Skip to content
Cookies

We value your privacy

With your permission, we use analytics cookies to understand how visitors use our website and how they found us. This helps us improve the website. You can change your choice at any time. See our Cookie Policy for details.

Cookie preferences

Choose what you allow

Necessary

Your theme, language and this choice, kept in your browser's local storage. Never used to track you. Always on.

Analytics

Google Analytics: which pages are read, how visitors found us, and which pages lead to a demo request.

No consent stored yet.Cookie Policy
Otector
HomePlatformAsset OwnersService ProvidersSecurityAbout
Book a demo
HomePlatformFor Asset OwnersFor Service ProvidersSecurity & ArchitectureAboutBook a demo
Legal

Terms & Conditions

Last updated: September 2026

These Terms & Conditions apply to the use of the Otector website, demo requests, commercial communications, and, where referenced, the procurement or use of Otector products and services. Specific customer agreements, order forms, pilot agreements, data processing agreements, support terms, service descriptions or statements of work may contain additional terms. If those documents conflict with these Terms, the signed or specifically agreed document takes precedence for the relevant engagement.

Contents

  1. About these Terms
  2. Definitions
  3. Website use
  4. Demo requests and commercial communications
  5. Customer agreements and order documents
  6. Access to Otector services
  7. Customer responsibilities
  8. Service Provider Portal use
  9. Site Agent, client deployment and connectivity
  10. Controlled Tunnels and native-tool access
  11. Secure File Transfer
  12. Support, maintenance and changes
  13. Availability and service levels
  14. Fees, payment and taxes
  15. Data, recordings and audit logs
  16. Personal data and DPA
  17. Security responsibilities
  18. Confidentiality
  19. Intellectual property
  20. Third-party services and integrations
  21. Acceptable use
  22. Suspension
  23. Term and termination
  24. Disclaimers
  25. Limitation of liability
  26. Indemnity
  27. Export control and sanctions
  28. Force majeure
  29. Language
  30. Governing law and jurisdiction
  31. Changes to these Terms
  32. Contact

1. About these Terms

These Terms & Conditions describe the rules that apply when you use the Otector website, submit a demo request, communicate with Otector, or use Otector products or services where these Terms are referenced.

For paid subscriptions, pilots, proofs of concept, professional services, support arrangements or partner engagements, the applicable order form, statement of work, subscription agreement, pilot agreement, data processing agreement or support terms may contain additional or different terms. If there is a conflict, the specifically agreed written document takes precedence for that engagement.

These Terms are intended for business use. Otector is not offered as a consumer product.

2. Definitions

TermMeaning
AgreementAny order form, pilot agreement, subscription agreement, statement of work, partner agreement or other written agreement that references these Terms.
CustomerThe legal entity that orders, evaluates, accesses or uses Otector products or services.
Customer EnvironmentThe networks, systems, assets, users, identities, credentials, data, devices, applications and infrastructure controlled by or on behalf of the Customer.
Customer DataData, content, configurations, files, logs, recordings, access requests, session metadata, asset information or other information submitted to, generated in, or processed through Otector on behalf of the Customer.
OtectorOtector B.V., registered in the Netherlands with KVK number 42118320.
Otector PlatformThe Otector software, portals, Site Agent, Service Provider Portal, controlled tunnels, secure file transfer functions, APIs, user interfaces, documentation and related services made available by Otector.
Service ProviderA vendor, OEM, system integrator, managed service provider, maintenance partner, contractor, consultant or other third party that requests or receives access to a Customer Environment through Otector.
Site AgentThe Otector component deployed in or near the Customer Environment that connects outward to the applicable Otector deployment and enables controlled access to approved assets.
Controlled TunnelA scoped access path for approved native tools, governed by Otector policy, device trust, permissions, session context and audit controls.
DocumentationUser guides, technical documentation, deployment guidance, support materials and written instructions provided by Otector.
Order FormA written or electronic order document agreed between Otector and the Customer that describes the purchased subscription, pilot, services, scope, fees, term and other commercial details.

3. Website use

The Otector website is provided to explain Otector’s products, services, security approach, use cases and company information. You may use the website only for lawful business purposes.

You must not misuse the website, attempt unauthorized access, interfere with its operation, scan or test systems without permission, introduce malware, scrape content at scale, impersonate others, or use the website in a way that violates applicable law. Security research must follow our Responsible Disclosure process.

Information on the website is provided for general commercial and informational purposes. It is not legal, technical, compliance or security advice for your specific environment.

4. Demo requests and commercial communications

When you submit a demo request, contact form or similar request, you confirm that the information you provide is accurate and that Otector may use it to respond to your request.

Submitting a form does not create an obligation for Otector to provide services, accept a customer, enter into an agreement or offer specific commercial terms.

Otector may decline a request where it reasonably believes the request is abusive, unlawful, outside Otector’s intended business scope, security-sensitive without appropriate context, or otherwise unsuitable.

5. Customer agreements and order documents

Subscriptions, pilots, proofs of concept, support, professional services and partner arrangements may be governed by separate written agreements. Those documents may define the specific scope, fees, subscription term, permitted use, support level, data processing terms, security obligations, deployment model and other details.

Order of precedence

In case of conflict, the following order applies unless agreed otherwise in writing:

  1. A signed agreement or master services agreement
  2. A data processing agreement
  3. An order form, pilot agreement or statement of work
  4. Service descriptions or support terms
  5. These Terms
  6. Website content or general marketing materials

Website content, product pages and marketing materials do not override signed commercial agreements.

6. Access to Otector services

Subject to the applicable Agreement and payment of applicable fees, Otector grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Otector Platform for the Customer’s internal business purposes and within the agreed scope.

The Customer may allow its employees, authorized contractors and approved Service Providers to use Otector only as permitted by the Agreement and configured by the Customer.

The Customer is responsible for managing users, roles, identity provider integrations, access approvals, credentials, connection profiles, asset scope and policies within its own Otector environment, unless Otector has expressly agreed to perform specific administrative tasks.

7. Customer responsibilities

The Customer is responsible for:

  • Ensuring that use of Otector is lawful and appropriate for the Customer Environment
  • Obtaining all internal approvals needed to deploy and use Otector
  • Configuring access policies, roles, approval flows, connection profiles and asset scopes
  • Managing user identities, identity provider integrations and user lifecycle
  • Ensuring that Service Providers are authorized and contractually permitted to access the relevant systems
  • Maintaining accurate asset, site and access information
  • Protecting credentials, certificates, keys and administrative accounts under Customer control
  • Ensuring that Site Agents and related components are installed in suitable environments
  • Reviewing logs, recordings, alerts and file-transfer decisions where appropriate
  • Maintaining backups and recovery procedures for Customer systems
  • Complying with applicable laws, sector rules and internal policies

Otector is an access-control and evidence platform. It does not replace the Customer’s responsibility for OT risk management, network security, identity governance, supplier governance, backups, incident response, safety procedures or compliance program.

8. Service Provider Portal use

The Service Provider Portal is intended to support external providers that work with one or more Otector-enabled customers.

A Service Provider may request or initiate access only where permitted by the relevant Customer. The Customer remains authoritative for access scope, approval, credentials, policies, recordings and audit data.

Service Providers must not attempt to bypass customer approvals, expand access beyond the granted scope, share accounts, reuse credentials, connect from unapproved devices, copy customer data without permission or use access for purposes outside the approved support activity.

Otector may suspend or restrict Service Provider access where reasonably necessary to protect security, prevent misuse, comply with law or enforce applicable terms.

9. Site Agent, client deployment and connectivity

The Site Agent is designed to support controlled access to approved Customer assets. The Customer is responsible for selecting the deployment location, network placement, firewall rules, routing, asset definitions, allowed connection profiles and operational procedures.

The Customer must install and operate the Site Agent in accordance with Otector Documentation and any agreed deployment guidance. Otector is not responsible for issues caused by unsupported deployment choices, incorrect network configuration, unsuitable infrastructure, Customer firewall rules, Customer identity systems, third-party outages, local environmental conditions or changes made outside Otector’s control.

Where Otector describes an outbound-only Site Agent architecture, this describes the intended access architecture of the Otector component. It does not mean the Customer’s wider environment has no other inbound paths, exposures, risks or dependencies. See the Security Architecture page for an overview.

10. Controlled Tunnels and native-tool access

Controlled Tunnels are intended for approved native tools and scoped access paths where browser-based sessions are not sufficient.

The Customer is responsible for defining which users, devices, assets, hostnames, IP addresses, network ranges, ports, protocols and tools are permitted. The Customer must ensure that any native tool used through a Controlled Tunnel is properly licensed, authorized, maintained and appropriate for the target environment.

A Controlled Tunnel must not be used as a general VPN replacement to provide unrestricted network access. It must be configured with appropriate scope and policy.

Otector may log tunnel decisions, connection metadata and policy decisions where configured. Otector does not guarantee protocol-level inspection for every protocol, encrypted channel, file, payload or native tool. Encrypted traffic may remain encrypted unless separate inspection arrangements are explicitly supported and configured.

11. Secure File Transfer

Otector may include secure file transfer capabilities such as upload and download controls, transfer links, file policy, malware scanning, DLP-style checks, quarantine, release workflows and audit logging.

The Customer is responsible for configuring file-transfer permissions and reviewing quarantined or flagged files. Otector does not guarantee that every malicious, sensitive, corrupted, encrypted or non-compliant file will be detected. File-transfer controls should be used as part of a broader security process.

Where files are exchanged with Service Providers, the Customer remains responsible for deciding whether files may cross into or out of the Customer Environment.

12. Support, maintenance and changes

Otector may provide updates, patches, improvements, bug fixes, security fixes, new features, documentation changes and service changes from time to time.

Otector may modify, improve, replace or discontinue features where reasonably necessary for security, reliability, maintainability, legal compliance or product development. Otector will use reasonable efforts to avoid materially reducing core functionality during an active subscription term without notice.

Support levels, response times, availability commitments and service credits apply only if expressly agreed in a separate support policy, order form or SLA.

13. Availability and service levels

Otector will use reasonable efforts to provide reliable access to the Otector Platform. However, unless a separate SLA is agreed, Otector does not guarantee uninterrupted availability, error-free operation or specific response times.

Availability may be affected by maintenance, updates, Customer infrastructure, internet connectivity, identity providers, cloud providers, third-party services, Site Agent deployment choices, force majeure events, security incidents, denial-of-service attacks or circumstances outside Otector’s reasonable control.

14. Fees, payment and taxes

Fees, billing frequency, subscription scope, pilot fees, payment terms and invoicing details are set out in the applicable order form or agreement.

Unless stated otherwise in writing:

  • Fees are exclusive of VAT and other applicable taxes
  • Invoices are payable within 30 days
  • The Customer may not withhold payment because of a disputed item that does not relate to the invoiced amount
  • Otector may charge interest and reasonable collection costs for overdue amounts where permitted by law
  • Subscription fees are non-refundable except as expressly agreed in writing
  • The Customer is responsible for providing accurate billing information

Otector may suspend access for overdue payments after reasonable notice, unless suspension would be unlawful or otherwise restricted by the applicable Agreement.

15. Data, recordings and audit logs

Otector may process or store Customer Data such as user information, access requests, approvals, session metadata, audit logs, recordings, file-transfer events, alerts, asset labels, configuration data and tunnel flow decisions.

As between Otector and the Customer, Customer Data remains the Customer’s data. Otector may process Customer Data to provide, secure, maintain, troubleshoot and improve the Otector Platform, comply with legal obligations and perform the applicable Agreement.

The Customer is responsible for deciding whether session recording, monitoring, file transfer logging and audit retention are appropriate for its users, Service Providers, works councils, employee policies, local laws and sector requirements.

Retention periods may be configured or agreed separately. If no retention period is agreed, Otector may apply its standard retention settings or delete Customer Data following termination in accordance with its operational procedures.

16. Personal data and DPA

Where Otector processes personal data on behalf of the Customer, the parties may enter into a separate data processing agreement. If a DPA is required and has not yet been signed, the Customer should not use Otector for personal data processing beyond what is necessary for pre-contractual discussions or demo requests.

The Customer is responsible for determining the legal basis for monitoring, recording, access logging and processing of user data within its own organization and for informing users and Service Providers where required. Website-related processing is further described in the Privacy Policy and Cookie Policy.

17. Security responsibilities

Otector is responsible for implementing reasonable technical and organizational measures for the Otector Platform under its control.

The Customer remains responsible for security of the Customer Environment, including identity providers, endpoint security, network segmentation, OT asset configuration, credentials, local firewall rules, backups, patching, user lifecycle management, approval decisions and Service Provider governance.

Otector does not guarantee that use of the platform will prevent all unauthorized access, cyber incidents, operational disruptions, malware, data loss or policy violations.

Security and compliance boundary

Otector helps control and evidence remote access where configured. It does not by itself guarantee security, regulatory compliance or conformity with a particular standard, and it does not replace the Customer’s wider security and compliance program.

18. Confidentiality

Each party may receive confidential information from the other party. Confidential information includes non-public business, technical, security, product, commercial, customer, pricing, architecture, credential, vulnerability and operational information that is marked confidential or should reasonably be understood to be confidential.

The receiving party must protect confidential information using reasonable care and may use it only for the purpose of the relevant commercial relationship. Confidential information may be disclosed to employees, advisors, contractors or affiliates who need to know it and are bound by confidentiality obligations.

Confidentiality obligations do not apply to information that is publicly available, already known without restriction, independently developed, lawfully received from a third party, or required to be disclosed by law.

19. Intellectual property

Otector and its licensors retain all rights, title and interest in the Otector Platform, Documentation, software, user interfaces, designs, methods, workflows, know-how, trademarks, logos, product names, security models, templates, code, algorithms and related materials.

The Customer receives only the limited use rights expressly granted in the applicable Agreement. No rights are transferred by implication.

The Customer must not copy, modify, reverse engineer, decompile, disassemble, resell, sublicense, lease, distribute, make available or create derivative works of the Otector Platform except as expressly permitted by law or agreed in writing.

Feedback, suggestions or improvement ideas provided to Otector may be used by Otector without restriction or obligation, provided Otector does not disclose Customer confidential information.

20. Third-party services and integrations

Otector may integrate with or depend on third-party services such as cloud infrastructure, identity providers, email services, analytics, security scanning, logging, communication tools, CRM systems or other integrations.

Otector is not responsible for third-party systems outside its control. The Customer is responsible for maintaining accounts, licenses, permissions, configurations and security settings for Customer-selected third-party services.

21. Acceptable use

The Customer and its users must not:

  • Use Otector for unlawful, harmful or unauthorized purposes
  • Attempt to bypass approvals, access controls, monitoring or logging
  • Access assets outside the approved scope
  • Share accounts, credentials, certificates, keys or session access
  • Introduce malware or unauthorized tools
  • Interfere with the platform or other customers
  • Attempt to scan, overload, disrupt or compromise Otector systems
  • Reverse engineer or attempt to extract source code
  • Use Otector to violate export controls, sanctions or third-party rights
  • Upload or transfer files they are not authorized to use or share
  • Misrepresent identity, authorization, affiliation or purpose of access

A violation of acceptable use may result in suspension or termination.

22. Suspension

Otector may suspend or restrict access immediately where reasonably necessary to:

  • Prevent unauthorized access
  • Protect the security, integrity or availability of Otector or Customer environments
  • Respond to suspected misuse
  • Comply with law or government orders
  • Address overdue payment after notice
  • Prevent harm to Otector, the Customer, Service Providers or third parties
  • Enforce applicable agreements

Otector will use reasonable efforts to notify the Customer where practical, unless urgent security, legal or operational reasons prevent notice.

23. Term and termination

The term of a subscription, pilot or services engagement is set out in the applicable order form or agreement.

Either party may terminate an Agreement where the other party materially breaches its obligations and fails to remedy the breach within 30 days after written notice, unless the breach cannot reasonably be remedied or a different period is agreed.

Upon termination, the Customer must stop using Otector, remove or disable access where applicable, uninstall Customer-managed components if required, and pay outstanding amounts.

Otector may delete or return Customer Data after termination in accordance with the applicable Agreement, DPA or retention policy.

24. Disclaimers

Except as expressly agreed in writing, Otector provides the website and any pre-contractual materials on an “as is” and “as available” basis.

Otector does not warrant that:

  • The website or platform will be uninterrupted or error-free
  • Every threat, malicious file, risky action or policy violation will be detected
  • Every protocol, tool, file type or encrypted stream can be inspected
  • Use of Otector will ensure compliance with NIS2, IEC 62443 or any other law, standard or framework
  • Otector will prevent all cyber incidents, operational disruptions, unauthorized access or data loss
  • The platform is suitable for every environment without Customer-specific assessment and configuration

Otector is not a substitute for the Customer’s own security governance, risk management, incident response, supplier management, safety procedures, compliance program, backups or operational controls.

25. Limitation of liability

Nothing in these Terms limits liability where liability cannot lawfully be limited, including liability for intent, deliberate recklessness or other liability that cannot be excluded under applicable law.

To the maximum extent permitted by law and unless otherwise agreed in a signed Agreement, Otector is not liable for indirect, incidental, special, consequential, punitive or exemplary damages, loss of profit, loss of revenue, loss of goodwill, loss of anticipated savings, business interruption, loss of production, loss of contracts, loss of data that could have been avoided through appropriate backup procedures, or damages caused by third-party systems outside Otector’s control.

Unless otherwise agreed in writing, Otector’s total aggregate liability arising out of or relating to an Agreement is limited to the fees paid by the Customer to Otector under the relevant Agreement during the 12 months preceding the event giving rise to the claim.

For free demos, free trials, unpaid pilots or website use, Otector’s total aggregate liability is limited to EUR 100 to the maximum extent permitted by law.

The limitations in this section apply regardless of the legal theory of liability, whether contract, tort, negligence, strict liability or otherwise.

26. Indemnity

The Customer will indemnify and hold Otector harmless from claims, damages, losses, costs and expenses arising from:

  • Unauthorized or unlawful use of Otector by the Customer, its users or Service Providers
  • Customer Data or files submitted to or transferred through Otector
  • Customer-controlled credentials, identity systems, networks, assets or configurations
  • The Customer’s breach of these Terms or an Agreement
  • The Customer’s violation of applicable law or third-party rights
  • Access granted by the Customer to Service Providers or other third parties

Otector will notify the Customer of relevant third-party claims where practical and will allow the Customer reasonable control of the defense, subject to Otector’s right to participate.

27. Export control and sanctions

The Customer must comply with applicable export control, sanctions and trade control laws. The Customer must not use, export, re-export, provide access to or make Otector available in violation of applicable laws or to sanctioned persons, entities, countries or territories.

Otector may refuse, suspend or terminate access where it reasonably believes that providing the product or service would violate export control, sanctions or trade control laws.

28. Force majeure

Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, labor disputes, government action, internet or telecommunications failures, cloud provider outages, power failures, supply-chain disruptions, pandemics, denial-of-service attacks or security incidents outside the affected party’s reasonable control.

Payment obligations are not excused by force majeure unless required by law.

29. Language

These Terms are provided in English. Otector may provide translations for convenience. If there is any difference between the English version and a translation, the English version prevails unless the parties expressly agree otherwise in writing.

30. Governing law and jurisdiction

These Terms and any non-contractual obligations arising out of or related to them are governed by the laws of the Netherlands.

Unless mandatory law provides otherwise or the parties agree differently in writing, disputes will be submitted to the competent court in the Netherlands.

31. Changes to these Terms

Otector may update these Terms from time to time. The updated version will be published on the website with a new last updated date.

For active paid subscriptions, material changes that significantly affect the Customer’s rights or obligations will apply only as permitted by the applicable Agreement or after reasonable notice.

32. Contact

For questions about these Terms, contact Otector:

Otector B.V.Dominee van Enkwarande 203907CC VeenendaalThe NetherlandsKVK: 42118320BTW / VAT: NL869812233B01Email: contact@otector.io
Otector

Secure remote access for operational technology environments, with approvals, monitoring, recordings and audit evidence under your control.

Get in touch
contact@otector.ioLinkedIn
01Product
Platform
  • Platform
  • Controlled Tunnels
  • Secure File Transfer
  • Book a demo
02Solutions
For teams
  • Asset Owners
  • Service Providers
Common challenges
  • Vendor Remote Access
  • Replace VPN Access
  • Maintenance Access
03Industries
By industry
  • Industries Overview
  • Manufacturing
  • Pharma
  • Water Utilities
  • Energy & Utilities
  • Healthcare
  • Food & Beverage
04Trust
Security & compliance
  • NIS2 Remote Access
  • Security Architecture
  • Audit Remote Access
  • Responsible Disclosure
Architecture topics
  • Outbound-only access
  • Session evidence
  • Service-provider governance
05Company
Company
  • About
  • Partners
  • Contact
  • LinkedIn
06Legal
Legal
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Company details
© 2026 Otector B.V. All rights reserved.Designed with industrial security principles in mind