This document is in draft and is pending review by counsel. It is published for transparency during Armada’s pre-launch period and does not yet constitute a binding agreement.
1. What this covers
This policy applies to every use of the Armada platform. It is incorporated by reference into the Terms of Service (§10). Breaking it is a material breach.
It is written to be short and specific. If a rule below is not clear enough for you to know whether something is allowed, email hello@armada-solutions.com and ask before doing it.
2. Enroll only tenants you are authorized to assess
You may enroll a Microsoft 365 tenant only if you have authority from that organisation to run a read-only security assessment of it. Authority comes from your client agreement or from a specific written authorization.
Holding a GDAP relationship is not, by itself, authority. Technical access and permission are different things. You are responsible for the difference.
We cannot verify authority. We take your word for it, and the Terms of Service put the consequences of that word being wrong on you.
Not allowed:
- Enrolling a tenant you do not manage.
- Enrolling a former client’s tenant after the engagement ended.
- Enrolling a prospect’s tenant to produce an unsolicited report as a sales tactic.
- Enrolling a competitor’s tenant, or any tenant, for reconnaissance.
- Keeping a tenant enrolled after the client has told you to stop.
If a client revokes access from their own Microsoft portal, that is the end of it. Do not attempt to re-establish access without fresh authorization.
3. Do not misrepresent what the output says
An Armada Report states which controls were verified at a moment in time, and which were not. It is not an audit, not a certification, and not a guarantee.
Not allowed:
- Presenting a Report as a compliance certification — SOC 2, HIPAA, CMMC, PCI, CIS, ISO, cyber-insurance qualification, or any other framework.
- Describing a Report as an audit, an assurance engagement, or a third-party attestation of security.
- Removing, obscuring, or editing the honesty labels.
not_verifiedmeans the control was not checked. It does not mean it passed. Presenting a not-verified control as passing, or omitting it so the report reads as complete, is prohibited. - Presenting a score computed over 2 verified controls as a full assessment of 13.
- Presenting a mock-mode result as a real scan. Every attestation records whether it came from live or mock data. That field exists so this cannot happen by accident, and removing it is prohibited.
- Editing scores, statuses, timestamps, or catalog versions in an exported Report.
- Claiming Armada monitors, defends, or responds to anything. It does not. It reads, scores, and reports.
- Attributing to Armada any certification we do not hold. We have no SOC 2 report.
If your client asks “does this mean we’re compliant?”, the honest answer is no, and the product is built so you can give that answer with a straight face. Do not undercut that.
4. Do not attack, probe, or reverse engineer the platform
Not allowed:
- Reverse engineering, decompiling, or disassembling the platform, or attempting to derive the source code, control catalog logic, or scoring methodology.
- Probing, scanning, or penetration-testing our infrastructure without prior written permission. Ask first — we will usually say yes to a scoped test with a real customer behind it.
- Circumventing authentication, rate limits, or tenant isolation.
- Accessing another customer’s data, tenants, attestations, or reports, or attempting to.
- Uploading malware, or using the platform to store or transmit anything unlawful.
- Automating the platform in a way that degrades it for others.
- Interfering with the hash chain — attempting to forge, alter, backdate, or replay an attestation or its signature.
5. Do not resell the raw platform
Your white-label license lets you deliver the service under your own brand, to your own clients, as part of your own service offering. That is the point of the product.
Not allowed without a separate written agreement:
- Reselling, sublicensing, renting, or leasing platform access itself to another MSP, reseller, or service provider.
- Sharing your credentials or console access outside your own organisation.
- Building a competing product from the platform, its catalog, its scoring, or its attestation format.
- Offering the platform’s raw functionality as a standalone product rather than as part of your service.
Distributing Reports to your own end clients is expressly permitted and encouraged. The line is between delivering a service and reselling the tool.
6. Do not misuse other people’s data
- Use the platform only for security-posture assessment of the tenants you enrolled.
- Do not use Reports, scores, or tenant data for any purpose your client has not agreed to — including marketing lists, resale, or benchmarking that identifies them.
- Do not attempt to extract raw telemetry from the platform. It is not there. The architecture holds scores, statuses, timestamps, and hashes, and nothing else.
7. Reporting a problem
If you find a security vulnerability in the platform, email hello@armada-solutions.com with “Security” in the subject line. Report it to us before disclosing it anywhere else, and give us a reasonable window to fix it. We will not pursue anyone who reports a genuine finding in good faith and does not exploit it, does not access other customers’ data, and does not degrade the service.
If you see another customer misusing the platform, tell us at the same address.
8. Enforcement
We can:
- Ask you to stop. For most issues this is the first and only step.
- Suspend access immediately, without prior notice, where we reasonably believe a tenant was enrolled without authority, a Report is being presented as a certification, the platform’s integrity is under attack, or there is a legal or safety risk to a third party. We will tell you as soon as practicable after suspending, and explain why.
- Terminate for material or repeated breach, under Terms of Service §17.
- Disclose where law or valid legal process requires it.
We are two people, not an enforcement bureaucracy. In practice, an honest mistake gets an email. Enrolling tenants without authority, or dressing a Report up as a certification, gets a suspension — those are the two that damage the product’s entire premise.
Suspension does not entitle you to a refund of fees for the suspension period where the suspension was justified.
9. Changes
We may update this policy. Material changes take effect 30 days after we email notice to existing customers, matching Terms of Service §21.