1. Who we are
Aneo B.V. (“Aneo,” “we,” “us,” or “our”) operates aneo.io and offers software products and related services, including Framework-Pro and IncidentAI, together referred to in this Disclaimer as the “Offerings.”
By using our website or Offerings, you accept this Disclaimer. For contractual rights, obligations, support commitments, warranties, payment terms, liability terms, and dispute terms, see the applicable Terms of Service, order form, subscription terms, data processing agreement, or signed agreement with Aneo B.V.
2. Scope
This Disclaimer applies to aneo.io and related websites, product surfaces, subdomains, aliases, and future subdomains under *.aneo.io, including examples such as www.aneo.io, app.aneo.io, api.aneo.io, docs.aneo.io, and status.aneo.io where operated by Aneo B.V.
It also applies to public website content, product descriptions, guides, blog posts, legal pages, examples, screenshots, generated outputs, downloadable documents, contact forms, and other materials made available by Aneo B.V., unless a signed agreement states otherwise.
3. General information only
The information on www.aneo.io and related public pages is provided for general product, educational, and informational purposes. It is intended to help visitors understand aneo, Framework-Pro, IncidentAI, security framework readiness, and incident response workflows.
Website content may not reflect the latest legal, regulatory, contractual, technical, operational, or security developments that apply to your specific organization.
4. Guidance only
The Offerings provide AI-assisted guidance for framework readiness, cybersecurity documentation, incident response workflows, and security operations. Outputs are for information and internal business review.
They are not legal advice. They are not a security guarantee. They are not a compliance certification. They are not a substitute for qualified professionals, accredited auditors, legal counsel, privacy advisers, security specialists, incident responders, or your own accountable decision-making.
5. No professional advice
Website content, guides, blog posts, product descriptions, examples, generated outputs, and communications from aneo should not be treated as legal, regulatory, audit, certification, compliance, privacy, tax, accounting, insurance, procurement, incident response, forensic, or cybersecurity advice for a specific situation.
You should obtain appropriate professional advice before making decisions that affect legal obligations, regulatory reporting, certifications, security controls, incident response, contracts, customers, employees, or personal data.
6. No certification or compliance guarantee
Framework-Pro can help with security framework readiness, framework selection, control mapping, policy drafts, supporting documents, evidence placeholders, and implementation planning. It does not certify your organization, guarantee audit success, or prove that controls have been implemented.
ISO 27001 certification, audit outcomes, customer approvals, regulatory compliance, and contractual acceptance depend on your scope, implementation, evidence, operating practices, auditor or reviewer judgment, and other factors outside aneo's control.
7. AI-generated output requires human review
aneo tools may generate AI-assisted summaries, classifications, policy drafts, control guidance, incident analysis, suggested actions, MITRE ATT&CK mapping support, documentation, or reports. These outputs are drafts or decision-support materials.
AI-generated content can be incomplete, incorrect, outdated, ambiguous, or unsuitable for your specific context. Always review outputs before use, keep human approval in your workflow, and do not rely on AI alone for decisions that carry legal, regulatory, safety, financial, operational, customer, privacy, or security impact.
8. Data handling summary
Personal data is processed as described in our Privacy Policy and, where applicable, the relevant Data Processing Agreement or customer agreement. Customer Content is not used to train foundation models unless you opt in or agree in writing.
A zero-retention mode and an EU data residency option may be available on supported plans or configurations. We may use vetted third-party model providers, infrastructure providers, payment providers, identity providers, support tools, and other sub-processors to deliver AI features and the Offerings.
9. High-risk and prohibited use
Do not use the website or Offerings for life-critical systems, emergency services, medical diagnosis or treatment, autonomous weapons, critical infrastructure control, or other high-risk uses where failure, delay, incorrect output, or misuse could lead to death, personal injury, severe environmental damage, severe financial damage, or other serious harm.
Do not submit unlawful content, malicious code, regulated data, secrets, credentials, payment card numbers, special category data, criminal-offence data, or other highly sensitive information unless you have a lawful basis, appropriate safeguards, and a written agreement with Aneo B.V. that permits that processing.
10. Framework-Pro limitation
Framework-Pro accelerates readiness and documentation. It does not replace security governance, risk assessment, control implementation, management review, internal audit, auditor engagement, legal review, or ongoing operation of an information security management system.
Generated policies and documents should be adapted to your organization, approved by accountable owners, communicated to relevant personnel, and supported by real operating evidence.
11. IncidentAI limitation
IncidentAI supports AI-assisted incident management, triage, categorization, ticketing, timelines, ownership, response records, and analysis support. It does not replace accountable incident commanders, security analysts, legal counsel, privacy teams, forensic specialists, law enforcement, regulators, or executive decision-makers.
IncidentAI suggestions should be reviewed by qualified personnel before containment actions, notification decisions, customer communications, public statements, regulatory submissions, or other material response steps are taken.
12. Security content and threat information
Security threats, vulnerabilities, frameworks, standards, best practices, and attack techniques change over time. Website content and generated output may become outdated or may not reflect the latest threat intelligence, legal requirements, vendor guidance, or framework updates.
You remain responsible for monitoring your own environment, maintaining security controls, validating indicators, patching systems, preserving evidence, and responding to incidents appropriately.
13. Customer responsibility
You are responsible for the accuracy, completeness, lawfulness, and appropriateness of information you provide to aneo tools. Product output depends on the quality of the input, selected options, customer configuration, available context, and human review.
You are also responsible for implementing controls, assigning owners, maintaining evidence, configuring access, reviewing documentation, training personnel, and meeting your own legal, regulatory, contractual, privacy, security, and compliance obligations.
14. Product availability and changes
Aneo B.V. aims to keep product and website information clear and useful, but product features, pricing, availability, screenshots, integrations, support options, documentation, and roadmap items may change over time.
Statements about future features, integrations, capabilities, or availability are informational only and do not create a binding commitment unless included in a signed agreement with Aneo B.V.
15. Website accuracy
We work to keep website information accurate, current, and useful. However, we do not guarantee that the website, guides, blog posts, legal pages, product descriptions, screenshots, examples, links, or other content are error-free, complete, current, or suitable for your specific use case.
If you notice an error or outdated statement, contact hello@aneo.io.
16. No warranty
The website and Offerings are provided “as is” and “as available” unless a signed agreement states otherwise. We do not promise that they will be accurate, complete, uninterrupted, secure, error-free, available at all times, or suitable for a particular purpose.
We may change, suspend, remove, or discontinue content, features, outputs, integrations, or availability at any time, subject to any commitments in an applicable signed agreement.
17. Third-party links and services
The website may link to third-party websites, frameworks, standards bodies, documentation, tools, payment providers, identity providers, social media pages, integrations, or other external services.
Third-party websites and services are controlled by their own providers. Aneo B.V. is not responsible for their content, availability, security, privacy practices, terms, or decisions.
18. Downloads, documents, and exports
Documents, reports, exports, policies, templates, checklists, or other materials generated by or downloaded from aneo products are provided for internal business use and review. They should be checked for accuracy, completeness, formatting, legal suitability, and business fit before use.
You should not submit generated material to customers, auditors, regulators, employees, suppliers, insurers, or other third parties without appropriate review and approval.
19. No public hosting or distribution of user content
aneo tools generate structured cybersecurity documentation and analysis reports for internal business use. The platform does not host or distribute public user-generated content.
Customer Content submitted to aneo products should be governed by the applicable agreement, data processing terms, privacy policy, and customer configuration.
20. Intellectual property
All materials on the website and in the Offerings, including text, graphics, logos, product names, screenshots, layouts, software, documentation, guides, examples, templates, generated formats, and other materials, may be protected by intellectual-property rights.
You may not copy, distribute, modify, publish, resell, reuse, scrape, or exploit aneo materials except as permitted by law, by product functionality, by applicable terms, or by written consent from Aneo B.V.
21. Limitation of reliance
Any reliance on website content, guides, product information, generated output, or other aneo materials is at your own risk. You should independently verify important information before acting on it.
Nothing on the website should be interpreted as a guarantee of security, compliance, certification, audit success, incident containment, risk reduction, commercial outcome, or regulatory acceptance.
22. Liability
To the maximum extent permitted by applicable law, Aneo B.V. is not liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, revenue, business, goodwill, data, use, opportunity, or anticipated savings, arising from or related to use of the website, content, generated outputs, or Offerings.
Nothing in this Disclaimer limits liability that cannot be limited under applicable law. Where you have a signed agreement with Aneo B.V., that agreement controls the liability, warranty, service level, support, dispute, and remedy terms for the relevant product or service.
23. No waiver of applicable rights
This Disclaimer does not exclude or limit rights that cannot be excluded or limited under applicable law. If any part of this Disclaimer is found unenforceable, the remaining parts should continue to apply as far as permitted by law.
24. Changes to this Disclaimer
We may update this Disclaimer when our website, products, legal position, or operating model changes. The Last updated date shows the latest version. Continued use of the website or Offerings after changes means you accept the updated Disclaimer.
25. Contact
Questions about this Disclaimer can be sent to hello@aneo.io.
Contact page: https://www.aneo.io/contact/.
Postal address: Aneo B.V., Thomas Morelaan 104, 2135 WC Hoofddorp, Netherlands.
