1. Acceptance of Terms
By accessing or using CanaryGuard ("the Service"), operated at canaryguard.app, you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an organization, you represent that you have the authority to bind that organization to these Terms.
If you do not agree to these Terms, you must not use the Service. Your continued use of the Service after any modifications to these Terms constitutes acceptance of the updated Terms.
2. Service Description
CanaryGuard is a cybersecurity platform that enables you to create, deploy, and manage canary tokens -- digital tripwires that alert you when sensitive resources are accessed or compromised. The Service includes:
- Creation and management of canary tokens across seven types: HTTP/URL, DNS, web image pixel, email pixel, Word document (DOCX), PDF document, and QR code
- Real-time alert notifications via email, webhook integrations (Slack, Discord, custom webhooks), and the CanaryGuard dashboard
- Geolocation enrichment of trigger events using IP address data
- A REST API (v1) for programmatic token management and alert retrieval
- API key management for secure programmatic access
- Team management with email-based invitations and role-based access control (owner, admin, member)
- Billing and credit system for token usage beyond plan limits
The callback infrastructure for token triggers operates via the svccdns.com domain.
3. Account Responsibilities
3.1 Registration
To use CanaryGuard, you must create an account with a valid email address and confirm it via the verification email we send. You agree to:
- Provide accurate, current, and complete information during registration
- Maintain and promptly update your account information
- Maintain the confidentiality of your password and API keys
- Accept responsibility for all activity that occurs under your account
- Notify us immediately of any unauthorized use of your account
3.2 Account Limits
Each account is associated with a single organization. You may not create multiple accounts to circumvent plan limits or other restrictions. We reserve the right to merge or terminate duplicate accounts.
4. Acceptable Use
You must use CanaryGuard in compliance with our Acceptable Use Policy (AUP) and all applicable laws. The Service is designed exclusively for legitimate security monitoring purposes. You agree not to:
- Deploy canary tokens to harass, stalk, or intimidate individuals
- Use the Service to collect personal data for purposes unrelated to security monitoring
- Embed tokens in content distributed to individuals without a legitimate security purpose
- Use the Service to generate fraudulent alerts or false security incidents
- Attempt to disrupt, overload, or compromise the CanaryGuard infrastructure
- Reverse-engineer, decompile, or attempt to extract the source code of the Service
- Resell or redistribute the Service without written authorization
- Use the Service in violation of any applicable local, state, national, or international law
Violation of the AUP may result in immediate suspension or termination of your account without notice or refund.
5. Intellectual Property
5.1 Our Property
The CanaryGuard platform, including its software, design, logos, trademarks, documentation, and all related intellectual property, is owned by CanaryGuard. These Terms do not grant you any right, title, or interest in our intellectual property except for the limited right to use the Service as described herein.
5.2 Your Data
You retain full ownership of the data you upload, create, or generate through the Service, including token configurations, labels, and alert records. You grant us a limited license to process, store, and transmit your data solely to provide and improve the Service.
6. Plans and Payment
6.1 Plans
CanaryGuard offers the following plans:
- Scout (Free) -- Up to 5 canary tokens, 1 user, email alerts, IP geolocation
- Starter ($29/month) -- Up to 50 tokens, 2 users, Slack and Discord alert integrations, dashboard access
- Team ($59/month) -- Up to 200 tokens, 5 users, custom webhook alerts, REST API access, custom callback domains
- Pro ($99/month) -- Up to 1,000 tokens, 15 users, crypto wallet canaries, audit log, SIEM integration
- Enterprise (custom pricing) -- Unlimited tokens, unlimited users, SSO, all features, custom SLA available on request
Plan features and limits are subject to change. Current details are available on the pricing page.
6.2 Credits and Payment
All payments are processed exclusively via Bitcoin and Lightning Network through our self-hosted BTCPay Server. Payments purchase credit packs that are added to your organization's credit balance. Credits can be used to create tokens beyond your plan's included limit (1 credit = 1 additional token).
- 50 credits -- $10
- 200 credits -- $35
- 500 credits -- $75
6.3 Refund Policy
Due to the irreversible nature of cryptocurrency transactions, all payments are final and non-refundable. Credits purchased cannot be converted back to cryptocurrency or fiat currency. Credits do not expire. We encourage you to start with the free Scout plan to evaluate the Service before purchasing credits.
6.4 Plan Limits
Each plan includes a specific limit on the number of active canary tokens. If you reach your plan's token limit, you may either upgrade to a higher plan or use credits to create additional tokens. We will not delete your existing tokens if you downgrade, but you will be unable to create new tokens until you are within the limits of your current plan or purchase credits.
7. Service Availability
We strive to maintain high availability of the CanaryGuard platform and callback infrastructure. However:
- The Service is provided on a "best effort" basis. We do not guarantee 100% uptime
- No service level agreement (SLA) is currently offered on any plan. Enterprise customers may negotiate custom SLAs separately
- We may perform scheduled maintenance with reasonable advance notice where possible
- We reserve the right to modify, suspend, or discontinue any feature of the Service with notice
- We reserve the right to throttle or limit API usage to ensure service quality for all users
8. Limitation of Liability
Canary tokens are detection tools, not prevention tools. CanaryGuard is designed to alert you when certain resources are accessed. We do not and cannot guarantee that our tokens will detect every unauthorized access, data breach, or security incident. The absence of a triggered alert does not indicate that your systems are secure.
To the maximum extent permitted by applicable law:
- The Service is provided "AS IS" and "AS AVAILABLE" without warranties of any kind, whether express or implied
- We disclaim all warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement
- We are not liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the Service
- Our total aggregate liability for any claims arising from or related to the Service is limited to the amount you paid us in the 12 months preceding the claim
- We are not responsible for any damages resulting from unauthorized access to your systems that our tokens failed to detect
- We are not liable for actions taken or not taken based on alert data provided by the Service
9. Indemnification
You agree to indemnify, defend, and hold harmless CanaryGuard, its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from or related to:
- Your use of the Service
- Your violation of these Terms or the Acceptable Use Policy
- Your deployment of canary tokens in a manner that infringes the rights of any third party
- Any data collected through your canary tokens and how you use that data
- Your violation of any applicable law or regulation
10. Termination
10.1 Termination by You
You may request account deletion by contacting support@canaryguard.app. Upon receiving your request, your account will be flagged for deletion. Your tokens will be deactivated, and your data will be removed in accordance with our Privacy Policy. Unused credits are forfeited upon account deletion.
10.2 Termination by Us
We may suspend or terminate your account if:
- You violate these Terms or the Acceptable Use Policy
- Your use of the Service poses a security risk to us or other users
- We are required to do so by law
- Your account has been inactive for an extended period (12+ months with no active tokens)
For AUP violations, we may terminate your account immediately without prior notice. For other reasons, we will provide reasonable notice and an opportunity to export your data where feasible.
11. Governing Law
These Terms are governed by and construed in accordance with applicable law. Any disputes arising under these Terms shall be resolved through good-faith negotiation. If negotiation fails, disputes shall be submitted to binding arbitration in accordance with the rules of a recognized arbitration body, unless you are in a jurisdiction where arbitration clauses are unenforceable, in which case local courts shall have jurisdiction.
12. Changes to These Terms
We may update these Terms from time to time. When we make material changes, we will:
- Post the updated Terms on this page with a new "Last updated" date
- Send an email notification to the address associated with your account at least 30 days before the changes take effect
- Provide a summary of the key changes
Your continued use of the Service after the effective date of the updated Terms constitutes acceptance.
13. Contact Us
For questions about these Terms of Service, please contact us:
Email: support@canaryguard.app
Website: canaryguard.app