Legal
Terms of Service
Please read these Terms of Service carefully before using Terra Ops. By creating an account or using the platform, you agree to be bound by these terms.
Last updated: 13 August 2026 · Effective immediatelyReview-readyTrust artifact
On this page
1. Acceptance of Terms2. Description of Service3. Account Registration and Security4. AWS Credentials and Authorised Use5. Acceptable Use Policy6. Intellectual Property7. Data and Privacy8. Service Availability and SLA9. Disclaimer of Warranties10. Limitation of Liability11. Indemnification12. Termination13. Governing Law and Disputes14. Changes to Terms15. Contact
MetadataScan-friendly review cues
Authorised use
The document explicitly restricts scans to AWS accounts the user owns or is authorised to assess.
Access posture
Terms state that Terra Ops performs read-only AWS operations and does not create, modify, or delete customer resources.
Account security
TOTP-based 2FA, secure credential handling responsibilities, and account misuse expectations are called out early.
Operational boundaries
Availability, warranties, acceptable use, and liability boundaries are grouped into scannable sections for reviewers.
Trust highlightsWhat reviewers usually look for first
✓The terms make explicit that only authorised AWS accounts may be connected and assessed.
✓Read-only platform behavior is documented as a contractual boundary, not just a product preference.
✓Security posture expectations for user accounts and AWS credentials are surfaced in dedicated sections.
✓Reviewers can quickly find acceptable use, warranty limits, termination, and dispute language from the summary layer.
1. Acceptance of Terms
These Terms of Service ("Terms") constitute a legally binding agreement between you ("User", "you") and the Terra Ops platform ("Terra Ops", "we", "us"), maintained by Sumit Bhadu — CKA, AZ-104, AZ-305 & MLOps certified (GitHub: sumit-bhadu).
By accessing or using any part of Terra Ops, you confirm that:
• You are at least 18 years of age
• You have the authority to enter into these Terms on behalf of yourself or your organisation
• You will comply with all applicable laws and regulations
• You have the authorisation to connect and scan the AWS accounts you provide to the platform
By accessing or using any part of Terra Ops, you confirm that:
• You are at least 18 years of age
• You have the authority to enter into these Terms on behalf of yourself or your organisation
• You will comply with all applicable laws and regulations
• You have the authorisation to connect and scan the AWS accounts you provide to the platform
2. Description of Service
Terra Ops is a cloud security assessment platform that provides:
• Risk Intelligence: Automated security checks across AWS services using the open-source Prowler framework
• Compliance Reporting: Automated assessment against CIS, NIST 800-53, PCI DSS, SOC 2, ISO 27001, HIPAA, and GDPR frameworks
• Threat Intelligence: MITRE ATT&CK-aligned threat analysis of your AWS environment
• CloudCanvas: Automated AWS architecture diagram generation with SVG, PNG, and Draw.io exports
• Cost Analyzer: AWS cost optimisation analysis and unused resource identification
• CloudFit: Workload rightsizing recommendations based on CloudWatch utilisation metrics
• IaC Generator: Infrastructure-as-Code generation for Terraform
• Reverse Import: Import existing AWS infrastructure into Terraform templates
• Reports: Consolidated advisory reports aggregating findings across modules (PDF and DOCX)
The platform is provided on an "as is" and "as available" basis. We reserve the right to modify, suspend, or discontinue any feature at any time.
• Risk Intelligence: Automated security checks across AWS services using the open-source Prowler framework
• Compliance Reporting: Automated assessment against CIS, NIST 800-53, PCI DSS, SOC 2, ISO 27001, HIPAA, and GDPR frameworks
• Threat Intelligence: MITRE ATT&CK-aligned threat analysis of your AWS environment
• CloudCanvas: Automated AWS architecture diagram generation with SVG, PNG, and Draw.io exports
• Cost Analyzer: AWS cost optimisation analysis and unused resource identification
• CloudFit: Workload rightsizing recommendations based on CloudWatch utilisation metrics
• IaC Generator: Infrastructure-as-Code generation for Terraform
• Reverse Import: Import existing AWS infrastructure into Terraform templates
• Reports: Consolidated advisory reports aggregating findings across modules (PDF and DOCX)
The platform is provided on an "as is" and "as available" basis. We reserve the right to modify, suspend, or discontinue any feature at any time.
3. Account Registration and Security
3.1 Account Creation
You must provide a valid email address and create a secure password. All accounts require TOTP-based two-factor authentication, which must be configured during registration. You are responsible for maintaining the confidentiality of your credentials.
3.2 Account Security
You are solely responsible for:
• All activity that occurs under your account
• Keeping your password and TOTP secret secure
• Immediately notifying us of any unauthorised account access
• Ensuring your AWS IAM credentials are appropriately scoped
3.3 One Account Per User
You may not create multiple accounts for the same person. Accounts may not be shared between individuals without prior written consent.
3.4 Organization Membership
Accounts may belong to an organization — typically your employer. If yours does, the following apply for as long as you remain a member, and they qualify 3.2 above:
• The organization administers your access. An administrator of your organization can add and remove members, change a member's role, trigger a password reset for a member, and enable or disable individual product modules for a member. Removal from an organization ends your access to that organization's cloud accounts and their data.
• Cloud accounts and their data belong to the organization. When you connect a cloud account while a member, that account and everything produced from it — scans, findings, reports, diagrams — are the organization's, not yours personally, and remain with the organization if you leave. Cloud accounts you connected before joining are claimed by the organization when it is created, so that your existing history is not stranded.
• Your activity is visible to the organization. Administrators and managers of your organization can read a record of the actions you take in the platform, including refused attempts. What is recorded, who can read it, and how long it is kept are set out in section 2.5 of the Privacy Policy.
• Some results may need approval before you can export them. If your organization has approvals enabled, a scan result you produce must be signed off by a manager or an administrator of your organization before it can be downloaded or shared. The decision, who made it, when, and any remark they added are recorded.
• Responsibility is shared accordingly. You remain responsible for keeping your own credentials secure. The organization is responsible for what its members do with the cloud credentials it holds, and for the lawfulness of granting its administrators the visibility described above in the jurisdictions where its members work.
3.5 Platform Administration
Separately from your organization, Terra Ops as the platform operator may lock or remove an account, or remove an account from an organization, where it is necessary to protect the platform, its customers, or to comply with a legal obligation. Every such action is recorded with a stated reason. We do not use this to read the contents of your scans, findings or activity, and we cannot reset your password — that remains with you and with your organization's administrators.
Terra Ops is not a party to the relationship between you and your organization and does not adjudicate disputes between them. If you do not belong to an organization, none of 3.4 applies and your data is visible only to you.
You must provide a valid email address and create a secure password. All accounts require TOTP-based two-factor authentication, which must be configured during registration. You are responsible for maintaining the confidentiality of your credentials.
3.2 Account Security
You are solely responsible for:
• All activity that occurs under your account
• Keeping your password and TOTP secret secure
• Immediately notifying us of any unauthorised account access
• Ensuring your AWS IAM credentials are appropriately scoped
3.3 One Account Per User
You may not create multiple accounts for the same person. Accounts may not be shared between individuals without prior written consent.
3.4 Organization Membership
Accounts may belong to an organization — typically your employer. If yours does, the following apply for as long as you remain a member, and they qualify 3.2 above:
• The organization administers your access. An administrator of your organization can add and remove members, change a member's role, trigger a password reset for a member, and enable or disable individual product modules for a member. Removal from an organization ends your access to that organization's cloud accounts and their data.
• Cloud accounts and their data belong to the organization. When you connect a cloud account while a member, that account and everything produced from it — scans, findings, reports, diagrams — are the organization's, not yours personally, and remain with the organization if you leave. Cloud accounts you connected before joining are claimed by the organization when it is created, so that your existing history is not stranded.
• Your activity is visible to the organization. Administrators and managers of your organization can read a record of the actions you take in the platform, including refused attempts. What is recorded, who can read it, and how long it is kept are set out in section 2.5 of the Privacy Policy.
• Some results may need approval before you can export them. If your organization has approvals enabled, a scan result you produce must be signed off by a manager or an administrator of your organization before it can be downloaded or shared. The decision, who made it, when, and any remark they added are recorded.
• Responsibility is shared accordingly. You remain responsible for keeping your own credentials secure. The organization is responsible for what its members do with the cloud credentials it holds, and for the lawfulness of granting its administrators the visibility described above in the jurisdictions where its members work.
3.5 Platform Administration
Separately from your organization, Terra Ops as the platform operator may lock or remove an account, or remove an account from an organization, where it is necessary to protect the platform, its customers, or to comply with a legal obligation. Every such action is recorded with a stated reason. We do not use this to read the contents of your scans, findings or activity, and we cannot reset your password — that remains with you and with your organization's administrators.
Terra Ops is not a party to the relationship between you and your organization and does not adjudicate disputes between them. If you do not belong to an organization, none of 3.4 applies and your data is visible only to you.
4. AWS Credentials and Authorised Use
4.1 Your Responsibility
By providing AWS credentials or IAM role ARNs to Terra Ops, you represent and warrant that:
• You are authorised to grant read-only access to the AWS accounts in question
• You have the legal right to perform security assessments on those accounts
• You will comply with AWS Terms of Service and all applicable laws
4.2 Read-Only Access
Terra Ops performs read-only operations against your AWS account. We never create, modify, or delete AWS resources. The minimum required IAM permissions are documented in our repository.
4.3 Prohibited Use
You may not use Terra Ops to scan AWS accounts that you do not own or have explicit authorisation to assess. Unauthorised scanning constitutes a violation of these Terms and may violate applicable computer crime laws.
By providing AWS credentials or IAM role ARNs to Terra Ops, you represent and warrant that:
• You are authorised to grant read-only access to the AWS accounts in question
• You have the legal right to perform security assessments on those accounts
• You will comply with AWS Terms of Service and all applicable laws
4.2 Read-Only Access
Terra Ops performs read-only operations against your AWS account. We never create, modify, or delete AWS resources. The minimum required IAM permissions are documented in our repository.
4.3 Prohibited Use
You may not use Terra Ops to scan AWS accounts that you do not own or have explicit authorisation to assess. Unauthorised scanning constitutes a violation of these Terms and may violate applicable computer crime laws.
5. Acceptable Use Policy
You agree NOT to use Terra Ops to:
• Scan AWS accounts without explicit authorisation from the account owner
• Circumvent, disable, or interfere with security features of the platform
• Attempt to gain unauthorised access to other users' data or accounts
• Upload, transmit, or store any content that is illegal, harmful, or violates third-party rights
• Use the platform for any competitive intelligence against Terra Ops
• Perform automated requests that overload the platform infrastructure
• Attempt to reverse engineer, decompile, or extract source code from the platform
• Use the platform in violation of any applicable law or regulation
Violation of this Acceptable Use Policy may result in immediate account suspension or termination.
• Scan AWS accounts without explicit authorisation from the account owner
• Circumvent, disable, or interfere with security features of the platform
• Attempt to gain unauthorised access to other users' data or accounts
• Upload, transmit, or store any content that is illegal, harmful, or violates third-party rights
• Use the platform for any competitive intelligence against Terra Ops
• Perform automated requests that overload the platform infrastructure
• Attempt to reverse engineer, decompile, or extract source code from the platform
• Use the platform in violation of any applicable law or regulation
Violation of this Acceptable Use Policy may result in immediate account suspension or termination.
6. Intellectual Property
6.1 Platform
The Terra Ops platform, including its code, design, and documentation, is proprietary software. The underlying security check engine is based on the open-source Prowler framework (Apache 2.0 licence).
6.2 Your Data
You retain all ownership rights to your scan results, reports, and AWS account data. By using Terra Ops, you grant us a limited licence to process and store this data solely for the purpose of providing the service.
6.3 Feedback
If you submit feedback, suggestions, or bug reports, you grant us an irrevocable, perpetual, royalty-free licence to use and incorporate that feedback into the platform.
The Terra Ops platform, including its code, design, and documentation, is proprietary software. The underlying security check engine is based on the open-source Prowler framework (Apache 2.0 licence).
6.2 Your Data
You retain all ownership rights to your scan results, reports, and AWS account data. By using Terra Ops, you grant us a limited licence to process and store this data solely for the purpose of providing the service.
6.3 Feedback
If you submit feedback, suggestions, or bug reports, you grant us an irrevocable, perpetual, royalty-free licence to use and incorporate that feedback into the platform.
7. Data and Privacy
Your use of Terra Ops is also governed by our Privacy Policy, which is incorporated into these Terms by reference. By accepting these Terms, you acknowledge that you have read and understood our Privacy Policy.
8. Service Availability and SLA
Terra Ops is provided on a best-effort basis. We do not guarantee:
• 100% uptime or uninterrupted access to the service
• That scan results will be error-free or complete
• That the platform will be free from security vulnerabilities
We will use commercially reasonable efforts to maintain platform availability and notify users of planned maintenance windows. Unplanned outages will be communicated as soon as practicable.
• 100% uptime or uninterrupted access to the service
• That scan results will be error-free or complete
• That the platform will be free from security vulnerabilities
We will use commercially reasonable efforts to maintain platform availability and notify users of planned maintenance windows. Unplanned outages will be communicated as soon as practicable.
9. Disclaimer of Warranties
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, TERRA OPS IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. WE EXPRESSLY DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO:
• Any implied warranties of merchantability, fitness for a particular purpose, or non-infringement
• Any warranty that the platform will meet your requirements
• Any warranty that security scan results are complete, accurate, or current
Security assessments provided by Terra Ops are indicative only. They should not be relied upon as the sole basis for security decisions. You should engage qualified security professionals to review your security posture.
• Any implied warranties of merchantability, fitness for a particular purpose, or non-infringement
• Any warranty that the platform will meet your requirements
• Any warranty that security scan results are complete, accurate, or current
Security assessments provided by Terra Ops are indicative only. They should not be relied upon as the sole basis for security decisions. You should engage qualified security professionals to review your security posture.
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, TERRA OPS AND ITS MAINTAINERS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO:
• Loss of profits, revenue, or data
• Business interruption
• Security breaches resulting from reliance on platform findings
• Unauthorised access to your AWS accounts
In no event shall our total liability exceed the amount you have paid to us in the twelve months preceding the claim.
• Loss of profits, revenue, or data
• Business interruption
• Security breaches resulting from reliance on platform findings
• Unauthorised access to your AWS accounts
In no event shall our total liability exceed the amount you have paid to us in the twelve months preceding the claim.
11. Indemnification
You agree to indemnify, defend, and hold harmless Terra Ops and its maintainers from any claims, damages, obligations, losses, liabilities, costs, or expenses arising from:
• Your use or misuse of the platform
• Your violation of these Terms
• Your violation of any applicable law
• Your scanning of AWS accounts without proper authorisation
• Any claim by a third party arising from your actions on the platform
• Your use or misuse of the platform
• Your violation of these Terms
• Your violation of any applicable law
• Your scanning of AWS accounts without proper authorisation
• Any claim by a third party arising from your actions on the platform
12. Termination
12.1 By You
You may terminate your account at any time by deleting it from the platform settings. Upon termination, your data will be purged within 30 days.
12.2 By Us
We reserve the right to suspend or terminate your account immediately, without notice, if we determine you have violated these Terms, engaged in fraudulent activity, or pose a security risk to the platform or other users.
12.3 Effect of Termination
Upon termination, your right to use the platform ceases immediately. Provisions of these Terms that by their nature should survive termination shall do so, including intellectual property, disclaimers, indemnification, and limitations of liability.
You may terminate your account at any time by deleting it from the platform settings. Upon termination, your data will be purged within 30 days.
12.2 By Us
We reserve the right to suspend or terminate your account immediately, without notice, if we determine you have violated these Terms, engaged in fraudulent activity, or pose a security risk to the platform or other users.
12.3 Effect of Termination
Upon termination, your right to use the platform ceases immediately. Provisions of these Terms that by their nature should survive termination shall do so, including intellectual property, disclaimers, indemnification, and limitations of liability.
13. Governing Law and Disputes
These Terms shall be governed by and construed in accordance with applicable laws. Any disputes arising from these Terms or your use of Terra Ops shall be resolved through good-faith negotiation. If negotiation fails, disputes shall be resolved through binding arbitration.
14. Changes to Terms
We reserve the right to modify these Terms at any time. Material changes will be communicated through the platform interface with at least 14 days' notice. Your continued use of Terra Ops after changes take effect constitutes acceptance of the revised Terms. If you do not agree to the updated Terms, you must stop using the platform.
15. Contact
For questions about these Terms, please contact us:
• GitHub: github.com/sumit-bhadu
• Project Repository: github.com/sumit-bhadu/terra-ops
We aim to respond to all legal inquiries within 5 business days.
• GitHub: github.com/sumit-bhadu
• Project Repository: github.com/sumit-bhadu/terra-ops
We aim to respond to all legal inquiries within 5 business days.