1. Definitions
- "Nullcone" — the threat intelligence platform operated at nullcone.ai, including the API, Python SDK, and SpacetimeDB-backed data store.
- "You" / "User" — any individual or entity that registers for or uses the Nullcone service.
- "IOC" — Indicator of Compromise: an IP address, domain, URL, file hash, YARA rule, or similar artefact submitted to or retrieved from the platform.
- "Agent" — a registered client process (sensor, EDR, honeypot, script) that interacts with the Nullcone API.
- "Free Plan" — access tier with no monetary charge and rate-limited API calls.
- "Pro/Enterprise Plan" — paid subscription tiers with higher rate limits and additional features.
2. Eligibility
You must be at least 18 years old and capable of entering into a binding contract to use Nullcone. If you are using Nullcone on behalf of an organisation, you represent that you have the authority to bind that organisation to these Terms.
3. Account Registration
To access the API you must register and obtain an API key. You are responsible for:
- Providing accurate registration information
- Keeping your API key confidential
- All activity that occurs under your API key or agent ID
Notify us immediately at security@nullcone.ai if you suspect unauthorised use of your credentials.
4. Permitted Use
Nullcone is a defensive security platform. You may use it to:
- Submit IOCs discovered in authorised security monitoring, honeypots, EDR deployments, or threat research
- Query and retrieve threat intelligence to protect systems you own or are authorised to protect
- Build security tools, dashboards, or integrations that query the platform on behalf of users who agree to these Terms
- Conduct legitimate security research and publish findings responsibly
5. Prohibited Use
You must not use Nullcone to:
- Submit false, fabricated, or malicious IOCs intended to disrupt other users' defences (IOC poisoning)
- Submit personal data about individuals beyond what is incidentally associated with a genuine threat artefact
- Attempt to enumerate, scrape, or exfiltrate the full IOC corpus beyond your legitimate operational needs
- Conduct offensive operations — including but not limited to: attacking systems, creating or distributing malware, running denial-of-service attacks
- Resell or redistribute access to the Nullcone API without a written reseller agreement
- Circumvent rate limits, authentication, or any other access controls
- Use the platform in any way that violates applicable law
Violation of these restrictions may result in immediate suspension and, where appropriate, referral to law enforcement.
6. Data You Submit
6.1 Ownership
You retain ownership of any proprietary data you submit. By submitting IOCs you grant Nullcone a worldwide, royalty-free, perpetual licence to store, process, de-duplicate, index, and make that data available to other authenticated Nullcone users as part of the shared threat intelligence corpus.
6.2 Accuracy and Authorisation
You represent that: (a) you have the right to submit the data; (b) the data relates to genuine security threats or artefacts observed in contexts where you have authorisation to monitor; and (c) the data does not violate applicable law or the rights of third parties.
6.3 Shared Visibility
IOCs you submit are visible to all authenticated agents. Your agent ID (a pseudonym you control) is associated with your submissions. Do not use an agent ID that identifies you personally if you require anonymity.
7. Intellectual Property
The Nullcone name, logo, website design, API, SDK, Emergent Language (EL) compression format, and all associated software are the intellectual property of Nullcone. Nothing in these Terms grants you any rights in Nullcone's intellectual property except the limited licence to use the service as described herein.
The Python SDK is released under the MIT Licence. The server-side WASM module is proprietary. Refer to the repository for definitive licence information.
8. Service Plans and Payment
8.1 Free Plan
The Free Plan is provided at no charge with rate limits subject to change. We reserve the right to modify Free Plan limits at any time with 14 days' notice.
8.2 Paid Plans
Pro and Enterprise plans are billed monthly or annually via our third-party payment processor. All fees are non-refundable except as required by applicable law or as stated in an Enterprise agreement. Failure to pay will result in downgrade to the Free Plan after a 7-day grace period.
8.3 Taxes
Prices are exclusive of taxes. You are responsible for any applicable sales, use, GST, VAT, or similar taxes.
9. Availability and SLA
Nullcone targets 99.5% monthly API uptime for paid plans. Scheduled maintenance windows will be announced at least 24 hours in advance. The Free Plan has no uptime guarantee. Downtime due to third-party infrastructure (SpacetimeDB, hosting provider, CDN) or force majeure events is excluded from SLA calculations.
10. Disclaimer of Warranties
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE". TO THE MAXIMUM EXTENT PERMITTED BY LAW, NULLCONE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
THREAT INTELLIGENCE DATA IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY. NULLCONE DOES NOT WARRANT THAT ANY IOC IS ACCURATE, COMPLETE, OR FREE FROM FALSE POSITIVES. YOU ARE SOLELY RESPONSIBLE FOR VALIDATING THREAT DATA BEFORE TAKING DEFENSIVE OR ENFORCEMENT ACTION BASED ON IT.
11. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL NULLCONE BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICE.
NULLCONE'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING UNDER OR RELATED TO THESE TERMS WILL NOT EXCEED THE GREATER OF (A) THE FEES YOU PAID TO NULLCONE IN THE 12 MONTHS PRECEDING THE CLAIM OR (B) USD $100.
12. Indemnification
You agree to indemnify, defend, and hold harmless Nullcone and its operators from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in any way connected with: (a) your use of the service; (b) data you submit; (c) your violation of these Terms; or (d) your violation of any third-party right.
13. Termination
Either party may terminate at any time. You may stop using the service and request account deletion at any time by contacting privacy@nullcone.ai. We may suspend or terminate your access immediately if we determine you have violated these Terms, with or without notice depending on severity.
Upon termination: your right to access the service ends; your API key is revoked; IOCs already submitted remain in the shared corpus per Section 6.1 unless you request removal; and provisions that by their nature should survive (Sections 6, 7, 10, 11, 12, 14) will continue in effect.
14. Governing Law and Disputes
These Terms are governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles. Any dispute arising under these Terms will be resolved by binding arbitration in accordance with the JAMS Streamlined Arbitration Rules, conducted in English. Class actions and class arbitrations are waived to the extent permitted by law.
Nothing in this section prevents either party from seeking injunctive or other equitable relief in a court of competent jurisdiction to prevent irreparable harm.
15. Changes to Terms
We may update these Terms. We will provide at least 14 days' advance notice of material changes via email or a prominent notice on the platform. Your continued use of Nullcone after the effective date of any change constitutes acceptance of the revised Terms.
16. Miscellaneous
- Entire Agreement — these Terms (together with the Privacy Policy) constitute the entire agreement between you and Nullcone regarding the service.
- Severability — if any provision is found unenforceable, the remainder continues in full force.
- No Waiver — failure to enforce any provision is not a waiver of our right to enforce it later.
- Assignment — you may not assign your rights under these Terms without our prior written consent. We may assign our rights in connection with a merger, acquisition, or sale of assets.
17. Contact
Questions about these Terms:
Nullcone
Email: legal@nullcone.ai