Scope and parties
This undertaking applies between CM Apps Software LLC ("SendTheCanary", "we") and the party using, or in discussions about using, our services ("you").
It applies even where no separate confidentiality agreement has been signed, and takes effect the moment we first access confidential information. Its purpose is to leave no gap while an agreement is being prepared.
The obligation runs one way: we protect your information. If you want a mutual undertaking, we will sign your agreement.
Confidential information
Confidential information is anything belonging to you that we learn in connection with a test. It does not matter whether it is written, spoken, visual or machine-readable, and it need not be marked "confidential".
It includes in particular: source code, architecture and infrastructure detail, unreleased features and roadmap, credentials and keys, business model and pricing, customer and user data, internal process documents, the findings a test produces, and the report itself.
Where we are unsure whether something is confidential, we treat it as confidential and ask you.
What falls outside
The following are outside this undertaking: information already public when it reaches us; information that later becomes public through no fault of ours; information lawfully in our possession before you gave it to us; information we developed independently without using yours at all; and information lawfully obtained from a third party under no confidentiality obligation.
The burden of proving that information falls into one of these exceptions rests with us.
Permitted purpose
We use confidential information solely to carry out the test we agreed on, report the findings and run the re-test round. We use it for nothing else.
Naming you as a reference, writing a case study about your product or listing you as a customer all require your written permission first. Withholding it carries no consequence and changes neither price, scope nor priority.
Who has access
Only the people who need to know in order to run the test have access: assigned members of our core team and the testers assigned to the engagement. Access is granted per person and limited to the duration of the test.
Every tester in our network signs a confidentiality undertaking equivalent to this one before being assigned to any test. We are directly liable for a tester’s breach; the nature of our relationship with them does not change that liability.
The infrastructure providers we rely on to deliver the service are listed on the Sub-processors page, and we hold a written confidentiality obligation with each of them.
We may disclose to our legal and financial advisers only to the extent necessary and under professional privilege.
Standard of care
We protect confidential information to a reasonable industry standard, and in no case with less care than we apply to our own trade secrets.
Our minimum measures: encryption in transit and at rest, least-privilege access control, multi-factor authentication, access logging, and a prohibition on copying test data to personal devices. Details are on the Security Policy page.
Credentials
Usernames, passwords, API keys and similar credentials you give us are held in an encrypted vault and released only to people assigned to the test.
We recommend revoking them once the test ends; we delete them from our records whether or not they are revoked.
If we discover we can reach a system outside the agreed scope, we do not use that access and tell you immediately.
AI and model training
We do not use your confidential information, source code, data or findings to train any AI model, and we do not permit third parties to do so.
Where a tool we use during testing feeds its input into model training, we disable that feature or we do not use the tool.
Reverse engineering and derivative work
We do not examine or take your product apart beyond what the agreed scope requires. We do not produce a copy, a derivative or a comparable product outside the purpose of the test.
This clause does not prohibit the observations black-box testing inherently produces; what it prohibits is using what we learn to build a competing product.
Intellectual property
This undertaking transfers no intellectual property to us and grants us no licence. All rights in your product remain yours.
The report and findings a test produces belong to you; you may use, reproduce and share them with third parties as you see fit.
Non-disclosure of findings
We never publicly disclose the security vulnerabilities or other findings identified in a test. Our Responsible Disclosure policy governs reports made about our own systems; it does not apply to yours.
Where we determine a finding originates in a third-party component, we recommend notifying that component’s vendor. We make such a notification only on your instruction and on your behalf.
Residual knowledge
Members of our team may continue to use the general methods and technical knowledge they retain after a test. This is limited to general experience recalled without reference to any written record.
This clause is not a route to deliberately memorising and reusing confidential information: no information, data, code, design or trade secret specific to your product falls within it.
Feedback
Feedback you give us about how we work may be used freely to improve our service. It covers nothing about your product.
Breach notification
If we learn that confidential information has been disclosed, accessed or lost without authorisation, we notify you within 24 hours.
The notice states what was affected, when it happened, what we did about it and what we will do to prevent a recurrence. We share the outcome of the investigation too.
Return and destruction
Ninety days after a test ends we permanently delete confidential information, test data, recordings and credentials. If you ask us to delete earlier, we do, and we give you the deletion record.
Copies held in automated backups cannot be deleted before the backup cycle completes. Those copies are not accessed, they expire on their own at the end of the cycle, and this undertaking applies to them throughout.
Records we are legally required to keep (invoices, contracts) fall outside this clause and are held only for the length of that retention obligation.
Compelled disclosure
Where a court order, an administrative demand or the law compels disclosure, we notify you as soon as legally possible and, where possible, before disclosing.
We limit the disclosure to the minimum required, request confidential treatment where available, and allow you reasonable time to object.
Duration
The undertaking begins the moment we first access confidential information.
It continues for 5 years after the engagement ends. For trade secrets, source code and personal data there is no time limit; the obligation is perpetual.
Remedies
We accept that the consequences of a confidentiality breach cannot be remedied by damages alone.
On a breach or a threatened breach you may seek any legal remedy, injunctive relief included, without prejudice to any claim for damages.
No warranty
Confidential information is shared as is. You are not treated as having warranted the accuracy or completeness of what you give us.
In return, we state plainly in the report the limits that incomplete information placed on the test; what could not be tested is written inside the report.
Your own NDA
You can ask us to sign your own confidentiality agreement. It is standard practice, we charge nothing for it, and it does not delay the start of testing. We will sign a mutual NDA as well.
Send the text to [email protected].
Where the two conflict, the agreement we sign prevails over this page. This page does not replace it; it defines the minimum that applies while no signed agreement exists.
Assignment, waiver and severability
You may transfer your rights under this undertaking to an acquirer on a sale of your business. We may not assign our rights or obligations without your written consent.
Failure to exercise a right is not a waiver of it. If one provision is invalid the others are unaffected, and the invalid provision is treated as replaced by the valid one closest to its purpose.
Governing law
This undertaking is governed by the law of Türkiye Cumhuriyeti. İstanbul Merkez (Çağlayan) Mahkemeleri ve İcra Daireleri has jurisdiction over disputes.
This does not remove rights you hold under mandatory legislation in your own country.
These documents are published in English and Turkish. In the event of conflict the Turkish text prevails.