Acceptance
By accessing or using the Cerberus website, access panel, or background agent binaries, you agree to be bound by these terms of use. If you do not agree to these terms, do not use the website or services.
Legal
These terms define the basic legal framework and conditions for using the Cerberus website, product interfaces, package selections, and related services.
Last updated: July 27, 2026By accessing or using the Cerberus website, access panel, or background agent binaries, you agree to be bound by these terms of use. If you do not agree to these terms, do not use the website or services.
Cerberus is an operations control plane service that governs and logs access to existing computers, servers, and terminal resources through dynamic permissions, secure browser sessions, real-time revocation, and cryptographic evidence trails.
The scope of service and resource limits are governed by your selected subscription plan, workspace configurations, and active product specifications.
Cerberus directly provides the technical control infrastructure that assists organizations in meeting their cybersecurity risk management, access control, and session auditability workflows under KVKK, GDPR, and the EU NIS 2 Directive (Directive (EU) 2022/2555).
Cerberus is designed for use only with authorized resources, workspaces, and accounts. Users must comply with the following rules and legal boundaries:
Users and organizations are responsible for the accuracy of their identity, device, resource health, and access policies.
Cerberus governs access decisions and session lifecycles. The infrastructure health of resource machines and local network policies remain organization responsibilities.
Organizations must comply with their own legal obligations when using the platform. Under Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications, they are solely responsible for generating, maintaining, and legally storing local traffic logs and IP allocation logs within their network boundaries.
The provider (Cerberus) does not interfere with the content of the data transmitted over the network, does not select the initiator or the destination of the data, and does not modify the transmitted data.
The provider acts solely as a data transmitter (mere conduit) for point-to-point data streams (active file transfers, clipboard actions, etc.) flowing through Cerberus connection channels, and cannot be held directly or indirectly liable for its content. Regarding recordings stored in a workspace where video or screen recording was separately enabled, the provider acts in the capacity of a hosting provider.
Cerberus stores access credentials (RDP/SSH) for target systems in encrypted vaults. However, the security of the accounts, passwords, Multi-Factor Authentication (MFA) configurations, and SSO (Single Sign-On) integrations used by the organization to access the Cerberus platform is entirely the organization's own responsibility.
The provider cannot be held liable for unauthorized access to target systems resulting from identity information or session keys falling into the hands of third parties.
It is strictly forbidden to use the services for excessive traffic consumption that disrupts network integrity, DDoS attacks, open proxy/VPN routing, cryptocurrency mining, or unauthorized penetration testing.
Upon detecting such unusual traffic or abuse, the provider reserves the right to immediately suspend the relevant workspace and tunnel access without prior notice.
The Cerberus name, logos, website content, access control plane design, documentation, and the binary code of the connection agents are protected by international copyright, trademark, and intellectual property laws.
Users may not copy, modify, distribute, lease, sell, or reverse-engineer any portion of our software or binary agents unless explicitly permitted under written agreement or active open-source licensing terms.
Under Law No. 5651, Cerberus acts in the capacity of a hosting provider and is not obligated to pre-screen or actively monitor content, data, or network traffic stored in workspaces or routed through the platform, nor to investigate any potentially unlawful activities.
However, upon receiving a substantiated notification of intellectual property infringement, personal rights violations, or criminal activity at legal@cerberusd.com, or upon receiving binding orders from official authorities, Cerberus will process the request within 24 hours to block access to or remove the relevant content.
Cerberus stores access credentials (RDP/SSH) for target systems in encrypted vaults. However, the security of the accounts, passwords, Multi-Factor Authentication (MFA) configurations, and SSO (Single Sign-On) integrations used by the organization to access the Cerberus platform is entirely the organization's own responsibility.
The provider cannot be held liable for unauthorized access to target systems resulting from identity information or session keys falling into the hands of third parties.
It is strictly forbidden to use the services for excessive traffic consumption that disrupts network integrity, DDoS attacks, open proxy/VPN routing, cryptocurrency mining, or unauthorized penetration testing.
Upon detecting such unusual traffic or abuse, the provider reserves the right to immediately suspend the relevant workspace and tunnel access without prior notice.
The Cerberus name, logos, website content, access control plane design, documentation, and the binary code of the connection agents are protected by international copyright, trademark, and intellectual property laws.
Users may not copy, modify, distribute, lease, sell, or reverse-engineer any portion of our software or binary agents unless explicitly permitted under written agreement or active open-source licensing terms.
Under Law No. 5651, Cerberus acts in the capacity of a hosting provider and is not obligated to pre-screen or actively monitor content, data, or network traffic stored in workspaces or routed through the platform, nor to investigate any potentially unlawful activities.
However, upon receiving a substantiated notification of intellectual property infringement, personal rights violations, or criminal activity at legal@cerberusd.com, or upon receiving binding orders from official authorities, Cerberus will process the request within 24 hours to block access to or remove the relevant content.
Users and organizations are solely liable for any legal claims, administrative fines, or litigation costs incurred by Cerberus resulting from their unlawful actions or non-compliant content routed through the platform.
Any such direct or indirect damages incurred by the platform will be fully recourse to the violating user or the service recipient organization.
Cerberus may from time to time introduce features labeled as 'Beta', 'Preview', or 'Early Access' on the platform.
These features are experimental and provided 'as is' without any warranty of performance, data integrity, or availability. The provider reserves the right to modify, suspend, or charge for these features at any time without prior notice.
Cerberus places the highest priority on system security. If you discover a potential vulnerability in our platform, you can report it to security@cerberusd.com.
As an exception to the restrictions in the 'Usage Rules' section of these Terms, activities by security researchers who act in good faith and adhere to the limits in this section are evaluated under Safe Harbor. Cerberus aims not to initiate legal action against researchers for responsible reports that stay within this scope.
Package scope, resource limits, session features, record options, and service scope are evaluated together with the current Pricing page.
Cerberus reserves the right to update package terms, pricing, and feature scope. Changes are announced through relevant channels before taking effect.
Unless otherwise specified in writing, all service payments are upfront and non-refundable. Service Level Agreement (SLA) or uninterrupted access commitments are only valid under custom Enterprise contracts. No uptime or availability commitments are provided for standard plans.
Cerberus exercises reasonable care in service delivery but does not warrant that the service will operate without interruption or error. Cerberus shall not be liable for service disruptions caused by events beyond its reasonable control, including but not limited to global cloud provider outages, telecommunication failures, cyberattacks targeting key internet exchange points, or natural disasters (Force Majeure).
To the maximum extent permitted by applicable law, Cerberus cannot be held liable for indirect, incidental, or consequential damages (including loss of data or business) arising from service use. The upper limit of liability is strictly restricted to the fee paid during the relevant service period.
Cerberus may suspend your account or terminate your access to the service in the event of a violation of these terms.
In case of termination, retention and disposal of your data is managed according to applicable legal regulations and workspace policy.
Cerberus services, software, and connection agents are subject to applicable export control laws and international sanction regulations.
The organization commits that it will not direct the service to, or access it from, embargoed countries, sanctioned regions, or targets on restricted person/entity lists.
These terms are governed by the laws of the Republic of Turkey. Istanbul courts and enforcement offices have jurisdiction over disputes.
In the event of a conflict or discrepancy between the Turkish and English versions of these terms, the Turkish version shall prevail.
Cerberus may update these terms. Important changes are announced on relevant publication surfaces or communication channels. The current text is always published on this page.
For questions and notices regarding these terms of use, please use the following channel.