, continued use of the Service requires a paid plan. Each paid plan includes a set number of reports per monthly billing period as described on the applicable pricing page. Included reports reset at the start of each billing period and do not carry over to the following month. Reports included in a plan are non-transferable.
KnightHawk reserves the right to modify the free tier offering at any time with reasonable notice.
5Acceptable Use
You agree to use the Service only for lawful purposes and in accordance with these Terms. You agree not to:
- Upload log files or other data that you do not have the legal right to process or analyze
- Use the Service to analyze systems or networks you do not own or have explicit written authorization to assess
- Attempt to reverse-engineer, scrape, or extract proprietary components of the platform
- Circumvent account limits, authentication controls, or per-customer data isolation mechanisms
- Use the Service in any way that violates applicable federal, state, or local law, including the Computer Fraud and Abuse Act (CFAA) and applicable data protection regulations
- Upload log files or data containing Controlled Unclassified Information (CUI), export-controlled data, classified information, regulated defense technical data, or other restricted government information unless KnightHawk has expressly agreed in writing to handle such data under an appropriate written agreement.
- Resell, sublicense, or white-label the Service without express written authorization from KnightHawk
KnightHawk reserves the right to suspend or terminate accounts found to be in violation of these provisions without prior notice.
6Data Handling & Privacy
Log File Data. Log files you upload are processed in memory to generate your report and stored in our database solely to support your account's report history, session Q&A, and evidence documentation. Log files are isolated to your individual customer account. No other customer can access your log data.
Data Minimization. We do not store raw log files beyond what is necessary to fulfill the Service. Processed event data (parsed log events, report outputs, and CMMC evidence summaries) are retained to support your account history and may be deleted upon account termination request.
No Shared Model Training. Your raw log data is never used to train shared AI models — by KnightHawk or any AI vendor — by default. Product improvements rely only on minimized, anonymized, or aggregated data. See Section 7 for AI vendor disclosures.
Data Retention. Processed report data and log event summaries are retained for the duration of your account. You may request deletion of your data at any time by contacting info@knighthawkcybersecurity.com. Deletion requests will be processed within 30 days.
Our full Privacy Policy, which is incorporated by reference into these Terms, is available at knighthawkcybersecurity.com/privacy.
7AI Processing Disclosure
The Service uses third-party AI APIs to generate security assessments, CMMC evidence analysis, and executive briefings. By using the Service, you acknowledge and agree that:
- Excerpts of your processed log data (parsed event summaries — not raw file contents) are transmitted to third-party AI vendors for inference. We do not transmit full raw log files to AI vendors.
- Log excerpts sent to AI vendors are governed by each vendor's data handling policy. For our current primary AI provider (OpenAI API), customer data submitted via the API is not used for model training by default unless explicitly opted in.
- KnightHawk documents what data each AI vendor receives and under what conditions. This documentation is available upon request.
- AI-generated outputs are probabilistic and may contain errors, omissions, or misclassifications. All reports should be reviewed by qualified personnel before being used for compliance, legal, or operational decisions.
8CMMC & Compliance Content
KnightHawk's CMMC Readiness & Evidence Reports and CMMC Executive Summary Reports are designed to support your organization's compliance documentation and internal risk awareness efforts. These outputs:
- Are informational only and do not constitute legal advice, regulatory guidance, or a formal compliance assessment
- Do not guarantee CMMC certification, NIST 800-171 compliance, or readiness for a C3PAO assessment
- Are not a substitute for a qualified CMMC Registered Practitioner Organization (RPO) assessment or C3PAO audit
- Are based solely on the log data you upload; they do not reflect your organization's full security posture, policies, or controls
Financial figures presented in CMMC Executive Summary Reports (contract risk exposure, audit gap risk estimates, compliance cost projections) are estimates based on industry benchmarks and the log data analyzed. They are not financial advice and should not be relied upon as accurate projections without independent verification.
KnightHawk is not a CMMC Third-Party Assessment Organization (C3PAO), Registered Practitioner Organization (RPO), or Certified CMMC Assessor. Use of the Service does not establish a professional engagement or create any professional obligation between KnightHawk and your organization.
9Intellectual Property
KnightHawk Property. The Watchtower platform, including all software, algorithms, workflows, report templates, MITRE mapping logic, scoring models, and visual design, is the exclusive intellectual property of KnightHawk Cybersecurity LLC. Nothing in these Terms grants you any ownership interest in the platform or its components.
Your Content. You retain all ownership rights to the log files and data you upload. By uploading data to the Service, you grant KnightHawk a limited, non-exclusive license to process that data solely for the purpose of delivering the Service to you.
Report Output. Reports generated by the Service from your log data are provided for your use. You may use, reproduce, and share generated reports internally and with authorized third parties (auditors, legal counsel, assessors). You may not represent AI-generated report content as independently produced by a human security analyst or certified assessor.
10Payment & Billing
Paid plans are billed monthly in advance based on the plan tier you select. All fees are stated in US dollars. By providing payment information, you authorize KnightHawk (via its payment processor) to charge your selected payment method for the applicable plan amount on each renewal date.
Refunds. Monthly plan fees are non-refundable except where required by applicable law, or where KnightHawk determines at its sole discretion that a refund is warranted due to a Service error or defect.
Overages. If you exceed your plan's monthly included reports, additional reports may be available at the per-report overage rate stated on the applicable pricing page at the time of use.
Price Changes. KnightHawk reserves the right to change plan pricing with at least 30 days' notice. Price changes take effect at your next renewal date following the notice period.
Taxes. You are responsible for all applicable taxes, duties, or levies imposed by any governmental authority in connection with your use of the Service.
11Disclaimer of Warranties
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, OR NON-INFRINGEMENT.
KNIGHTHAWK DOES NOT WARRANT THAT: (A) THE SERVICE WILL MEET YOUR SPECIFIC REQUIREMENTS; (B) REPORTS WILL BE ERROR-FREE OR COMPLETE; (C) THE SERVICE WILL BE UNINTERRUPTED OR SECURE; OR (D) ANY SECURITY VULNERABILITY, THREAT, OR COMPLIANCE GAP IDENTIFIED OR NOT IDENTIFIED BY THE SERVICE IS ACCURATE OR EXHAUSTIVE.
AI-generated outputs are probabilistic in nature. Threat classifications, MITRE mappings, CMMC domain scores, and financial estimates may contain inaccuracies. You assume full responsibility for verifying and acting on any findings produced by the Service.
12Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, KNIGHTHAWK CYBERSECURITY LLC AND ITS OFFICERS, EMPLOYEES, AGENTS, AND LICENSORS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES — INCLUDING LOST PROFITS, DATA LOSS, BUSINESS INTERRUPTION, OR LOSS OF CONTRACT REVENUE — ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
IN NO EVENT SHALL KNIGHTHAWK'S TOTAL CUMULATIVE LIABILITY TO YOU FOR ALL CLAIMS ARISING UNDER THESE TERMS EXCEED THE GREATER OF: (A) THE TOTAL FEES PAID BY YOU TO KNIGHTHAWK IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM; OR (B) ONE HUNDRED US DOLLARS ($100).
13Indemnification
You agree to indemnify, defend, and hold harmless KnightHawk Cybersecurity LLC and its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable attorneys' fees) arising out of or in any way connected with:
- Your use of the Service in violation of these Terms
- Your upload of log files or data you did not have the legal right to process
- Any misrepresentation of KnightHawk report outputs to third parties (including auditors, regulators, or clients)
- Your violation of any applicable law or regulation
14Termination
You may terminate your account at any time by contacting info@knighthawkcybersecurity.com. Upon termination, your access to the Service will be revoked and your stored data will be scheduled for deletion within 30 days.
KnightHawk may suspend or terminate your account immediately and without prior notice if you violate these Terms, engage in conduct that could harm KnightHawk or its users, or fail to pay applicable fees when due.
Sections 8 (CMMC & Compliance Content), 9 (Intellectual Property), 11 (Disclaimer of Warranties), 12 (Limitation of Liability), 13 (Indemnification), and 16 (Governing Law) survive termination of these Terms.
15Changes to These Terms
KnightHawk reserves the right to update or modify these Terms at any time. When we make material changes, we will update the Effective Date at the top of this page and, where practicable, provide notice via email to registered account holders.
Your continued use of the Service after updated Terms are posted constitutes your acceptance of the revised Terms. If you do not agree to the revised Terms, you must stop using the Service and may request account termination.
16Governing Law
These Terms shall be governed by and construed in accordance with the laws of the State of Colorado, without regard to its conflict of law provisions. Any dispute arising under or relating to these Terms shall be subject to the exclusive jurisdiction of the state and federal courts located in Colorado, and you consent to personal jurisdiction in those courts.
If any provision of these Terms is found to be unenforceable, the remaining provisions shall remain in full force and effect.
17Contact
If you have any questions about these Terms or the Service, please contact us:
KnightHawk Cybersecurity LLC
Email: info@knighthawkcybersecurity.com
Website: knighthawkcybersecurity.com