Last updated: 23 July 2026

Terms of Service

These Terms of Service ("Terms") govern access to and use of the SecForge SPLM platform and this website, operated by SecBerg ("SecBerg"). By creating an account or using the service you accept these Terms. If a signed order form or master agreement exists between your organization and SecBerg, it prevails over these Terms.

1. Scope and eligibility

SecForge SPLM is a business tool offered exclusively to companies, public bodies, and other organizations — not to consumers. The person accepting these Terms warrants that they are authorized to bind their organization.

2. The service

SecBerg grants you a non-exclusive, non-transferable right to access SecForge SPLM — including its modules for organization-level GRC, TARA, security concepts, requirements management, security testing, review management, security patching, and security defense & operations — for the number of users and projects in your subscription. You may not sublicense, resell, copy, or reverse-engineer the service.

3. Accounts and security

You are responsible for maintaining the confidentiality of your credentials and for all activity under your account. Notify us immediately at security@secberg.com if you suspect unauthorized access.

4. Acceptable use

You may not use the service to: (a) upload content you do not have the rights to; (b) attempt to circumvent tenant isolation or access other tenants' data; (c) probe, scan, or test the vulnerability of the service except under an agreed security-testing arrangement; (d) use automated scraping beyond legitimate API use; or (e) violate any applicable law or regulation.

5. Your data and intellectual property

You own all content your team creates in the platform — system models, TARA artifacts, security concepts, requirements, reports, and other work products. SecBerg processes it solely as a processor under the Data Processing Agreement. SecBerg and its licensors retain all rights in the platform itself, including its catalogs, question libraries, templates, and documentation. You may give us feedback; we may use it to improve the product without obligation.

6. AI-assisted features

Parts of the platform provide AI-assisted analysis and suggestions. These outputs are decision support for qualified engineers, not a substitute for professional judgment. You are responsible for reviewing and approving AI-assisted outputs before relying on them in any safety- or security-relevant work product.

7. Confidentiality

Each party will keep the other party's non-public information confidential and will not disclose it to third parties without prior written consent, except as required by law or court order.

8. Fees and payment

Fees are billed annually in advance (or monthly for monthly plans). Taxes are additional where applicable. Invoices unpaid 30 days after the due date may lead to suspension of the service. Fees for partial periods are not refunded.

9. Availability and support

We target 99.5% monthly uptime, measured across our monitoring regions and excluding planned maintenance. Where your tier includes SLA credits, they are issued as service credits against future invoices and are your sole remedy for downtime.

10. Warranties and disclaimer

SecBerg provides the service with reasonable skill and care. However, SecBerg does not warrant that use of the platform by itself ensures conformity with ISO/SAE 21434, UNECE R155/R156, or any other standard or regulation, nor acceptance by any authority, auditor, or customer. Responsibility for your cybersecurity engineering and its results remains with you. Further warranties are excluded to the extent permitted by law.

11. Limitation of liability

SecBerg is liable without limitation for intent and gross negligence, for injury to life, body, or health, and under the German Product Liability Act. For slight negligence, SecBerg is liable only for the breach of essential contractual obligations, limited to the damage that is foreseeable and typical for this type of contract, and capped at the fees you paid in the 12 months preceding the claim. Liability for indirect or consequential damages is otherwise excluded.

12. Export control

You are responsible for complying with applicable export-control and sanctions rules when using the platform, in particular for programs involving defense or dual-use systems.

13. Term, termination, and data export

Either party may terminate the subscription at the end of the current billing period with 30 days' notice. SecBerg may terminate immediately for material breach. After termination, you have 30 days to export your data (ReqIF, xlsx, JSON) before it is deleted in accordance with our Privacy Policy.

14. Governing law and contact

These Terms are governed by German law; the UN Convention on Contracts for the International Sale of Goods does not apply. Exclusive venue is Berlin, Germany. Contact: SecBerg · Friedrichstraße 100 · 10117 Berlin · Germany · legal@secberg.com.