Terms of Service
Last updated: July 26, 2026
Read section 4 before you run anything.
Sinon sends deliberately deceptive emails to real people on your instruction. You are responsible for having the authority to do that. Section 4 sets out what you are promising us when you launch a campaign.
1. Who these terms are between
These Terms of Service (the “Terms”) are an agreement between Sinon Security, operator of the Sinonplatform (“Sinon”, “we”, “us”), and the organization that opens an account (“you”, “Customer”).
By creating an account, subscribing to a paid plan, or using the service, you agree to these Terms. If you are agreeing on behalf of a company, you confirm you have authority to bind it. If you do not agree, do not use the service.
These Terms incorporate our Authorized Use Policy, Privacy Policy, Refund & Cancellation Policy, and Data Processing Agreement. Where the DPA conflicts with these Terms in respect of personal data, the DPA governs.
2. What the service is
Sinon is a security-awareness platform. It lets an organization design and send simulated phishing emails to its own personnel, measure who opened, clicked, submitted credentials or reported the message, deliver training at the moment someone fails, and produce reports and evidence from those results.
Simulated credential submissions are never stored. The platform records only that a submission occurred and when, and redirects the person to a teaching page.
3. Accounts
You are responsible for the accuracy of your account details, for keeping credentials secure, and for all activity under your account. Tell us promptly at [email protected] if you believe an account has been compromised. You must be at least 18 and using the service for a business purpose.
4. Authorization to test — your responsibilities
This is the most important clause in these Terms. Every time you launch a campaign, you represent and warrant to us that:
- You are authorized by your organization to conduct simulated phishing against the recipients you have loaded, and that authorization comes from someone with the standing to give it.
- The recipients are your own personnel, contractors, or people your organization is otherwise entitled to test — never members of the public, customers, or another company's staff without their organization's written authorization.
- You have a lawful basis for processing recipients' personal data, and you have met any employment-law, notification, works council, or employee-representative consultation requirements that apply where those people are employed. Some jurisdictions require prior consultation before monitoring or testing staff.
- You own or control any sending domain or mailbox you connect, and any domain or brand you imitate in a simulation, or you have permission to use it.
- Your use complies with the Authorized Use Policy and with all applicable law.
You are the controller of the personal data you load and process through the platform. We act as your processor, on your instructions, as described in the DPA.
We do not verify your authorization and are not in a position to. We rely on the warranties above.
5. Prohibited use
You must not use Sinonto conduct real phishing, harvest genuine credentials, target people outside your own organization without authorization, harass or single out individuals, test systems you do not own, or circumvent the platform's safeguards — including the protections that prevent tracking links being edited or replaced. The Authorized Use Policy sets this out in full and forms part of these Terms.
We may suspend an account immediately, without notice, where we reasonably believe it is being used in breach of this section.
6. Plans, fees and billing
- Sentinel is free and covers up to 10 employees. Paid plans are a flat monthly or annual fee that includes a stated employee allowance. Annual plans are billed once for twelve months at a 30% discount.
- We sell through Paddle, our merchant of record. Paddle handles payment, invoicing, sales tax and VAT, and processes refunds. Paddle's buyer terms apply to the transaction alongside these Terms.
- Subscriptions renew automatically at the end of each period until cancelled. You can cancel at any time from your billing settings; cancellation takes effect at the end of the current period.
- Refunds are governed by our Refund & Cancellation Policy, including the 30-day service guarantee.
- We may change prices. Changes take effect at your next renewal, and we will give you reasonable notice beforehand. Your existing term is not repriced mid-period.
- If payment fails, we may suspend paid features until it is resolved.
7. Plan limits
Each plan includes an employee allowance and a monthly quota for AI-generated templates. The platform enforces these. We may decline to process a downgrade that would leave your directory over the target plan's allowance. Fair-use limits may apply to sending volume where usage threatens platform stability or the deliverability of other customers' mail.
8. AI-generated content
The platform can generate simulation content, teaching pages and report drafts using third-party AI models. That output is produced automatically and may be inaccurate, generic, or unsuitable for your context.
You are responsible for reviewing generated content before you send it. You decide what goes out under your organization's name. We do not warrant that generated content is accurate, original, or fit for a particular purpose.
9. Reports and compliance evidence
The platform produces reports and framework-mapped evidence packs referencing standards such as ISO 27001, SOC 2, NIST CSF, PCI DSS, HIPAA and GDPR. These are a record of the awareness activity you actually carried out on the platform, presented against the clauses those standards contain.
- They are not a certification, attestation, audit opinion, or legal advice, and we are not a certification body or auditor.
- They cover only the security-awareness portion of those frameworks. Each pack states which controls it does not evidence and what an assessor will require from other sources.
- We do not warrant that any assessor, auditor, regulator or certification body will accept them, nor that using Sinon will result in you passing an audit or achieving certification.
- Packs are generated from live records at the time you export them. You are responsible for retaining exported evidence for as long as your obligations require.
Where your plan includes Expert Advisory, guidance given through it is practitioner opinion offered in good faith. It is not legal, regulatory, or audit advice, and does not create a professional advisory relationship.
10. Availability and support
We aim to keep the service available and to fix faults promptly, but we do not offer a contractual uptime commitment unless we have agreed one with you in writing. The service may be unavailable during maintenance or because of third-party failures. Email delivery depends on providers and receiving mail systems we do not control.
Support is provided by email at [email protected], at the level described for your plan.
11. Third-party services
The platform depends on third parties — including hosting, AI, email delivery, and payment providers — listed in our Privacy Policy and DPA. If you connect your own mailbox or sending infrastructure, your use of that provider remains governed by your agreement with them.
12. Intellectual property
We own the platform, its software, and its ready-made template library. You receive a non-exclusive, non-transferable right to use the service during your subscription. You may not copy, resell, reverse engineer, or make the platform available to third parties as a service.
You own your data — your employee directory, campaign results, custom templates, and exported reports. As between you and us, they are yours. You grant us the limited licence needed to host and process them in order to provide the service. We may use aggregated, anonymized statistics that do not identify you or any individual to improve the product.
13. Confidentiality
Each party will keep the other's non-public information confidential and use it only to perform under these Terms. This does not apply to information that is public through no fault of the recipient, independently developed, or required to be disclosed by law.
14. Disclaimer of warranties
To the fullest extent permitted by law, the service is provided “as is” and “as available”, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement.
In particular, we do not warrant that using Sinon will prevent a real phishing attack, eliminate human risk, or satisfy any legal, regulatory or contractual obligation you are subject to. Security awareness reduces risk; it does not remove it.
15. Limitation of liability
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenue, data, goodwill, or business opportunity, however caused.
Our total aggregate liability arising out of or relating to these Terms is limited to the amount you paid us in the twelve months preceding the event giving rise to the claim. Where you are on a free plan, that amount is zero and our liability is limited accordingly.
Nothing in these Terms excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.
16. Indemnity
You will indemnify and hold us harmless against claims, losses, damages, liabilities and reasonable legal costs arising from: your breach of section 4 or section 5; a claim by one of your personnel, a contractor, a regulator, or a third party arising from a campaign you ran; your use of a domain, brand or mailbox you were not entitled to use; or content you chose to send.
17. Suspension and termination
You may stop using the service at any time and cancel from your billing settings. We may suspend or terminate an account that breaches these Terms, that we reasonably believe is being used unlawfully or to cause harm, or where fees remain unpaid.
On termination, your right to use the service ends. Export any reports or evidence you need beforehand — exporting is not included on the free plan, and we are not obliged to retain your data indefinitely after termination. Deletion and return of personal data are governed by the DPA. Sections 12 to 16 survive termination.
18. Changes to the service and these Terms
We continue to develop the platform and may add, change or withdraw features. Where a change materially reduces core functionality of a plan you are paying for, we will give you reasonable notice and you may cancel and receive a pro-rata refund of the unused period.
We may update these Terms. We will revise the “Last updated” date and, for material changes, notify account holders. Continued use after a change takes effect means you accept the revised Terms.
19. General
These Terms, together with the policies incorporated in section 1, are the entire agreement between us on this subject. If any provision is held unenforceable, the rest remains in force. Failure to enforce a provision is not a waiver of it. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition or sale of assets. Neither party is liable for failure to perform due to events beyond its reasonable control.
20. Governing law and disputes
These Terms are governed by the laws of the jurisdiction in which Sinon Security is established, and the parties submit to the courts of that jurisdiction. If you are a consumer, this does not deprive you of the protection of mandatory rules of the country in which you live.
Before starting any formal proceedings, please contact us at [email protected]. Most disputes are billing or access issues we can resolve within a couple of days.
21. Contact
Questions about these Terms: [email protected]. These Terms are offered by Sinon Security, operator of the Sinon platform.