These Terms of Service (“Terms”) govern your access to and use of the FDIE (Firmware Delta Intelligence Engine) platform, operated by MAGDOX Private Limited (“Magdox,” “we,” “us,” or “our”), a company incorporated under the laws of India with registered address at St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India. These Terms constitute an electronic record under the Information Technology Act, 2000. By accessing or using the Service, you agree to these Terms. If you are agreeing on behalf of an organization, you confirm that you have the authority to bind that organization. The Service is intended for users who are at least 18 years old. If you are under 18, you may not use the Service.
1. How These Terms Fit Together
For FDIE Enterprise subscriptions, these Terms are supplemented by an Order Form and, where applicable, a Data Processing Agreement (DPA). If a signed Order Form or Master Service Agreement (MSA) conflicts with these Terms, the signed document controls for that customer. Applicable DPA provisions govern personal-data processing, and mandatory transfer-clause provisions prevail over conflicting commercial terms.
These Terms incorporate our Privacy Policy and Information Security Addendum by reference. You should read all of them.
2. What FDIE Is
FDIE is a cloud-hosted Software-as-a-Service (SaaS) platform for automated firmware security analysis. It provides:
- CVE detection with CVSS and EPSS scoring
- SBOM (CycloneDX and SPDX), CBOM, and VEX document generation
- A deterministic security test suite
- Technical control assessments across supported frameworks, with coverage limits; separate CRA disclosure review, without an automated CRA conformity grade
- Cross-version Delta Intelligence
FDIE is offered under one subscription plan, FDIE Enterprise: a hosted cloud service accessed over the internet, with every capability of the Service included. The number of seats, the storage allowance, the hosting arrangement (cloud hosting in India, with the shared or dedicated arrangement agreed for the deployment; on-premise deployment on request for customers that need their data kept outside India) and the support level are set in the Order Form. Details are on our Plan page.
Every capability of the Service is included in the plan. The Plan page describes the offering; the agreed scope is recorded in your Order Form. Later website edits do not silently change an existing signed scope.
3. Your Account
To use the Service, you must register for an account and provide accurate, current information. You are responsible for:
- Keeping your account credentials confidential
- Configuring authentication options (including multi-factor authentication) appropriately for your organization
- All activity that happens under your account
If you suspect unauthorized access, tell us immediately at [email protected].
4. User Representations
By using the Service, you represent and warrant that:
- All registration information you submit is true, accurate, current, and complete, and you will promptly update it as it changes
- You have the legal capacity to agree to these Terms and are not a minor in the jurisdiction where you reside
- You will not access the Service through automated or non-human means, including bots or scripts, except through our documented REST API in accordance with your plan’s usage limits
- Your use of the Service will not violate any applicable law or regulation
If any information you provide is untrue, inaccurate, or incomplete, we may suspend or terminate your account.
5. Acceptable Use
You agree not to:
- Upload firmware or other content you do not have the legal right to analyze
- Use the Service to develop, test, or distribute malware or other malicious code
- Reverse-engineer, decompile, or attempt to extract the source code of the Service itself
- Circumvent rate limits, usage quotas, or other technical restrictions, or abuse the Service in a way that degrades it for other customers
- Use the Service in violation of applicable export control or economic sanctions laws (see Section 21)
- Systematically retrieve data from the Service to build a separate collection, compilation, or database, other than through your own account’s normal use of our documented API
- Trick, defraud, or mislead us or other users, including attempting to obtain another user’s account credentials
- Circumvent, disable, or otherwise interfere with security-related features of the Service
- Impersonate another user, or access or use another user’s account without authorization
- Upload or transmit viruses, spyware, tracking pixels, or similar material intended to collect information about other users or to interfere with the Service’s operation
- Use the Service to build, operate, or support a product or service that competes with FDIE
Authorized analysis of potentially vulnerable or malicious firmware using the intended analysis workflow is permitted. This does not authorize using the Service to attack another system or intentionally compromise the platform. Good-faith research that complies with our Responsible Disclosure Policy is governed by that policy’s authorization and safe-harbor terms. Restrictions here apply only to the extent permitted by law. We may suspend accounts for other violations of this policy.
6. Fees and Invoicing
The Service is offered under the subscription plan described on our Plan page. Fees, the subscription term and renewal are set in your Order Form or other signed agreement. Subscriptions renew at the end of each term unless either party gives notice of non-renewal as that agreement provides.
FDIE is sold on invoice. MAGDOX Private Limited invoices you directly in your region’s currency (Indian rupees for customers in India, euros in the European Union, US dollars elsewhere), unless your Order Form states a different currency. Invoices are payable by bank transfer within the terms stated on the invoice; a purchase order may be referenced for procurement but is not itself payment. Taxes, duties or levies applicable in your jurisdiction are stated on the invoice and are your responsibility.
Refunds. Invoiced fees are non-refundable except as these Terms or applicable law require. If you terminate for our material breach that remains uncured under Section 19, or if we discontinue the Service, we refund the prepaid fees for the unused part of the term, pro rata. Evaluations are free.
7. Free Trial
New customers can evaluate the shared SaaS Service through a team-arranged 21-day free trial before subscribing. Access is arranged by Magdox: we create your organisation, your first administrator sets their own password, and the trial runs for 21 days from that first sign-in. During the trial you have the complete Service, not a reduced edition.
Customers evaluating a dedicated or on-premise deployment may request a 21-day proof of concept instead, on the terms set out in the applicable Order Form. A proof of concept is a scoped evaluation, not a free trial of a subscription plan.
Nothing is invoiced to start a trial. Your account does not automatically convert to a paid subscription when the trial ends, and you will not be invoiced without your authorization. If you do not subscribe before the trial ends, access is suspended. Your organisation and its data are retained for 30 days so you can subscribe later without losing anything; after that they become eligible for deletion under the schedule in Privacy Policy Section 10. There is no free tier after the trial ends.
8. Intellectual Property
Magdox retains all right, title, and interest in the Service, including the FDIE platform, its underlying software, and its documentation.
You retain all rights to the firmware images, configuration data, and other content you upload, as well as the analysis results, reports, and SBOM, CBOM, and VEX documents generated from that content (“Customer Data”).
FDIE’s analysis engine performs deterministic, rule-based static analysis and sandboxed dynamic analysis. It does not use generative AI or machine learning to produce findings. Customer Data is never used to train any model, whether operated by Magdox or a third party, and is not shared with any third party except as described in our Privacy Policy and DPA.
Feedback. If you send us feedback, suggestions, or ideas about the Service (“Submissions”), you agree that we may use them for any purpose, including to improve the Service, without any obligation to compensate you. Submissions do not include Customer Data, which remains governed by the ownership and confidentiality terms above.
9. Third-Party Websites and Services
The Service links to or references third-party websites, tools, and data sources, including public vulnerability databases (NVD, OSV.dev, the CISA KEV catalogue), and geolocation lookup for sign-in records. We do not control and are not responsible for the content, accuracy, or practices of these third parties. A third-party site you choose to visit has its own terms. This does not remove Magdox’s responsibilities for providers it appoints to process Customer Data under the DPA.
10. Confidentiality
Each party agrees to protect the other’s confidential information with the same degree of care it uses for its own confidential information of a similar nature, and in any event no less than a reasonable standard of care. Each party agrees not to disclose the other’s confidential information except as necessary to provide or use the Service, or as required by law.
Your firmware and the findings derived from it are treated as your confidential information.
This Section survives termination of these Terms for five (5) years, except for trade secrets, which remain protected for as long as they retain trade secret status.
Nothing in this Section restricts either party’s use of general knowledge, skills, or experience retained in the unaided memory of personnel who had access to the other party’s confidential information, provided that use does not involve disclosure of the confidential information itself.
11. Force Majeure
Neither party will be liable for any failure or delay in performing its obligations under these Terms (except for payment obligations) to the extent caused by events beyond its reasonable control, including natural disasters, acts of God, war, terrorism, riots, cyberattacks, denial-of-service attacks, cloud infrastructure or telecommunications outages, power failures, or governmental restrictions (“Force Majeure Event”). The affected party will make reasonable efforts to mitigate the impact of any such event.
12. Data Protection and Security
Our collection and use of personal data is described in our Privacy Policy. If you need a Data Processing Agreement, see our DPA.
The technical and organizational security measures we implement (encryption, access control, secrets management, and audit logging) are described in our Information Security Addendum, which is incorporated into these Terms by reference.
Cloud hosting is provided in India only; the deployment arrangement is agreed in the Order Form before provisioning. Customers that need their data kept outside India can deploy FDIE on-premises. Customers must have authority to provide the data and agree the applicable processing and transfer safeguards before covered data is transferred. Use of the Service is not, by itself, a substitute for a lawful transfer mechanism or any required data-subject consent. See our Privacy Policy and DPA.
13. Service Availability
We aim to maintain high availability of the SaaS Service. Enterprise customers may be offered a contractual uptime SLA (target: 99.9% monthly uptime) with associated service credits, as set out in their Order Form. Credits are applied to future invoices and are not paid out as cash. Every contract includes a support response-time commitment by email; it is not an uptime guarantee and carries no service credits. Recovery objectives, scenario limits and their contractual status are stated in the Information Security Addendum, Section 7.4.
14. Services Management & Emergency Suspension
We may monitor the Service for violations of these Terms and may restrict, suspend, or remove content that is unlawful or infringes third-party rights.
Notwithstanding any cure period in Section 19, Magdox reserves the right to immediately suspend or restrict access to any account without prior notice if we reasonably determine that the account is being used to launch security attacks, abuse API limits, distribute malicious code, or pose an active threat to the Service or other customers.
15. What FDIE Can and Cannot Do
15.1 Static and Dynamic Analysis
FDIE performs rule-based static binary analysis and bounded runtime analysis of firmware images. Results depend on the firmware, engine, vulnerability-feed context, configuration and assessment coverage. Recorded analysis context identifies available inputs; older results may lack complete stage or feed snapshots and must not be treated as fully reproducible assessments. Re-analysis of unchanged firmware can add or retire findings when analysis inputs or coverage change. A changed finding is not, by itself, evidence of a product regression or a verified fix.
FDIE additionally performs dynamic analysis. It executes the firmware’s own binaries inside an isolated sandbox across supported CPU architectures, attempts full-system boot for compatible Linux images, and runs coverage-guided fuzzing on supported targets to record observed runtime behaviour. Architecture support does not guarantee extraction or successful execution of every image.
Dynamic analysis reports what was observed during a bounded execution run. Because a run is bounded by time and by the code paths actually exercised, code reached only by a specific request or configuration may not be observed. The Service does not report “not observed” as “not present”. Where a firmware image is encrypted or otherwise cannot be unpacked, the Service reports that rather than inferring a result.
15.2 Vulnerability Database Timing
CVE and vulnerability data comes from the NIST National Vulnerability Database (NVD), OSV.dev, CISA’s KEV catalogue (actively-attacked vulnerabilities), and EPSS scoring data. These databases are synchronized on a schedule: NVD daily, the KEV catalogue every six hours, EPSS scores daily with a full weekly refresh. Previously analysed firmware is re-matched against the updated NVD data daily and against KEV after each six-hourly check; notifications are raised after that re-match, and you may trigger a re-match on demand. The Service does not provide real-time vulnerability data.
A vulnerability published after the most recent database sync may not appear in analysis results until the next scheduled sync. Each SBOM exported by FDIE includes the age of the NVD cache at the time of export so you can assess how current the data is.
15.3 Detection Limitations
The Service identifies firmware components through ELF dynamic-linking metadata, binary string extraction, version banner matching, and known component signature databases. The Service cannot guarantee detection of components or vulnerabilities in these situations:
- Firmware images that are encrypted, compressed with an unsupported algorithm, or packed using custom or proprietary packaging formats
- Components that are statically compiled into a monolithic binary without version strings or recognizable identifiers
- Components distributed under vendor-specific or private names that differ from the canonical product names used in public vulnerability databases
- Components whose vulnerabilities are described in vendor-specific security advisories not indexed by the databases FDIE queries
15.4 SBOM, CBOM, and VEX Completeness
SBOMs, CBOMs, and VEX documents generated by the Service reflect the components, cryptographic assets, and vulnerabilities identified by the analysis performed at the time of the analysis run. They are not a complete or authoritative inventory of all software present in a firmware image.
Each exported SBOM includes two properties:
fdie:analysis_method: identifies which analysis methods produced the document (static analysis, or static and dynamic analysis)fdie:nvd_last_sync_days: indicates the age of the vulnerability database used
15.5 Regulatory Compliance Is Your Responsibility
The Service provides analysis results, compliance scoring, and document artifacts to help you with your regulatory and supply-chain security programmes. Using the Service does not, by itself, make you compliant with any regulatory framework. This includes, but is not limited to:
- EU Cyber Resilience Act (CRA)
- ETSI EN 303 645 and EN 18031-1, -2 and -3
- NIST SP 800-193 and NIST IR 8259A
- IEC 62443-4-2 and IEC 81001-5-1
- OWASP FSTM
- FDA FD&C Act section 524B
- TEC 31318
You remain solely responsible for:
- Validating analysis results against your specific products and supply chains
- Determining whether and how analysis results trigger reporting obligations under applicable law, including CRA Article 14 reporting through the designated reporting platform to the relevant CSIRT coordinator and ENISA where applicable. FDIE records review decisions and submission references; it does not submit an official notification merely by recording a finding
- Taking corrective action in response to identified vulnerabilities
- Ensuring that SBOMs, CBOMs, and VEX documents you submit to regulators, customers, or other third parties meet those recipients’ requirements
15.6 Not a Substitute for Professional Assessment
The Service is an automated analysis tool. It does not replace professional penetration testing, manual code review, or expert security assessment. For high-assurance or safety-critical applications, you should supplement FDIE outputs with appropriate professional review.
16. Corrections
The Service, including our website, may contain typographical errors or inaccuracies, including in pricing, plan descriptions, or feature availability. We reserve the right to correct these errors and to change or update information on the Service at any time, without prior notice for non-material corrections. This does not override signed commercial terms or the material-change process in Section 23.
17. Disclaimers and Limits on Liability
EXCEPT FOR EXPRESS COMMITMENTS IN THE APPLICABLE AGREEMENT AND RIGHTS THAT CANNOT LAWFULLY BE EXCLUDED, THE SERVICE IS PROVIDED “AS IS” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
Excluded losses. To the maximum extent permitted by law, neither party is liable for any indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenue or goodwill, arising out of or related to these Terms, even if advised of their possibility. This exclusion does not apply to a party’s fraud, gross negligence or wilful misconduct, to a party’s indemnification obligations, to your obligation to pay fees properly due, or to any liability that cannot be limited or excluded under applicable law.
General cap. To the maximum extent permitted by law, each party’s total liability arising out of or related to these Terms will not exceed the amount you paid for the Service in the twelve (12) months before the claim.
Enhanced cap for confidentiality and security breaches. The general cap above does not apply to these two categories. Instead, each party’s total liability for (a) breach of the confidentiality obligations in Section 10, or (b) breach of its own security obligations that results in unauthorized access to the other party’s confidential information, will not exceed two (2) times the fees you paid for the Service in the twelve (12) months before the claim.
Carve-outs: what the caps do not limit. Neither cap applies to:
- A party’s indemnification obligations under Section 18
- Damages arising from a party’s fraud, gross negligence, or willful misconduct
- A party’s infringement of the other party’s intellectual property rights outside the scope of the license granted in these Terms
Nothing in this Section limits liability that cannot be limited or excluded under applicable law.
IN PARTICULAR, MAGDOX MAKES NO WARRANTY THAT THE SERVICE WILL DETECT ALL VULNERABILITIES, COMPONENTS, OR COMPLIANCE GAPS IN ANY FIRMWARE IMAGE. THE LIMITATIONS ABOVE APPLY TO CLAIMS ARISING FROM UNDETECTED VULNERABILITIES OR INCOMPLETE ANALYSIS, SUBJECT TO THE EXPRESS COMMITMENTS, ENHANCED CAP AND CARVE-OUTS IN THIS SECTION.
18. Mutual Indemnification
18.1 Your Indemnity to Us
You agree to indemnify, defend, and hold Magdox harmless from third-party claims arising out of:
- Your breach of these Terms
- Your misuse of the Service
- Content you upload in violation of Section 5 (Acceptable Use)
18.2 Our Indemnity to You
Magdox will indemnify, defend, and hold you harmless from third-party claims alleging that the Service, as provided by Magdox and used in accordance with these Terms, infringes that third party’s intellectual property rights. We will pay resulting damages finally awarded or agreed to in settlement.
This obligation applies only if you:
- Promptly notify us of the claim
- Give us sole control of the defense and settlement
- Provide reasonable cooperation
If such an infringement claim arises or is likely to arise, Magdox may at its option and expense: (a) procure the right for Customer to continue using the Service; (b) replace or modify the Service so it becomes non-infringing; or (c) terminate the subscription and refund any prepaid, unearned fees.
This obligation does not apply to claims arising from:
- Your Customer Data or third-party materials
- Modifications to the Service not made by Magdox
- Use of the Service in combination with products or services not provided by Magdox, where the infringement would not have occurred without that combination
19. Termination
Either party may terminate the Service for convenience at the end of the current billing period, or immediately for a material breach that remains uncured for 30 days after written notice.
When the Service ends, you will have a reasonable window (at least 30 days) to export your Customer Data. An earlier valid deletion instruction takes priority. Security or legal restrictions may require a supervised export instead of ordinary access. Data deletion follows the Privacy Policy and any applicable DPA; the export window does not extend the agreed deletion deadline.
20. Electronic Communications and Signatures
By using the Service, you consent to receive communications from us electronically, including by email and through notices posted on the Service. You agree that these electronic communications satisfy any legal requirement that such communications be in writing, and that, to the extent permitted by applicable law, electronic signatures and records have the same legal effect as physical signatures and records.
21. Export Compliance and Sanctions
The Service and firmware analyzed using it may be subject to applicable export controls and economic sanctions. You must not obtain or use the Service where applicable law prohibits its provision to you, your organization or the intended use, including relevant restricted-party prohibitions. You must obtain any required authorizations and must not use FDIE to transfer firmware or technical data unlawfully. The applicable restrictions depend on the parties, product, destination and use; this clause does not impose a blanket prohibition based only on nationality.
22. Governing Law and Disputes
These Terms are governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000 and rules thereunder, without regard to conflict-of-laws principles. Any disputes arising under these Terms will be resolved in the competent courts of West Bengal, India.
Enterprise customers may negotiate an alternative governing law and venue in their Order Form or MSA. This Section does not override any separately negotiated governing-law clause in an Enterprise Order Form or MSA.
23. Changes to These Terms
We may update these Terms from time to time. Material changes will be communicated to the designated customer contact with their effective date. Posting a revision does not retroactively amend an executed MSA or Order Form; changes to those agreements follow their agreed amendment process. The “Last updated” date at the top of this page reflects the most recent revision. Prior versions of these Terms are archived and available on request.
24. General
These Terms, together with the Privacy Policy, DPA (where applicable), and any Order Form, are the entire agreement between the parties about the Service. They replace all prior agreements on the subject matter.
Failure by either party to enforce any provision of these Terms will not be deemed a waiver of future enforcement. If any provision is held unenforceable, the remaining provisions stay in full force and effect.
Notices under these Terms should be sent to the contact addresses in Section 25.
25. Contact
Questions about these Terms can be sent through our Contact page, or directly to:
MAGDOX Private Limited
St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India
Email: [email protected]