These terms govern your use of this website. They are a contract between you and Grey Technologies Kft. Read section 12 and section 13 carefully, they limit our liability to you.
If you engage us for professional services, a separate agreement governs that work. See section 5.
1. Who we are
Grey Technologies Kft. is a limited liability company (korlátolt felelősségű társaság) registered in Hungary.
| Legal entity | Grey Technologies Kft. |
| Company registration number | 01-09-445879 |
| Registered office | Ferenciek tere 2. Fsz., 1053, Budapest, Hungary |
| EU VAT number | HU32848865 |
| General contact | info@greytechnologies.io |
| Security contact | security@greytechnologies.io |
In these terms, "we", "us", and "our" mean Grey Technologies Kft. "You" means you, and any organisation you access this site on behalf of.
2. Accepting these terms
By accessing or using this website you accept these terms. If you do not accept them, do not use the site.
If you use this site on behalf of an organisation, you confirm that you have authority to bind that organisation, and "you" includes that organisation.
You must be at least 18 years old to use this site. It is intended for professional and business use.
3. Changes to these terms
We may change these terms. When we do, we update the effective date at the top and publish the revised version here.
Changes apply from the date they are published. They are not retrospective, they do not alter rights or obligations that had already accrued before publication. Continuing to use the site after a change means you accept the revised terms. If you do not accept them, stop using the site.
We do not undertake to notify you individually of changes to this page. Check it periodically. Changes to a signed Master Services Agreement are governed by that agreement's own variation clause, not by this section.
4. What this website is, and what it is not
This site is a publication. It describes who we are, what we do, and what we are researching.
Nothing on this website is security advice, technical advice, legal advice, regulatory advice, or professional advice of any kind.
That includes our research pages, blog posts, architectural descriptions, compliance material referencing frameworks such as NIST, DORA, NIS2, SOC 2, or ISO 27001, and any description of threat detection, secure AI/ML operations, or quantum research. It is general information published to a general audience. It is not an assessment of your systems, your threat model, your regulatory position, or your risk.
Do not act on it without advice specific to your circumstances. Security and compliance decisions depend on facts we do not have. A control that is correct for one organisation is negligent in another.
Using this site does not create a client relationship. No consultant–client, advisory, or professional relationship arises from:
- reading anything published here;
- submitting the contact form;
- an exchange of emails, a call, or a meeting to scope possible work;
- our replying to your enquiry.
A relationship begins only when a written agreement is signed by both parties. See section 5.
Content is provided as at the date of publication. Security moves. We do not undertake to keep past material current, and material may be out of date by the time you read it.
5. Professional engagements and the Master Services Agreement
We provide cybersecurity consulting, detection engineering, secure AI/ML operations, compliance advisory, and research services. We do not provide any of them through this website.
All engagements are governed by a separate written Master Services Agreement (MSA) and its associated statements of work, order forms, and any data processing agreement.
If there is any conflict or inconsistency between these terms and a signed MSA, the MSA prevails in respect of that engagement, to the extent of the inconsistency. These terms continue to govern your general use of the website.
Nothing on this site, including any description of services, capability, methodology, or pricing, is an offer capable of acceptance. It is an invitation to discuss. We are not obliged to accept any engagement, and we may decline any enquiry without giving a reason.
Descriptions of services on this site are indicative. Actual scope, deliverables, timelines, acceptance criteria, service levels, and liability are defined in the MSA and statement of work. Where those documents say something different from this website, those documents are correct.
6. ARC, invite-only MVP demonstrator
The Agent Response Center ("ARC") is an MVP demonstrator. It is not a generally available product.
- Access is by invitation only. No right of access arises from these terms, from an enquiry, or from any discussion.
- ARC is provided "as is" and "as available". To the fullest extent permitted by law, we exclude all warranties, conditions, and representations of any kind in respect of ARC, whether express, implied, statutory, or otherwise, including any implied terms as to satisfactory quality, fitness for a particular purpose, accuracy, or non-infringement.
- There is no service level agreement. No uptime commitment, no availability target, no support commitment, and no response time applies to ARC. It may be slow, unavailable, or withdrawn at any moment.
- It is not a production security control. ARC is a demonstrator. Do not connect it to production systems, do not rely on its output for any operational, security, or compliance decision, and do not treat any output as an assurance that a system is secure.
- Its output may be wrong. ARC output is illustrative. It is not verified, not assured, and not a professional opinion.
- It may change or disappear without notice. We may modify, restrict, suspend, or discontinue ARC, in whole or in part, at any time, with or without notice, and with no liability to you.
- Feedback. If you give us feedback on ARC, we may use it freely, without restriction, obligation, or payment to you. Do not send us feedback containing anything confidential or anything you are not free to disclose.
Where an invited evaluation is governed by a separate evaluation agreement or NDA, that agreement prevails over this section for that evaluation.
7. Acceptable use
You may read this site, and use the contact form to contact us. That is what it is for.
You must not:
- probe, scan, or test the vulnerability of this site or any system or network connected to it, except strictly as permitted by section 8;
- breach, circumvent, or attempt to circumvent any security, authentication, rate limiting, or anti-bot measure, including Cloudflare Turnstile;
- attempt to gain unauthorised access to any part of this site, any account, any server, or any system or network connected to it;
- interfere with the availability or integrity of the site, including by denial-of-service attack, flooding, or overloading the contact endpoint;
- submit anything to the contact form that is unlawful, defamatory, malicious, or that you have no right to send us, including another party's confidential information, personal data you are not entitled to disclose, credentials, or malware;
- scrape, harvest, or systematically extract content or data from this site, or use automated means to access it, other than search engine crawlers acting in accordance with our
robots.txt; - use this site or its content to build, train, or evaluate a machine learning model, without our prior written consent;
- reverse engineer, decompile, or disassemble any part of the site, except to the extent that restriction is prohibited by law;
- misrepresent your identity or your affiliation with any person or organisation;
- use this site for any unlawful purpose, or in any way that breaches any applicable law or regulation.
Unauthorised access to computer material, and unauthorised acts impairing the operation of a computer, are criminal offences under sections 423 and 424 of the Hungarian Criminal Code (Act C of 2012). We treat them as such and report them where appropriate.
8. Security research and responsible disclosure
We are a security company. We would rather hear from you than not.
Good-faith security research is welcome, and we will not pursue legal action against a researcher who acts in accordance with our published disclosure policy. That policy is set out in this section, and our contact details and PGP key fingerprint are published at /.well-known/security.txt.
Report findings to security@greytechnologies.io, encrypted with our PGP key where the content is sensitive.
To stay within scope, you must:
- act in good faith, and only to find and report vulnerabilities;
- avoid privacy violations, data destruction, and any degradation of service to others;
- stop as soon as you have enough to demonstrate the issue, do not pivot, do not escalate further than necessary, and do not access, modify, or exfiltrate data belonging to us or to anyone else;
- give us a reasonable opportunity to fix the issue before disclosing it publicly;
- comply with all applicable law, including the Hungarian Criminal Code (Act C of 2012) and the GDPR.
Testing that goes beyond this, automated scanning that degrades the service, social engineering of our staff or suppliers, physical attacks, or testing third-party infrastructure such as Cloudflare or Microsoft, is not authorised by us and we cannot authorise it. Our providers' own policies govern their systems.
9. Intellectual property and your licence to use this site
All content on this site, text, research papers, architectural specifications, diagrams, code samples, the ARC demonstrator and its interface design, the Grey Technologies name, logo, and branding, and the selection and arrangement of all of it, is owned by us or licensed to us, and is protected by copyright, trade mark, database, and other intellectual property rights.
We grant you a limited, personal, non-exclusive, non-transferable, revocable licence to access and view this site, and to print or download individual pages for your own internal reference. That is the whole of the licence.
You must not, without our prior written consent:
- republish, redistribute, or commercially exploit any content;
- copy or adapt substantial parts of the site, or extract or re-utilise a substantial part of any database within it;
- remove or obscure any copyright, trade mark, or other proprietary notice;
- use our name, logo, or branding in a way that suggests endorsement, partnership, or affiliation.
You may quote short extracts with clear attribution and a link to the source page. Free-use rights under the Hungarian Copyright Act (Act LXXVI of 1999), including for criticism, review, quotation, and news reporting, are unaffected.
Third-party names, trade marks, and framework references (including NIST, DORA, NIS2, SOC 2, and ISO 27001) belong to their respective owners. Their use here is descriptive. It does not imply endorsement, certification, accreditation, or affiliation in either direction.
We reserve all rights not expressly granted.
10. Links to other sites
This site may link to third-party websites and resources. We provide those links for convenience.
We do not control those sites, we do not endorse them, and we are not responsible for them, for their content, their accuracy, their availability, their security, or their privacy practices. A link is not a recommendation, and it is not a warranty that anything on the far side of it is safe or correct.
When you follow a link away from this site, these terms stop applying and the other site's terms and privacy policy take over. Read them.
11. Availability, changes, and withdrawal of the site
We do not guarantee that this site will be available, uninterrupted, or error-free. It is provided on an "as available" basis.
We may change, suspend, restrict, or withdraw all or any part of this site at any time, without notice and without liability. We may also change or remove content at any time.
We are not liable if this site is unavailable for any period, for any reason.
You are responsible for arranging your own access, for the security of the device and network you use, and for ensuring that anyone accessing this site through your connection is aware of these terms and complies with them.
12. Disclaimers
To the fullest extent permitted by law:
- This site and all content on it are provided "as is" and "as available", without warranty of any kind.
- We exclude all conditions, warranties, representations, and other terms that might otherwise be implied by statute, common law, or the law of equity.
- We do not warrant that the content is accurate, complete, current, or fit for any purpose.
- We do not warrant that this site, its servers, or any content or email sent from us is free of viruses or other harmful components. You are responsible for your own protective measures.
- Any reliance you place on content on this site is entirely at your own risk.
This section is subject to section 13.2, nothing here excludes liability that cannot lawfully be excluded.
13. Limitation of liability
Read this section. It limits what you can recover from us.
13.1 What we are not liable for
To the fullest extent permitted by law, we are not liable to you for:
- any loss of profits, revenue, business, contracts, anticipated savings, goodwill, or reputation;
- any loss or corruption of data;
- any business interruption;
- any security incident, breach, or compromise of your systems;
- any regulatory fine, penalty, or enforcement cost;
- any indirect or consequential loss;
however arising, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, and whether or not the loss was foreseeable or we were advised of its possibility.
13.2 What we do not, and cannot, exclude
Nothing in these terms excludes or limits our liability for:
- damage to human life, bodily integrity, or health, and any harm caused intentionally, these cannot lawfully be excluded (Civil Code, Act V of 2013, section 6:152);
- fraud or fraudulent misrepresentation, this cannot lawfully be excluded;
- any other liability that cannot lawfully be excluded or limited under Hungarian law.
If any part of section 13.1 or section 13.3 is held to be unenforceable, the rest of this section continues to apply.
13.3 Cap on liability
Subject to section 13.2, our total aggregate liability to you arising out of or in connection with your use of this website, in contract, tort (including negligence), breach of statutory duty, or otherwise, is limited to €100.
This cap applies to your use of the website. Liability arising from a professional engagement is governed by the liability provisions of the applicable MSA, and this section does not limit, extend, or otherwise affect it.
13.4 If you are a consumer
If you are using this site as a consumer rather than for business purposes, your statutory rights are unaffected. Nothing in these terms excludes or limits any right you have under the Civil Code (Act V of 2013), Act CLV of 1997 on Consumer Protection, or other mandatory consumer protection law, and any term that would do so does not apply to you.
14. Indemnity
You agree to indemnify us, and our officers, employees, and contractors, against all liabilities, losses, damages, claims, and reasonable costs (including reasonable legal fees) arising out of or in connection with:
- your breach of these terms;
- your use of this site in breach of section 7 (acceptable use);
- any unlawful act or omission by you in connection with this site;
- any material you submit to us that infringes a third party's rights or that you had no right to send.
This indemnity does not apply to the extent that the liability arises from our own breach, negligence, or wilful misconduct. We will notify you promptly of any claim we intend to seek indemnity for, and will not settle it without first consulting you.
15. Suspension and termination of access
We may suspend, restrict, or terminate your access to this site, immediately and without notice, if we reasonably believe you have breached these terms, particularly section 7.
We may also block IP addresses, ranges, or automated clients that abuse the site or its contact endpoint, at our discretion and without notice. Our anti-abuse measures may occasionally block legitimate traffic. If that happens to you, email info@greytechnologies.io.
Termination does not affect any rights or obligations that had already accrued. Sections 9, 12, 13, 14, 18, and 19 survive termination.
16. Privacy
Our handling of personal data is set out in our Privacy Policy at /privacy. It forms part of your use of this site and should be read alongside these terms.
Where you send us personal data, through the contact form or otherwise, you confirm that you are entitled to send it to us.
17. Contact
| Purpose | Address |
|---|---|
| Questions about these terms | info@greytechnologies.io |
| Security vulnerability reports | security@greytechnologies.io |
| Postal | Grey Technologies Kft., Ferenciek tere 2. Fsz., 1053, Budapest, Hungary |
Notices to us are not validly served by contact form submission. Use email to the addresses above, or post to the address given.
18. General
Entire agreement. These terms, together with our Privacy Policy, are the entire agreement between you and us in relation to your use of this website, and supersede any earlier version. They do not affect, replace, or supersede any signed MSA, statement of work, NDA, or evaluation agreement, each of which stands on its own terms and prevails over these terms in respect of its subject matter.
Severability. If any provision of these terms is held to be invalid, illegal, or unenforceable, it is severed to the minimum extent necessary and the remaining provisions continue in full force. Where possible, the severed provision is treated as modified to the minimum extent needed to make it enforceable while preserving its intent.
No waiver. If we do not enforce a provision, or delay in enforcing it, that is not a waiver of that provision or of any other. A waiver is effective only if given in writing.
Assignment. You may not assign or transfer your rights or obligations under these terms. We may assign or transfer ours, including on a sale or reorganisation of our business, provided your rights are not adversely affected.
Third party rights. A person who is not a party to these terms has no right to enforce them, except that our officers, employees, and contractors may rely on the indemnity in section 14.
Force majeure. We are not liable for any failure or delay caused by events beyond our reasonable control.
Headings. Headings are for convenience only and do not affect interpretation.
19. Governing law and jurisdiction
These terms, their subject matter, and their formation, including any non-contractual dispute or claim arising out of or in connection with them, are governed by and construed in accordance with the laws of Hungary.
The courts of Hungary have exclusive jurisdiction over any dispute or claim arising out of or in connection with these terms or your use of this website.
If you are a consumer, this clause does not deprive you of the protection of any mandatory rule of law in your country of habitual residence, and you may be entitled to bring proceedings in the courts of that country.