CONDITIONS
FOR USING THE "DEMO" VERSION OF THE REMOTE SERVICE FOR EVALUATING
THE VULNERABILITY OF INFORMATION SYSTEMS
1. Introduction
Emaze Networks S.p.A. provides a remote service, called "ipLegion",
created for verifying the vulnerability of information systems.
2. Purpose
Following the acceptance of the terms and conditions contained in this
Agreement, Emaze Networks S.p.A. will provide Users with the complementary
("Demo") version of the ipLegion service in order to evaluate
its effectiveness.
The ipLegion demo service does not comprise verifications of the "Denial
of Services (DoS)" type which are included in the full version.
The verification operations offered free-of-charge in the "demo"
version are specifically described in the "Services" table.
No other operations are included.
3. Means of access to the Demo
Users intending to use the ipLegion Demo service should register by
filling in the relative form with the required data and accept these
terms and conditions.
Following acceptance, Users will receive a registration code (username
and password) by e-mail which will allow them to use the Demo.
The above username and password, delivered under the User's responsibility
are personal and must therefore remain confidential.
The network configuration tests will be made on the machine featuring
the IP address with which the User accesses the Web area set aside for
the ipLegion demo service.
At the end of the verification of the system vulnerabilities in question,
Emaze Networks S.p.A. will provide the User with "Reports"
on any vulnerable points discovered. These reports may only be consulted
by the User using his username and password in a protected area of the
site www.iplegion.com.
Users must keep a record of all the data in relation to the reports
generated while using the Service without modifying them in any way.
If Users decide not to keep a record of the data sent to and received
from the Service, they recognise the probative effect of the records
kept by Emaze Networks.
If any disputes should arise, the records of the scans made by Emaze
Networks will be accepted as proof, unless an action for falsehood is
brought, and will have probative effect on that of the recognised private
deed.
The User agrees and accepts that, in all cases, the number of scans
made and the number of scans available will only be determined by the
counter located in the ipLegion database responsible for the management
of the login sessions and User data.
4. Undertakings of the User
The User agrees and accepts that, while using the ipLegion Demo
service, Emaze Networks S.p.A. will make network configuration tests
on the User's machine.
The User is required to take all suitable measures to ensure that third
parties do not come into possession of the User registration code (username
and password) mentioned in the previous article.
If the User registration code (username and password) is lost, the User
undertakes to promptly inform Emaze Networks S.p.A. by e-mail.
5. Duration
If they decide to activate the ipLegion Demo service as indicated
in article 3 of this Agreement, Users will be allowed to use the Demo
for a period of 60 (sixty) days starting from the moment they receive
the User registration code, plus a further 30 (thirty) days during which
it will only be possible to consult the reports made. The ipLegion
"demo" service is limited to a total of 5 (five) scans.
After 90 days - or if this Agreement is terminated earlier for any
reason - Users will be refused access to the reserved area as their
username and password profile will be deactivated. At the same time,
Emaze Networks S.p.A undertakes to cancel the data relative to the
"Reports" made by Users.
The activation by Emaze Networks S.p.A. of the ipLegion service
in the "demo" version binds Emaze Networks S.p.A. until the
end of the Trial period (no more scans available or 60 day expiry).
This proposal, though irrevocable for the time established in this Agreement,
will terminate before the natural expiry if Users act in such a way
as to compromise the functionality of the ipLegion service, such as
- purely for the sake of example - tampering with the service, unauthorised
attempts to use the service for over 60 + 30 days or more than 5 scans.
If, at the end of the Trial period, Users decide to use the full ipLegion
service, they must adhere to the agreement proposal for the supply of
this service, sign the relative contract and pay the fee required for
the use of this service.
6. Limits to liability
In no case may Emaze Networks S.p.A. be held responsible for any malfunctions
or blocks of the computers subjected to network configuration tests
in the "demo"version. If the above should occur, Users may
not claim damage compensation from Emaze Networks S.p.A.
No damage compensation may be claimed from Emaze Networks S.p.A. for
damage, either direct or indirect, caused by the inappropriate use of
the ipLegion demo service.
Emaze Networks accepts no liability for the suspension or interruption
of the service or for any damage that may derive from this if such suspensions
or interruptions are caused by third parties moving or tampering with
the Equipment.
7. Handling personal data
The information note and agreement to the handling of personal data
are contained in attachment 2 of this agreement.
Emaze Networks S.p.A. will only use the personal data transmitted by
the User to carry out the vulnerability verifications in the "demo"
version and only for the time required for such verifications.
Within the above limits, Emaze Networks S.p.A. undertakes to handle
the data transmitted by Users in compliance with Law n° 675 of 31st
December 1996 and not reveal it to unauthorised people. However, Emaze
Networks S.p.A. may transmit such data to parties it appoints to carry
out the above verifications.
The User expressly declares he has been informed of the contents of
articles
10 and 13 of Italian Law n° 675/1996 and allows his personal
data to be handled for the above purposes.
8. Applicable law:
This agreement is governed by Italian law
9 Court of jurisdiction
Any disputes arising from this agreement will be exclusively settled
by the Court of Trieste, Italy.
"SERVICE" TABLE
-Scan of TCP ports (from port 1 to 1024, plus port 6667) + set of selected
security checks-Scan of UDP ports (minimum set: ports 7-13-53-67-123-512-513
-514-520)
-Scan start and end mail
-Scan progress monitor (visualisation of progress of report with detail
of ports analysed and security checks applied)
-Report available within one hour from the end of scan
-Access reserved to the Emaze Web site through HTTPS at 128 bit (SSL
and TLS protocol)
-Authentication with User Name and Password