Terms of Service

Last updated: 10 September 2026

These Terms of Service govern access to and use of SOCsimple.

By creating an account, requesting or accepting access, or using SOCsimple, you agree to these Terms.

If you are using SOCsimple on behalf of a company or other organization, you represent that you are authorized to accept these Terms on its behalf.

1. The service

SOCsimple is a detection content management platform designed to help users understand, review, manage, test, track, and deploy Wazuh detection content.

Features may include management of rules, decoders, CDB lists, environment synchronization, findings, drafts, deployment, activity history, and related workflows.

The features available to you may depend on your account, beta status, subscription, connected environment, Wazuh version, or other technical factors.

In these Terms, your Wazuh environment means the Wazuh manager, indexer, agents and related systems that you operate and connect to SOCsimple. It is yours: SOCsimple does not host, operate or administer it.

2. Private beta

SOCsimple is currently offered in private or limited-access beta.

Beta access may be provided selectively and does not guarantee future access, commercial availability, particular features, or pricing.

During beta:

Unless we separately agree otherwise in writing, beta access does not include a guaranteed uptime, availability commitment, support response time, or service-level agreement.

3. Access and accounts

You must provide accurate information when requesting or creating an account.

You are responsible for:

You may not share credentials in a manner that bypasses account controls or permits unauthorized use.

4. Authorized environments

You may connect SOCsimple only to systems, environments, infrastructure, accounts, and data that you are authorized to access and manage.

You are responsible for ensuring that your use of SOCsimple complies with your organization's security requirements and any obligations you have to customers or third parties.

5. Detection changes and deployment

SOCsimple may provide functionality that allows authorized users to create, modify, review, test, or deploy detection content.

You acknowledge that changes to security monitoring and detection configuration can affect alerts, detection coverage, system behavior, and operational outcomes.

SOCsimple provides controls intended to make changes reviewable and traceable, but you remain responsible for determining whether a proposed change is appropriate for your environment.

You should review changes before deployment and maintain appropriate operational safeguards, backups, testing practices, and access controls.

6. Your Wazuh environment

SOCsimple is a management layer above your Wazuh environment. It reads your detection content, explains it, and records what changes. It is designed not to change your Wazuh environment on its own: content reaches your manager through SOCsimple only by a deploy that a member of your team reviewed and approved, and each deploy is recorded with who approved it and why. Changes made in your Wazuh environment outside such a deploy — by hand, by another tool, or by another account you have given access to — are shown to you as drift when SOCsimple's next sync observes them. Before writing, every deploy reads the target file from your manager as it is at that moment and compares it with the content your change was built on. If the file has changed since then, the deploy is refused and nothing is written; you re-sync, review the difference and rebuild the change. This check runs when you deploy, not continuously while you work, and observation depends on a successful sync, so SOCsimple does not promise to notice every external change as it happens, or to tell you who made it.

Because the environment is yours, the following remain your responsibility:

7. Your content

You retain ownership of content you or your organization provide to SOCsimple, including your detection rules, decoders, lists, configuration, and related materials.

You grant us the limited rights necessary to host, process, transmit, display, analyze, back up, and otherwise handle that content solely as needed to operate, secure, support, and improve SOCsimple.

You represent that you have the rights necessary to provide that content to the service.

8. SOCsimple intellectual property

SOCsimple, including its software, interfaces, designs, workflows, branding, documentation, and related technology, is owned by us or our licensors.

Except for the limited right to use the service under these Terms, no ownership rights in SOCsimple are transferred to you.

You may not, except where applicable law expressly permits otherwise:

Nothing in these Terms restricts rights granted under any applicable open-source license for software separately made available under such a license.

9. Feedback

If you provide suggestions, ideas, bug reports, or other feedback about SOCsimple, you allow us to use that feedback to develop and improve the product without obligation to you.

This does not give us ownership of your detection content or confidential customer data.

10. Acceptable use

You may not use SOCsimple:

We may restrict or suspend access where reasonably necessary to investigate or prevent misuse or security risks.

11. Third-party services

SOCsimple may interoperate with third-party products and services, including Wazuh.

Those third-party services are not controlled by SOCsimple and may change independently.

Your use of a third-party service is governed by the agreement between you and that provider.

References to Wazuh do not imply ownership of or affiliation with Wazuh unless expressly stated.

12. Availability and changes

We aim to operate SOCsimple reliably, but we do not guarantee that the service will always be available, uninterrupted, error-free, or compatible with every environment.

We may modify the service as the product evolves.

Where practical, we will try to avoid changes that unnecessarily disrupt active customers.

13. Security

You are responsible for using appropriate credentials and permissions when connecting external environments to SOCsimple.

You must not intentionally provide credentials that grant broader access than reasonably required for your intended use.

If you become aware of a suspected security issue involving SOCsimple, please contact us promptly at hello@socsimple.com.

14. Suspension and termination

You may stop using SOCsimple at any time.

We may suspend or terminate access where reasonably necessary because of:

Where reasonable under the circumstances, we will try to provide notice before terminating access.

Termination does not affect provisions that by their nature should continue, including intellectual-property, limitation-of-liability, confidentiality- related, and dispute provisions.

15. Disclaimers

To the extent permitted by applicable law, SOCsimple is provided on an "as is" and "as available" basis.

We do not warrant that SOCsimple will detect every security issue, prevent every attack, identify every misconfiguration, or produce a particular security outcome.

SOCsimple is a detection management tool and should not be treated as a replacement for appropriate security operations, review, monitoring, backup, incident response, or professional judgment.

Nothing in these Terms excludes rights or warranties that cannot legally be excluded.

16. Limitation of liability

To the maximum extent permitted by applicable law, SOCsimple and its operators will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, revenue, business, goodwill, data, or business opportunity arising from use of the service.

For free or beta use, and unless a separate written agreement provides otherwise, our aggregate liability arising out of or relating to SOCsimple will not exceed the greater of:

Some jurisdictions do not allow certain limitations of liability, so some of these limitations may not apply to you.

17. Indemnity

To the extent permitted by law, if you are using SOCsimple on behalf of a business or organization, you agree to be responsible for claims arising from:

18. Governing law

These Terms are governed by the laws of the State of Israel, without regard to conflict-of-law principles. The competent courts in Israel will have exclusive jurisdiction over disputes arising out of or relating to these Terms, except where applicable law requires otherwise.

19. Changes to these Terms

We may update these Terms as SOCsimple evolves.

If changes are material, we may provide notice through the service, by email, or by another reasonable method.

Your continued use after updated Terms take effect constitutes acceptance where permitted by applicable law.

20. Contact

Questions about these Terms may be sent to: hello@socsimple.com