Last updated: 4 August 2026

Terms of Service

1. Legal notice

Operator: Herr Godfrey Mwasanje c/o Block Services Stuttgarter Straße 106 70736 Fellbach Deutschland Email: contact@revealmyrisk.com

Hosting takes place on European infrastructure operated by our contracted hosting providers.

German law applies. Place of jurisdiction for merchants is the registered seat of the operator. This choice of court does not deprive a consumer of the protection of mandatory provisions allowing proceedings at their place of domicile.

2. The service

RevealMyRisk is a breach-intelligence and exposure-discovery platform. It provides a governed interface to licensed third-party datasets containing credentials and other information that was technically accessible on the internet at the time of collection, without bypassing authentication, paywalls or technical protection measures.

For eligible text-based datasets, some plans include a Raw Search capability that allows searching inside the body of a dataset. For some URLs limited page metadata (title, HTTP status, page text, meta description) may be shown.

The service is intended for professional use (B2B). We do not encourage or facilitate intrusions and do not knowingly target datasets that primarily contain banking or medical records. If we become aware that a dataset is unlawful or was not intended to be publicly accessible, we remove or restrict it as soon as reasonably possible. Notices can be sent under Section 14.

3. Authorised use

You confirm that you have a lawful basis to process any personal data you query and that you are authorised to assess the assets you query, whether your own or those of a client. You are solely responsible for the legality of your use; we do not pre-validate assets or mandates.

Commercial use: your subscription is licensed for your own internal use, including monitoring and protecting your own organisation, employees, customers and assets. Using the service or its data to provide a commercial offering to third parties — reselling, redistributing or mirroring access or data, delivering managed or consulting services based on it, or embedding it into a paid product — requires a separate written agreement. Contact contact@revealmyrisk.com.

Strictly prohibited: credential stuffing, unauthorised account access, doxxing or harassment, publishing full credential dumps, contacting affected individuals, re-selling or mirroring our datasets, large-scale benchmarking, scraping the interface or connection endpoints, bypassing access restrictions, or using output to exploit exposures.

Bug bounty: permitted only where the target programme explicitly authorises the use of external breach-intelligence and OSINT sources of this nature.

Access controls: sensitive contents are restricted by default and require an active subscription and the applicable entitlements. Per-period limits mitigate abuse. We may cap or deny access for highly sensitive material or where misuse is suspected. Attempting to bypass these controls is a breach of these Terms.

Connection access and fair use: programmatic access requires a valid key. Do not share keys or exceed plan limits. Automated high-volume extraction, dataset mirroring and resale are prohibited. We may apply rate limits and revoke keys that breach these Terms.

Raw Search: where included in your plan, it may only be used on assets you are authorised to assess and never to target obviously sensitive datasets such as banking or medical databases. If you discover that a dataset focuses on such data you must stop using it and report it to us.

Security logging: for searches we log the timestamp, your account identifier, the module used and query metadata. For privileged actions we log the timestamp, the account identifier and the affected record. Records may be preserved to handle abuse reports or legal obligations.

4. Sensitive domains and geographic restrictions

We maintain an internal list of high-risk domains — in particular government, public-institution and social-security domains — for which no results are returned. This list may be extended or modified at any time.

For other sensitive domains we may require manual validation and proof that you are authorised to act for the organisation concerned. Access is denied from territories subject to EU, UN or OFAC sanctions and from Russia, Iran and North Korea. Circumventing these measures (for example via VPN or proxy) is a breach and may lead to immediate suspension.

5. Subscriptions and withdrawal

Plans are prepaid and renew for the agreed term unless cancelled. Access is granted immediately after activation. If you are a consumer, by expressly requesting immediate performance you acknowledge the loss of your 14-day withdrawal right for digital content supplied without a tangible medium (§ 356 (5) BGB). Business users are not entitled to this consumer right.

6. Long-term licences

Where a long-term or perpetual licence is granted, it is granted for the operational lifetime of the service. No refund, partial or total, is due in case of discontinuation, whatever the cause. In case of a voluntary planned shutdown we notify holders at least 90 days in advance and maintain access to export features during this period. This commitment does not apply in case of force majeure, insolvency proceedings, or a shutdown imposed by an administrative or judicial authority. In case of a business transfer, the acquirer assumes the obligations toward existing licence holders.

7. Cancellation and refunds

You may cancel at any time by written notice to contact@revealmyrisk.com or through the billing options provided in your account. The service remains active until the end of the current period. No refunds are issued for unused time, except where mandatory law requires otherwise.

8. Statutory guarantee

Where applicable to consumers, the statutory provisions for digital products (§§ 327 ff. BGB) apply. For a one-off supply they cover defects appearing within two years of supply; for continuous supply they apply for the duration of the contract.

9. Compatibility and interoperability

The platform works on current desktop and mobile browsers. Reports are available as PDF from the interface; structured results are returned by the connection endpoints in JSON. Volumes and rate limits depend on the selected plan.

10. Cookies

We do not use analytics, marketing or cross-site tracking cookies and therefore display no consent banner. Only strictly necessary storage is used: the authentication session and the device fingerprint. Details are set out in the Privacy Policy.

11. Intellectual property

The service, its interface and the compiled datasets are protected by copyright and database rights. Publishing or sharing complete credentials or bulk exports is forbidden. Reports are for your lawful internal cybersecurity use only. You may not reproduce, resell or create derivative datasets from the index, nor otherwise exploit the service commercially without a separate written agreement (see Section 3).

12. Liability

The service is provided "as is" and contains third-party content whose accuracy cannot be guaranteed. To the maximum extent permitted by law, total liability is capped at the fees paid in the 12 months preceding the event, or, for a long-term licence, at the price paid for that licence. Nothing limits liability for intent, gross negligence, injury to life, body or health, or where liability is mandatory by law.

Payment provider verification: payments may be processed by third-party providers that request identity verification (KYC) in accordance with their own policies and applicable anti-money-laundering rules. We have no control over such requests and accept no liability for consequences arising from verification procedures initiated by payment providers.

13. Minors

Registration is reserved for users aged 18 or above.

14. Notice and action

Notices concerning illegal content (Art. 16 DSA) and authority requests (Art. 11 DSA) must be sent to contact@revealmyrisk.com. We follow a notice-and-action process consistent with the EU Digital Services Act, including a statement of reasons where we restrict content or access. Requests are processed within five business days.

15. Changes

Material changes are announced at least 30 days before they take effect. Continued use constitutes acceptance. Material changes that would reduce the rights or features of existing long-term licence holders do not apply to those licences without the holder's express acceptance.

16. Severability

If any clause is or becomes invalid, the remainder of these Terms stays in force.

17. Misuse and cooperation with authorities

We may suspend or terminate your access without refund if we reasonably suspect that you are using the service to commit or facilitate criminal offences, to exploit exposures, or to otherwise breach these Terms. Where permitted or required by law, we may share relevant logs and account information with competent authorities in connection with investigations into cybercrime or abuse of the service.

18. Discount codes and promotional offers

Discount codes and promotional offers are a commercial gesture and not a contractual right. Unless a specific offer states otherwise, they are reserved for consumers and for companies whose total annual revenue, net of tax and based on the last closed financial year, is below EUR 100,000. By entering a code you represent that you meet this condition. Codes are personal, single use per account, non-transferable, cannot be combined with other offers, have no cash value and apply only to the plans and validity period defined for each code. Where the eligibility condition is not met, or a code is used in breach of these Terms, or in case of error or abuse, we may decline or cancel the code and invoice at the standard price. These conditions do not affect a discount already validly applied to a concluded order.

19. Indemnification

You agree to indemnify, defend and hold harmless the operator, its contractors and partners from and against any claim, demand, liability, damage, loss, cost or expense, including reasonable legal fees, arising out of or related to: (a) your use of the service; (b) your breach of these Terms or of any applicable law or third-party right; (c) the absence of a lawful basis or of authorisation for the assets, queries or data you process through the service; or (d) any claim brought by a third party, a data subject or an authority in connection with your use of the service. This obligation survives termination of your account. We may assume the exclusive defence of any matter otherwise subject to indemnification by you, in which case you agree to cooperate with us.

20. General provisions

Force majeure. We are not liable for delay or failure to perform caused by events beyond our reasonable control, including war, terrorism, riots, embargoes, acts of civil or military authorities, fire, flood, accidents, hosting or network outages, cyber-attacks, strikes or shortages of transport, facilities, energy, labour or materials. Our obligations are suspended for the duration of the event.

Entire agreement. These Terms, together with the Privacy Policy and any plan-specific terms presented at checkout, constitute the entire agreement and supersede all prior communications, proposals and representations. Marketing materials and public statements do not form part of the agreement.

Governing language. These Terms and the Privacy Policy are drafted in English; the German version is provided for convenience. In case of discrepancy the English version prevails.

No waiver. Failure to enforce any provision is not a waiver of that provision or of the right to enforce it later.

Assignment. You may not assign or transfer your rights or obligations without our prior written consent. We may assign these Terms, in whole or in part, including in connection with a merger, acquisition, reorganisation or sale of assets, provided your rights are not reduced.

21. Free access for public authorities

As a commercial gesture and not a contractual right, we may grant free access to law-enforcement, government and military bodies established in a Member State of the European Union or in the United States of America. Access may be used solely by their personnel and strictly in the course of their official duties, and is limited to a maximum of four (4) accounts per organisation. To request access, contact us from an official email address at contact@revealmyrisk.com; eligibility is verified before access is granted. This benefit is personal, non-transferable, granted at our sole discretion and may be modified, suspended or withdrawn at any time, in particular in case of misuse or use outside the permitted scope. It does not give rise to any refund or compensation.

22. Device binding and device recognition

Accounts are personal and may be bound to a single approved device. When you sign in, your browser computes a device fingerprint: it reads a set of stable technical characteristics — user agent, browser language settings, processor cores and reported device memory, screen resolution, colour depth and pixel ratio, time zone and UTC offset, and the rendering signature of a tiny image drawn invisibly by the browser — and hashes them with SHA-256 into a single non-reversible string. Only that hash is transmitted; the underlying characteristics are neither sent nor stored and cannot be recovered from the hash.

The fingerprint is stored on our servers and linked to your account. If your account is device-locked, every login is compared against your registered devices: an unknown fingerprint is refused, and a known but unapproved device remains blocked until an administrator approves it. This mechanism exists to prevent account sharing and the use of stolen credentials; circumventing, spoofing or automating around it is a breach of these Terms and may lead to suspension.

We do not use tracking cookies, advertising identifiers or software installed on your device for this purpose. You may request a reset of your device binding — for example after replacing a device — at contact@revealmyrisk.com. Further detail is set out in our Privacy Policy and in our Technical and Organisational Measures.

23. AI-generated imagery and transparency

Some visual content on the RevealMyRisk website, application interface and social media channels is created or assisted by artificial intelligence (AI-generated images). This includes illustrative graphics, marketing visuals and certain imagery used on our social media platforms.

We use AI-generated imagery for operational efficiency and to support the visual communication of complex cybersecurity concepts. Where such content is used for informational, illustrative or marketing purposes, we disclose its AI-generated nature in accordance with applicable transparency requirements under EU law, including the AI Act and related digital-services regulations.

AI-generated images are not presented as documentary evidence, real-world photographs or authoritative representations of specific events, persons or places unless explicitly labelled otherwise. If you have questions about our use of AI-generated content, contact us at contact@revealmyrisk.com.