Last updated: September 1, 2026
Welcome to CyberExchange, operated by IT-Harvest, LLC (“IT-Harvest”, “we”, “us”, or “our”). By creating an account, using CyberExchange at cyberexchange.ai (the “Service”), or subscribing to a paid plan, you agree to these Terms of Service, the Privacy Policy, and the Acceptable Use Policy below. If you do not agree, do not use the Service.
If you accept on behalf of a company, you confirm that you are authorised to bind it, and “you” means that company.
These Terms, the Acceptable Use Policy, the Privacy Policy, and any addendum we publish and you accept — such as the Data Processing Addendum — are the agreement between us. If we sign a separate written agreement or order form with you for the Service, that document governs wherever it conflicts with this page.
CyberExchange is a cybersecurity product and vendor intelligence platform. It lets you discover, compare and manage cybersecurity products and vendors, and includes search, vendor and market intelligence, security stack management, framework mapping, AI-assisted answers, and programmatic access on the plans that carry it.
Which features and limits you get depends on the plan you are on. The details of a plan are shown when you buy it and in your account; they are not restated here, because they change.
The Service is a research and decision-support tool. It is not advice — security, legal, financial or otherwise — and decisions you make using it remain yours.
The Service is for business and professional use. You agree to provide accurate information, to keep your credentials secure, and to tell us promptly if you believe your account has been compromised. You are responsible for activity under your account.
We may suspend or terminate accounts that breach these Terms or that we reasonably believe are being used fraudulently.
Plans renew automatically. Paid plans are subscriptions. Unless the plan says otherwise, they are billed in advance for a recurring period and renew for the same period until you cancel. You authorise us and our payment processor to charge your payment method for each renewal at the price then in effect.
Changing plan. An upgrade takes effect immediately and is charged immediately for the remainder of the current period, prorated. A downgrade also takes effect immediately; the unused value is applied as a credit against your next invoice rather than paid back to you.
Seats. Some plans let you buy seats for people in your organization or agency. Seats are billed per seat. Adding a seat is charged from the time you add it. Releasing a seat reduces what you pay from the next period onward — releasing it part-way through a period does not produce a refund or a credit for the rest of that period.
Usage limits. Plans carry limits — for example on searching, on AI-assisted answers, and on exports. Monthly limits reset at the start of each calendar month, and unused allowance does not carry over. The limits that apply to your plan are shown with the plan, and we may slow or decline requests to enforce them.
Taxes. Prices exclude taxes. You are responsible for any sales, use, VAT or similar tax on your purchase, other than tax on our income. Where we are required to collect a tax, it will be shown at checkout or on your invoice.
Price changes. We may change our prices. A change to the price of a plan you are already on applies from your next renewal, and we will tell you before it takes effect. If you do not want to pay the new price, cancel before the renewal.
Refunds. Fees are non-refundable except where the law requires otherwise. Cancelling stops future charges; it does not refund the period you have already paid for.
Cancelling. You can cancel from your account at any time. Cancellation takes effect at the end of the period you have already paid for, and you keep access until then. Two things are worth knowing before you try:
If a payment fails. Paid features stop immediately when a payment fails — including on a temporary card decline — and any organization or agency you own is suspended, along with an Enterprise API licence if you hold one. Suspension is not deletion: members, shared content and issued keys are preserved, and access is restored when a payment succeeds. We will notify you so you can update your payment method. If payment keeps failing, the subscription ends.
After a paid plan ends. Your account reverts to the free tier and paid features stop. Content you created remains yours; you can ask us to export or delete it, as described in the Privacy Policy. We may remove content a reasonable time after a plan ends, so if you want a copy, ask before you cancel or shortly after.
Some plans include programmatic access, through the Enterprise API or the MCP server. Where yours does:
You own what you create. Security stacks, notes, tags, comparisons and other content you put into the Service stay yours. You grant us a non-exclusive licence to host, store, process, transmit and display that content for the purpose of operating the Service for you and for the people you share it with, and for as long as we need it to do that. We claim no other rights in it.
We own the platform. The Service itself — the software, the interfaces, the CyberExchange and IT-Harvest names and logos, and the datasets, analysis and intelligence we compile — belongs to us or our licensors. Your subscription is a right to use it, not a transfer of it. You may use what the Service shows you for your own internal business purposes. You may not reproduce, redistribute, publish, resell or build a competing dataset from it without our written permission.
Vendors own theirs. Vendor and product material — logos, product names, descriptions and marketing copy — belongs to the vendors concerned and is shown for information.
If you send us feedback or suggestions, we may use them freely and owe you nothing for them.
Each of us may learn things about the other that are not public. Neither of us will use the other’s confidential information for anything other than performing under these Terms, or disclose it to anyone except people who need it and are under a similar obligation. This does not cover information that is public, already known, or independently developed, or that must be disclosed by law — and where the law compels disclosure, we will tell you if we are permitted to.
CyberExchange displays information about third-party products, vendors and the people who work at them. We do not endorse, warrant or guarantee any third-party product or service. Information is provided as-is and may not reflect current offerings.
Links to external websites are provided for convenience. We are not responsible for the content or practices of linked sites.
If you are a vendor and something we show about your company or products is wrong, or if you believe material on the Service infringes your rights, tell us. See Copyright and Corrections for how, and what happens next.
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE.
We do not warrant that information about any product, vendor, company or person on the Service is complete, current or accurate. It is compiled from public and licensed sources and from automated analysis, and you should verify anything you intend to rely on.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, IT-HARVEST SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM YOUR USE OF THE SERVICE, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Our total liability for all claims arising out of or relating to the Service or these Terms will not exceed the amount you paid us for the Service in the twelve months before the event giving rise to the claim. Nothing in these Terms limits liability that cannot be limited by law.
You agree to indemnify and hold harmless IT-Harvest, its officers, directors, employees, and agents from any claims, losses, or damages arising from your use of the Service or violation of these terms.
We may suspend or terminate your access if you breach these Terms or the Acceptable Use Policy, if your payment fails, if the law requires it, or if your use puts the Service or other customers at risk. Where the circumstances allow it, we will tell you first and give you a chance to put the problem right. You may stop using the Service at any time.
When the agreement ends, your right to use the Service ends with it. The sections that should outlive it do — ownership, confidentiality, disclaimers, limitation of liability, indemnity, and governing law.
We develop the Service continuously, and features change. We will not remove a material part of what a paid plan provides without telling the customers on that plan.
We may change these Terms. Where a change is material and you are on a paid plan, we will give you at least 30 days notice and the change applies from your next renewal. Other changes take effect when posted here with a new date. If you do not accept a change, cancel before it applies.
Notices to you go to the email address on your account or appear in the Service. Notices to us go to team@cyberexchange.ai, and legal notices additionally by post to IT-Harvest, LLC, 850 New Burton Rd., Suite 201, Dover, Delaware 19904, Kent County. Keep the email address on your account current; a notice we send to it is given when sent.
You may not assign this agreement without our consent; we may assign it to a successor in a merger or a sale of the business. Neither of us is liable for a failure caused by something outside our reasonable control. If a provision is unenforceable, the rest stands. Not enforcing a right straight away does not waive it. Nothing here creates a partnership or agency between us.
These Terms are governed by the laws of the State of Delaware, without regard to its conflict-of-law provisions. The courts located in the State of Delaware have exclusive jurisdiction over any dispute arising out of them, and each of us consents to that jurisdiction.
CyberExchange is operated by IT-Harvest, LLC. This Privacy Policy explains what information we handle, why, and the choices you have. Most of it concerns people who use the Service. One section — Information about companies and their personnel — concerns people whose professional information appears in the Service without their being users of it.
We do not sell your personal information, and we do not use it for third-party advertising.
Parts of the Service use AI models to interpret what you are asking for and to generate an answer. When you use one of those features, your query — and the material needed to answer it — is sent to a model, which may be run by a provider acting on our behalf. We keep a record of the questions asked and the answers returned so we can operate, support, secure, account for and improve the feature.
We do not use your content to train AI models, and we do not share it with anyone for them to train theirs.
AI answers can be wrong or incomplete. Check anything that matters before relying on it.
CyberExchange is a business-intelligence product about the cybersecurity industry. Alongside information about companies and their products, it contains professional information about people who work at them — typically a name, a job title, employment history, a business contact address, a professional profile link, and a photograph.
That information comes from public sources and from commercial data providers who license it to us. We make it available to our customers for business purposes: market research, vendor evaluation, and business contact. For this information we act on our own behalf rather than on a customer’s. Where a lawful basis is required, we rely on our legitimate interest, and that of our customers, in operating and using a business-information service — which is why what we hold is professional information about people in their working capacity, and not information about their private lives.
If this is about you. You can ask us to correct the information, to remove it, or to object to our holding it at all. Write to team@cyberexchange.ai, tell us who you are and what you want done, and we will action it and reply.
We use other companies to run the Service. They handle data on our instructions, under contract, and only as much as their job requires. They fall into a few categories: cloud hosting and infrastructure; database and authentication; payment processing; email delivery; search infrastructure; AI model providers; and bot protection.
We keep the current list on a separate page — see Subprocessors — so it stays accurate as providers change. If you need advance notice of changes to that list, ask us.
Integrations you connect yourself, such as a messaging workspace, send content where you direct it. Those services handle it under their own terms, not ours.
We use cookies that are necessary to sign you in, to remember your interface preferences, and to protect our forms from automated abuse. We do not use advertising or cross-site tracking cookies. See the Cookie Policy.
Where the GDPR or a similar law applies, we handle personal information because we need it to provide the Service you asked for, because we have a legitimate interest in operating and securing a business-information service, because you consented, or because the law requires it. If you want to know which basis applies to a particular use, ask us and we will tell you.
We retain your information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion at any time — see Your Rights below for how, and for what deletion covers.
For any request about your information, write to team@cyberexchange.ai. Tell us what you want done. We will check that the request really comes from you before we act on it, and we will respond within the time the law allows us. There is no self-serve control in the product for this — a person handles it.
This applies whether or not you hold an account with us. If we hold information about you because of your professional role at a company we cover, the same address reaches us.
What deletion means. When we action a deletion request we remove or irreversibly de-identify the information associated with you. Records we are required to keep — billing and tax records, security and audit logs, and anything under a legal hold — are retained for as long as the law requires and are not linked back to you afterwards.
You have the right to ask for a copy of your personal data, to have it corrected or erased, to have our use of it restricted, to receive it in a portable form, and to object to processing we carry out on the basis of our legitimate interests. Where we rely on your consent you can withdraw it at any time, which does not affect what we did before you did.
Our legal bases are: performing our contract with you, where you hold an account; your consent, where we ask for it; and our legitimate interests in operating, securing and improving the Service and in maintaining a business-information dataset about companies in the security industry and the people who represent them professionally. Where you object to processing based on legitimate interests, we will stop unless we have grounds that override your objection.
We are established in the United States and your information is processed there. You also have the right to complain to your local supervisory authority, and we would ask that you raise it with us first.
Under the CCPA as amended by the CPRA you have the right to know what personal information we have collected about you and where it came from, to request its deletion, to request that we correct it, and to opt out of any sale or sharing of it. You have the right not to be treated differently for exercising any of these rights, and we do not.
We do not sell or share the personal information of our own users, and we do not use it for cross-context behavioural advertising. Separately, we license access to a business-information dataset that includes professional contact details of people at the companies we cover — name, employer, role and similar work-related detail. If you are in that dataset and want us to stop, write to team@cyberexchange.ai and we will action it. We do not knowingly collect or license the personal information of anyone under 16.
Several states — among them Virginia, Colorado, Connecticut, Utah, Texas and Oregon — give residents rights to access, correct, delete or obtain a copy of their personal data, and to opt out of targeted advertising, sale, or profiling with legal effects. We do not carry out targeted advertising or that kind of profiling. For everything else, the address above is the route, and some of these laws give you a right to appeal a decision we make — reply to our answer and say so, and a different person will look at it.
We take reasonable measures to protect the information we hold, including encryption in transit and access controls that limit who and what can reach it. No method of transmission or storage is perfectly secure. If an incident affects your information, we will tell you without undue delay after becoming aware of it, where we are required to do so. Our security overview describes our approach; our vulnerability disclosure policy explains how to report a problem to us.
We operate in the United States. If you access the Service from outside the U.S., your information may be transferred to, stored in, and processed in the U.S. and other countries where our service providers operate.
The Service is intended for business and professional use and is not directed to children under 16. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Material changes will be posted here with an updated date.
CyberExchange’s data, content, and infrastructure are protected resources. Except where your plan expressly licenses the activity — see Licensed automated access below — you agree not to:
Some plans include automated access: the Enterprise API, the MCP server, and export features. Using those is permitted and is not a breach of anything above, provided you stay within the limits of your plan and the Terms.
What remains prohibited is automated access outside the interfaces we license to you, above the limits of your plan, or in a way that works around a control. Data retrieved through a licensed interface is still subject to the restrictions on redistribution and competing datasets in the Terms — the interface changes how you get the data, not what you may do with it.
We welcome good-faith security research, and we will not pursue claims against research that follows our Vulnerability Disclosure Policy. Read it before you test; it sets out what is in scope and what is not. Testing outside it — reaching another user’s data, degrading the Service, or extracting data at scale — is not covered by that protection.
We may, at our discretion and without notice, rate-limit, throttle, suspend, or terminate access; revoke API credentials; and pursue any available legal and equitable remedies for violations of this policy. We act on automated signals as well as on reports.
For any question about these documents — including a privacy request, a security report, a copyright or accuracy complaint, or a billing dispute — write to us. One address reaches us for all of it.
IT-Harvest, LLC
Email: team@cyberexchange.ai
Website: it-harvest.com
Notices: 850 New Burton Rd., Suite 201, Dover, Delaware 19904, Kent County