Terms of Service & Privacy
Plain language, short on purpose. Last updated 2026-07-20.
1. The service
Harpia provides vulnerability and exploitation intelligence - via the web interface, the JSON API, and the STIX/TAXII feed. The data is aggregated from public sources and our own analysis, and is provided for defensive security purposes.
2. Plans & commercial use
The free plan is for personal, evaluation, and internal non-commercial use only. Commercial use of the feed is not permitted on the free plan. Commercial use means using the data - through the web interface, the JSON API, or the STIX/TAXII feed - in or for a paid product or service, in client, consulting, or managed-security deliverables, or in any revenue-generating workflow. Commercial use requires a paid plan (Pro or Enterprise) and is limited to your own organisation's internal use under that plan.
Reselling, redistributing, or otherwise making the feed available to third parties is not permitted on any plan - including the Pro and Enterprise plans. If you have a use case that needs it, get in touch first so we can discuss a suitable arrangement. Entitlements are per-account and per-plan: do not share API keys, pool accounts, or rotate keys/accounts to extend limits or circumvent the plan you hold.
3. Your account
You are responsible for your credentials and for every request made with your API keys. Keys are secrets: do not embed them in client-side code or public repositories. Revoke a key immediately if you suspect exposure.
4. Acceptable use
- Do not use the free plan for commercial purposes - see §2. Commercial use requires a paid plan.
- Stay within the rate and daily limits of your plan; do not evade them with key or account rotation.
- Do not resell, redistribute, or expose the feed to third parties on any plan. If you need to, contact us first.
- Do not use the service to facilitate unlawful access to systems you are not authorized to test.
5. No warranty
Vulnerability intelligence is inherently incomplete and time-shifted. The service is provided "as is", without warranty of any kind. Exploitation states, decisions, and remediation windows are advisory inputs to your risk process - they are not a guarantee that a system is safe or unsafe.
6. Liability
To the maximum extent permitted by law, Harpia is not liable for indirect or consequential damages arising from use of the service. Our total liability is capped at the fees you paid in the twelve months preceding the claim.
7. Changes & termination
We may update these terms; material changes are announced on this page with a new date. We may suspend accounts that violate the acceptable-use rules. You can delete your account at any time from the account page.
What we collect
- Account data - e-mail address, password hash (bcrypt), plan, and API key metadata. OAuth sign-in shares only your e-mail and provider identifier.
- Usage data - request counts per endpoint for rate limiting, quota accounting, and abuse prevention. Client IPs are used for anonymous rate limiting and short-lived security logs.
What we do not do
- No advertising, no tracking pixels, no third-party analytics scripts.
- We do not sell or share personal data with third parties.
- Search queries are not tied to your identity beyond operational logs.
Retention & your rights
Account data is kept while the account exists and deleted on account deletion. Operational logs rotate on a short schedule. You may request export or erasure of your personal data at support@harpia.ae.
Cookies
One first-party session cookie (__spa_tok), HttpOnly and same-site strict,
used solely to keep you signed in. No consent banner is needed because there is nothing else.
