Terms of Service

Last updated: September 2, 2026

By accessing or using threatcluster.io, its REST API or its feeds (together, the "Service"), you agree to these Terms of Service. If you do not agree, do not use the Service.

ThreatCluster Ltd
Company No. 17124226
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

1. Description of the Service

ThreatCluster is a threat intelligence data product. It collects reporting from 20,000+ publicly available sources and first-party dark-web observation, clusters it into scored incident records, and serves the result through:

  • A REST API over incidents, IOCs, entities, vulnerabilities and dark-web data, with a free read-only key on every account
  • Public feeds that need no key or account: RSS, the ransomware feed, the IOC blocklist and MISP feeds
  • A web platform: the live feed, cluster and entity pages, personalised feeds and alerting
  • Email digests and alerting
  • Exports in STIX 2.1, MISP, CSV, JSON and plain-text formats

2. Plans, API allowances and credits

The Service is priced as an API, with the web platform included in every plan:

Free ($0)

  • A read-only API key with a daily credit allowance over a limited lookback window, with trimmed records
  • Open reading of the web platform and a personalised feed

Researcher (monthly subscription)

  • A larger daily credit allowance, full records and all history over the API
  • Custom feeds and alert rules, and the full analyst web platform

Business (monthly subscription)

  • No daily API budget, higher rate limits and per-key overrides
  • Per-client feeds, org sharing and team features

API usage is metered in credits. Different endpoints cost different numbers of credits, and every response reports its cost. A request that returns nothing refunds its credits where stated in the API documentation. Credit packs are one-time purchases that add credits spent only after the day's allowance; unused pack credits do not expire.

Allowances, rate limits, credit costs and prices are subject to change and the current values are displayed on the pricing page and in the API documentation, which take precedence over any figures elsewhere.

3. Free trial

A time-limited Researcher trial is available without a payment method. If you do not add a payment method before the trial ends, your account returns to the Free plan and nothing is charged. Nothing is ever charged automatically at the end of a trial.

4. Billing and payments

Payment processing

All payments are processed securely through Stripe. By purchasing a subscription or a credit pack you agree to Stripe's Terms of Service. We do not store your full payment card details on our servers.

Billing cycle

Subscriptions are billed monthly in advance and renew automatically at the end of each billing period unless cancelled. You are charged on the same date each month, or the last day of the month where that date does not exist. Credit packs are one-time payments, not subscriptions.

Price changes

We may change subscription prices, credit-pack prices and credit costs. Existing subscribers are notified at least 30 days before a price increase takes effect, and the change applies from the next billing cycle after the notice period.

Failed payments

If a payment fails we will retry your payment method. If payment cannot be collected after multiple attempts, your account may be downgraded to the Free plan until payment is resolved. Credits already purchased in packs remain yours.

5. Cancellation and refunds

Cancellation

You may cancel at any time from account settings or by contacting us. Your subscription and its API allowances remain active until the end of the current billing period, you are not charged again, and the account then returns to the Free plan. The free API key never expires.

Refunds

Subscription fees are generally non-refundable. We may offer refunds at our discretion for technical issues that prevented use of the Service for an extended period, accidental duplicate charges, or first-time subscribers within 7 days of initial purchase who have not extensively used the Service. To request a refund, use the contact page.

6. Accounts and API keys

You may use the public feeds without an account. An account is required for the web platform and to mint API keys. You are responsible for:

  • Maintaining the confidentiality of your account credentials and API keys
  • All activity under your account and all requests made with your keys
  • Notifying us immediately of any unauthorised use or suspected key compromise

API keys identify you, not your organisation's customers or the public: do not embed a key where third parties can extract it, and do not share keys to give others access the plan does not grant. Keys can be rotated and scoped from account settings.

7. Acceptable use

You agree not to:

  • Use the Service for any unlawful purpose or in violation of applicable laws
  • Attempt to gain unauthorised access to any part of the Service
  • Interfere with or disrupt the integrity or performance of the Service
  • Circumvent rate limits, credit budgets, lookback windows or other plan limits, including by rotating accounts or keys
  • Systematically replicate the corpus or a substantial part of it, whether over the API, the feeds or the website, to build a copy of the database
  • Scrape or harvest the website in an automated manner instead of using the API and feeds provided
  • Use the Service to distribute malware or engage in malicious activity
  • Misrepresent your identity or affiliation

8. Data licensing and redistribution

What you may do with the data depends on how you receive it:

  • Public feeds (RSS, the ransomware feed, the IOC blocklist, MISP) are published TLP:CLEAR. You may redistribute them with attribution to ThreatCluster.
  • Keyed API responses are licensed for your own internal use and your own tooling on any plan, including Free.
  • Embedding the data in a product or service you sell, including serving it to your customers through your own platform, requires a Business or MSSP agreement.

Original source articles remain the property of their respective publishers. ThreatCluster's incident records, summaries, scores, entity graph and platform features are proprietary to ThreatCluster.

9. Disclaimer of warranties

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. We do not warrant that:

  • The Service or the API will be uninterrupted, timely, secure or error-free
  • The threat intelligence provided is complete, accurate or current
  • AI-generated summaries, scores and analysis are free from errors or omissions
  • The Service will meet your specific requirements

ThreatCluster is an informational tool. You should independently verify threat intelligence, including indicators consumed over the API or feeds, before making security decisions or taking blocking actions.

10. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THREATCLUSTER SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, OR ANY LOSS OF DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES RESULTING FROM:

  • Your use of or inability to use the Service or the API
  • Any unauthorised access to or use of our servers
  • Any interruption or cessation of transmission to or from the Service
  • Any errors or omissions in threat intelligence, indicators or AI-generated content, or actions you take in reliance on them

11. Email communications

By subscribing to a digest or creating an account, you consent to receive email communications from ThreatCluster. You may unsubscribe at any time using the unsubscribe link in our emails or by contacting us directly.

12. Termination

We reserve the right to suspend or terminate your access to the Service, including revoking API keys, for violations of these Terms, fraudulent activity, or other reasons at our discretion. In case of termination for cause:

  • Access to the Service and its API keys is immediately revoked
  • No refund is provided for the current billing period
  • Any outstanding balances become immediately due

You may stop using the Service at any time by cancelling from account settings. See section 5 for the cancellation process.

13. Changes to these Terms

We may modify these Terms at any time. We will notify users of material changes by posting the updated Terms on this page with a new "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the modified Terms.

14. Governing law

These Terms shall be governed by and construed in accordance with applicable laws, without regard to conflict of law principles.

15. Contact

If you have questions about these Terms, reach us through the contact page or at [email protected].