← Back to ChainShield

Terms of Service

Last updated: 28 May 2026

1. About These Terms

These Terms of Service ("Terms") govern your access to and use of the ChainShield platform ("Platform", "Service"), operated by Simplecore Pty Ltd (ACN 641 930 627, ABN 39 641 930 627) ("we", "us", "our"), a company incorporated in Australia. "ChainShield" is a registered business name (registered with ASIC on 28 May 2026) held by Simplecore Pty Ltd; references to ChainShield mean Simplecore Pty Ltd trading as ChainShield.

By accessing or using the Platform, you agree to be bound by these Terms. If you are using the Platform on behalf of an organisation, you represent that you have authority to bind that organisation to these Terms.

Relationship to a signed Master Services Agreement.If your organisation has executed a written Master Services Agreement ("MSA") and Order with us, that MSA and Order govern your access to and use of the Platform. To the extent the MSA conflicts with these public Terms, the MSA prevails for that customer. These public Terms apply (i) to all visitors to the chainshield.com.au website, (ii) to users of any free, trial, evaluation, or self-service tier that is not the subject of an executed MSA, and (iii) as the default contractual baseline where no MSA has been signed.

Eligibility. The Platform is provided for business use only. You must be at least 18 years old, legally able to enter into a binding contract, and not subject to Australian, UN, EU, UK, or US sanctions or located in a sanctioned jurisdiction. You must not be a competitor of ChainShield using the Platform to benchmark, replicate, or build a competing product.

2. Service Description

ChainShield is a supply chain risk management (SCRM) platform that assists organisations in assessing and monitoring the security posture of their vendors and service providers. The Platform provides:

  • Automated collection of publicly available information about vendor digital infrastructure
  • Risk scoring and analysis based on open-source intelligence (OSINT)
  • AI-assisted risk narratives and recommendations
  • Vendor assessment questionnaire management
  • Compliance mapping against Australian regulatory frameworks
  • Reporting and dashboards for risk oversight

3. Data Collection — Open Source Intelligence

The Platform collects information exclusively from publicly available and open sources.This includes, but is not limited to:

  • DNS records, domain registration data, and SSL/TLS certificate information
  • Publicly exposed network services and ports (via Shodan, Censys, and similar OSINT platforms)
  • Published vulnerability databases (NVD, CISA KEV, EPSS)
  • Publicly available security news and media reports
  • Australian Business Register (ABR) public records
  • GitHub and other public code repositories
  • Google Places and other public business directory information

We do not:

  • Contact vendors directly on your behalf (unless you explicitly initiate an assessment questionnaire)
  • Perform active penetration testing, vulnerability exploitation, or intrusive scanning
  • Access non-public systems, internal networks, or confidential vendor data
  • Intercept, monitor, or collect private communications
  • Engage in any activity that would contravene the Criminal Code Act 1995 (Cth) Part 10.7 (computer offences) or equivalent state/territory legislation

Assessment questionnaires and vendor responses are initiated solely by your organisation. Any information provided by a vendor through the assessment portal is provided voluntarily at your organisation's request, not ours.

4. AI-Generated Content

The Platform uses artificial intelligence (AI) models to generate risk narratives, analysis summaries, and recommendations. You acknowledge that:

  • AI-generated content is provided as a decision-support tool, not as professional advice
  • AI analysis may contain inaccuracies, hallucinations, or incomplete assessments
  • You are responsible for reviewing and validating AI-generated content before relying on it
  • AI narratives and recommendations are indicative only. Note: Risk scores themselves are calculated deterministically via algorithmic formulae per our published scoring methodology (worker/scoring/engine.py), not generated by AI models
  • We do not warrant the accuracy, completeness, or fitness for purpose of any AI-generated content
  • AI narrative generation runs on ChainShield's internal AI models within our own infrastructure. No customer or vendor data is sent to a third-party AI provider.

5. Data Accuracy and Disclaimer

The information provided through the Platform is collected from third-party sources and is provided "as is" without warranty of any kind.

We make reasonable efforts to ensure the accuracy and currency of information, however:

  • Public data sources may be incomplete, outdated, or inaccurate
  • Risk scores are calculated algorithmically and may not reflect the full security posture of a vendor
  • Findings may include false positives or miss genuine security issues
  • Regulatory compliance mappings are indicative and do not constitute legal or compliance advice
  • The absence of findings does not indicate the absence of risk

You should not rely solely on the Platform for regulatory compliance, vendor due diligence, or risk management decisions. The Platform is a tool to supplement, not replace, your organisation's existing risk management processes.

6. Your Obligations and Acceptable Use

You agree to:

  • Use the Platform only for lawful purposes consistent with your organisation's legitimate risk management activities
  • Not use the Platform to harass, defame, or cause harm to any vendor or third party
  • Not attempt to circumvent access controls, authentication, security measures, rate limits, or tenant boundaries
  • Not reverse-engineer, decompile, disassemble, or attempt to derive the source code, scoring methodology, model weights, prompts, or algorithms of the Platform, except to the extent that such restriction is prohibited by law
  • Not scrape, bulk-export, or systematically extract data from the Platform other than through documented APIs and within published rate limits, and not use any automated agent, bot, or crawler in a manner that exceeds normal interactive use
  • Not resell, sublicense, white-label, host, or otherwise make the Platform available to any third party, except under a separate written reseller or partner agreement with us
  • Not use the Platform, its outputs, or information derived from it to build, train, market, or operate a product or service that competes with the Platform
  • Not share your login credentials or allow unauthorised access to your account; you are responsible for all activity occurring under your account
  • Maintain the confidentiality of risk reports and assessments generated through the Platform
  • Comply with all applicable Australian laws, including the Privacy Act 1988 (Cth) and the Spam Act 2003 (Cth), when handling personal information or sending communications through or in connection with the Platform
  • Obtain appropriate authorisation before initiating vendor assessments on behalf of your organisation, and ensure you are entitled to nominate each vendor for monitoring
  • Not introduce malware, viruses, or harmful code into the Platform; not perform unauthorised security testing against the Platform or its infrastructure
  • Comply with applicable export-control and sanctions laws; not provide access to any person on a sanctions list or in a sanctioned jurisdiction

We may suspend or terminate access without liability where we reasonably believe a use of the Platform breaches this clause 6, threatens the security or integrity of the Platform, or exposes us to legal risk.

7. Multi-Tenancy and Data Isolation

The Platform operates as a multi-tenant service using row-level security to segregate organisation data. ChainShield discovers and stores information about vendors from public sources (domains, certificates, CVEs, published vulnerabilities, ABR records, news coverage). Because this information comes from the public internet and is identical regardless of who is looking at the vendor, a single vendor record can be referenced by many customer organisations. ChainShield does not segregate public vendor facts by tenant. Your organisation's data remains strictly private. This includes how you use each vendor, your criticality and data-sensitivity ratings, your regulatory scope, your accepted-risk decisions, your assessment responses, your internal notes, and your per-organisation risk score. This information is stored separately from public vendor intelligence (primarily in the organisation_vendors junction table) and is protected by Postgres Row-Level Security so it is only visible to your organisation's users, your assigned MSP (if any), and ChainShield staff acting under documented support procedures.

You acknowledge that:

  • Shared Public Vendor Intelligence: ChainShield discovers and stores information about vendors from public sources (domains, certificates, CVEs, published vulnerabilities, ABR records, news coverage).
  • Tenant-Private Organisation Context: Your organisation's data remains strictly private.
  • Cross-tenant MSP access: MSP (Managed Service Provider) users may have access to multiple client organisations as part of their service arrangement, constituting a legitimate disclosed access path under documented service agreements.

8. Warranties, Disclaimers and Limitation of Liability

8.1 Service warranty

We warrant that we will provide the Service with reasonable care and skill.

8.2 Disclaimer

Except as expressly stated in these Terms and to the extent permitted by law, the Platform is provided "as is" and we exclude all other warranties, conditions, and representations, express or implied, including warranties of merchantability, fitness for a particular purpose, completeness of risk detection, non-infringement, and uninterrupted or error-free operation. Vendor risk monitoring is inherently probabilistic; the Platform is calibrated to avoid false positives and may therefore omit uncertain detections.

8.3 Australian Consumer Law

Nothing in these Terms excludes, restricts, or modifies any guarantee, right, or remedy under the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)) that cannot lawfully be excluded. Where our liability may be limited under that law, our liability is limited (at our option) to re-supplying the Services or paying the cost of having them re-supplied.

8.4 Limitation

Subject to clauses 8.3 and 8.5 and to the extent permitted by law:

  • Neither party is liable for any indirect, consequential, special, exemplary, or punitive loss, or for loss of profit, revenue, goodwill, anticipated savings, data, or business opportunity, however arising
  • We are not liable for any loss arising from reliance on information, risk scores, AI-generated content, or compliance mappings provided through the Platform without independent verification
  • We are not liable for any decision taken or not taken by you in reliance on Platform outputs
  • We are not liable for the security posture, actions, or omissions of any vendor assessed through the Platform, or for the accuracy of data obtained from public sources
  • For paid subscriptions, our total aggregate liability arising out of or in connection with these Terms is capped at the fees paid by you in the three (3) months immediately preceding the event giving rise to the claim
  • For free, trial, or evaluation use where no fees have been paid, our total aggregate liability is capped at AUD $100

8.5 Exceptions

The exclusions and cap in clause 8.4 do not apply to: your obligation to pay Fees; either party's breach of confidentiality; either party's indemnity obligations; or liability that cannot be limited or excluded under law (including for fraud, wilful misconduct, death, or personal injury caused by negligence).

8.6 Reliance on the Platform

You acknowledge that the Platform supports, but does not replace, your own risk-management judgement, and that you remain responsible for your regulatory obligations.

8A. Indemnity

You indemnify us against any loss, liability, cost, or expense (including reasonable legal costs) arising from:

  • Your breach of clause 6 (Acceptable Use) or any unlawful use of the Platform;
  • Your nomination of a vendor you were not entitled to nominate, or your provision of inaccurate vendor identifiers;
  • Any third-party claim that your use of the Platform infringes the rights of, or causes loss to, that third party;
  • Any breach by you of Privacy Law, the Spam Act, or applicable export-control or sanctions laws in connection with your use of the Platform.

We will notify you promptly of any claim under this indemnity, allow you to control the defence (subject to our reasonable approval of counsel and settlement terms), and provide reasonable assistance at your cost.

9. Intellectual Property

The Platform, including its software, algorithms, risk scoring methodologies, user interface, and documentation, is our intellectual property or that of our licensors.

Data you input into the Platform (assessment responses, internal notes, risk context settings) remains your property. You grant us a limited licence to process this data solely for the purpose of providing the Service to you.

Risk reports and outputs generated by the Platform are licensed to you for your internal business purposes only. You may share reports with your auditors, regulators, and board as required.

10. Subscription, Fees and Payment

Access to the Platform is provided on a subscription basis. Fees, billing cycles, and inclusions are as agreed in your Order or as published on our pricing page. Unless your Order states otherwise:

  • Currency and GST. Fees are quoted in Australian Dollars and are exclusive of GST. Where we make a taxable supply, GST is payable in addition to the Fees on receipt of a valid tax invoice.
  • Billing cycle. Fees are invoiced monthly in advance.
  • Payment methods. You may pay (a) by bank transfer against a tax invoice, with payment due within 14 days of the invoice date; or (b) by credit or debit card via our nominated payment processor (currently Stripe), in which case the card on file is charged automatically in advance for each billing period. Card details are processed by Stripe; we do not store full card numbers.
  • Recurring card billing. Where you pay by card, you authorise us, through our payment processor, to charge the nominated card in advance for each billing period and for any additional amounts owing (including additional vendor allocations). If a scheduled charge fails, we may retry the charge and the late-payment provisions below apply.
  • Late payment. Interest may be charged on overdue amounts at the Reserve Bank of Australia cash rate plus 4% per annum, calculated daily. We may suspend access where an amount is more than 30 days overdue.
  • Vendor allocation changes. Additional vendors are charged at the per-vendor rate in your Order, pro-rated to the next billing cycle. Vendor reductions take effect at the next renewal.
  • Price changes. We may adjust subscription pricing at the start of any renewal term on at least 45 days' written notice. If you do not accept the adjusted pricing, you may decline to renew without penalty by giving notice under clause 11.

For visitors using any free, trial, or evaluation access where no Fees are payable, this clause 10 does not apply except to the extent we elect to convert your access to a paid subscription with your express consent.

11. Term, Renewal and Termination

Unless your Order states otherwise, your subscription runs for an initial 12-month term from the Subscription Start Date and renews automatically for successive 12-month terms unless either party gives at least 30 days' written notice before the end of the then-current term. Either party may terminate immediately by notice if the other materially breaches these Terms and does not remedy the breach within 14 days of notice, or becomes insolvent.

On termination or expiry of your subscription:

  • Your access to the Platform will cease
  • You must pay all Fees accrued up to the termination date
  • For 30 days after termination, we will, on request, make your Customer Data available for export in a commonly used format
  • We will then retain your Customer Data for a further 60 days to allow for late export requests, after which it will be deleted or de-identified except where retention is required by law

12. Service Availability, Support and Suspension

We use commercially reasonable efforts to achieve 99.9% monthly availabilityof the Platform. Availability is measured excluding planned maintenance (notified in advance where practicable), emergency maintenance, and unavailability caused by factors outside our reasonable control, including failures of third-party infrastructure providers and force majeure events. We do not provide service credits.

Support is provided by email during business hours (Brisbane time). We do not provide 24/7 incident response under these Terms.

We may suspend access where required by law, where necessary to protect the security or integrity of the Platform or other customers, or where an amount is more than 30 days overdue. We will give notice where reasonably practicable and will restore access promptly once the cause is resolved.

13. Force Majeure

Neither party is liable for delay or failure to perform any obligation (other than to pay money) caused by events beyond its reasonable control, provided it takes reasonable steps to mitigate. If a force majeure event continues for more than 30 days, either party may terminate the affected services on notice.

14. Governing Law and Dispute Resolution

These Terms are governed by the laws of Queensland, Australia. The parties submit to the non-exclusive jurisdiction of the courts of Queensland. Before commencing court proceedings (other than for urgent injunctive or equitable relief or to recover an undisputed debt), the parties must first attempt to resolve the dispute through good-faith negotiation between senior representatives within 14 days of written notice of the dispute, and if not resolved, by mediation administered by the Resolution Institute (Australia) under its Mediation Rules, with each party bearing its own costs and sharing the mediator's fees equally.

15. Changes to These Terms

We may update these Terms from time to time. Material changes will be notified via email or through the Platform at least 14 days before taking effect. Your continued use of the Platform after changes take effect constitutes acceptance of the updated Terms. Where your organisation has a signed MSA, changes to that MSA require written agreement of both parties.

16. General

  • Entire agreement. These Terms (together with any Order and MSA referenced) are the entire agreement between you and us in relation to the Platform and supersede prior discussions. Your purchase-order or standard terms do not apply.
  • Variation. A variation is only effective if agreed in writing by both parties (or, for these public Terms, posted in accordance with clause 15).
  • Assignment. You may not assign or transfer your rights or obligations without our prior written consent (not unreasonably withheld). We may assign to a related entity or in connection with a sale of our business.
  • Subcontracting. We may use subprocessors and subcontractors to provide the Service and remain responsible for their performance.
  • Survival. Clauses relating to intellectual property, confidentiality, data, liability, indemnity, governing law, and these general provisions survive termination.
  • Severance. If a provision is unenforceable, it is severed and the remainder continues in full force.
  • Waiver. A failure or delay in enforcing a right is not a waiver of that right.
  • Notices. Notices to us must be in writing to legal@chainshield.com.au.
  • Independent contractors. The parties are independent contractors. Nothing in these Terms creates a partnership, agency, or employment relationship.
  • Counterparts. Any Order or amendment may be executed in counterparts, including by electronic signature.

17. Contact

For questions about these Terms, contact us at:
Email: legal@chainshield.com.au
Entity: Simplecore Pty Ltd (ACN 641 930 627, ABN 39 641 930 627) trading as ChainShield
Postal address: PO Box 273, Lawnton QLD 4501, Australia

See also: Privacy Policy | Security Statement