DriftAlarm
How It WorksGuidesPricing

Terms of Service

Last Updated: March 2026

1. Acceptance of Terms

By accessing or using DriftAlarm ("the Service"), you agree to be bound by these Terms of Service, our Privacy Policy, our Acceptable Use Policy, and (if applicable) our Data Processing Agreement. If you are accepting on behalf of an organization, you represent that you have the authority to bind that organization to these Terms. You must be at least 18 years old to use the Service.

2. Description of Service

DriftAlarm is an AI-enabled External Attack Surface Management (EASM) platform. The Service provides:

  • Fast Scan — rapid security assessment of domains and IP addresses
  • Deep Scan — comprehensive vulnerability analysis including DAST testing, SSL/TLS auditing, and web server analysis (Standard+ tiers)
  • Asset Monitoring — continuous automated monitoring of domains and IP ranges with inventory tracking
  • Drift Detection — automatic detection of configuration changes across ports, subdomains, certificates, DNS, and findings with customizable alarm rules
  • AI-Powered Analysis — AI-generated remediation guidance, risk scoring, executive reports, and technology analysis powered by Anthropic's Claude models
  • Notification & Alerting — email, Slack webhook, and generic webhook notifications for drift events and scan results
  • Interactive Security Tools — DNS, SSL, port scanning, and WHOIS/RDAP lookup tools
  • API Access — programmatic access via API keys for integration with your security workflows (Standard+ tiers)
  • Scheduled Scanning — automated recurring scans on configurable schedules
  • Reporting — weekly and monthly trend reports with AI analysis

3. Account Registration and Security

Accounts are created through Microsoft Azure AD External ID (CIAM). You are responsible for maintaining the security of your account. You must promptly notify us of any unauthorized access. Account sharing is prohibited.

4. Subscription Tiers and Payment

  • Trial: $0 for 30 days, full Standard-tier capabilities, 1 domain + 1 IP, automatically expires
  • Standard: $99/month or $999/year, 1 domain + 1 IP, API access (5 keys, 60 req/min)
  • Pro: $389/month, 5 domains + 10 IP ranges, advanced features (Deep Security, Drift Analytics, Inventory, Validate), API access (10 keys, 300 req/min)
  • Enterprise: Custom pricing, contact sales@driftalarm.com

All fees are non-refundable except as required by law. We reserve the right to modify pricing with 30 days' email notice. Tier feature availability is subject to current platform capabilities. All subscription actions are processed through sales@driftalarm.com.

5. Scanning Authorization

You represent and warrant that you have authorization to scan all targets (domains, IP addresses, IP ranges) submitted to DriftAlarm. Authorization means: (a) you own the asset, OR (b) you have explicit written permission from the asset owner.

DriftAlarm performs active reconnaissance including DNS enumeration, port scanning, web crawling, vulnerability detection, SSL/TLS testing, and technology fingerprinting. You are solely responsible for ensuring your scanning activities comply with all applicable laws.

DriftAlarm is not responsible for any consequences of scanning unauthorized targets. We reserve the right to suspend scanning for any target if we receive a complaint or have reason to believe scanning is unauthorized.

6. AI-Powered Analysis

DriftAlarm uses Anthropic's Claude AI models to provide:

  • Remediation guidance for discovered vulnerabilities
  • Risk scoring and analysis
  • Executive security reports
  • Technology stack analysis

AI-generated content is advisory only and should not be treated as professional security advice. You should verify all AI recommendations before implementing changes. Scan data (findings, technology data, configurations) is sent to Anthropic's API for processing — see our Privacy Policy for details. Anthropic's commercial API does not use customer data for model training.

7. API Access

API keys are available on Standard+ tiers. API keys use a da_live_ prefix and are SHA-256 hashed for storage — the full key is shown only once at creation. You are responsible for the security of your API keys.

API key usage is subject to per-tier rate limits (Standard: 60/min, Pro: 300/min, Enterprise: 600/min). API keys cannot be used for key management operations (CIAM authentication required). DriftAlarm may revoke API keys that are compromised, abused, or used in violation of these Terms. See our Acceptable Use Policy for API usage guidelines.

8. Drift Detection and Alerting

DriftAlarm automatically detects changes to your attack surface by comparing scan results against established baselines. 34 built-in alarm rules across 7 categories monitor for security-relevant changes. Custom alarm rules are available (Trial: 5, Standard: 10, Pro: 25, Enterprise: unlimited).

Notifications are delivered via your configured channels (email, Slack, webhooks). Notification delivery is provided on a best-effort basis — DriftAlarm does not guarantee delivery of all alerts. You are responsible for configuring and maintaining your notification channels.

9. Data Retention

  • Scan result files: stored in Azure Blob Storage with lifecycle policy (30 days active → 30 days Cool tier → deletion)
  • Asset findings: retained while asset is active, deleted when asset is removed
  • Drift events and baselines: retained while asset is active
  • User account data: retained while account is active, deleted within 90 days of account closure
  • Weekly/monthly reports: retained per blob lifecycle policy

See our Privacy Policy for complete data handling details.

10. Third-Party Services

DriftAlarm integrates with the following third-party services:

  • Microsoft Azure — cloud hosting, storage, authentication (East US region)
  • Anthropic — AI-powered analysis via Claude API (commercial terms, no training on customer data)
  • GreyNoise — IP reputation and noise classification (24-hour cache)
  • Certificate Transparency Logs — subdomain discovery via crt.sh
  • RDAP/WHOIS — domain registration data lookup
  • Microsoft Graph API — email delivery for notifications and onboarding

Each service is subject to its own terms and privacy policies. DriftAlarm is not responsible for the availability or accuracy of third-party service data.

11. Intellectual Property

The Service, including its software, design, user interface, and documentation, is owned by DriftAlarm and protected by intellectual property laws. You retain ownership of all data you submit for scanning. Scan results, findings, and analysis generated by the Service are licensed to you for your internal use only. You may not reverse engineer, decompile, or create derivative works from the Service.

12. Limitation of Liability

THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. DRIFTALARM.AI SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES. OUR TOTAL LIABILITY SHALL NOT EXCEED THE AMOUNT PAID FOR THE SERVICE IN THE PRECEDING 12 MONTHS.

DRIFTALARM.AI IS NOT LIABLE FOR: (a) vulnerabilities missed by scanning, (b) false positives or false negatives, (c) consequences of acting on AI recommendations, (d) unauthorized access to your targets resulting from scanning, (e) third-party service interruptions.

13. Indemnification

You agree to indemnify and hold harmless DriftAlarm from any claims, damages, losses, or expenses arising from:

  • Your use of the Service
  • Unauthorized scanning activities
  • Violation of these Terms or the Acceptable Use Policy
  • Your negligence or willful misconduct

14. Termination

We may suspend or terminate your access for violation of these Terms or the Acceptable Use Policy. Upon termination: access is revoked immediately, data is deleted per retention policy (within 90 days). You may cancel your subscription by contacting sales@driftalarm.com.

Sections that survive termination: Limitation of Liability, Indemnification, Governing Law.

15. Changes to Terms

We may update these Terms from time to time. Material changes will be communicated via email to your registered address and posted on the Service. Continued use after changes constitutes acceptance. We will provide at least 30 days' notice for material changes.

16. Governing Law

These Terms are governed by the laws of the State of Texas, United States, without regard to conflict of law principles. Any disputes shall be resolved in the courts located in Texas. You agree to submit to the personal jurisdiction of such courts.

17. Contact

For questions about these Terms, contact us at support@driftalarm.com. For sales inquiries, contact sales@driftalarm.com.

18. Related Policies

  • Privacy Policy
  • Acceptable Use Policy
  • Data Processing Agreement

Terms of Service|Privacy Policy|Acceptable Use|DPA