Licensing
How SecuryxAI platform access is licensed, what you can do with it, and the open-source components that power it.
1. Platform Subscription Licence
SecuryxAI grants you a limited, non-exclusive, non-transferable, revocable right to access and use the SecuryxAI platform (the “Service”) during the term of your active subscription, subject to these licensing terms and our Terms of Service.
This licence is granted to your organisation as a whole, not to individual employees. You may allow employees and contractors acting on your behalf to use the Service, subject to the user seat limits of your subscription tier.
What You May Do
- Access and use the Service for your own internal GRC and compliance management purposes
- Export your data and compliance artefacts in supported formats
- Grant access to auditors and external reviewers within your subscription’s user limit
- Publish a Trust Center powered by SecuryxAI to your customers and prospects
- Integrate with third-party tools via supported APIs and webhooks
What You May Not Do
- Sub-license, resell, or provide the Service as a bureau or managed service to third parties
- Reverse engineer, decompile, or attempt to extract the source code of the platform
- Circumvent, disable, or interfere with security features or access controls
- Use the Service in a manner that exceeds your subscription tier’s usage limits
- Copy or replicate the platform’s design, user interface, or proprietary features in a competing product
2. User Licensing
User seats are defined as named accounts that can authenticate to the platform. Shared login credentials are not permitted.
Role-Based Access
SecuryxAI uses role-based access control with six distinct roles:
- Owner: Full platform access, billing, and member management. One per organisation.
- Admin: Full platform access excluding billing. Unlimited on Enterprise; 2 on Professional.
- Contributor: Can update control status, upload evidence, and draft policies.
- Reviewer: Can approve evidence, policies, and questionnaire answers.
- Auditor: External auditor role with read access to assigned audit projects.
- Viewer: Read-only access to controls and reports. Does not count toward seat limits on most plans.
Auditor accounts granted to external auditors conducting a formal audit engagement are provided at no additional charge up to the limit defined in your subscription plan.
3. Trial & Free Tier Licensing
Starter Plan (Free)
The Starter plan is provided free of charge with limited features and usage quotas. It is intended for evaluation and early-stage use. Starter plan users agree to the same terms as paid subscribers.
Trial Accounts
When a free trial programme is available, trial accounts include:
- 14-day access to Professional plan features
- Up to 5 user seats
- Full data export at any time during and after trial
- Automatic suspension (not deletion) at trial end — 30-day grace period for upgrade or export
4. Framework Content Licensing
SecuryxAI includes content derived from the following public frameworks. Each is used under its own licence terms:
- Secure Controls Framework (SCF): Used under the SCF non-commercial/research licence. SecuryxAI is not a licensed SCF distributor. Control content is used for internal mapping only.
- ISO 42001 / ISO 27001: Clause descriptions are referenced with attribution to ISO. Full standard text is not included — a valid ISO licence is required to access the full standard.
- NIST AI RMF / NIST CSF: NIST publications are in the public domain. SecuryxAI uses and references NIST framework content freely.
- EU AI Act:EU legislative text is published under the EU’s open data policy and is freely reusable with attribution.
SecuryxAI is not affiliated with, endorsed by, or a licensed partner of any standards body, including ISO, NIST, or the European Commission.
5. Open-Source Software Attribution
SecuryxAI is built using open-source software. We are grateful to the open-source community. Key components include:
- Next.js — MIT Licence (Vercel, Inc.)
- React — MIT Licence (Meta Platforms, Inc.)
- Prisma — Apache 2.0 Licence (Prisma Data, Inc.)
- NextAuth.js — ISC Licence (Balázs Orbán)
- Tailwind CSS — MIT Licence (Tailwind Labs, Inc.)
- ExcelJS / SheetJS — MIT / Apache 2.0 Licence
- @react-pdf/renderer — MIT Licence
A complete list of open-source dependencies and their licences is available in our package.json. Requests for specific attribution information: legal@securyxai.com
6. Intellectual Property
SecuryxAI retains all rights to the platform software, design, trademarks, and proprietary content. “SecuryxAI” and the SecuryxAI logo are trademarks of SecuryxAI. You may not use our trademarks without prior written permission.
7. Contact
Licensing questions: legal@securyxai.com