Terms & Conditions
Last updated: 9 August 2026
The MCP Server's two contribution tools have been removed from the product. This revision deletes the provisions that governed contributed data — the licence you granted over it, the warranties you gave, and the related acceptable-use and indemnity terms — because there is no longer any way to contribute. Section 9.5 is marked Reserved rather than renumbered so that references to later sections continue to resolve. Nothing else changes.
1. Acceptance of Terms
These Terms & Conditions (the "Terms") form a binding agreement between you and viaGraph B.V., a private limited company registered in the Netherlands ("viaGraph", "we", or "us"). "Whisper Security" is the trading name under which viaGraph offers the services described in these Terms.
By accessing our website at whisper.security, by signing in to our customer console at console.whisper.security, or by sending requests to our query API at graph.whisper.security or our Model Context Protocol server at mcp.whisper.security (together, the "Services"), you accept and agree to be bound by these Terms.
The Services are offered to businesses and to individuals acting in the course of a trade, business, craft, or profession. They are not offered to consumers. By accepting these Terms you confirm that you are acting in that capacity and that you have authority to bind the organization on whose behalf you use the Services.
You can review, download, and store the current version of these Terms at any time from this page. We keep previous versions available on request.
2. Definitions
- "Graph Data" means the data we make available through the Services, including the internet-infrastructure graph and threat-intelligence data derived from it.
- "Output" means the result an AI assistant, agent, or other client produces by combining Graph Data with its own processing.
- "Connected Client" means any AI assistant, agent, script, or other software that accesses the Services using your credentials.
3. Use License
Subject to these Terms and to payment of any applicable fees, we grant you a non-exclusive, non-transferable, revocable license to access and use the Services in accordance with your plan, and to use Graph Data internally for security investigation, threat intelligence, and infrastructure research. This license terminates automatically if you violate these Terms and may be terminated by us under Section 9.7.
All rights not expressly granted are reserved. We and our licensors retain all intellectual property rights in the Services and in Graph Data, including any database rights subsisting in the graph. Nothing in these Terms transfers ownership of the graph, or of any substantial part of it, to you.
4. Your Account and Credentials
You are responsible for keeping your credentials confidential and for all activity that occurs under them, whether or not you authorized it. Do not share a credential with a third party or embed it in a client you do not control. If you believe a credential has been exposed, revoke it from the console immediately; revocation takes effect on the next request.
You must provide accurate account information and keep it current. You are responsible for the acts and omissions of your personnel and of any Connected Client operating under your credentials.
5. Disclaimer
The Services and the Graph Data are provided on an "as is" and "as available" basis. viaGraph makes no warranties, express or implied, and disclaims all other warranties including, without limitation, implied warranties of merchantability, fitness for a particular purpose, accuracy, completeness, and non-infringement.
6. Accuracy of Materials
Graph Data is aggregated from public registries, open datasets, and third-party feeds, and may contain technical, typographical, or factual errors, or may be out of date. A threat verdict reflects what our sources report at the time of the query and is not a determination that any person or organization has done anything wrong. viaGraph does not warrant that any of the data is accurate, complete, or current, and disclaims liability for decisions made in reliance on it. You are responsible for verifying Graph Data before acting on it, in particular before taking any action that affects a third party.
7. Limitation of Liability
To the maximum extent permitted by law, viaGraph and its suppliers shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of profits, revenue, data, goodwill, or business opportunities, arising out of or in connection with your use of, or inability to use, the Services, even if viaGraph has been advised of the possibility of such damages.
To the maximum extent permitted by law, our aggregate liability arising out of or related to the Services shall not exceed the fees you have paid to viaGraph in the twelve (12) months preceding the event giving rise to the claim, or, if you are on the anonymous or a free tier and have paid no fees, one hundred euros (EUR 100). Those tiers are provided without charge, and the parties agree that this limit reflects that allocation of risk.
Nothing in these Terms excludes or limits our liability for death or personal injury caused by our negligence; for fraud or fraudulent misrepresentation; for damage caused by intent or deliberate recklessness (opzet of bewuste roekeloosheid) on the part of viaGraph or its managerial staff; or for any other liability that cannot lawfully be excluded or limited, including liability under applicable product-liability legislation.
8. Links and Third-Party Data
Our platform may contain links to third-party sites. viaGraph has not reviewed all such sites and is not responsible for their contents. The inclusion of any link does not imply endorsement.
Parts of the Graph Data are licensed to us by third parties on terms that restrict onward redistribution, attribution, or commercial reuse. You may use such data through the Services for your own internal purposes, but you may not redistribute, resell, or republish it where the originating provider's license restricts that use. Where a provider requires attribution, you must preserve it. We will identify the applicable restriction on request.
9. Use of the MCP Server and Query API
The provisions in this Section 9 apply specifically to your use of the MCP Server and the query API, in addition to the general Terms above. If a provision in this Section 9 conflicts with another provision of these Terms, the provision in this Section 9 controls with respect to that use.
9.1 Acceptable Use
When you access the MCP Server or the query API, you agree that you will not:
- attempt to bypass, evade, or interfere with authentication, the query-safety validator, plan limits, or any other technical control;
- submit queries deliberately designed to exhaust server resources or to induce a denial of service;
- resell, redistribute, or sublicense access to the Services to third parties without our prior written agreement;
- use Graph Data to identify, target, surveil, harass, or harm individuals or entities, except where doing so forms part of a lawful security investigation or threat-intelligence activity that constitutes a legitimate purpose of the Services;
- use Graph Data to make decisions about a natural person's eligibility for credit, insurance, employment, housing, or any similar benefit;
- systematically extract, copy, or index the graph, or any substantial part of it, whether by repeated querying or otherwise, in order to reconstruct or republish the dataset;
- use the Services or Output to train, fine-tune, or evaluate a machine-learning model that competes with the Services;
- probe, scan, or test the Services for security vulnerabilities other than through our published vulnerability-disclosure channel described in Section 9.8.
9.2 Authentication and Anonymous Access
Every request to the MCP Server must carry valid credentials, either an OAuth 2.0 access token or a static API key issued from your account. There is no unauthenticated access to the MCP Server. The MCP Server is read-only: every tool it exposes reads the graph, and a write or administrative instruction in a query is refused before it reaches the database.
The query API additionally serves a keyless anonymous tier, at reduced rate limits and with reduced query depth, so that the documentation examples can be run without an account. Anonymous access is provided for evaluation and lightweight public use; it is not intended to support production workloads, and it is not covered by any service-level commitment. We may suspend, throttle, or withdraw anonymous access at our discretion and without notice. An unrecognized, expired, or revoked key does not fail the request: it degrades to the anonymous tier, so a query that suddenly returns less than expected may indicate a credential problem rather than a data problem.
9.3 Plan Limits, Rate Limits, and Query-Safety Limits
Your plan determines the limits that apply to your account, most importantly the maximum traversal depth of a single query. These limits are enforced by the graph engine. You can read the limits that actually apply to your credential at runtime from the whisper://quota resource exposed by the MCP Server, and that resource is authoritative for your account.
The query API applies rate limits and request quotas that vary by tier, and reports them in the rate-limit response headers it returns; a request that exceeds them is rejected with an HTTP 429 and a Retry-After header. Current limits are documented in the API documentation. The MCP Server itself applies no rate or usage limits; where you encounter one while using it, it originates from the graph engine.
Independently of plan, fixed query-safety limits apply to every caller: a maximum result-set size, a cap on the number of rows a single query may return, a pre-execution cost gate that rejects a query whose execution plan would be disproportionately expensive, and a server-side execution deadline. These limits are not plan-based and are not negotiable. Circumventing or attempting to circumvent any of the limits in this Section is grounds for suspension under Section 9.7.
9.4 Service Availability
We target 99.5% monthly availability for the MCP Server and the query API but do not contractually guarantee any specific service level on the anonymous or free tiers. Customers on a paid plan may be entitled to a separate Service Level Agreement; in case of conflict between these Terms and an executed SLA, the SLA controls.
9.5 [Reserved]
This Section previously governed data contributed through the MCP Server. Those tools have been removed from the Services and there is no longer any way to contribute data, so the Section is deleted. It is marked Reserved rather than renumbered so that references to Sections 9.6 to 9.9 continue to resolve.
9.6 Reporting and Removing Data
If you believe data in the graph is inaccurate, unlawful, or should not be published, tell us at legal@whisper.security. Requests concerning personal data are handled under our Privacy Policy.
We review reports using a combination of automated checks and human review. Automated checks flag records that conflict with other sources or with our own enrichment; a member of our team reviews anything a check flags and every report we receive from a person. We will tell you the outcome of your report and our reasons, and you may ask us to reconsider a decision by replying to that response.
Feedback about the Services themselves, such as suggestions, feature requests, and bug reports, may be used by us without restriction and without obligation to you.
9.7 Suspension and Termination
We may suspend or terminate your access to the Services, with or without notice, if:
- you breach these Terms or the acceptable-use rules in Section 9.1;
- your account has overdue invoices that remain unpaid after the cure period in Section 11;
- your usage poses a risk to the integrity, availability, or security of the Services for other customers; or
- we receive a credible legal demand requiring suspension.
You may stop using the Services and close your account at any time from the console. On termination your license under Section 3 ends and you must stop using Graph Data, except that you may retain copies made in the ordinary course of your own security records. Sections 5, 6, 7, 8, 9.9, 11, 12, 13, 14, 16, 17, and 18 survive termination.
9.8 Vulnerability Disclosure
If you believe you have found a security vulnerability in the MCP Server or any other Whisper Security service, please report it to security@whisper.security. Our disclosure metadata is published at whisper.security/.well-known/security.txt and mirrored at mcp.whisper.security/.well-known/security.txt. We will acknowledge reports within five (5) business days. Good-faith security research conducted under this disclosure channel is not subject to suspension under these Terms, provided the research stays within the bounds of Section 9.1.
9.9 Export of Your Data
You can export the data associated with your account, including your account record and your usage history, at any time while your account is active, using the console or the query API. On request within 30 days of termination we will provide a machine-readable export of that data. This does not extend to Graph Data, which is licensed rather than yours.
10. AI Agents and Connected Clients
The Services are designed to be used by AI assistants and agents as well as by people. When you connect one:
- Acts of a Connected Client are your acts. You are responsible for every request made under your credentials, whether or not it was authorized, intended, automated, or initiated by a person.
- A Connected Client cannot change our data, but it acts as you. Every tool on the MCP Server is read-only, so a misbehaving client cannot corrupt the graph. It can still read anything your credentials reach, and every request it makes counts as yours — issue it a credential you are willing to be accountable for, and revoke that credential rather than trusting the client to stop.
- Output is probabilistic and is not advice. Output is produced by combining Graph Data with a model you control. It may be incomplete or wrong. It is not legal, professional, or security advice, and you must verify it, including against the evidence trail returned with each result, before acting on it.
- Treat returned data as untrusted input. Values in the graph, such as domain names, registration records, and text fields, originate from third parties and may be crafted to influence a model that reads them. Do not let a Connected Client execute instructions found in query results.
- No bulk extraction and no competing models. A Connected Client may not be used to systematically extract the graph or to train, fine-tune, or evaluate a competing model. Sections 9.1 and 3 apply equally to automated access.
11. Fees, Payment and Renewal
Free and anonymous tiers are provided at no charge and may be modified or withdrawn at any time. Paid plans are described on our pricing page and are agreed either through the console or in a written order form.
- Billing. Fees are billed in advance for the subscription period you select, and are non-refundable except where required by law or expressly stated in an executed order form. Payments are processed by Stripe; we do not receive or store your card details.
- Renewal. Subscriptions renew automatically for successive periods of the same length unless you cancel before the end of the current period. You can cancel at any time from the console, and cancellation takes effect at the end of the period you have paid for.
- Price changes. We may change our prices for a renewal period on at least 30 days' notice before that period begins. If you do not accept a change, your remedy is to cancel before it takes effect.
- Taxes. Fees are exclusive of VAT and any other applicable taxes, which are added where required. Where you are established in the EU outside the Netherlands and provide a valid VAT identification number, the reverse charge applies.
- Non-payment. If an invoice remains unpaid we will notify you and allow fourteen (14) days to cure. After that period we may suspend the account under Section 9.7. Statutory commercial interest applies to overdue amounts.
12. Your Indemnity
You will defend, indemnify, and hold harmless viaGraph and its officers, employees, and suppliers against any third-party claim, and any resulting loss, liability, damage, cost, or reasonable legal expense, arising from or relating to:
- your use of the Services or of Graph Data in breach of these Terms, in particular the acceptable-use rules in Section 9.1;
- an action you take against a third party in reliance on Graph Data or Output, including a takedown request, a block, an accusation, or a report to a registrar, hosting provider, or authority;
- the acts or omissions of a Connected Client operating under your credentials.
We will notify you promptly of any claim to which this Section applies, give you control of the defense and settlement (except that you may not settle in a way that admits our liability or imposes an obligation on us without our written consent), and cooperate at your expense.
13. Compliance, Sanctions and Export Control
You represent that you are not located in, organized under the laws of, or ordinarily resident in a country or territory subject to comprehensive economic sanctions administered by the European Union, the United Nations, the United Kingdom, or the United States, and that you are not a person or entity designated on any applicable sanctions or restricted-party list.
You will not make the Services, Graph Data, or Output available to any such person, entity, or territory, and you will comply with all applicable export-control, sanctions, and anti-corruption laws in your use of them. We may suspend or terminate access under Section 9.7 where we reasonably believe this Section has been breached.
14. Data Protection
Each party will comply with the data-protection law applicable to it. Our processing of personal data in connection with the Services is described in our Privacy Policy, which forms part of these Terms.
In respect of the account, usage, and audit data described in that Policy, we act as an independent controller rather than as your processor: we determine why and how that data is processed, in order to run, secure, and bill the Services. Graph Data is likewise our own dataset, not data processed on your behalf.
Where a particular engagement does require us to process personal data on your behalf, our data processing agreement applies and is available on request from legal@whisper.security. Do not send us personal data you do not need to send: in particular, the free-text fields of a data-quality report are for technical descriptions, not for customer records.
15. Beta and Preview Features
We may make features available as alpha, beta, preview, or otherwise clearly identified as not generally available. Those features are provided as is and as available, may be changed or withdrawn at any time without notice, are excluded from any availability target or Service Level Agreement, and are not covered by any warranty. Where a beta feature carries additional terms, those terms control for that feature.
16. General
- Force majeure. Neither party is liable for a delay or failure to perform caused by an event beyond its reasonable control, including an act of war or terrorism, civil unrest, natural disaster, epidemic, industrial action, failure of a public telecommunications network, or a large-scale internet outage or attack. This does not excuse an obligation to pay amounts already due.
- Notices. We give notice to you by email to the address on your account or by a notice inside the console; you give notice to us at legal@whisper.security. Notice is deemed given on the next business day after it is sent.
- Entire agreement. These Terms, together with the Privacy Policy and any executed order form or Service Level Agreement, are the entire agreement between the parties on their subject matter and supersede any prior understanding. Nothing in this clause limits liability for fraud or fraudulent misrepresentation.
- No third-party beneficiaries. These Terms confer no rights on anyone who is not a party to them.
- Independent parties. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.
- Publicity. Neither party may use the other's name or marks in publicity without prior written consent, except that we may list you as a customer where you have agreed in writing.
17. Modifications
viaGraph may revise these Terms from time to time. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by direct notice to account holders. By continuing to use the Services after revisions take effect, you agree to be bound by the then-current version of these Terms. If you do not accept a revision, your remedy is to stop using the Services and close your account.
18. Governing Law
These Terms are governed by and construed in accordance with the laws of the Netherlands, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods. You irrevocably submit to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands, in respect of any dispute arising out of or in connection with these Terms.
If any provision of these Terms is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable and the remaining provisions will continue in full force. Our failure to enforce a provision is not a waiver of it. You may not assign these Terms without our written consent; we may assign them to a successor in connection with a merger, acquisition, or sale of assets.
Contact Information
Company Name: viaGraph B.V.
Address: Keizersgracht 520 H, 1017 EK, Amsterdam, Netherlands
VAT Number: NL867322433B01
KVK Number: 95822429
DUNS Number: 965751230
General questions: legal@whisper.security
Privacy questions: privacy@whisper.security
Security disclosures: security@whisper.security