Rocheston · Vulnerability Vines AI

Vulnerability Vines AI
Terms of Service

Effective date: October 9, 2026
Version: 1.0
Website: https://vines.rosebird.org

Important notice

Vulnerability Vines AI is a security assessment tool for lawful, expressly authorized testing. Security scans may interfere with systems, alter data, expose vulnerabilities, trigger alerts, interrupt services, or produce inaccurate or incomplete results. You must establish and maintain authority to test every target and accept the responsibilities stated below. Sections 24 through 29 contain important provisions concerning warranties, assumption of risk, liability, indemnification, and disputes. Mandatory rights that cannot lawfully be excluded remain protected.

1 The agreement and the contracting parties

1.1 These Terms of Service ("Terms") govern access to and use of Vulnerability Vines AI, also called "Vines," its website, associated applications, scan engines, APIs, account features, reports, AI assistance, and other functionality offered under these Terms (collectively, the "Service"). The Service is operated by Rocheston ("Rocheston," "we," "us," or "our").

1.2 "You" or "Customer" means the individual accepting these Terms or, where that individual acts with authority on behalf of an organization, that organization. "Authorized Users" means individuals you permit to access the Service under your subscription and within its applicable user limits. "Consumer" means an individual entitled to mandatory consumer protections because of the purpose and circumstances of the transaction, as determined by applicable law. A professional email address or a statement in these Terms does not, by itself, eliminate Consumer status.

1.3 You enter into this agreement by selecting an acceptance checkbox or button that clearly refers to these Terms, executing an order that incorporates them, or otherwise affirmatively accepting them through a legally effective process. Where legally sufficient notice has been given and applicable law permits, your subsequent use also constitutes acceptance. If you do not agree, do not create an account, purchase a plan, submit a target, or use the Service. Account access, third-party authentication, and payment alone do not give you permission to test any target.

1.4 An accepted order or checkout confirmation specifies your plan and commercial entitlements (an "Order"). A separately signed master agreement overrides these Terms only to the extent it expressly addresses the same subject. An executed data processing agreement ("DPA") and mandatory transfer terms control their respective data-protection subject matter. An Order controls its stated prices, quantities, and subscription periods; other amendments to these Terms require express agreement by an authorized Rocheston representative. These Terms otherwise control use of Vines and supersede inconsistent general Rocheston website terms for Vines, including inconsistent dispute-resolution provisions. Other Rocheston products retain their own terms.

1.5 The Vines Privacy Policy at https://vines.rosebird.org/privacy.html explains personal-information processing. It is not a substitute for a DPA where one is legally required. These Terms do not expand data-processing permissions beyond applicable law, a controlling DPA, or applicable privacy notices and consents. Purchase orders, procurement portals, emails, or other Customer documents do not amend this agreement merely because Rocheston processes an order or accepts payment.

2 Eligibility and authority

2.1 You must be at least 18 years old and have legal capacity to contract. If a higher minimum age applies to your transaction, that higher age applies. You must not use the Service where doing so is prohibited by applicable law or binding sanctions restrictions.

2.2 If you act for an employer, client, government body, partnership, or other organization, you represent that you have authority to bind that organization to this agreement and authorize the activities you request. You must accurately identify the contracting organization and your role. You may not claim organizational authority merely because you possess an email account, job title, certification, administrative login, or payment card.

2.3 You are responsible for selecting competent personnel to configure and supervise scans, interpret findings, handle sensitive information, and validate remediation. A subscription does not establish professional competence, confer any certification, or create authority to conduct penetration testing for others.

3 Accounts and access security

3.1 Provide accurate registration, billing, and contact information and keep it current. Keep passwords, identity-provider accounts, API tokens, session cookies, recovery methods, and devices secure. Use available security controls appropriate to the sensitivity of the Service. Do not share individual credentials or allow access beyond your plan's permitted users.

3.2 You are responsible for instructions and activity submitted by you and your Authorized Users, and for unauthorized account activity to the extent caused by your failure to meet these obligations. This allocation does not transfer Rocheston's responsibility for its own breach of security obligations or override protections required by law. Notify us promptly of suspected compromise, unauthorized scans, lost credentials, or misuse, and revoke affected access using available controls.

3.3 Where supported, an organization's authorized administrator may manage access, plans, targets, and information in that organization's workspace. Do not place personal or unrelated client information in a workspace controlled by someone else. Changes of workspace ownership, account recovery, and subscription transfers may require reasonable verification. We may refuse access or transfers when authority cannot reasonably be established.

3.4 Google, Apple, or other identity providers authenticate accounts under their own terms. Access may be affected by their availability, revocation decisions, or account changes. You must maintain a functioning contact channel, including any private relay address you elect to use. We will not merge accounts solely because their display names match; account linking may require proof of control.

4 Permitted use and service license

4.1 Subject to this agreement and payment of applicable fees, Rocheston grants you a limited, nonexclusive, nontransferable, nonsublicensable right, during your authorized access period, to use the Service for legitimate security assessment, vulnerability management, remediation support, and related internal operations within your plan. Authorized automation through documented APIs is permitted within published limits.

4.2 You may test your own systems and systems of clients who have expressly authorized the relevant testing and use of the Service. Providing assessments to authorized clients is permitted within your plan's target, user, and usage allowances. Selling account access, operating an unapproved public scanning service, sublicensing the platform, or offering white-label or reseller access requires a separate written agreement. Client ownership of a target does not establish your authority to bind that client to this agreement.

4.3 You may download, retain, and share reports for authorized security, audit, compliance, remediation, or client-delivery purposes, subject to the target owner's rights and the confidentiality obligations below. Authorized report use does not permit resale of the Service, redistribution of proprietary scanning engines, or misleading claims that Rocheston has certified a target.

4.4 Access is limited to the features actually made available to your account. Feature descriptions, examples, demonstrations, integrations, and planned capabilities do not entitle you to functionality outside your Order. Nothing in this paragraph overrides an express contractual commitment or an accurate description of the product you purchased on which you are legally entitled to rely.

5 Mandatory target authorization

5.1 A "Target" is any domain, subdomain, URL, IP address, network range, application, API, host, device, repository, cloud resource, account, container, or other system submitted for testing or reached through your requested scan. Before each scan, including automated and recurring scans, you represent and warrant that you own the Target with authority to authorize the testing, or hold current, explicit, documented permission from every person or entity whose approval is required.

5.2 Your authorization must cover the actual techniques, scope, credentials, traffic volumes, scan window, data handling, and potential effects of the selected scan. Where the work is for a client or third party, obtain written authorization identifying the Target and confirming that you may use Rocheston and its authorized infrastructure and service providers to perform the agreed testing. Retain the authorization and associated scope records while testing continues and for a reasonable lawful period afterward sufficient to address an authorization dispute.

5.3 Ownership of a domain, subscription to a cloud service, control of a DNS record, or possession of a login does not automatically authorize testing of a hosting provider, shared server, content-delivery network, identity provider, payment processor, managed platform, other tenant, or connected third-party system. Obtain any additional permissions required by those providers and their applicable testing policies.

5.4 A public website, visible IP address, open port, missing password, software vulnerability, research interest, or absence of an express objection is not permission under this agreement. A bug-bounty or vulnerability-disclosure program supplies permission only within its current, applicable scope and conditions, including restrictions on automated testing, timing, methods, and cloud-hosted scanners. Do not treat a general security-research policy or prosecutorial policy as a substitute for the authorization required by these Terms.

5.5 Each submission, queued job, API request, scan restart, and recurring schedule constitutes your continuing instruction and renewed representation that the required authority exists. You must stop testing and cancel pending or recurring jobs immediately if permission expires, is withdrawn, becomes disputed, or no longer covers the proposed activity. Notify Rocheston promptly if you cannot stop an unauthorized or out-of-scope job through available controls.

5.6 We may require evidence of identity, target control, scope, or written permission before or during a scan, and may refuse or stop testing if that evidence is inadequate or circumstances create a reasonable concern. Our verification, acceptance of a target, processing of a payment, or failure to request evidence is not a legal determination or confirmation of your authority. We do not grant rights in third-party systems and do not promise immunity from complaints, investigation, or liability.

6 Target scope and changes

6.1 You must accurately configure included and excluded hosts, addresses, ports, paths, accounts, repositories, test methods, time windows, and request limits. Broad discovery options, crawling, redirects, authentication flows, and linked resources may encounter other systems. You must exclude systems outside your authority and must not intentionally use discovery, redirects, name resolution, or integrations to expand a scan beyond its authorized scope.

6.2 Recheck scope when domain ownership, DNS records, dynamic addresses, cloud allocations, hosting arrangements, personnel, or customer permissions change. Cancel schedules associated with reassigned addresses, expired domains, transferred assets, or former clients. A previously authorized scan does not establish permission for a later scan.

6.3 Do not submit internal management interfaces, loopback or link-local resources, cloud metadata endpoints, unrelated private networks, or Rocheston infrastructure as indirect targets through redirect or resolution manipulation. Legitimate testing of an internal network is permitted only through an expressly supported deployment or connection method and within documented authorization. A successful connection is not proof of permission.

6.4 If an out-of-scope resource, unexpected personal information, third-party secret, or unintended system effect appears, stop the affected activity, limit further access and disclosure, preserve only evidence you may lawfully retain, and promptly notify the appropriate target owner and Rocheston. Do not exploit or further investigate beyond the authority you possess.

7 Scanning risks and your operational responsibilities

7.1 Security testing is inherently intrusive. Depending on the enabled feature, scans may discover hosts and services, crawl pages, submit requests and forms, authenticate with supplied credentials, exercise application behavior, and send diagnostic or active-test payloads. Even a scan described as limited, passive, safe, or read-only may have unexpected effects because of target behavior, configuration, defects, or dependencies.

7.2 Potential effects include increased load and costs; latency; failed transactions; account lockouts; triggered emails or workflows; altered, duplicated, corrupted, or deleted records; exhausted storage or resources; application or device crashes; service interruption; firewall or fraud alerts; blocked addresses; exposure of secrets or personal information; and third-party complaints. The existence of timeouts, rate limits, exclusions, and other safeguards does not guarantee that a scan will be nondisruptive or complete within a particular time.

7.3 Before testing, assess suitability, obtain approvals, notify relevant operations and security teams, use appropriate maintenance windows, establish tested backups and recovery procedures, and select the least intrusive settings appropriate to the objective. Use isolated test environments and synthetic data where practicable. You remain responsible for excluding sensitive workflows, monitoring the target, verifying scan settings, and deciding whether a production scan is appropriate.

7.4 You are responsible for your decisions to modify firewall rules, identity controls, WAF settings, network routes, tunnels, permissions, or other defenses to enable scanning. Any such change must be independently evaluated, narrowly scoped, time-limited, and reversed when no longer needed. Documentation, examples, or AI suggestions do not remove your responsibility to secure the resulting configuration.

7.5 Stop controls may not immediately recall requests already sent, stop third-party processing, undo target-side effects, or terminate all externally queued activity. You must maintain your own emergency response and recovery procedures. Rocheston is not an emergency response service unless a separate written agreement expressly provides one.

7.6 You bear your own authorized testing, connectivity, hosting, bandwidth, restoration, and operational costs, subject to any remedy you retain under this agreement or applicable law. The allocation of testing responsibilities does not authorize Rocheston to act outside your lawful instructions or relieve it of nonwaivable obligations.

8 Prohibited uses

8.1 You must not use the Service, allow it to be used, or knowingly assist another person to:

  1. test a Target without the authorization required by Section 5 or exceed the approved scope, methods, time window, or data-access permissions;
  2. conduct malicious reconnaissance, retaliatory scanning, indiscriminate scanning of unrelated targets, or testing intended to facilitate unlawful access, theft, fraud, sabotage, extortion, or harassment;
  3. conduct denial-of-service or destructive stress testing, deploy malware or ransomware, establish unauthorized persistence, move laterally beyond an approved target, steal credentials, or extract data beyond what is necessary and authorized to evidence a finding;
  4. perform credential stuffing, password spraying, phishing, social engineering, spam, surveillance, or impersonation, except for a specific feature separately approved by Rocheston in writing and expressly authorized by all required target owners;
  5. knowingly target operational medical devices, emergency services, transportation controls, industrial control systems, nuclear facilities, weapons systems, or other safety-critical infrastructure without a separate written agreement with Rocheston and all required owners that expressly approves the proposed testing;
  6. evade target verification, blocklists, safety controls, subscription limits, payment requirements, rate limits, tenant boundaries, or other restrictions; conceal an unauthorized target through proxies, redirects, manipulated DNS, encoded addresses, or misleading descriptions;
  7. attack, probe, disrupt, or exploit Rocheston's production infrastructure, other users' accounts, or supporting providers without separate express written authorization; a demonstration or training target is authorized only within its published exercise scope;
  8. use stolen, leaked, or improperly obtained accounts, keys, payment methods, source code, personal information, or other material;
  9. falsify findings, remove material context from evidence, forge authorization, misrepresent the origin of a report, or claim a security or compliance certification that has not actually been issued;
  10. disclose target vulnerabilities or sensitive reports without authority, threaten disclosure to obtain money or access, or use findings to harm a person or organization;
  11. sell, rent, transfer, sublicense, scrape, mirror, or commercially redistribute the Service or Rocheston's proprietary materials outside the rights expressly granted by this agreement;
  12. reverse engineer, decompile, or attempt to extract proprietary software, nonpublic rules, models, credentials, or infrastructure information, except to the extent an applicable open-source license or a right that cannot be excluded expressly permits it;
  13. use Rocheston's proprietary materials or nonpublic outputs to build a substitute scanning service or train a competing model without written permission; this does not restrict your independent development, your own data and findings, legally protected activities, or rights under an applicable open-source license;
  14. interfere with abuse investigations, intentionally corrupt logs, create accounts to evade suspension, or misuse support, authentication, billing, or recovery mechanisms;
  15. upload unlawful material, infringe intellectual property or privacy rights, or violate applicable computer-misuse, interception, privacy, export-control, sanctions, or other laws.

8.2 Ordinary, authorized use of an expressly supported active-scanning feature within its documented scope is not prohibited solely because it sends diagnostic test payloads. This qualification does not permit destructive testing, unauthorized data extraction, or any activity outside the authority and limits stated above.

8.3 These Terms do not prohibit truthful reviews, lawful complaints, protected whistleblowing, reporting suspected violations to regulators, or other conduct protected by mandatory law. Reporting a concern does not authorize further intrusion or public disclosure of third-party secrets.

9 Authenticated scans and sensitive credentials

9.1 Where supported, provide only credentials you are entitled to supply and authorize us to use for the specified assessment. Prefer dedicated, least-privilege test accounts with limited validity. You are responsible for configuring their permissions, restricting sensitive operations, and revoking or rotating credentials after testing or suspected exposure.

9.2 Do not enter passwords, private keys, tokens, full payment-card data, or sensitive personal information into ordinary support messages, chat prompts, sample code, or fields not designated for that information. Scan requests, responses, URLs, screenshots, logs, and report exports may contain confidential data or secrets. Review and redact material before sharing it.

9.3 Possession of credentials does not warrant that a scan will authenticate successfully, preserve a session, reach every protected area, avoid all state changes, or detect every authorization weakness. You must independently verify coverage and target behavior.

10 Schedules apis and customer automation

10.1 Scheduled scans, CI/CD jobs, API clients, scripts, webhooks, and integrations are your instructions. You are responsible for their targets, permissions, timing, retries, concurrency, recipient addresses, notification destinations, and continued validity. Cancel jobs at their originating systems as well as in Vines when necessary.

10.2 Use documented interfaces and comply with technical limits. We may queue, throttle, reject, pause, or change execution priority to protect the Service, targets, or other users. Published schedules and status indicators are operational tools and do not guarantee an exact start time, completion time, delivery, or continuous monitoring unless an applicable written service-level agreement expressly states otherwise.

10.3 Keep API secrets confidential, restrict them to approved systems, revoke unused access, and implement controls against repeated or unintended requests. You are responsible for automated decisions made by your own pipelines, including release blocking, remediation deployment, ticket creation, and report distribution.

11 Findings ai assistance and professional judgment

11.1 Reports, vulnerability descriptions, severity scores, threat feeds, summaries, code suggestions, compliance mappings, and Aina or other AI-generated responses are decision-support materials. They may be incomplete, outdated, misleading, inconsistent, or incorrect. False positives, false negatives, coverage gaps, model errors, and failures to detect known or emerging vulnerabilities are possible.

11.2 Results describe the scope and conditions observed during a particular assessment. A completed scan, low score, resolved finding, or absence of findings does not establish that a system is safe, secure, free of malware, legally compliant, or protected against future attacks. A scan may miss vulnerabilities because of access restrictions, encryption, configuration, dependencies, timing, evasive behavior, unavailable services, or limitations of the selected techniques.

11.3 Validate findings, evidence, recommendations, and generated code through appropriately qualified personnel before acting. Test changes in a suitable environment, obtain change approval, and maintain rollback and recovery arrangements. Do not execute generated instructions or disclose information merely because a report or AI assistant recommends it; target content and external sources may themselves be malicious or misleading.

11.4 The Service does not provide legal, regulatory, insurance, financial, medical, or other licensed professional advice. It is not an independent audit, penetration-testing certification, incident response engagement, managed security service, or guarantee of compliance unless a separate written agreement specifically provides that deliverable. References to NIST, OWASP, CISA, CVSS, EPSS, ISO, SOC, PCI DSS, or other organizations or frameworks do not establish their endorsement, accreditation, or approval of a target or report.

11.5 You remain responsible for selecting controls, prioritizing remediation, determining reporting obligations, maintaining insurance, and deciding whether further testing or professional advice is necessary. We do not assume a duty to monitor your systems continuously, notify every person affected by a finding, implement a fix, or detect an ongoing attack merely because you use the Service.

12 Customer data and processing permission

12.1 "Customer Data" means targets, scope settings, credentials, source material, documents, prompts, technical evidence, and other information you supply or authorize us to collect from your Targets, together with target-specific findings attributable to that information. As between you and Rocheston, you retain your rights in Customer Data; rights belonging to target owners, individuals, and other third parties remain theirs.

12.2 You grant Rocheston a nonexclusive, limited permission to receive, transmit, host, reproduce, analyze, and otherwise process Customer Data as reasonably necessary to provide your requested Service, produce and deliver results, troubleshoot support requests, protect the Service from misuse, meet legal obligations, and perform an applicable agreement. Authorized service providers may perform those activities subject to applicable confidentiality, privacy, and data-processing requirements. This permission lasts only for those purposes and applicable retention periods; it is not a transfer of ownership.

12.3 You represent that you have the rights, notices, lawful bases, and consents required for the Customer Data and instructed processing, including testing data belonging to employees, clients, or other people. Your authority over a network does not eliminate rights in the information held on that network. You must limit collection to what is reasonably necessary for the authorized assessment.

12.4 The permission in this section does not authorize public disclosure of private Customer Data, sale of personal information, or unrelated general-purpose model training. Any separate training, analytics, or independent processing must have an applicable lawful basis and be consistent with controlling notices, agreements, and any consent that is required. Customer configuration or consent cannot waive another person's mandatory privacy rights.

12.5 Do not intentionally submit classified information, export-restricted technical data, payment-card security codes, or regulated data requiring special contractual or technical protections unless we have expressly agreed in writing to those protections and the Service is configured accordingly. Where the law requires a DPA, business associate agreement, or other special arrangement, it must be in place before that processing begins. A marketing reference to a compliance framework is not such an agreement.

12.6 Legal roles depend on the actual processing. Where we process personal data solely for your organization's documented assessment instructions, a required DPA governs that processing. Where we determine purposes for account administration, billing, fraud prevention, or other independent activities, the Privacy Policy explains the applicable processing. Neither party may avoid statutory duties by assigning itself a label in these Terms.

12.7 Processing and support may involve locations and providers identified in applicable notices or contractual documentation. Where international-transfer safeguards are required, they must be established separately as applicable; accepting these Terms alone is not a blanket waiver of transfer restrictions. We may decline instructions that are unlawful or cannot be performed under the required protections.

13 Confidentiality security and retention

13.1 Each party will protect the other's nonpublic information received under this agreement using reasonable care and use it only to perform this agreement or exercise lawful rights. Customer scan evidence, credentials, private reports, and nonpublic target information are confidential whether or not labeled. Rocheston's nonpublic software, methods, pricing proposals, credentials, and security information are likewise confidential. Disclosure is permitted to personnel, professional advisers, and providers with a legitimate need to know and appropriate confidentiality obligations.

13.2 Confidentiality does not cover information the receiving party can demonstrate was lawfully known without restriction, independently developed, lawfully received from another source without restriction, or made public without breach. Required disclosures must be limited to what is legally necessary; where lawful and practicable, the receiving party will give advance notice and reasonable assistance with protective measures.

13.3 Each party must satisfy security obligations imposed on it by law and any controlling agreement. No system can promise absolute security. You are responsible for securing your endpoints, downloads, reports, notification channels, integrations, and access permissions. That responsibility does not release Rocheston from its own security or breach-notification duties.

13.4 The Service is not your backup, legal archive, or evidence-preservation service unless specifically contracted as such. Retention, deletion, export availability, and backup handling are governed by applicable notices, your plan, any DPA, and law. Export information you are entitled to retain before account closure or the end of an applicable retention period. Do not assume that historical reports, deleted data, logs, or credentials can be recovered.

13.5 We may preserve relevant records when reasonably necessary for a specific legal hold, billing obligation, security investigation, abuse complaint, or defense of a claim, subject to applicable law and data minimization. Retained records remain protected and are not retained indefinitely merely because retention could be useful. Mandatory deletion and access rights remain subject to their legally applicable exceptions.

14 Integrations third party services and open source

14.1 Features may interoperate with identity providers, payment processors, hosting services, vulnerability feeds, scanning components, AI providers, repositories, communication systems, or other third-party services. Their availability and policies can affect the Service. We do not promise uninterrupted access to an independent third-party service or the accuracy of its data. This does not excuse obligations we expressly undertake or legally retain for our selected processors or subcontractors.

14.2 When you enable an optional integration, you authorize the configured exchange of information within its disclosed function and scope. You must have authority to connect the accounts and choose recipients. Verify destination permissions before sending a report to a messaging channel, ticket, webhook, or repository. Removing an integration may not delete copies already delivered to another service.

14.3 Third-party and open-source components remain subject to their applicable licenses. Those licenses control any rights they expressly grant in the components themselves. These Terms do not restrict rights that the applicable license requires us to preserve, and do not grant ownership of third-party technology or additional rights in Rocheston's hosted infrastructure.

15 Plans quotas and measurement

15.1 Your Order or the plan details presented before purchase specify the applicable subscription period, permitted targets, scans, users, concurrency, storage, API access, and other entitlements. A listed target allowance, annual scan allowance, and re-scan allowance are distinct limits unless the purchased offer expressly states otherwise. "Unlimited" re-scans apply only to the qualifying targets and period described in that offer and remain subject to reasonable technical safety controls.

15.2 Scan-credit consumption, resets, expiry, rollover, and the treatment of interrupted or failed jobs must follow the rules disclosed for the purchased plan. These Terms do not create an undisclosed charge or authorize us to retroactively change how purchased allowances are counted. Metered overages or additional charges require an applicable agreed pricing arrangement or a separate purchase.

15.3 We may investigate unreasonable resource consumption, misuse, and attempts to defeat limits. Protective throttling does not authorize a material reduction of paid entitlements without the notice and remedies required by this agreement or law. Free and promotional allowances may change prospectively, subject to any specific promise made when offered.

16 Fees billing and payment

16.1 You agree to pay the prices, currency, billing intervals, applicable taxes, and charges clearly disclosed in your Order or checkout. Unless stated otherwise, fees are payable in advance for the selected period. Taxes that we are required to collect will be charged as applicable; you are responsible for taxes on your purchase other than taxes on Rocheston's net income.

16.2 You authorize the designated payment processor to process the specific charges you approve. Provide a valid payment method and accurate billing information. Card issuer, exchange-rate, and bank charges may be governed by your separate financial arrangements. We may use payment providers, including Stripe, subject to their applicable payment terms and privacy notices.

16.3 If payment fails, we may request a replacement method, retry authorized charges in accordance with applicable rules, and suspend paid access after any required notice. We may recover reasonable, documented collection costs for undisputed overdue business debts to the extent lawful. We will not impose an undisclosed penalty or charge fees prohibited by law.

16.4 Notify us promptly of a suspected billing error so we can investigate. Nothing in these Terms eliminates rights to dispute an unauthorized or incorrect charge, contact your payment provider, or exercise statutory remedies. Fraudulent chargebacks, knowingly false payment claims, and deliberate payment evasion constitute misuse. We will not characterize a good-faith dispute as fraud solely because you contest a charge.

17 Automatic renewal cancellation and refunds

17.1 A subscription renews automatically only if automatic renewal, the amount or clearly explained pricing method, billing frequency, renewal period, cancellation deadline, and cancellation method are clearly disclosed and you provide the required affirmative consent. If your Order is expressly nonrenewing, access ends at the stated expiry unless you make a new purchase. Acceptance of these Terms alone is not consent to an undisclosed recurring charge.

17.2 For an authorized recurring subscription, you authorize charges at each disclosed renewal interval until cancellation. We will provide required purchase acknowledgments, renewal or trial reminders, material-change notices, and any additional consent or remedies required by applicable law. Renewal-price changes are prospective and subject to those requirements; a general right to change prices does not authorize charging a higher amount without required notice or consent.

17.3 You may cancel automatic renewal at any time using the online cancellation mechanism made available with your account or subscription confirmation. If that mechanism is unavailable or you need assistance, contact [email protected]. We will not make cancellation unreasonably difficult or delay a timely cancellation to impose another charge. Any additional cancellation channels required by law remain available.

17.4 Unless your Order or mandatory law provides otherwise, cancellation stops future renewals and access continues through the current paid period. Removing the app, revoking a social-login permission, or abandoning the account is not itself a cancellation request. A clearly communicated account-deletion request will also be treated as a request to stop future direct-billed renewals; purchases billed by an app marketplace must be managed through that marketplace's applicable process, and we will provide appropriate direction.

17.5 Except where an Order states otherwise, these Terms expressly provide a refund, or law requires one, paid fees are nonrefundable for a period already begun and unused allowances have no cash value. This does not exclude remedies for unauthorized charges, failure to supply the purchased service, legally required withdrawals, or other nonwaivable rights. Statutory cooling-off rights are not waived by these Terms; any lawful request for early performance and acknowledgment of its consequences must be obtained separately when required.

17.6 An upgrade, downgrade, added capacity, or replacement plan takes effect on the date and at the price disclosed and accepted for that change. Proration and credits apply only as disclosed or required by law. Review the change before confirming it. We do not guarantee that canceling an account will immediately erase all legally retained records.

18 App marketplaces and cross platform access

18.1 If you obtain an application or subscription through Apple or another marketplace, that marketplace's applicable purchase, billing, cancellation, refund, and usage rules also apply. Website terms do not authorize us or you to bypass a marketplace's payment or distribution requirements. External checkout is offered within an application only where permitted under the applicable platform rules and legal requirements.

18.2 Access across web, desktop, and mobile interfaces depends on the purchased plan, supported features, and successful association with the correct Vines account. A marketplace subscription and a website subscription do not automatically merge merely because the same name or email appears on both. We may require reasonable proof of purchase or account control to restore or link access. Contact us if duplicate billing occurs.

18.3 Any separate application license and mandatory marketplace end-user terms govern the application itself. These Terms govern the Vines service relationship to the extent consistent with those controlling requirements. Apple and other marketplaces are not parties to the Vines service agreement merely because they distribute an application or process a payment.

19 Intellectual property reports and feedback

19.1 Rocheston and its licensors retain all rights in the Service, proprietary software, interfaces, report layouts, documentation, trademarks, nonpublic methods, and other preexisting or independently developed materials. The Service is licensed, not sold. No rights are granted by implication beyond those expressly stated here or under a controlling license.

19.2 Your Customer Data and target-specific facts remain subject to Section 12. To the extent a report or output contains Rocheston-owned material, we grant you a nonexclusive license to use, reproduce, annotate, and share the report for the authorized purposes in Section 4, subject to payment of applicable fees. That license survives termination for reports lawfully obtained and paid for, and does not authorize continued access to the platform. AI output may not be unique or eligible for exclusive rights; we do not promise exclusive ownership or noninfringement of it.

19.3 Preserve applicable proprietary notices and distinguish your edits from the original findings. Do not misstate the scan date, scope, methodology, origin, or limitations, or represent an edited report as Rocheston's unchanged assessment. You may make truthful, lawful references to Vines; using Rocheston branding to imply certification, sponsorship, partnership, or endorsement requires authorization.

19.4 If you voluntarily provide nonconfidential product suggestions or feedback, you grant us a perpetual, worldwide, royalty-free right to use and implement that feedback without compensation. This permission does not include private Customer Data, target secrets, personal information, or confidential materials merely because they appear in a support conversation. We will obtain appropriate permission before using your name, logo, or private report as a public testimonial or case study.

20 Abuse complaints investigations and cooperation

20.1 Report suspected unauthorized scanning, compromised credentials, infringement, or misuse to [email protected], identifying the relevant Target, approximate time and time zone, source details, and available evidence. We may request proof that you control the affected Target or are entitled to make the request. Do not send secrets or unnecessary personal information in the initial report.

20.2 We may review relevant operational records and Customer Data to the extent necessary and lawful to investigate abuse, respond to complaints, validate authority, protect the Service, comply with legal process, and enforce this agreement. We may restrict access while investigating. These rights do not create an unlimited surveillance permission or eliminate applicable confidentiality and privacy obligations.

20.3 We may cooperate with competent authorities, courts, affected providers, or target owners where legally required or otherwise lawful and reasonably necessary to address actual or suspected misuse. Disclosure will be limited to an appropriate lawful basis and necessary information. We may preserve relevant evidence and provide notice when permitted and appropriate; we do not promise advance notice where prohibited or where it would materially undermine a lawful investigation.

20.4 You must promptly provide reasonable evidence of authorization and cooperate with a legitimate investigation concerning your scans. Deliberate misrepresentation, refusal to substantiate authority, or continued activity after a justified stop request may result in suspension or termination. We are not required to adjudicate ownership disputes or continue a scan while authority remains uncertain.

21 Service changes support and availability

21.1 We may maintain, update, patch, replace, or retire components, rules, integrations, and interfaces. Scanning capability and results may change as targets, third-party sources, threats, and detection methods change. No uptime, response-time, coverage, remediation, or support-level commitment applies unless expressly included in your Order or a signed service-level agreement.

21.2 For a material adverse change to paid core functionality during a prepaid term, we will give reasonable advance notice where practicable and offer substantially equivalent functionality or the termination and refund remedy in Section 22.3. Immediate changes may be necessary for security, legal compliance, third-party withdrawal, or prevention of harm; required remedies still apply.

21.3 Free, trial, beta, preview, and experimental functionality may have additional limitations, may change or end, and is excluded from service-level commitments unless expressly included. It remains subject to mandatory law, confidentiality obligations, and the data-processing terms that actually apply. Do not use experimental functionality for safety-critical or irreversible decisions.

22 Suspension termination and consequences

22.1 We may immediately block a Target, stop or queue scans, restrict a feature, or suspend an account when reasonably necessary to address unauthorized activity, suspected compromise, harmful traffic, legal requirements, infringement, nonpayment, or a material violation of these Terms. We may act before completing an investigation where delay could expose a person, system, or the Service to harm. We will provide an explanation and a reasonable opportunity to address the issue when lawful and appropriate.

22.2 We may terminate for a material breach that remains uncorrected after a reasonable notice and cure period, or immediately for a serious, repeated, unlawful, dangerous, or incurable breach. You may terminate by stopping use and requesting account closure; outstanding authorized fees remain payable and cancellation is governed by Section 17. Suspension does not permit us to continue charging for periods when the law or a controlling agreement requires billing to stop.

22.3 If we terminate a paid subscription for our convenience, permanently discontinue its paid core service without a substantially equivalent replacement, or materially reduce that core service and cannot reasonably remedy the reduction, you may terminate the affected subscription and receive a prorated refund of prepaid fees for its unused remaining period. Other mandatory remedies remain available. A justified termination for your material breach ordinarily does not entitle you to a refund except as law requires.

22.4 When access ends, cancel external automation, stop using the Service and APIs, and revoke credentials issued for testing. Existing reports may be retained only as Section 19 and third-party rights permit. Data export and deletion remain subject to Section 13, any DPA, lawful preservation obligations, and required access rights. We need not restore unlawfully held data or provide access that would expose another party's information.

22.5 Provisions intended by their nature to survive continue to apply, including accrued payment obligations, confidentiality, permitted retained-report use, intellectual property, responsibility for prior scans, liability limitations, indemnification, dispute provisions, and legally required data protections. Survival does not authorize processing beyond a lawful retention purpose.

23 Your representations and warranties

23.1 Throughout your use, you represent and warrant that your registration and authorization information is accurate; your instructed scans are lawful and properly scoped; you possess the rights necessary for Customer Data and testing; you will comply with applicable laws and provider policies; and you will not make unauthorized promises, warranties, or representations on Rocheston's behalf.

23.2 You are responsible for your agreements with clients, employers, target owners, contractors, and Authorized Users. Obtain their required approvals and make relevant testing risks and data-handling arrangements clear. You may not promise a client that Vines guarantees security, assumes that client's operational risks, or gives that client contractual rights against Rocheston unless Rocheston has expressly agreed in writing.

24 Disclaimer of warranties

24.1 TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, AND EXCEPT FOR EXPRESS COMMITMENTS IN A CONTROLLING WRITTEN AGREEMENT, THE SERVICE AND ITS REPORTS, OUTPUTS, RECOMMENDATIONS, AI FEATURES, AND RELATED MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE." ROCHESTON DISCLAIMS IMPLIED OR STATUTORY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NONINFRINGEMENT, ACCURACY, AND ANY WARRANTY ARISING FROM A COURSE OF DEALING OR USAGE OF TRADE, TO THE EXTENT THOSE WARRANTIES MAY LAWFULLY BE DISCLAIMED.

24.2 WE DO NOT WARRANT THAT THE SERVICE WILL FIND EVERY VULNERABILITY; PREVENT A BREACH, ATTACK, LOSS, OR CLAIM; OPERATE WITHOUT INTERRUPTION OR ERROR; AVOID ALL TARGET DISRUPTION; PRODUCE COMPLETE OR ACCURATE RESULTS; MEET EVERY REGULATORY REQUIREMENT; OR MAKE ANY SYSTEM SECURE. WE DO NOT WARRANT THAT EVERY DEFECT WILL BE CORRECTED OR THAT THIRD-PARTY INFORMATION WILL REMAIN CURRENT.

24.3 Informal advice, demonstrations, general marketing descriptions, and AI statements do not amend this agreement or create additional warranties beyond commitments that are expressly made or legally binding. Nothing here disclaims fraudulent representations, mandatory precontract information obligations, or an express warranty or other protection that applicable law does not allow us to exclude.

25 Assumption of testing risks and allocation of responsibility

25.1 YOU ACKNOWLEDGE THE RISKS DESCRIBED IN SECTIONS 5 THROUGH 11 AND VOLUNTARILY ASSUME THE ORDINARY, REASONABLY FORESEEABLE RISKS INHERENT IN YOUR LAWFULLY AUTHORIZED TESTING CHOICES, TO THE EXTENT PERMITTED BY LAW. You control the choice of Target, authority to test, scan configuration, deployment decisions, and actions taken in response to findings.

25.2 To the extent legally permissible, Rocheston is not responsible for loss caused by your unauthorized Targets, out-of-scope instructions, inaccurate permissions, insecure credentials, failure to maintain suitable backups, unsafe configuration changes, unauthorized report disclosures, or other breach of your responsibilities. Responsibility for a loss involving both parties is determined under this agreement and applicable law; this paragraph does not make you responsible for Rocheston's separate unlawful conduct.

25.3 We do not insure your systems, guarantee business continuity, or assume the target owner's duties. Fees reflect provision of the contracted tool and the allocation of risk in these Terms. You should determine whether your own operational, professional-liability, and cyber-risk arrangements are appropriate. This paragraph does not require a waiver of insurance rights or subrogation without a separate enforceable agreement.

26 Limitation of liability

26.1 SUBJECT TO SECTION 26.5, TO THE MAXIMUM EXTENT PERMITTED BY LAW, ROCHESTON AND ITS AFFILIATES, MEMBERS, MANAGERS, DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, LICENSORS, AND SERVICE PROVIDERS (COLLECTIVELY, THE "ROCHESTON PARTIES") WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICE.

26.2 SUBJECT TO SECTION 26.5 AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE EXCLUDED LOSSES ALSO INCLUDE LOSS OF PROFITS, REVENUE, BUSINESS, ANTICIPATED SAVINGS, GOODWILL, OPPORTUNITY, OR DATA; BUSINESS INTERRUPTION; AND COSTS OF SUBSTITUTE SERVICES, RESTORATION, FORENSIC INVESTIGATION, NOTIFICATION, OR REMEDIATION ARISING FROM USE OR INABILITY TO USE THE SERVICE, WHETHER CHARACTERIZED AS DIRECT OR INDIRECT. THESE EXCLUSIONS DO NOT ELIMINATE A REFUND EXPRESSLY REQUIRED BY THESE TERMS OR A REMEDY THAT CANNOT LAWFULLY BE EXCLUDED.

26.3 SUBJECT TO SECTION 26.5, THE TOTAL AGGREGATE LIABILITY OF ALL ROCHESTON PARTIES FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICE OR THIS AGREEMENT WILL NOT EXCEED THE GREATER OF (A) THE FEES YOU ACTUALLY PAID FOR THE AFFECTED VINES SERVICE DURING THE TWELVE MONTHS IMMEDIATELY BEFORE THE FIRST EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED UNITED STATES DOLLARS (US$100). RELATED EVENTS CONSTITUTE ONE EVENT FOR THIS PURPOSE. MULTIPLE CLAIMS, CLAIMANTS, TARGETS, REPORTS, OR LEGAL THEORIES DO NOT MULTIPLY THAT CAP. A SEPARATELY NEGOTIATED WRITTEN LIABILITY ALLOCATION CONTROLS WHERE APPLICABLE.

26.4 These limitations apply regardless of the form of action, including contract, tort, ordinary negligence, strict liability, misrepresentation other than fraud, or other theory, even if a Rocheston Party was advised that loss was possible or a limited remedy fails of its essential purpose. Each exclusion and limitation is intended to operate independently to the extent enforceable. They do not cap your agreed payment obligations or liabilities under Section 27, except where law requires otherwise.

26.5 NOTHING IN THESE TERMS EXCLUDES OR LIMITS LIABILITY FOR FRAUD, FRAUDULENT MISREPRESENTATION, GROSS NEGLIGENCE, WILLFUL MISCONDUCT, DEATH OR PERSONAL INJURY WHERE EXCLUSION IS PROHIBITED, OR ANY OTHER LIABILITY OR REMEDY THAT APPLICABLE LAW DOES NOT ALLOW TO BE EXCLUDED OR LIMITED. THESE TERMS DO NOT REMOVE NONWAIVABLE CONSUMER, PRIVACY, DATA-PROTECTION, OR STATUTORY RIGHTS, OR RESTRICT A REGULATOR'S POWERS. FOR A CONSUMER, AN EXCLUSION OR CAP APPLIES ONLY TO THE EXTENT LAWFUL AND FAIR UNDER THE APPLICABLE MANDATORY RULES.

26.6 The contract is with the identified Rocheston contracting entity. Solely by acting for that entity, a founder, owner, officer, employee, or representative does not personally undertake its contractual obligations. This does not immunize any person from personal wrongdoing or liability imposed by mandatory law. The Rocheston Parties may enforce the protections expressly granted to them as intended third-party beneficiaries, subject to all stated exceptions.

27 Customer indemnification

27.1 If you act for business or professional purposes, you will defend, indemnify, and hold harmless the Rocheston Parties from third-party claims, demands, proceedings, and resulting damages, judgments, approved settlements, and reasonable legal expenses to the extent arising from: your lack of testing authority; an out-of-scope or unlawful scan you request; your breach of Sections 5 through 10 or 23; Customer Data you unlawfully supply; your infringement of another person's rights; or your unauthorized disclosure or misuse of findings. This includes claims by target owners, hosting providers, affected clients, and individuals whose data you were not entitled to access.

27.2 Indemnification extends to reasonably necessary, documented defense costs and legally recoverable amounts. Regulatory fines or penalties are included only where their indemnification is lawful. It does not cover liability to the extent caused by a Rocheston Party's fraud, gross negligence, willful misconduct, independent infringement, breach of its own data-protection duties, or other conduct for which shifting liability is prohibited. We may not recover twice for the same loss.

27.3 We will give prompt notice of a claim, with delayed notice reducing your obligations only to the extent it materially prejudices the defense. You may control the defense using competent counsel reasonably acceptable to us, and we may participate at our own expense. Where you fail to defend promptly, a material conflict exists, or urgent protection is reasonably necessary, we may control the defense and recover reasonable covered costs to the extent lawful. Neither party may settle a covered claim in a manner admitting fault, imposing a nonmonetary obligation, or failing to release the other affected party without that party's prior written consent, which will not be unreasonably withheld.

27.4 You must reimburse reasonable, documented direct costs we incur because of your intentional or materially negligent misuse, including proportionate investigation and containment costs, to the extent recoverable by law. These are compensatory obligations, not automatic fines or predetermined penalties.

27.5 For a Consumer, no business indemnity or automatic duty to fund a defense is imposed where prohibited or unfair. Any responsibility for third-party loss is limited to the extent recoverable under applicable law because of that Consumer's own culpable breach, unlawful conduct, or infringement. Mandatory defenses and proportionality requirements remain available.

28 Governing law and courts

28.1 Subject to mandatory protections described below, these Terms and disputes arising from them are governed by the laws of the State of New York, United States, without applying conflict-of-law principles that would require another jurisdiction's law. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

28.2 Before commencing an ordinary contractual claim, each party should send a written notice describing the dispute, relevant account, requested resolution, and contact details, and allow 30 days for a good-faith effort to resolve it. Send notices to [email protected] with the subject "Vines Legal Notice." This process is not required before urgent protective relief, a regulator complaint, or a filing needed to preserve a legal deadline, and does not shorten or automatically suspend a statutory limitation period.

28.3 For business and professional Customers, the parties submit to the exclusive jurisdiction of the state and federal courts located in New York County, New York, for disputes under this agreement and waive objections based on inconvenient forum to the extent permitted by law. Either party may seek urgent interim relief in a competent court where necessary to protect systems, confidential information, or intellectual property, without changing the forum for the merits where enforceable.

28.4 If you are a Consumer, this choice of law and forum does not deprive you of mandatory protections of your habitual residence or any right to bring proceedings in a court available to you under mandatory law. Lawful small-claims procedures, complaints to regulators, and nonwaivable remedies remain available. These Terms do not impose mandatory arbitration.

29 Business dispute limitations

29.1 FOR BUSINESS AND PROFESSIONAL CUSTOMERS ONLY, AND TO THE EXTENT ENFORCEABLE, EACH PARTY KNOWINGLY WAIVES TRIAL BY JURY IN A DISPUTE ARISING OUT OF THIS AGREEMENT. EACH SUCH PARTY AGREES TO ASSERT ITS CONTRACTUAL CLAIMS IN ITS OWN CAPACITY AND NOT AS A CLASS OR COLLECTIVE REPRESENTATIVE OR MEMBER, EXCEPT WHERE THAT RESTRICTION IS PROHIBITED OR UNENFORCEABLE. THIS DOES NOT RESTRICT A REGULATOR, PROTECTED PUBLIC INJUNCTIVE RELIEF, OR RIGHTS THAT CANNOT BE WAIVED.

29.2 To the extent law permits, a business Customer must commence an ordinary contractual claim within one year after it accrues. This provision does not apply to Consumers, fraud, claims subject to a nonwaivable statutory period, or circumstances in which shortening the period would be unlawful or unreasonable. Accrual, discovery rules, and lawful tolling are determined by applicable law.

29.3 Each party ordinarily bears its own legal costs except for a valid indemnification obligation, legally recoverable collection costs, an applicable statute, or a court order. If an individual dispute restriction is unenforceable, it is severed to the extent permitted; it does not authorize a court to eliminate mandatory collective remedies or Consumer protections.

30 International use export controls and sanctions

30.1 You must comply with laws applicable to you, the Target, the data, and the requested activity, including applicable U.S. and other export-control, sanctions, computer-misuse, and privacy requirements. You may not obtain, export, reexport, transfer, or use the Service for a prohibited person, destination, or end use, or where a required authorization has not been obtained.

30.2 You represent that your access is not prohibited by applicable sanctions or export restrictions. You must not conceal the identity, location, end user, or end use of a prohibited transaction. We may restrict availability or request information reasonably necessary to comply with these requirements. These Terms do not create an export license or a representation that every security-testing activity is lawful in every country.

31 Force majeure

31.1 Neither party is responsible for a delay or failure caused by an event beyond its reasonable control that could not reasonably have been prevented or overcome through the measures required of it, including natural disasters, war, government restrictions, widespread infrastructure failure, or comparable events. The affected party must use reasonable efforts to mitigate the effects and resume performance.

31.2 This section does not excuse accrued payment obligations, legally required security measures, responsibility for a party's own actionable failure, or mandatory refunds. A cyberattack or provider failure is not automatically excused merely because it occurred. If an event prevents the paid core Service for more than 30 consecutive days, either party may end the affected service, and unused prepaid fees will be refunded proportionately, subject to any more favorable mandatory right.

32 Changes to these terms

32.1 We may update these Terms prospectively and will identify the revised version and effective date. For material changes, we will provide reasonable advance notice through your account or contact address and obtain renewed acceptance where required. More immediate changes may be necessary to comply with law or address an urgent security issue, with notice as soon as reasonably practicable.

32.2 A change will not retroactively alter accrued rights or impose a new dispute restriction on an existing dispute without legally effective agreement. Paid price changes and subscription notices are governed by Section 17. If you do not agree to a material change requiring acceptance, stop using the affected Service and contact us regarding termination and any refund required for the unused prepaid portion by this agreement or law.

33 Electronic records and notices

33.1 Subject to applicable electronic-transactions law, the parties may form this agreement and maintain records electronically. We may retain versioned acceptance records, timestamps, account identifiers, scan instructions, and authorization confirmations for lawful evidentiary, security, and administrative purposes, subject to applicable retention and privacy requirements.

33.2 We may send service, security, billing, and legal notices to your registered contact channel or within the Service, using any additional method required by law. Maintain a current, functioning address. Marketing messages and optional tracking remain subject to separate applicable consent and opt-out requirements. These Terms do not provide blanket consent to marketing or electronic service of court proceedings.

34 General contract provisions

34.1 Entire agreement. These Terms, the applicable Order, and any controlling signed agreement constitute the agreement concerning the Service and replace prior agreements on that subject to the extent validly superseded. Privacy notices and mandatory rights retain their independent effect. No provision excludes a claim for fraud or another nonwaivable right based on precontract statements.

34.2 Assignment. You may not transfer this agreement, your account, or your Service license without our written consent, except as a controlling agreement permits. We may assign this agreement in connection with a merger, reorganization, or transfer of the relevant business or assets, provided the successor assumes the applicable obligations. Any required notice, Consumer remedy, or data-transfer safeguard remains applicable.

34.3 Relationship. The parties are independent contractors. No partnership, agency, employment, fiduciary, or joint-venture relationship is created. A technical instruction to scan does not authorize either party to make legal commitments on the other's behalf. No client, target owner, or report recipient acquires contractual rights against Rocheston without its express agreement, except for intended beneficiaries identified in Section 26 or rights imposed by law. These Terms do not extinguish claims of third parties who have not agreed to them.

34.4 Severability. An invalid provision will be severed or limited only as the applicable law permits, and the remainder continues where it can lawfully operate. A court is not asked to rewrite an unfair Consumer term in order to enforce an otherwise prohibited result.

34.5 No waiver. A failure or delay in exercising a right does not waive it. A waiver must be clear and applies only to the specified instance. Rights and remedies are cumulative except where a lawful provision expressly states otherwise.

34.6 Interpretation. Headings are for convenience. "Including" means including without limitation. References to law include applicable amendments. Any translation is provided for accessibility; the English version controls only to the extent lawful and without defeating mandatory local-language rights. A specific provision controls a conflicting general provision on the same subject.

35 Contact and legal notices

Service: Vulnerability Vines AI
Operator: Rocheston
Email: [email protected]
Website: https://vines.rosebird.org
Privacy Policy: https://vines.rosebird.org/privacy.html

Use the subject "Vines Legal Notice" for contractual notices, "Vines Scan Abuse" for suspected unauthorized scanning, and "Vines Privacy Request" for privacy requests. Provide enough information to identify the matter without exposing unnecessary secrets. These contact instructions do not replace formal service requirements imposed by law.

Copyright Rocheston. All rights reserved.