These terms are between you (“you”, or “the customer”) and [business name not configured] (“we”, “us”), who operate this service at https://scepnet.tech.
Reach us at [contact address not configured].
ScepNet operates a certificate authority on your behalf. It generates and holds a private certificate authority for your organization, and issues X.509 certificates to devices that enroll over SCEP using a challenge password you control. It publishes a certificate revocation list at a fixed address so your network equipment can check whether a certificate is still valid.
The certificates it issues are trusted only by systems you configure to trust them. This is not a publicly trusted certificate authority, and its certificates are not accepted by web browsers.
You are responsible for what happens under your account, including actions by people you invite to it. Owners can add and remove members and change their access at any time.
Your SCEP challenge passwords are enrollment credentials. Anyone who holds one can obtain a certificate from your certificate authority. Keep them scoped to the devices that need them, and rotate them from your dashboard if one is exposed.
We do not have access to your account password. We cannot recover it, only reset it to an address you control.
Every account includes a free tier of up to 5 devices. It has no end date and requires no payment details. Only a sixth device requires a plan.
Plans are measured in devices — distinct certificate subjects that are currently valid — not in certificates issued. A device that re-enrolls does not consume another slot. Revoking a certificate frees its slot.
Nothing renews automatically. Each period is a separate payment. We email you before a period ends.
When a period ends without renewal you keep a 30-day grace period. During it your devices carry on authenticating and re-enrolling exactly as before; you simply cannot add new ones. We warn you by email and on your dashboard as the end of that window approaches.
After 30 days we revoke the certificates issued under that plan. Those devices then stop authenticating to your network once your equipment fetches the updated revocation list. Renewing at any point inside the grace period cancels this and nothing is revoked; renewing afterwards restores your account, but every device has to enroll again.
An account whose plan has ended returns to the free tier described above. It is not closed, and up to 5 devices may be enrolled on it as before.
Prices are in South African Rand and are inclusive of any applicable value-added tax. Payments are processed by Paystack; we do not receive or store your card details.
Yearly plans carry a 30-day full refund. Ask within 30 days of paying and we refund the whole year, for any reason and without pro-rating it. Write to [contact address not configured].
Monthly plans are not covered by that. Nothing renews on its own, so a monthly plan ends at the end of its period unless you buy another.
Separately, and at any time: if the service does not work as described, contact us and we will refund the period in question.
A refund revokes your certificates. When we refund a payment we also reverse what it bought: every certificate issued during that period is added to your revocation list, and the devices holding them stop authenticating as soon as your network equipment fetches the updated list. You cannot enroll new ones either.
This is deliberately different from simply not paying, described in section 4. A period that ends without renewal leaves your devices working — you paid for what you used. A refund returns the money, so the service goes back with it.
We do not offer a service-level agreement. We aim to keep the service available and monitor it continuously, but we do not guarantee uninterrupted operation.
Certificates already issued to your devices do not depend on this service being reachable. They continue to authenticate for as long as they are valid. What requires the service is enrolling new devices, re-enrolling existing ones, and fetching a current revocation list. If you need revocation checking to survive an outage on our side, you can mirror the revocation list to an address you control — see the setup guide.
We may suspend an account that is being used to attack others, that is not paid for, or where we are required to by law. Suspension stops portal access and new enrollments. We will tell you why, at the address on the account.
You can stop using the service at any time; unused time is not refunded. You can ask us to delete your account by writing to [contact address not configured].
When an account is removed, its certificate authority private key is destroyed. Certificates issued under it can no longer be revoked or re-issued, and no revocation list can be published for it. If your devices still rely on those certificates, remove the trust anchor from them first.
We keep audit records after deletion where we are required to — see the privacy policy.
Nothing in these terms excludes liability that cannot lawfully be excluded.
Subject to that, our total liability to you for any claim is limited to the amount you paid us in the twelve months before the claim arose. We are not liable for indirect or consequential loss, including lost profits or business interruption.
You remain responsible for how certificates issued to you are used, and for the configuration of the systems that trust them.
We may change these terms. If a change materially affects you we will email the address on your account before it takes effect. Continuing to use the service after that means you accept the change.
These terms are governed by the law of the Republic of South Africa, and the courts of South Africa have exclusive jurisdiction.
[contact address not configured]