Terms of service
Last updated: 16 September 2026 路 Business customers only 路 Legal notice and privacy policy
Cemply is sold to businesses, not to consumers. By subscribing you confirm that you act for the purposes of your trade or profession.
1. Parties and scope
These terms govern the supply of the Cemply service by Arthur Denis, publisher of cemply.io (company incorporation in progress in France), referred to as "Cemply", to any business subscriber, referred to as "the Customer".
They form the sole basis of the commercial relationship and prevail over the Customer's own purchase conditions, unless expressly agreed otherwise in writing. Creating an account or subscribing to a plan constitutes acceptance without reservation.
2. Definitions
Service: the Cemply software available at cemply.io. Product: a product with digital elements registered by the Customer in the Service. SBOM: the software bill of materials generated or imported for a Product. CRA: Regulation (EU) 2024/2847.
3. What the Service does
Cemply generates and versions an SBOM for each Product, matches its components daily against public vulnerability databases, cross checks them against the CISA catalogue of known exploited vulnerabilities, keeps an append only audit trail of those checks, and prepares draft documents: incident reports under Article 14 of the CRA, and a technical documentation file following Annex VII.
4. What the Service does not do, and its limits
This article is deliberately explicit. It defines the scope of what Cemply undertakes, and the Customer acknowledges having read it before subscribing.
- Cemply never files anything with a regulator. It prepares content. The Customer reviews it, submits it on the official EU single reporting platform, and signs it. The reporting obligation of Article 14 of the CRA rests on the manufacturer, and only on the manufacturer.
- Cemply does not certify conformity and is neither a law firm nor a notified body. Nothing in the Service is legal advice or a guarantee that a Product complies with the CRA or with any other regulation.
- Monitoring covers the latest scanned version of each Product. A Customer who still supports earlier versions in the field must register each supported version as its own Product.
- Native inventory covers the npm and PyPI ecosystems through their lockfiles. Other ecosystems are covered only where the Customer imports an existing CycloneDX or SPDX document, and the resulting inventory is then only as accurate as that document.
- An inventory built from a manifest rather than a lockfile is approximate: it lists direct dependencies only, with declared version ranges rather than shipped versions. The Service states this on every such scan and records it in the audit trail.
- Monitoring is daily, not real time, and depends on third party databases whose completeness and timeliness Cemply does not control. A vulnerability absent from those sources cannot be detected.
- Build time dependencies are inventoried but excluded from vulnerability matching, as they are not shipped in the product placed on the market.
5. Account, roles and security
The Customer registers with a professional email address at the domain of its own organisation. It is responsible for the confidentiality of credentials, for the acts of its users, and for removing users who leave. Roles are available: administrator, engineer, and viewer with strict read only access.
6. Plans, prices and VAT
Plans and prices are those published at cemply.io/pricing on the day of subscription. Pricing is per monitored Product, with unlimited users. All prices are stated excluding VAT. VAT is added where due, and the reverse charge applies to a business established in another Member State that provides a valid VAT identification number.
Cemply may change its prices. A change applies to the Customer only from the renewal following a notice of at least thirty days, and the Customer may cancel before that renewal.
7. Payment, late payment and mandatory notices
Subscriptions are payable monthly in advance by card, through our payment provider Stripe. Invoices are issued automatically and available in the billing portal.
In accordance with articles L441-10 and D441-5 of the French Commercial Code: late payment penalties are due, without a reminder being necessary, at a rate equal to the interest rate applied by the European Central Bank to its most recent refinancing operation plus ten percentage points; a fixed indemnity for recovery costs of forty euros is due for each unpaid invoice, without prejudice to additional compensation where recovery costs exceed that amount. No discount is granted for early payment.
Failure to pay may lead to suspension of the Service after a formal notice that remains without effect for fifteen days. Data is retained during suspension and remains exportable.
8. Term, renewal and cancellation
The subscription runs for one month and renews automatically for successive one month terms.
The Customer may cancel at any time from the billing portal. Cancellation takes effect at the end of the current billing period: any month started is due, and no pro rata refund is granted. Access to the Service, and to exports of SBOMs and of the audit trail, remains open until that date.
The Customer may delete its account and all of its data at any time from the dashboard. Deletion is immediate and irreversible. Cemply recommends exporting the audit trail and the SBOMs beforehand: they are the Customer's evidence of diligence, and the CRA expects a manufacturer to keep its technical documentation for ten years after placing a product on the market.
9. Customer obligations
The Customer warrants that it holds the rights to the data it submits and that submitting it to the Service infringes no third party right. It undertakes not to attempt to circumvent quotas, not to disrupt the Service or the third party sources it depends on, and not to submit content that is unlawful or that contains personal data beyond what the Service requires.
Where the Customer connects a source code repository, it provides an access token limited to reading the contents of that repository. It is responsible for the scope of the rights granted and may revoke the connection at any time.
10. Intellectual property
Cemply retains all rights to the Service. The Customer receives a non exclusive, non transferable right to use it for the duration of its subscription.
The Customer retains all rights to its own data: source manifests, generated SBOMs, vulnerability records, audit trail, incident reports and technical documentation files. These are exportable in open formats at any time and remain usable after termination.
11. Personal data
For account and billing data, Cemply acts as controller, as described in the privacy policy.
For any personal data that the Customer introduces into the Service, Cemply acts as processor within the meaning of article 28 of the GDPR. Subject matter: providing the Service. Duration: the term of the subscription. Nature and purpose: hosting, processing and restitution. Data: identification data of the Customer's users. Data subjects: the Customer's staff.
Cemply undertakes to: process such data only on documented instructions from the Customer; ensure that persons authorised to process it are bound by confidentiality; implement appropriate technical and organisational measures; assist the Customer in responding to requests from data subjects and in meeting its obligations under articles 32 to 36; notify the Customer without undue delay of any personal data breach; delete all such data on termination, which the account deletion function performs; and make available the information needed to demonstrate compliance.
Authorised sub processors: Neon (database, Frankfurt), Vercel (hosting and execution, Frankfurt region), Hostinger (transactional email). Stripe acts as an independent controller for payment data. Cemply informs the Customer of any intended change of sub processor, and the Customer may object by terminating without penalty.
12. Warranty and liability
Cemply is bound by an obligation of means, not of result. Its essential obligation is to make available a monitoring and documentation tool that operates as described in article 3, within the limits set out in article 4. Cemply gives no warranty that a Product is or will be compliant, that every vulnerability affecting a Product will be detected, or that a document prepared by the Service will be accepted by an authority.
The Customer remains solely responsible for the regulatory obligations that the CRA places on the manufacturer, for reviewing and signing any document before submission, and for the decisions it takes on the basis of information supplied by the Service.
Cemply's total liability, all claims combined, is limited to the amounts actually paid by the Customer over the twelve months preceding the event giving rise to liability. Cemply is not liable for indirect damage, in particular loss of profit, loss of business, damage to reputation, or any administrative fine imposed on the Customer.
These limitations do not apply in the case of wilful misconduct or gross negligence, nor where the law prohibits their exclusion.
13. Availability and force majeure
The Service is provided without a contractual availability commitment. Cemply may carry out maintenance, and endeavours to schedule it outside business hours.
Neither party is liable for a failure caused by force majeure within the meaning of article 1218 of the French Civil Code, which includes the unavailability of the third party vulnerability databases on which the Service depends.
14. Suspension and termination for cause
Cemply may suspend or terminate the Service, after a formal notice that remains without effect for fifteen days except in cases of manifest illegality or of a threat to the security of the Service, in the event of a serious breach of these terms.
15. Changes to these terms
Cemply may amend these terms. Any amendment is notified at least thirty days before it takes effect. Continued use after that date constitutes acceptance; otherwise the Customer may terminate without penalty.
16. Governing law and jurisdiction
These terms are governed by French law. Failing an amicable settlement, any dispute falls within the exclusive jurisdiction of the competent courts of Paris, France, including in the event of multiple defendants or third party proceedings.
In accordance with article L441-1 of the French Commercial Code, these terms are communicated to any business customer who requests them, and are permanently available at cemply.io/terms.
Questions about these terms: contact@cemply.io