Terms of Service
These terms cover subscribing to and using Maester Cloud. They are written to be read, not to hide things in fine print.
Effective date: September 30, 2026
Run it in your own Azure
A Self-Hosted subscription lets you run Maester Cloud in your own Azure subscription. The service is still in active development and features may change.
Cancel any time
The price is the one shown on the pricing page when you buy. You can cancel whenever you like, and your access and perks run to the end of the paid period.
The open core stays free
These terms cover Maester Cloud, the commercial service. The open-source Maester framework and core tests stay free under the MIT license, always.
A real service, not a donation
You receive the software, deployment support, and roadmap input. Your subscription also keeps the open Maester tests maintained for everyone. If you only want to support the open-source project, sponsor it on GitHub instead: that is a donation, carries none of these terms, and grants no access to Maester Cloud.
Who we are and what this covers
Maester Cloud is operated by Jozra ("we", "us"). These terms are an agreement between you (or the organization you represent) and us, and they apply when you visit maester.cloud, subscribe, or use the Maester Cloud portal and related services. By subscribing or using the service you agree to them. They do not cover the open-source Maester project, which you run in your own environment under its MIT license.
Account terms
- You are responsible for keeping your access secure. Portal sign-in uses a Microsoft Entra application you register and control in your own tenant. You decide who you assign to it, and you are responsible for what they do.
- You must be a person. The account holder must be a human, not a bot. Automated report uploads run through tokens you issue, but the account itself belongs to a real person.
- You are responsible for the content and activity in your portal, and for using the service lawfully and only for your own organization's security work.
- You may not use the service to break the law, infringe anyone's rights, or abuse the infrastructure it runs on.
What a Self-Hosted subscription includes
A Self-Hosted subscription entitles you to deploy and run Maester Cloud in your own Azure subscription, set up from your Maester Cloud account, together with deployment support and ongoing updates for as long as the subscription is active. You provide and pay for the Azure resources it runs on. Maester Cloud is in active development: features shown on this site or in the demo may change, ship later, or differ from the current release. Hosted Maester Cloud, where we operate the service for you, is not yet available and has no committed date.
Subscribers also receive a direct line to the roadmap and an optional place on the Supporters wall. Subscribers who joined during the earlier funding period are recognised as Founding Supporters and keep the additional benefits offered at that time, including a lifetime 10% discount on any future Hosted Maester Cloud tier; that founding offer is closed to new subscriptions. These are thank-yous, and the specific perks may be refined as the product takes shape.
Provided subdomains
A subscription includes subdomains under a Maester-operated domain (for example
contoso.maester.fyi) that point at your own Maester Cloud instances. Because the
namespace is shared, these rules apply to every name you claim:
- A subdomain may only point at a Maester Cloud instance you operate. The claim flow enforces this technically: only the Azure environment registered with the claim can serve the name, and a claim whose instance never proves it holds a certificate for the name is removed within a day. Repurposing the name for anything else breaks these terms.
- Names are first come, first served among subscribers, with a reserved list for infrastructure- and security-shaped words. Do not claim names that impersonate another person, company, or product. We resolve trademark and impersonation disputes on evidence, and we may rename or remove a claim to do so.
- Serving phishing, malware, or deceptive content from a Maester-provided subdomain, or using it in mail or links designed to mislead, leads to immediate removal of its DNS records, without notice while harm is active. Egregious abuse forfeits the name permanently and can end the subscription.
- Subdomains are a benefit of an active subscription. If a subscription lapses, the address keeps working through a 30-day grace period, after which we may take it offline; it stays reserved to your account, and you can claim it again once your subscription is active. A name you release yourself stays reserved to your account until we make it available again; after that you can still claim it back for 30 days, after which another customer may claim it. Names removed for abuse can never be claimed again.
- Your instance always remains reachable at its own Azure hostname, whatever happens to the subdomain.
To report a subdomain serving abusive content, email [email protected] with the address and what you observed. Reports are read by a human and acted on quickly.
Payment, refunds, and plan changes
- The price of the Self-Hosted subscription is the one shown on the pricing page at the time you buy, billed monthly or yearly as you choose. Prices in currencies other than US dollars, and prices on Azure Marketplace, are set separately and may differ.
- Card payments are handled by our payment provider, who acts as merchant of record and manages checkout, billing, receipts, and applicable taxes. By subscribing you also agree to the payment provider's terms for the payment transaction. A subscription bought this way renews automatically at the end of each billing period until you cancel, and you can switch between monthly and annual billing from your billing page; the change takes effect at your next renewal.
- Organisations can instead buy an annual subscription on a quote from us. A quote is valid for 30 days and states the currency and amount. Accepting it by bank transfer turns the quote into a tax invoice from us, payable within 30 days; the subscription starts when the payment arrives and runs for twelve months. Applicable taxes, including Australian GST and the EU and UK reverse charge for business customers, are shown on the quote. Invoiced subscriptions do not renew automatically: we send a renewal quote about a month before the year ends, and the subscription lapses if it is not paid.
- Where the service is listed on Azure Marketplace, you can buy it there instead. Microsoft then bills you at the Marketplace price, in your Azure billing currency, under your Microsoft agreement, and handles applicable taxes for that purchase.
- Because the subscription funds ongoing development, we do not automatically pro-rate refunds for the current billing period once it has started. That said, we want you to feel good about backing this: if something is not right, especially in your first 30 days, email us and we will find a fair resolution, including a refund where appropriate.
- We may change the price for future billing periods, but we will give you notice before any change affects you.
Cancellation and termination
- You can cancel at any time from your billing page, from the Azure portal for a Marketplace purchase, or, for an invoiced subscription, by not accepting the renewal quote. Cancellation stops future renewals; your access and perks continue until the end of the period you have already paid for.
- We may suspend or end your access if you seriously or repeatedly break these terms, or to protect the service, our other customers, or the public. Where it is reasonable, we will tell you why first.
- When your subscription ends, we delete your Customer Data within 30 days, except where we are legally required to keep it.
Modifications to the service and prices
The service is evolving, and features shown on this site or in the demo may change, ship later, or differ from the current release. We may add, change, or remove features over time. We will avoid removing something you actively rely on without a reasonable alternative or notice where practical.
Uptime, security, and privacy
We do not currently offer a formal uptime guarantee, but we work to keep the service available and secure. Your Customer Data is stored and processed in the Azure region you choose, and portal sign-in runs through the application in your own tenant. How we handle data is described in our Privacy Statement, and the architecture is detailed in the security documentation.
Your content and the open core
- The assessment results, reports, configuration, and accepted-risk decisions you send to your portal are yours. We process them only to provide the service to you, as set out in the Privacy Statement, and we do not sell them or use them to train AI models.
- The Maester framework and core tests are open source under the MIT license and are not affected by these terms. They stay free to run in your own environment.
- The Maester Cloud software you deploy under a Self-Hosted subscription is licensed to you for your own deployment and use for as long as your subscription is active. It is not open source, and it may not be redistributed or resold.
The Supporters wall
Appearing on the public Supporters wall is optional and opt-in. If you opt in, you give us permission to display the name, link, and image you provide to recognize your support. You are responsible for having the rights to what you submit, and you can ask us to update or remove your entry at any time by emailing us.
Features and bugs
We decide what features to build and when, guided heavily by subscriber input. The live demo shows the direction we are heading, not a promise that every feature ships in the first release. We do our best to keep the service working well, and when you find a bug, tell us and we will do our best to fix it.
Liability
Maester Cloud helps you track and prove your Microsoft 365 security posture. It is a tool to support your security and compliance work, not a guarantee of security, compliance, or any particular outcome; you remain responsible for your own configuration and decisions. To the extent permitted by law, the service is provided "as is", and our total liability for any claim relating to the service is limited to the amount you paid us in the three months before the claim. Nothing in these terms limits liability that cannot be limited by law.
Governing law
These terms are governed by the laws of the State of Victoria, Australia, and you agree to the exclusive jurisdiction of the courts of Victoria, except where the Australian Consumer Law or other applicable consumer law gives you the right to bring a claim where you live.
Changes to these terms
We will update these terms as the service grows. When we make material changes, we will update the effective date above and notify subscribers by email or through the portal before the changes take effect.
How to contact us
Questions about these terms, billing, or your subscription? Email [email protected]. A human reads it.
Parts of these terms are adapted from the Basecamp open-source policies, used and modified under CC BY 4.0.