Legal · Terms of Service
Keyvaci Terms of Service
These Terms of Service (the "Terms") govern access to and use of Keyvaci, a zero-knowledge credential vault operated by XNOR Group Pte. Ltd., a company incorporated in Singapore ("Keyvaci", "we", "us"). They form a binding agreement between us and the organisation that subscribes to the Service (the "Customer", "you").
The person who creates an organisation on Keyvaci confirms that they are authorised to bind that organisation to these Terms. Where the organisation is created through Microsoft Entra ID, that person must hold a Global Administrator or Privileged Role Administrator role in the Customer's own directory, and we treat that role as evidence of authority. Where it is created with an email address, we can verify only that the person controls that address, so the confirmation they give is what we rely on. Section 3 sets out both routes.
Read this before you continue
Keyvaci is designed so that we cannot read your stored credentials. That is the product's central security property, and it has an unavoidable consequence: if the relevant keys are lost, your data cannot be recovered by anyone, including us. No support request, legal order, backup, or payment can reverse it. Section 5 explains exactly when this happens and what you must do to prevent it.
Contents
- Definitions
- The Service
- Accounts, authority and members
- Zero-knowledge architecture
- Irreversible loss of data
- Customer responsibilities
- Administrator recovery and visibility
- Trial, fees, seats and renewal
- Non-payment and frozen accounts
- Acceptable use
- Data, privacy and processing
- Requests from authorities
- Availability and support
- Security disclosure and limits of assurance
- Term, suspension and termination
- Warranties and disclaimers
- Limitation of liability
- Indemnity
- Changes to these Terms
- Governing law and disputes
- General
1. Definitions
| Term | Meaning |
|---|---|
| Service | The Keyvaci web application, API and related components. |
| Organisation | A tenant on the Service, created by and belonging to the Customer. |
| Member | An individual authorised by the Customer to use the Service under the Customer's Organisation. |
| Administrator | A Member holding the ADMIN role in the Organisation. |
| Vault | A container of encrypted entries within an Organisation. |
| Customer Data | Everything the Customer or its Members store in the Service, including the encrypted contents of Vaults. |
| Sign-in Link | Where email sign-in is used, a single-use link we send to a person's email address. Opening it proves they hold that address, which is how they sign in. It expires five minutes after it is sent, and it does not decrypt anything. There is no separate sign-in password: we neither ask for one nor hold one. |
| Master Password | The passphrase a Member chooses at enrolment, from which their personal keys are derived. Never transmitted to us. It is what actually decrypts Vault contents, and it cannot be reset by us or by email. |
| Organisation Recovery Key | The key generated in the Customer's browser at signup, which can decrypt the private keys of every Member. Never transmitted to us. |
| Organisation Signing Key | The key generated at signup with which the Customer confirms the identity keys of its Members. Never transmitted to us. |
| Recovery Kit | The file containing the Organisation Recovery Key and Organisation Signing Key, produced once, in the browser, at signup. |
2. The Service
Keyvaci stores credentials and similar secrets on behalf of the Customer in encrypted form, and provides controlled sharing of those secrets between Members. Subject to these Terms and to payment of the applicable fees, we grant the Customer a non-exclusive, non-transferable right to use the Service during the subscription term.
We may change, add or remove features. Where a change materially reduces the security or core functionality of the Service, we will give reasonable prior notice by email to Administrators or through the Service.
3. Accounts, authority and members
-
Two ways to sign in. An Organisation may use Microsoft Entra ID, or an email
address with a password held by us, depending on what the Service offers in the Customer's
environment.
- Microsoft Entra ID. Authentication happens at Microsoft. The Customer is responsible for its own directory, including which accounts exist, which of them retain privileged directory roles, and what conditional access or multi-factor policies apply. We never receive directory passwords and cannot issue or reset them.
- Email address and password. We receive the password, verify it, and store only a salted hash of it, never the password itself. We issue the session token. A Member may add a second factor in the form of a time-based one-time code from any authenticator application, and an Administrator may require one across the Organisation before a credential is revealed. Recovery codes are issued once at that point and are the only way back in if the authenticator is lost.
- Authority to create an Organisation. With Microsoft Entra ID, only a Global Administrator or Privileged Role Administrator of the Customer's own directory may create one, and the Organisation is bound to that directory's tenant identifier. With an email address, the person must have confirmed control of that address through a link we send to it, and must not already belong to an Organisation. One address belongs to one Organisation.
- Membership is by invitation issued by an Administrator. An invitation is addressed to an email address, but identity within the Service is the Entra object identifier of the account that accepts it. An invited person does not gain access to any Vault until an Administrator has confirmed their identity keys as described in section 6.
- The Customer is responsible for all activity carried out under its Organisation, and for promptly removing or suspending Members who should no longer have access.
4. Zero-knowledge architecture
Encryption and decryption of Vault contents take place in the Member's browser. The keys required to read Customer Data are derived from the Master Password, or are protected by the Organisation Recovery Key. None of these ever leave the browser in a form we can use.
What this means in practice, stated plainly so that it is not misunderstood:
| We cannot | We can |
|---|---|
| Read the contents of any Vault entry. Reset a forgotten Master Password. Recover data when the relevant keys are lost. Produce decrypted Customer Data to anyone, including a court or regulator. Restore readable data from a backup. | See and process the operational data described in section 11 and in the Privacy Policy, including Member names and email addresses, the structure of Organisations and Vaults, who holds access to which Vault, and audit records of access. See the encrypted form of Customer Data. Suspend or delete an Organisation. |
The Customer acknowledges that this design is a deliberate trade-off which it has selected: it removes us as a party capable of reading Customer Data, and in exchange it removes us as a party capable of restoring it.
5. Irreversible loss of data
Conditions under which data is permanently lost
- A Member forgets their Master Password. Their data can be restored only by an Administrator performing a recovery using the Organisation Recovery Key. We cannot perform this for you.
- The Customer loses the Recovery Kit. No Member who forgets their Master Password can then be recovered, and no new Member can be confirmed, so the Organisation can no longer grow or heal. We hold no copy of the Recovery Kit.
- Both of the above. The affected Customer Data is permanently unreadable by everyone, permanently.
The Customer accepts sole responsibility for these outcomes and agrees that we bear no liability for loss of, or inability to access, Customer Data arising from loss of a Master Password, the Recovery Kit, or any other key material held by the Customer or its Members. This allocation of risk is a fundamental basis on which the Service is offered at its stated price.
The Customer shall maintain independent arrangements for business continuity, including exporting Customer Data at intervals appropriate to its own risk assessment. The Service provides export of Customer Data at any time while the Organisation is not suspended or deleted.
6. Customer responsibilities
- Safeguarding the Recovery Kit. The Recovery Kit is generated once, in the browser, and is shown once. The Customer must store it in a manner appropriate to its value, which is the value of every credential the Organisation will ever hold. It should be treated at least as carefully as the most sensitive credential it protects.
- Confirming Member identity keys. A Member becomes able to receive access to Vaults only after an Administrator signs their identity keys. That signature is the Customer's assertion that the keys belong to the real person. Administrators must verify the displayed key fingerprint with the individual through a channel other than the Service before signing. Signing without verifying defeats a control that exists to prevent an impostor obtaining access, and the consequences of doing so rest with the Customer.
- Choice of Master Passwords. The Service enforces a minimum strength, but the Customer remains responsible for its own password policy and for informing Members that no reset is possible.
- Mailbox security. Where email sign-in is used, opening a Sign-in Link we send is what signs a Member in, so whoever can read a Member's email can sign in as that Member. The security of the Member's mailbox is therefore a precondition of the security of their account. This replaces a separate sign-in password, which the Service no longer uses: there is one fewer secret to be stolen or reused, and the mailbox carries the weight instead. A second factor is available, and an Organisation may require one before an entry is revealed.
- What a Sign-in Link cannot do. Getting back into an account does nothing to the data. Vault contents stay sealed by the Master Password, which never reaches us and cannot be reset by us or by any link we send. The Customer should make sure its Members understand this, because the most likely consequence of confusing the two is a person believing that signing in again has recovered data when it has not.
- Directory hygiene. Because authority to create an Organisation, and the identity of every Member, derive from the Customer's Entra directory, the security of that directory is a precondition of the security of the Organisation.
- Lawful basis for Member data. The Customer is responsible for giving its Members any notice, and obtaining any consent, required by law in connection with their use of the Service, including the matters described in section 7.
7. Administrator recovery and visibility
This section describes capabilities the Customer's own Administrators hold. It is set out separately because it has employment-law and data-protection consequences the Customer must manage.
- Recovery. A person holding the Organisation Recovery Key can decrypt the personal private keys of any Member, and therefore any Vault that Member can open. The Service performs recovery only in response to a request initiated by the affected Member, and records it in the audit trail. However, possession of the Organisation Recovery Key is itself sufficient to decrypt Member key material obtained from stored data, without using the Service. The Customer must therefore control that key as a matter of governance, not rely on the Service's workflow alone.
- Audit visibility. The Service records security-relevant events, including when a Member opens a Vault, reveals an entry, is granted or loses access, and when recovery is used. Administrators can obtain these records. They constitute monitoring of individuals' activity.
- Customer obligation. Where the Customer's Members are employees or contractors, the Customer is the controller of this monitoring and recovery capability. The Customer must inform them of it and establish a lawful basis for it under applicable law. We provide the mechanism; we do not determine the purpose for which the Customer uses it.
- Personal use. Members should not store purely personal credentials unrelated to the Customer's business in the Service, because those credentials would fall within the Customer's recovery and audit capabilities.
8. Trial, fees, seats and renewal
- Trial. New Organisations receive a free trial of the length stated in the Service at signup. No payment method is required to start it. At the end of the trial, an Organisation that has not subscribed becomes frozen as described in section 9.
- Fees. Prices are those displayed in the Service at the time of purchase. Payments are processed by Stripe; we do not receive or store card details. The Customer is responsible for any taxes, duties or bank charges not collected by Stripe.
- Seats. For per-seat plans, a seat is consumed by each Member who is not suspended, plus each outstanding invitation. Adding Members during a paid period results in a prorated charge; removing them results in a credit applied to a subsequent invoice. Seat counts are synchronised with Stripe automatically.
- Automatic renewal. Subscriptions renew automatically at the end of each billing period, monthly or annual as selected, at the then-current price, until cancelled. The Customer may cancel at any time through the billing portal in the Service.
- No refunds. Fees already paid are non-refundable, in whole or in part, including on cancellation, on reduction of seats below the paid quantity, and on termination for the Customer's breach. On cancellation, the subscription remains active until the end of the period already paid for, and does not renew. The free trial exists so that the Customer can evaluate the Service before paying.
- Price changes. We may change prices with at least 30 days' notice by email to Administrators. Changes take effect at the next renewal. If the Customer does not accept a price change, its remedy is to cancel before that renewal.
9. Non-payment and frozen accounts
If an invoice fails, the Organisation enters a grace period during which it continues to work normally. If payment is not resolved within that period, or if a subscription ends without renewal, the Organisation becomes frozen.
A frozen Organisation remains able to read and export all of its Customer Data, and its Administrators can still reach checkout to restore the subscription. What is suspended is the ability to write: creating Vaults, adding or changing entries, and granting access. We consider it unacceptable to hold a customer's own credentials hostage over an invoice, and this clause is a commitment not to do so.
Recovery workflows remain available while frozen, so that a Member who forgets their Master Password during a lapse does not lose access to data they are entitled to export.
10. Acceptable use
The Customer shall not, and shall not permit any Member to:
- use the Service in breach of applicable law, or to store material whose possession is unlawful;
- attempt to gain access to another organisation's data, or to any part of the Service not intended for it;
- interfere with the operation of the Service, including by circumventing rate limits or automating access in a manner that degrades it for others;
- resell, sublicense or provide the Service to third parties as a service of its own, without our written agreement;
- reverse engineer the Service except to the extent that restriction is unenforceable by law.
Security research is welcome under section 14 and is not a breach of this section when conducted within the scope described there.
11. Data, privacy and processing
Our handling of personal data is described in the Privacy Policy. Where we process personal data on the Customer's behalf, the Data Processing Addendum applies and forms part of these Terms. The Customer is the controller of that data and we are its processor.
Because of the architecture described in section 4, the personal data we can actually process is limited to operational data. We cannot process the contents of Vault entries, and no instruction from the Customer, and no legal order, can make us able to.
12. Requests from authorities
If we receive a binding legal demand relating to Customer Data, we will, unless legally prohibited, notify the Customer so that it may seek protective relief, and we will disclose only what the demand requires and what we actually hold.
The Customer should understand what that is: we can produce operational data and encrypted ciphertext. We cannot produce readable Vault contents, because we do not possess the means to decrypt them. A demand that we do so cannot be complied with as a matter of fact, not of willingness.
13. Availability and support
We aim for high availability but do not commit to a service level in these Terms. Where a separate written service level agreement is signed with a Customer, that agreement prevails for availability and support response.
Support is provided by email to Administrators. We will never ask a Member for their Master Password or for the Recovery Kit, and no communication requesting them is from us.
14. Security disclosure and limits of assurance
- Reporting. Suspected vulnerabilities should be reported to keyvaci@xnorgroup.com. We will acknowledge within five business days. Good-faith research that avoids privacy violations, data destruction and service degradation, and that does not access data belonging to others, will not be pursued by us as a breach of section 10.
- Incident notification. We will notify affected Customers without undue delay of any breach of security leading to accidental or unlawful destruction, loss, alteration or unauthorised disclosure of data we process, with the detail required by the Data Processing Addendum.
- No guarantee of unbreakability. The Service uses established cryptography, with the algorithms and parameters documented in the Service. We do not warrant that this cryptography cannot be broken, whether by advances in cryptanalysis, by future computing capability, or by a flaw in an underlying component. The Customer's protection against such developments is the ability to rotate keys and to change stored credentials, both of which the Service provides.
15. Term, suspension and termination
- These Terms apply from the creation of the Organisation until it is deleted.
- The Customer may terminate at any time by cancelling the subscription and deleting the Organisation. Section 8.5 applies to fees already paid.
- A Member ending their own membership. A Member may delete their own account at any time from their profile. Their access, their profile and their keys are removed immediately. Entries they created remain in the Organisation's vaults, because those entries are the Customer's data and not the Member's. The Member may reverse the deletion within 14 days, using a link sent to their own address; after that it is permanent. A Member who is the last Administrator of the Organisation, or the only Administrator of a vault, cannot delete their account until that responsibility has been handed to somebody else.
- Deleting the Organisation. An Administrator may schedule deletion of the Organisation from the administration area. It takes effect 30 days later. During that period the Organisation continues to work normally, every Administrator is notified that a deletion is scheduled, and any Administrator may cancel it. Once it completes, the vaults, the entries, the Member profiles and the audit records are deleted and cannot be recovered by anybody, including us.
- We may suspend an Organisation immediately where required by law, or where its use presents a serious and immediate risk to the Service or to others. We will notify Administrators and, where the cause is capable of remedy, restore access on remedy.
- We may terminate for material breach not remedied within 30 days of written notice.
- On termination, the Customer may export its Customer Data for 30 days. After that period we delete Customer Data from live systems, and from backups within a further 35 days as backup cycles expire. Audit records and records required for legal, tax or accounting purposes are retained for the periods stated in the Privacy Policy. Because we cannot read Customer Data, deletion is deletion of ciphertext.
16. Warranties and disclaimers
We warrant that we will provide the Service with reasonable skill and care. Except as expressly stated in these Terms, and to the fullest extent permitted by law, the Service is provided "as is" and we disclaim all other warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose and non-infringement.
We do not warrant that the Service will be uninterrupted or error free, nor that it will meet requirements the Customer has not communicated to us in writing.
17. Limitation of liability
- Neither party excludes liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be excluded.
- Excluded losses. Neither party is liable for loss of profit, loss of business, loss of anticipated savings, loss of goodwill, or indirect or consequential loss, however arising.
- Cap. Our total aggregate liability arising out of or in connection with these Terms is limited to the fees paid by the Customer to us in the twelve months immediately before the event giving rise to the claim. Where no fees have been paid, our total aggregate liability is limited to SGD 100.
- Loss of key material. For the avoidance of doubt and as provided in section 5, we have no liability whatsoever for loss of or inability to access Customer Data caused by loss, disclosure or misuse of a Master Password, the Recovery Kit, the Organisation Recovery Key, the Organisation Signing Key, or any credential of the Customer's directory.
- The Customer acknowledges that these limits are a reasonable allocation of risk given the nature of the Service and the fees charged, and that we would not offer the Service on these terms without them.
18. Indemnity
The Customer shall indemnify us against claims, losses and reasonable costs arising from: its use of the Service in breach of section 10; its failure to give Members the notices required by section 7; and any claim by a Member or third party relating to the Customer's exercise of the recovery or audit capabilities described in section 7.
19. Changes to these Terms
We may amend these Terms. Each version carries a version identifier, shown at the top of this document.
- For changes that do not materially reduce the Customer's rights, we will publish the updated Terms and update the version identifier.
- For material changes, we will give at least 30 days' notice by email to Administrators, and the Service will require an Administrator to accept the new version before continued administrative use. Continued use after the effective date constitutes acceptance.
- The Service records which version was accepted, by whom, and when. That record is what we will rely on to evidence agreement.
20. Governing law and disputes
These Terms are governed by the laws of Singapore, without regard to conflict of laws rules. The parties shall first attempt in good faith to resolve any dispute by negotiation between senior representatives for 30 days.
Any dispute not so resolved shall be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre (SIAC) under its Rules in force at the time, by one arbitrator, seated in Singapore, conducted in English. Nothing prevents either party from seeking urgent injunctive relief from any court of competent jurisdiction.
Nothing in this section deprives a Customer that is a consumer, or that has non-waivable rights under the law of its own country, of the protection of those rights.
21. General
- Entire agreement. These Terms, the Privacy Policy and the Data Processing Addendum are the entire agreement between the parties on their subject matter, and replace any prior understanding.
- Order of precedence. If there is a conflict, a signed written agreement between the parties prevails, then the Data Processing Addendum for matters of personal data, then these Terms, then the Privacy Policy.
- Assignment. Neither party may assign these Terms without the other's consent, except to a successor of substantially the whole of its business.
- Severability. If any provision is held unenforceable, the remainder continues in effect and the provision is modified to the minimum extent necessary to be enforceable.
- No waiver. A failure to enforce a provision is not a waiver of it.
- Language. These Terms are authored in English. Any translation is provided for convenience, and the English version governs in the event of a discrepancy.
- Notices. Notices to us go to keyvaci@xnorgroup.com. Notices to the Customer go to the email addresses of its Administrators recorded in the Service.