Terms of Service
Drop Table Pulse - Azure DevOps Security Assessment Platform
Effective Date: 12 February 2026 | Version: 1.0
1. Introduction and Acceptance
These Terms of Service ("Terms") constitute a legally binding agreement between you ("Customer", "you", or "your") and Drop Table Ltd, a company registered in England and Wales ("Drop Table", "we", "us", or "our"), governing your access to and use of the Drop Table Pulse security assessment platform ("Service").
By creating an account, accessing, or using the Service, you acknowledge that you have read, understood, and agree to be bound by these Terms. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have the authority to bind such entity to these Terms.
If you do not agree to these Terms, you must not access or use the Service.
2. Definitions
- "Assessment" means a security and compliance scan of your Azure DevOps organisation or project(s) performed by the Service.
- "Assessment Report" means the PDF document or web-based report generated following an Assessment, containing findings, scores, and remediation guidance.
- "Azure DevOps" means Microsoft's Azure DevOps Services platform (dev.azure.com).
- "Billing Period" means the monthly period during which your usage is measured and billed, aligned with your subscription start date.
- "Customer Data" means all data, including metadata and configuration information, retrieved from your Azure DevOps organisation during an Assessment.
- "Organisation" means the billing and administrative entity within the Service under which one or more Users operate and to which Azure DevOps organisations are connected.
- "PAT Token" means a Personal Access Token issued by Azure DevOps that grants the Service access to your Azure DevOps organisation.
- "Scan Units" means the unit of measurement for billing purposes, calculated based on the number and type of entities within your Azure DevOps organisation.
- "User" means any individual who accesses the Service using valid credentials associated with your Organisation.
3. Service Description
Drop Table Pulse provides:
- Security Assessments: Automated analysis of your Azure DevOps organisation including repositories, pipelines, service connections, permissions, and configurations.
- Compliance Mapping: Assessment findings mapped to industry compliance frameworks including ISO 27001, NIST 800-53, SOC 2, PCI DSS, GDPR, and others.
- Scoring: DevOps Maturity Score and Security Compliance Score (scale of 0-10).
- Assessment Reports: Detailed PDF reports with executive summaries, technical findings, and remediation guidance (available on paid tiers).
- Automated Remediation Scripts: PowerShell scripts to address identified security issues.
- Scheduled Assessments: Recurring automated assessments with trend analysis.
4. Account Registration and Security
4.1 Eligibility
The Service is intended for business use only. By using the Service, you represent that you are at least 18 years of age and have the legal capacity to enter into these Terms.
4.2 Account Creation
To access the full features of the Service, you must create an account by providing accurate and complete information, including a valid email address. You must verify your email address before gaining full access to the Service.
4.3 Account Security
You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to:
- Use a strong, unique password
- Enable two-factor authentication where available
- Notify us immediately of any unauthorised access to your account
- Not share your account credentials with third parties
4.4 Organisation Membership
Users may be members of one or more Organisations with different roles (Owner, Admin, Reader). Organisation Owners are responsible for managing membership and access rights within their Organisation.
5. Pricing and Billing
5.1 Pricing Tiers
The Service is offered under the following pricing models:
- Free Tier: Limited to a single project scan per organisation. Does not include PDF report downloads. Assessment schedule is fixed (weekly on Mondays at 04:00 UTC).
- One-Off Assessment: A single comprehensive assessment with full PDF report for a fixed fee.
- Usage-Based (Metered) Billing: Monthly billing based on Scan Units consumed during the Billing Period.
5.2 Scan Unit Calculation
For usage-based billing, charges are calculated based on the maximum number of Scan Units observed during your Billing Period ("High Water Mark"). Scan Units are determined by the number and type of entities in your Azure DevOps organisation, including but not limited to:
- Users
- Projects
- Repositories
- Pipelines
- Service Connections
- Environments
Current Scan Unit multipliers and pricing are displayed in the Service's pricing section and may be updated from time to time with 30 days' notice.
5.3 Payment Processing
Payments are processed through our third-party payment providers:
- Stripe: For direct credit/debit card payments. By using Stripe, you also agree to Stripe's Terms of Service.
- Microsoft Azure Marketplace: For customers purchasing through the Azure Marketplace. Additional Microsoft terms apply.
5.4 Supported Currencies
We accept payment in GBP (British Pounds), USD (US Dollars), EUR (Euros), AUD (Australian Dollars), and CAD (Canadian Dollars). Currency is selected at account setup and cannot be changed mid-subscription.
5.5 Payment Failure
If a payment fails, we will notify you and provide a 7-day grace period to resolve the issue. If payment is not received within the grace period, we may suspend your access to the Service until payment is received.
5.6 Taxes
All prices are exclusive of applicable taxes (including VAT) unless otherwise stated. You are responsible for paying any taxes associated with your use of the Service.
6. Service Availability
6.1 Uptime Target
We target 99.9% availability for the Service, measured on a monthly basis. This excludes:
- Scheduled maintenance windows (announced at least 24 hours in advance)
- Emergency maintenance required for security or stability
- Outages caused by factors outside our reasonable control, including Azure platform outages
- Outages of third-party services (Azure DevOps, Stripe, etc.)
6.2 Support
Support is provided via email at support@droptable.io. We aim to respond to support requests within 2 business days.
7. Customer Obligations
You agree to:
- Provide Valid Credentials: Supply valid PAT Tokens with appropriate permissions for the Service to perform Assessments. You are responsible for the security of your PAT Tokens.
- Authorised Access Only: Only connect Azure DevOps organisations for which you have authorisation to perform security assessments.
- Comply with Azure DevOps Terms: Your use of the Service must comply with Microsoft's Azure DevOps Terms of Service.
- Accurate Billing Information: Provide accurate and complete billing information and keep it up to date.
- Lawful Use: Use the Service only for lawful purposes and in compliance with all applicable laws and regulations.
- No Reverse Engineering: Not attempt to reverse engineer, decompile, or derive the source code of the Service.
- No Interference: Not interfere with or disrupt the Service or servers or networks connected to the Service.
8. Data Handling and Privacy
8.1 Data Location
All Customer Data is processed and stored in the United Kingdom using Microsoft Azure UK regions. We do not transfer Customer Data outside the UK unless required by law or with your explicit consent.
8.2 Data Collection
During Assessments, the Service collects metadata and configuration information from your Azure DevOps organisation, including but not limited to:
- User accounts and permissions
- Project configurations
- Repository settings and branch policies
- Pipeline definitions and configurations
- Service connection configurations
- Environment and deployment settings
The Service does not access or store the contents of your source code, build artifacts, or secret values.
8.3 Data Use
We use Customer Data solely to provide the Service to you. We do not use Customer Data for benchmarking, analytics, product improvement, or any other purpose without your explicit consent.
8.4 Data Retention
Upon termination of your account, we will delete your Customer Data upon your request. You may request deletion at any time by contacting support@droptable.io.
8.5 Privacy Policy
Our collection and use of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference.
9. Intellectual Property
9.1 Our Intellectual Property
The Service, including all software, algorithms, user interfaces, designs, documentation, and Assessment methodologies, is owned by Drop Table Ltd and is protected by intellectual property laws. These Terms do not grant you any rights to our intellectual property except the limited right to use the Service as described herein.
9.2 Your Data
You retain all ownership rights to your Customer Data. You grant us a limited, non-exclusive licence to access, process, and store your Customer Data solely for the purpose of providing the Service to you.
9.3 Assessment Reports
Assessment Reports generated by the Service are provided for your internal use. You may share Assessment Reports with third parties (such as auditors or customers) at your discretion.
10. Termination
10.1 Termination by You
You may cancel your subscription at any time through the Service's account settings. Cancellation will take effect at the end of your current Billing Period. You will continue to have access to the Service until the end of the Billing Period.
10.2 Termination by Us
We may suspend or terminate your access to the Service immediately if:
- You breach these Terms
- You fail to pay fees when due (after the 7-day grace period)
- Your use of the Service poses a security risk
- We are required to do so by law
10.3 Effect of Termination
Upon termination:
- Your access to the Service will cease
- You may request deletion of your Customer Data
- Provisions of these Terms that by their nature should survive will survive (including limitations of liability, indemnification, and governing law)
10.4 No Refunds
Fees paid are non-refundable except where required by applicable law.
11. Limitation of Liability
11.1 Service Provided "As Is"
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
11.2 No Guarantee of Results
While we strive to provide accurate and comprehensive Assessments, we do not guarantee that the Service will identify all security vulnerabilities or compliance issues in your Azure DevOps organisation. The Service is a tool to assist your security efforts and should not be relied upon as your sole security measure.
11.3 Exclusion of Indirect Damages
TO THE MAXIMUM EXTENT PERMITTED BY LAW, DROP TABLE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, BUSINESS OPPORTUNITIES, OR GOODWILL, ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICE.
11.4 Liability Cap
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE TOTAL FEES PAID BY YOU TO US IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
11.5 Essential Purpose
The limitations in this section apply regardless of the legal theory upon which a claim is based and even if we have been advised of the possibility of such damages.
12. Indemnification
You agree to indemnify, defend, and hold harmless Drop Table and its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising out of or related to:
- Your use of the Service
- Your breach of these Terms
- Your violation of any applicable law or third-party rights
- Unauthorised use of PAT Tokens or other credentials provided to the Service
- Assessments performed on Azure DevOps organisations without proper authorisation
13. Third-Party Services
The Service integrates with and depends upon third-party services including:
- Microsoft Azure DevOps: The data source for Assessments
- Microsoft Azure: Our cloud infrastructure provider
- Stripe: Payment processing
- Microsoft Azure Marketplace: Alternative billing channel
We are not responsible for the availability, accuracy, or quality of third-party services. Your use of third-party services is subject to those services' respective terms of service.
14. Modifications to Terms
We may modify these Terms from time to time. For material changes, we will provide at least 30 days' notice by email or through the Service before the changes take effect. Your continued use of the Service after the effective date of revised Terms constitutes acceptance of those Terms.
If you do not agree to the revised Terms, you must stop using the Service before the changes take effect. You may cancel your subscription as described in Section 10.1.
15. Governing Law and Disputes
15.1 Governing Law
These Terms are governed by and construed in accordance with the laws of England and Wales, without regard to conflict of law principles.
15.2 Jurisdiction
Any dispute arising out of or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
15.3 Informal Resolution
Before initiating any legal proceedings, you agree to contact us at legal@droptable.io to attempt to resolve the dispute informally.
16. General Provisions
16.1 Entire Agreement
These Terms, together with our Privacy Policy, constitute the entire agreement between you and Drop Table regarding the Service and supersede all prior agreements and understandings.
16.2 Severability
If any provision of these Terms is found to be unenforceable, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.
16.3 Waiver
Our failure to enforce any provision of these Terms shall not constitute a waiver of that provision or any other provision.
16.4 Assignment
You may not assign or transfer these Terms or your rights hereunder without our prior written consent. We may assign these Terms without restriction.
16.5 Force Majeure
Neither party shall be liable for any failure or delay in performance due to circumstances beyond its reasonable control, including acts of God, natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, epidemics, or failures of third-party services.
17. Contact Information
If you have any questions about these Terms, please contact us:
Drop Table LtdEmail: hello@droptable.io
Legal enquiries: legal@droptable.io
Support: support@droptable.io
Last updated: 12 February 2026