Terms of service
What this service is, and what it is not.
Version 25 September 2026. These are framework terms. Where a specific contract or order form says something different, that document governs.
1. The parties
Provider, outside Vietnam: ATK New Technology One Member Company Limited — tax code 0110935486 — No. 1, Lane 454 Xuan Dinh Road, Xuan Dinh Ward, Hanoi, Vietnam.
Provider, inside Vietnam: DataQ, per the specific contract.
Contact: dongnx@atkvn.com
Customer: the organisation that submits an infrastructure description and receives measurement results.
2. What the service does
- Builds a digital twin of your attack surface from the file you provide.
- Executes real ATT&CK techniques against that twin in our laboratory — not synthetic log injection.
- Reads real alerts from the monitoring stack (Wazuh, Splunk, QRadar, Sentinel or Elastic, depending on configuration).
- Delivers a report, and detection content for those gaps where we have it. Not every gap has a rule behind it — where there is none, we say so rather than inventing one. Each rule is labelled verified to fire on a live SIEM or not yet verified.
- Re-measures after you apply the content, so the change is a measured delta rather than an assertion.
2b. What the service does not do
- We do not touch your running systems. No agent installed, no network scanning, no access to your infrastructure. We work from the file you choose to send.
- By default the measurement does not run on your monitoring, but on a replica on our bench built from your declaration. The result answers “what would a stack configured as I declared catch?”, not “what does my running stack catch?” Every report carries that label beside the figure. If you want your own SIEM measured directly, you provide the endpoint and credentials, and the label changes.
- This is not a penetration test, a compliance audit, or security insurance.
- We do not claim to detect every attack. We measure a finite, enumerated technique set.
3. Your data
- We ask only for the fields that actually take part in the measurement. The full list, and how to anonymise the rest, is in Prepare your infrastructure file.
- We recommend you anonymise before sending. Hostnames and IP addresses play no part in the result — replacing them with pseudonyms changes nothing in the measurement.
- The pseudonym-to-real-name mapping is yours. We do not ask for it, do not want it, and do not keep it.
- Retention is as agreed in the contract. You may request deletion at any time; we delete and confirm in writing.
- No third-party sharing. We do not sell, transfer, or use your data to pitch other organisations.
- Reference use only with your written agreement, and only in anonymised form.
4. Your responsibilities
- Authority. You confirm you are entitled to describe the infrastructure in question, and to scan it if you scan it yourself.
- Accuracy of declaration. The result reflects what was declared. Under-declaring the controls you have biases the result towards over-reporting gaps; over-declaring biases it towards missing them. We state which way a given report leans.
- Review before deployment. Detection content must be reviewed and adapted by you before it goes into a production monitoring stack.
5. Billing
- Per measurement. Unit price and volume per the contract or order form.
- We do not charge for a measurement that could not measure. If the monitoring could not execute the query, or the log pipeline was not running, or the attack never reached the sensor, that run is marked non-billable and does not appear on the invoice. This is enforced in the software: every run records how many cells were actually measurable, and you can read that ledger.
- Free pilots are scoped separately. Every commitment in Service commitments about measurement integrity applies to a free pilot in full, with nothing removed.
6. Limitation of liability
- The service provides information for a decision, not a guarantee of security. Deployment decisions and their consequences are yours.
- Our financial liability in any case does not exceed the amount you paid for the portion of service giving rise to the claim.
- Neither party is liable for indirect loss, lost profit, or data loss arising outside the scope of the service.
- Exception: the above limit does not apply to a breach of the data obligations in section 3, or to wilful misconduct.
7. Changes · 8. Termination · 9. Governing law
Changes to these terms are notified at least 30 days in advance; if you do not accept them you may terminate and be refunded for service not yet delivered. Either party may terminate on 30 days' notice; on termination, at your request, we delete all files and results and confirm in writing. Vietnamese law governs unless the specific contract says otherwise; disputes go to good-faith negotiation first.
10. Software licences (ATK Rule Doctor)
- What you buy. A non-exclusive, non-transferable licence to use ATK Rule Doctor on one Wazuh cluster
(one manager cluster and its indexer) for the term purchased, normally 12 months, including updates released during
that term and support by email.
- Where it runs. On your infrastructure. It sends nothing to ATK. You are responsible for running it on systems
you are authorised to change, and for reviewing a change before applying it; the mapping fix includes a rollback.
- You may not resell, sublicense, or redistribute the software, or use one licence for more than one cluster.
A service provider may use it on a client's cluster with one licence per client cluster.
- Renewal. Licences do not renew automatically unless you choose a subscription at checkout; you can cancel a
subscription at any time and it ends at the close of the paid term.
- Refunds follow the refund policy. Liability follows section 6.
11. Online orders
Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record
for all our online orders. Paddle provides all customer service inquiries and handles returns for those orders.
Services under a contract or order form are invoiced by ATK directly.
Service commitments · Prepare your infrastructure file