LISA Terms of Service
[DRAFT — AWAITING LEGAL REVIEW]
Terms of Service for LISA Platform
Last Updated: 2026-05-10
Version: 1.0 (Draft)
Effective Date: [Upon v1.0 Launch]
1. Introduction
LISA GmbH ("LISA," "Service Provider," "we," "us") provides a software-as-a-service (SaaS) platform for Microsoft 365 governance and security assessment ("Service"). These Terms of Service ("Terms") govern your access to and use of the Service.
By accessing the LISA platform, creating an account, or using the Service in any way, you ("Customer," "User," "you") agree to be bound by these Terms. If you do not agree, you may not use the Service.
2. Service Description
2.1 What LISA Provides
LISA provides:
- Automated security and governance assessment of your Microsoft 365 tenant
- Analysis of 13+ security categories (Conditional Access, MFA, Teams policies, etc.)
- Human-readable findings synthesized from machine-readable signals
- Executive dashboard with findings, remediation guidance, and risk scoring
- Multi-tenant support for Microsoft Service Providers (MSPs) and MSP customers
2.2 Scope of Access
LISA connects to your M365 tenant via:
- OAuth 2.0 delegated permissions (Admin Consent required)
- Microsoft Graph API read-only access to configuration data
- No write, modify, or delete permissions are requested or granted
LISA does NOT:
- Access user mailboxes, files, Teams messages, or user-generated content
- Store raw Microsoft Graph data; all entity identifiers are pseudonymized immediately
- Perform continuous monitoring; assessments are point-in-time scans
- Modify your M365 environment in any way
2.3 Service Availability
- LISA operates on a best-effort basis. We target 99.5% uptime for scan scheduling and dashboard access.
- Scheduled maintenance may occur with 48-hour advance notice posted on our website.
- We are not liable for downtime caused by third-party services (Microsoft Graph API, Azure, Supabase infrastructure).
3. User Accounts & Access Control
3.1 Account Creation
To use the Service, you must:
- Create an account via OAuth2 / SSO authentication
- Provide accurate, complete information during registration
- Ensure the person granting admin consent has authority to do so on behalf of your organization
3.2 Account Security
You are responsible for:
- Keeping your login credentials confidential
- Notifying us immediately of unauthorized access or security breaches
- Complying with your organization's access control and identity policies
LISA uses industry-standard protections (encryption, password hashing, secure sessions) but cannot guarantee security against all threats.
3.3 Admin Consent & Permissions
By granting Admin Consent to LISA's app registration:
- You authorize LISA to query your M365 configuration via Microsoft Graph API
- You confirm the consenting admin has authority to grant these permissions
- You may revoke consent at any time via your Azure Admin Center; this will immediately stop new scans
4. Subscription Plans & Pricing
4.1 Starter Tier
- Monthly Subscription: CHF 290/month (up to 50 users)
- Billing: Monthly, invoiced via credit card
- Features: All 12 security scanners, daily automated scans, executive-ready reporting, email support
- Target: Small teams, SMBs
4.2 Business Tier
- Monthly Subscription: CHF 790/month (51–500 users)
- Billing: Monthly, invoiced via credit card
- Features: All scanners, daily scans, advanced reporting, email support
- Target: Mid-market companies
4.3 Scale Tier
- Monthly Subscription: CHF 1,490/month (501–2,000 users)
- Billing: Monthly, invoiced via credit card
- Features: All scanners, daily scans, API access, email support
- Target: Enterprises
4.4 Custom Tier
- Pricing: Quote for >2,000 users or multi-tenant (MSP) requirements
- Invoicing: Annual or custom billing terms (negotiated per agreement)
- Features: All scanners, custom scan frequency, API access, priority support, SLA guarantees
- Target: Large enterprises, MSPs
4.5 Optional Add-ons
- Governance Modules: DSC Management (CHF 290/mo), Guest Lifecycle (CHF 190/mo), Teams Lifecycle (CHF 190/mo)
- Governance Pack (bundled): CHF 490/month (all 3 modules, saves CHF 180/mo)
4.6 Free Trial
- Duration: 14 days, full feature access (Starter tier level)
- Cancellation: Cancel anytime before trial ends; no charge if cancelled before billing begins
4.4 Billing & Payment
- Invoices are sent at the start of each billing cycle (monthly) or annually
- Payment methods: Credit card, bank transfer (enterprise only)
- Unpaid invoices accrue a late fee of 1.5% per month (or legal maximum if lower)
- LISA may suspend service for accounts 30+ days past due
5. Acceptable Use Policy
You agree NOT to:
5.1 Prohibited Activities
- ❌ Use the Service for any illegal purpose or in violation of laws (GDPR, nDSG, CFAA, etc.)
- ❌ Attempt to gain unauthorized access to the Service, other accounts, or LISA systems
- ❌ Interfere with the Service's availability (DDoS, resource exhaustion, malware)
- ❌ Reverse-engineer, decompile, or disassemble the Service
- ❌ Resell or redistribute the Service without a signed reseller agreement
- ❌ Scrape, spider, or automated access to the dashboard without permission
- ❌ Upload or transmit malware, viruses, or malicious code
- ❌ Harass, threaten, or abuse LISA support staff
5.2 Consequences of Violation
If you violate this Acceptable Use Policy:
- LISA may immediately suspend your account without notice
- You forfeit any remaining prepaid subscription balance
- LISA may pursue legal remedies for damages, including injunctive relief
6. Data Handling & Privacy
6.1 Data Controller vs. Processor
- LISA's role: Data processor for customer M365 tenant configuration (GDPR, nDSG)
- You (Customer): Data controller; responsible for lawful basis and user consent in your jurisdiction
6.2 Data LISA Collects
From M365 Tenant Scans:
- Configuration data (policies, security settings, app permissions)
- Entity counts and metadata (user count, group count, app registrations)
- Audit logs and activity data available via Microsoft Graph API
Immediately pseudonymized:
- User Principal Names (UPNs), Entra Object IDs → hashed with HMAC-SHA256
- Email addresses, display names → never stored in plaintext
Never collected:
- Email contents, attachments, files, chats, calendar events
- Passwords, API keys, certificates, or secrets
- Personal data beyond configuration metadata
6.3 Data Retention
| Data Type | Retention |
|---|---|
| Findings & Configuration Snapshot | 90 days (for customer reference) |
| Raw Microsoft Graph API logs | 30 days (then deleted) |
| Pseudonymized entity identifiers | 90 days (non-linkable to real entities) |
| Backup copies | 30 days after primary deletion |
6.4 Subprocessors & Third Parties
LISA shares your data with:
- Supabase (EU region): Database hosting; EU Standard Contractual Clauses apply
- Microsoft Graph API: You authorize this via Admin Consent
- Anthropic Claude API: Findings synthesis; no customer-identifying data sent
- Azure Key Vault: Encryption keys for pseudonym secrets (LISA's tenant only)
A current list of subprocessors is available in our Data Processing Agreement.
6.5 GDPR & Privacy Rights
Under GDPR and Swiss nDSG, you have the right to:
- Access: Request a copy of data we hold about your tenant
- Deletion: Request deletion of your data (subject to legal retention obligations)
- Correction: Request correction of inaccurate data
- Portability: Request your data in a standard format
To exercise these rights, contact dpo@runlisa.ch with:
- Your company name and customer ID
- Specific request (access, deletion, correction, portability)
- Proof of authority to represent your organization
We will respond within 30 days (or 45 days for complex requests).
7. Intellectual Property
7.1 LISA's IP
All LISA intellectual property is owned by LISA GmbH:
- Source code, scanners, algorithms, and findings synthesis — proprietary
- Dashboard UI, branding, documentation — copyrighted
- Pseudonymization algorithm — trade secret
- Security methodologies and threat models — confidential
You may NOT copy, modify, distribute, or reverse-engineer any LISA IP.
7.2 Your Data & Findings
You own:
- ✅ Raw findings and remediation reports we generate for your tenant
- ✅ Configuration snapshots and historical assessment data
- ✅ Derivative works you create from LISA findings
LISA retains:
- ✅ Anonymized, aggregated data for product improvement (never tied to your identity)
- ✅ Pseudonymized signals for trend analysis and threat intelligence
8. Warranties & Disclaimers
8.1 LISA's Warranty
LISA warrants that:
- ✅ The Service will be provided in a professional and workmanlike manner
- ✅ We will use industry-standard security practices to protect your data
- ✅ The Service will substantially conform to our documentation
8.2 Disclaimer of Other Warranties
EXCEPT AS EXPRESSLY STATED ABOVE, LISA PROVIDES THE SERVICE "AS-IS" WITHOUT ANY OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING:
- ❌ Merchantability, fitness for a particular purpose, or non-infringement
- ❌ Uninterrupted, error-free, or secure operation
- ❌ That findings are 100% accurate, complete, or sufficient for security decisions
- ❌ That the Service will prevent all security breaches or compliance violations
YOU ARE RESPONSIBLE FOR:
- Validating LISA findings before taking action
- Implementing additional controls beyond LISA recommendations
- Consulting security experts for business-critical decisions
9. Limitation of Liability
9.1 Liability Cap
Except for gross negligence or willful misconduct, LISA's total liability to you is limited to:
- The amount you paid for the Service in the 12 months prior to the claim, or
- CHF 10,000, whichever is less
9.2 Excluded Damages
LISA is NOT liable for:
- ❌ Lost profits, revenue, or business opportunity
- ❌ Data loss or corruption (see Section 6 for our data security practices)
- ❌ Indirect, incidental, consequential, or punitive damages
- ❌ Costs of substitute goods or services
- ❌ Third-party claims or third-party damages
9.3 No Liability for Third-Party Services
LISA is not liable for downtime, errors, or security breaches caused by:
- Microsoft Graph API or Azure services
- Supabase infrastructure or outages
- Anthropic Claude API errors or unavailability
- Your ISP, network, or device security
10. Confidentiality
10.1 Your Confidential Information
During the course of this Service, you may share:
- Your M365 tenant configuration, policies, and audit logs
- Organizational information (team structure, security practices)
- Feedback on LISA's product
LISA will:
- ✅ Keep this information confidential (except where aggregated and anonymized)
- ✅ Use it only to provide the Service and improve LISA
- ✅ Not disclose to third parties without your consent
Exception: We may disclose if required by law (with notice to you if legally permitted).
10.2 LISA's Confidential Information
Our Service, algorithms, threat models, and code are confidential and proprietary. You agree not to:
- Disclose LISA's internal design, methodology, or vulnerability information
- Share detailed findings that might reveal our detection logic
- Reverse-engineer our pseudonymization algorithm
11. Indemnification
You agree to defend, indemnify, and hold harmless LISA and its officers, directors, employees, and agents from any claims, damages, or costs (including attorneys' fees) arising from:
- Your use of the Service in violation of these Terms
- Your violation of applicable laws (GDPR, nDSG, etc.)
- Your alleged infringement of third-party intellectual property rights
- Your unauthorized access to another organization's M365 tenant
12. Term & Termination
12.1 Term
- Monthly Plan: Automatically renews each month unless cancelled
- Annual Plan: Renews annually unless cancelled 30 days before renewal
- Free Trial: Ends after 14 days
12.2 Cancellation
- By You: Cancel anytime via your account dashboard or email to support@runlisa.ch
- Effective: End of current billing period (no refunds for partial months)
- By LISA: We may terminate for:
- Non-payment (30 days overdue)
- Violation of Acceptable Use Policy (immediate)
- Regulatory requirements (with 30-day notice if possible)
12.3 Effect of Termination
Upon termination:
- Your access to the Service ceases immediately
- You may download your findings and configuration snapshots within 30 days
- We will delete your data per our Data Retention Policy (except where legally required to retain)
13. Modifications to Terms & Service
13.1 Changes to These Terms
LISA may modify these Terms at any time. We will:
- ✅ Notify you of material changes via email
- ✅ Give you at least 30 days' notice before changes take effect
- ✅ Provide a summary of what changed
If you object to changes, you may cancel before the new terms take effect.
13.2 Changes to the Service
LISA may:
- ✅ Add new scanners and features
- ✅ Deprecate old scanners (with 60-day notice)
- ✅ Change pricing at annual renewal (with 30-day notice)
- ✅ Modify service uptime targets (with 30-day notice)
14. Governing Law & Dispute Resolution
14.1 Governing Law
These Terms are governed by Swiss law (Canton Zurich), without regard to conflict-of-law principles.
14.2 Disputes
Informal Resolution (Required First Step):
- Either party will attempt good-faith negotiation for 14 days
Mediation (If negotiation fails):
- Appoint a neutral mediator
- Split mediation costs equally
- Mediation location: Zurich, Switzerland
Binding Arbitration (If mediation fails):
- Single arbitrator under Swiss Rules of International Arbitration
- Arbitrator location: Zurich, Switzerland
- Arbitrator fees split equally
- Judgment may be enforced in any competent court
15. Compliance & Legal
15.1 Data Protection
- ✅ GDPR compliance: LISA is a certified processor (ISO 27001 certified [target: 2026])
- ✅ Swiss nDSG compliance: Same protections as GDPR apply
- ✅ Data Processing Agreement available upon request
15.2 Export Controls
You agree not to use the Service in connection with:
- ❌ Sanctioned countries, organizations, or individuals (OFAC, UN, EU sanctions lists)
- ❌ Weapons of mass destruction, military applications, or nuclear weapons programs
- ❌ Violation of export control laws (US EAR, EU Dual-Use Regulation)
15.3 Regulatory Changes
If new regulations require changes to the Service:
- LISA will implement changes in good faith and at reasonable cost
- If compliance becomes commercially impracticable, LISA may terminate with notice
16. Entire Agreement
These Terms, together with:
- Data Processing Agreement
- Privacy Policy
- NDA (if signed)
- Any signed Order Form or Statement of Work
constitute the entire agreement between you and LISA regarding the Service. They supersede all prior agreements, understandings, and negotiations.
17. Contact Information
For Service Issues:
Email: support@runlisa.ch
Response Time: Within 24 hours (business days)
For Legal Questions:
Email: legal@runlisa.ch
For Data Privacy / GDPR Requests:
Email: dpo@runlisa.ch
Mailing Address:
LISA GmbH
[Address TBD at GmbH registration]
Zurich, Switzerland
18. Miscellaneous
18.1 Severability
If any provision of these Terms is unenforceable, the remaining provisions stay in effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable.
18.2 Waiver
Failure to enforce any provision does not constitute a waiver of that provision or any other provision.
18.3 Assignment
You may not assign these Terms without LISA's written consent. LISA may assign these Terms to a successor company.
18.4 Notices
Legal notices to you will be sent to the email address associated with your account. Notices to LISA should be sent to legal@runlisa.ch.
Last Updated: 2026-05-10
Status: DRAFT — Awaiting legal review before publication (v1.0 launch)