Legal
Terms of Service
Effective date: July 21, 2026
These Terms of Service ("Terms") govern your access to and use of the website located at cvescorecard.com and any related pages, features, content, data, email alerts, and services (collectively, the "Site"). The Site is published under the name "CVE Scorecard" ("CVE Scorecard," "we," "us," or "our"). "You" and "your" refer to the individual or entity accessing or using the Site.
Please read these Terms carefully. They include disclaimers of warranties, a limitation of liability, an assumption of risk, an indemnity, a shortened time to bring claims, and other important provisions that affect your legal rights. Sections presented in capitalized text are intended to be conspicuous.
1. Acceptance of These Terms
1.1. By accessing or using the Site, creating an account, subscribing to email alerts, submitting information through any form on the Site, or otherwise interacting with the Site, you acknowledge that you have read, understood, and agree to be bound by these Terms and by our Privacy Policy, which is incorporated by reference (see Section 16).
1.2. Where the Site presents a checkbox, button, or similar mechanism asking you to agree to these Terms (for example, at account creation, at email-alert signup, or when submitting a form), your affirmative action confirms your agreement, and we may retain a record of that agreement, including your user identifier, the date and time, and the version of these Terms then in effect.
1.3. If you do not agree to these Terms, do not access or use the Site.
1.4. If you are using the Site on behalf of an organization, you represent and warrant that you have authority to bind that organization to these Terms, and "you" includes that organization.
1.5. You must be at least the age of majority in your jurisdiction, and legally able to form a binding contract, to use the Site or create an account.
2. Informational and Educational Purposes Only; No Professional, Security, or Legal Advice
2.1. The Site is a free, public, informational, and educational resource. All content, data, characterizations, visualizations, funnels, counts, category groupings, and other materials on the Site (collectively, the "Content") are provided for general informational and educational purposes only.
2.2. The Content is not professional advice of any kind. It is not, and must not be treated as, cybersecurity advice, risk-management advice, procurement advice, engineering advice, investment advice, legal advice, or any other form of professional advice. It is not a substitute for the exercise of your own independent judgment or for the engagement of qualified professionals.
2.3. Nothing on the Site creates any professional, advisory, fiduciary, or client relationship between you and CVE Scorecard.
2.4. You are solely responsible for evaluating the Content and for any decision you make or action you take or do not take. Before making any purchasing, divestment, deployment, configuration, remediation, security, procurement, or risk decision, you should consult the primary sources described in Section 4, the affected vendor, and your own qualified advisors.
3. Not a Score, Rating, Ranking, Grade, Certification, or Endorsement; Reporting of Public Data and Editorial Opinion
3.1. Despite the name "CVE Scorecard," the Site does not produce, and does not purport to produce, a security score, security rating, risk score, ranking, grade, certification, seal, accreditation, audit, benchmark, or endorsement of any vendor, product, service, or organization. It is not an assessment of the actual security of any product, vendor, or network, and it is not a recommendation to purchase, avoid, retain, or discontinue any product or vendor. The name of the Site is a title and not a characterization of any vendor.
3.2. The Site has two kinds of Content, and we distinguish them deliberately:
(a) Reported public data. Certain items are reports of what a public source states. Each such item is intended to convey what the identified public source (for example, NVD, CISA KEV, or Shodan) recorded as of the date and time we retrieved it. Where practicable, we present these items with their source, their retrieval date, and, for vulnerability records, the underlying CVE identifiers, so that any reader can consult the same source and confirm what it says. We do not represent that the public sources are themselves accurate, complete, current, or correctly attributed (see Section 4).
(b) Editorial characterizations. Other items reflect our selection, arrangement, grouping, categorization, comparison, ordering, and interpretation of that public data, including category groupings, funnels, exploited-fraction figures, exposure context, disclosure-posture descriptions, inferred latest-version estimates, and accompanying commentary (collectively, the "Characterizations"). The Characterizations are our subjective editorial expression: they are how we have chosen to organize and describe public information. Each Characterization discloses the public data on which it is based and the methodology used to derive it, so that a reader can review the same source data and the same method and reach an independent conclusion, including one that differs from ours.
3.3. CVE Scorecard does not state, and the Content should not be read to imply, that any vendor or product is secure, insecure, safe, unsafe, vulnerable, invulnerable, compromised, breach-prone, breach-resistant, better, worse, more risky, or less risky than any other. The presence, absence, count, or characterization of vulnerability data for any vendor, a particular severity mix, a listing in a public exploited-vulnerabilities catalog, or a particular level of internet-exposure context does not, by itself, indicate that a vendor's products are or are not secure or suitable for any purpose. A higher or lower figure may reflect factors unrelated to actual security, including the volume of a vendor's disclosures, its transparency, its market share, its research attention, its code volume and install base, differences in how data sources record information, and the limitations described in Section 4. A vendor that discloses more may simply be more transparent.
3.4. Where the Site describes a vulnerability as potentially affecting a current or "latest" product version, that statement is an inference derived from public records by an automated heuristic that, as described in Sections 4 and 5, is known to lag actual vendor releases and may be wrong. It is presented with its supporting records and a confidence indicator where practicable. It is not a statement by CVE Scorecard that any currently shipping product is in fact vulnerable, unpatched, or exploitable, and it is not a substitute for the vendor's own advisories and release notes, which control.
3.5. The Content reflects only certain categories of public information selected by our methodology and does not reflect a vendor's complete security posture, internal controls, response practices, unpublished or undisclosed information, or overall product quality.
3.6. Our methodology and its known limitations are described on a methodology page on the Site, which we date and version. You are encouraged to read the published methodology before drawing any conclusion from the Content. Reasonable people may reach different conclusions from the same public data, and the Content represents one organized presentation of that data. We invite readers to reach their own conclusions.
4. Data Sources and Third-Party Data Disclaimer
4.1. The Content is derived substantially from public, third-party data sources, which currently include: (a) the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD), accessed through the NVD API; (b) the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog; and (c) Shodan (internet-exposure host counts). We may add, remove, or change data sources at any time.
4.2. CVE Scorecard does not create, control, audit, verify, or guarantee the underlying third-party data. That data may be inaccurate, incomplete, out of date, delayed, superseded, duplicated, or misattributed. Among other known limitations: NVD and CISA records may lag actual vendor releases, advisories, and fixes; severity scores and metadata may be revised over time; Common Platform Enumeration (CPE) matching used to associate vulnerabilities with vendors and products is heuristic and may over-include or under-include records; and internet-exposure counts are point-in-time estimates that may not reflect actual deployments, ownership, or risk.
4.3. CVE Scorecard is not affiliated with, sponsored by, endorsed by, or acting on behalf of NIST, NVD, CISA, Shodan, MITRE, or any other data source or vendor. References to these sources are for attribution and identification only and do not imply any partnership, endorsement, review, or approval by them of CVE Scorecard, the Site, or the Content. We include the attributions required by each source. Your use of any third-party data may also be subject to that source's own terms and licenses, and you are responsible for complying with them.
4.4. Any processing, normalization, categorization, aggregation, or presentation applied by CVE Scorecard to third-party data is our own editorial work and does not represent the position of any data source or vendor, as described in Section 3.2(b).
4.5. To the extent any factual data point on the Site reflects the content of these public sources, that data point is intended to report what the public source states as of the date and time on which we retrieved it. We do not represent that the public sources are themselves accurate, complete, current, or correctly attributed, and we are not responsible for errors, omissions, delays, or misattributions originating in those sources. We may present, describe, and update the public record as it stands, including as it changes over time. An update or correction reflects the evolving state of public data or our presentation of it and is made in the ordinary course; it is not an acknowledgment that any prior presentation was false or made without a reasonable basis.
4.6. The Site incorporates and reflects data and materials provided by third parties, including the public sources identified above. CVE Scorecard does not control and is not responsible for the content, accuracy, or availability of third-party sources, and reflecting third-party data on the Site is not an endorsement of it. To the extent any content on the Site was provided by another information content provider, responsibility for that content rests with its provider.
5. Accuracy; No Warranty; "AS IS" and "AS AVAILABLE"
5.1. THE SITE AND ALL CONTENT ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS AND WITHOUT WARRANTY OF ANY KIND.
5.2. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, CVE SCORECARD AND ITS SUPPLIERS AND LICENSORS DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, COMPLETENESS, TIMELINESS, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE.
5.3. Without limiting the foregoing, CVE Scorecard does not warrant that the Content is accurate, complete, reliable, current, or error-free; that the Site will be uninterrupted, secure, or available at any particular time or location; that defects will be corrected; or that the Site is free of viruses or other harmful components.
5.4. No advice or information, whether oral or written, obtained from CVE Scorecard or through the Site, creates any warranty not expressly stated in these Terms.
5.5. Some jurisdictions do not allow the exclusion of certain warranties, so some of the above exclusions may not apply to you. In that case, such warranties are limited to the minimum scope and duration permitted by applicable law, and nothing in these Terms limits any warranty or other right that cannot be excluded or limited under the law that applies to you.
5.6. You acknowledge the data limitations described in Section 4. You further acknowledge that category groupings, funnels, comparisons, and exposure context are analytical constructs that involve judgment and simplification, and that inferred product versions and similar derived values are estimates and not authoritative statements from any vendor. CVE Scorecard does not warrant that any Characterization is free from error, and may revise, correct, recategorize, or remove any Content at any time.
6. Assumption of Risk; No Reliance
6.1. You use the Site and the Content at your own risk. You acknowledge that the Content includes reports of imperfect third-party data and our own editorial characterizations, and that both are subject to the limitations described in Sections 2 through 5.
6.2. You agree that you will not treat the Content as the sole basis for any decision, and that any decision you make should be based on your own independent investigation, verification against primary sources, and professional advice. You acknowledge that CVE Scorecard has no knowledge of, and takes no responsibility for, your particular circumstances, environment, or requirements.
6.3. You acknowledge that reasonable people may reach different conclusions from the same public data, and that the Content represents one presentation of that data and not a definitive statement of fact about any vendor or product.
6.4. Nothing in this Section 6 applies to, waives, or limits any claim to the extent it arises from fraud, fraudulent misrepresentation, or intentional misrepresentation by CVE Scorecard, or any liability that cannot lawfully be waived or limited.
7. Limitation of Liability
7.1. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL CVE SCORECARD OR ITS PARENTS, SUBSIDIARIES, AFFILIATES, OFFICERS, DIRECTORS, MEMBERS, MANAGERS, EMPLOYEES, CONTRACTORS, AGENTS, SUPPLIERS, LICENSORS, SUCCESSORS, OR ASSIGNS (COLLECTIVELY, THE "COVERED PARTIES") BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS OPPORTUNITY, OR ALLEGED SECURITY BREACH, ARISING OUT OF OR RELATING TO YOUR ACCESS TO OR USE OF, OR INABILITY TO ACCESS OR USE, THE SITE OR THE CONTENT, WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE, OR ANY OTHER THEORY, AND WHETHER OR NOT ANY COVERED PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
7.2. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, THE TOTAL AGGREGATE LIABILITY OF THE COVERED PARTIES FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS, THE SITE, OR THE CONTENT WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (USD $100.00). BECAUSE THE SITE IS PROVIDED FREE OF CHARGE, YOU ACKNOWLEDGE THAT THIS CAP IS A REASONABLE ALLOCATION OF RISK AND A MATERIAL BASIS OF THE BARGAIN.
7.3. The limitations in this Section 7 apply to all claims, including claims arising from the third-party data described in Section 4 and from any interruption, error, or unavailability of the Site.
7.4. NOTHING IN THESE TERMS EXCLUDES OR LIMITS THE LIABILITY OF ANY COVERED PARTY FOR: (a) fraud, fraudulent misrepresentation, or intentional misrepresentation; (b) gross negligence, recklessness, or willful misconduct; (c) death or personal injury caused by negligence; or (d) any other liability that cannot be excluded or limited under applicable law. The disclaimers and limitations in Sections 5 through 7 apply only to the extent permitted by the law that governs your relationship with us, and where they exceed what that law allows, they are limited to the maximum permitted and the remainder of these Terms remains in effect.
7.5. Some jurisdictions do not allow the exclusion or limitation of certain damages, so some of the above limitations may not apply to you. In that case, the liability of the Covered Parties is limited to the maximum extent permitted by applicable law.
7.6. Each provision of these Terms that provides for a limitation of liability, disclaimer of warranties, or exclusion of damages is intended to and does allocate the risks between the parties. This allocation is reflected in the free nature of the Site and is an essential element of the basis of the bargain. Subject to Section 7.4, these provisions apply to the maximum extent permitted by applicable law.
8. Indemnification
8.1. To the fullest extent permitted by applicable law, you agree to defend, indemnify, and hold harmless the Covered Parties from and against any third-party claim, demand, action, or proceeding, and any resulting liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees and costs), to the extent arising out of or relating to: (a) your misuse of the Site or the Content; (b) your violation of these Terms; (c) your violation of any applicable law or of the rights of any third party; or (d) any content or information you submit through the Site.
8.2. This indemnity does not apply to, and you are not required to indemnify the Covered Parties for, any claim to the extent it arises from a Covered Party's own negligence, willful misconduct, fraud, or violation of law, or from the Content as published by CVE Scorecard itself. Your total indemnification obligation under this Section is subject to the same limitations that apply to the Covered Parties under Section 7.
8.3. If applicable law entitles a prevailing party to recover attorneys' fees in connection with a claim covered by this Section, that entitlement will be applied reciprocally between you and CVE Scorecard to the extent required by that law.
8.4. CVE Scorecard reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which case you agree to cooperate with CVE Scorecard's defense of that matter. Neither party will settle any matter that imposes liability or an admission on the other, or that affects the other's rights, without that party's prior written consent, which will not be unreasonably withheld.
9. Acceptable Use
9.1. You agree to use the Site only for lawful purposes and in accordance with these Terms.
9.2. You agree that you will not, and will not attempt to, and will not permit any third party to:
(a) scrape, crawl, spider, harvest, data-mine, or use any automated means or bot to access, extract, or copy the Site or the Content at a volume or in a manner that materially burdens or disrupts the Site, except as expressly permitted in writing by CVE Scorecard or as permitted by our published robots directives or applicable law;
(b) access the Site through any interface other than the interfaces we provide in order to bypass access controls, rate limits, or usage restrictions;
(c) reproduce, duplicate, copy, sell, resell, license, sublicense, distribute, or commercially exploit the Site or the Content, or create derivative works from them, except as expressly permitted by these Terms or by applicable law (including fair use);
(d) interfere with, disrupt, overload, or impair the Site or the servers or networks connected to it, including by launching any denial-of-service attack, injecting malicious code, or transmitting any virus or harmful component;
(e) probe, scan, or test the vulnerability of the Site or breach or circumvent any security or authentication measure;
(f) misrepresent the Content, including by presenting any figure, label, or characterization as a security score, rating, ranking, grade, certification, or endorsement (see Section 3), or by removing, altering, or obscuring any disclaimer, methodology notice, attribution, or source reference;
(g) use the Site or the Content to harass, defame, disparage, or unlawfully harm any person or entity, or in a manner that violates any third party's rights;
(h) impersonate any person or entity, or misrepresent your affiliation with any person or entity; or
(i) use the Site in violation of any applicable law, regulation, or third-party terms, including the terms of the data sources described in Section 4.
9.3. Accounts. Certain features, including email alerts, may require you to create an account. The Site uses passwordless "magic-link" authentication. You are responsible for maintaining the security of the email account associated with your account, for all activity that occurs through your account, and for keeping your contact information current. You agree not to share, transfer, or allow unauthorized use of your account or authentication links. Notify us promptly using the contact form on the Site of any unauthorized use or suspected compromise. We may suspend, disable, or terminate your account at any time, with reasonable notice where practicable, including for any violation of these Terms.
9.4. Email Alerts. If you subscribe to per-vendor email alerts, you consent to receive automated email messages from the Site relating to your selected topics. Alerts are provided on the same informational, "as is," and "as available" basis as the rest of the Content, and they are subject to the same disclaimers and limitations. Alerts may be delayed, incomplete, duplicated, or undelivered, and you should not rely on them for time-sensitive or critical decisions. Every alert email will identify the sender accurately, include our postal address, and provide a working unsubscribe mechanism; we will honor unsubscribe requests within the period required by applicable law. You may unsubscribe at any time using that mechanism or by contacting us. Delivery of alerts depends on third-party email and infrastructure providers that we do not control.
9.5. Forms and Lead Capture. The Site may include embedded third-party forms (for example, a HubSpot form) for contact or lead-capture purposes. Information you submit through these forms is handled as described in our Privacy Policy (see Section 16) and may be processed by third-party providers under their own terms.
9.6. We may, but are not obligated to, monitor use of the Site and may investigate and take appropriate action against any suspected violation of these Terms, including restricting or terminating access.
10. Intellectual Property and Trademarks
10.1. Site Materials. The Site, its design, layout, original text, graphics, compilations, methodology descriptions, and the selection, arrangement, and presentation of the Content are owned by CVE Scorecard or its licensors and are protected by intellectual property and other laws. Except for the limited permission to view the Site for your own informational use, no rights are granted to you in the Site or its materials, and all rights are reserved. Underlying third-party data remains subject to the rights and terms of its respective sources (see Section 4).
10.2. Vendor Names and Marks. Vendor names, product names, logos, and other trademarks referenced on the Site (for example, Cisco, Fortinet, Juniper, Palo Alto Networks, F5, Citrix, and Ivanti) are the property of their respective owners. CVE Scorecard is not affiliated with, authorized by, sponsored by, or endorsed by any of these owners.
10.3. Nominative Fair Use. CVE Scorecard uses vendor names and marks solely to identify and refer to the vendors and products to which the publicly available vulnerability information relates, and for related commentary, comparison, and reporting. This use is intended as nominative fair use: it is limited to what is reasonably necessary to identify the vendor or product, it does not use any more of a mark than necessary, and it does not suggest sponsorship, affiliation, or endorsement by the mark owner. No such reference should be construed as a claim of ownership of, or a commercial association with, any vendor's marks.
10.4. "CVE" and Third-Party Program Marks. "CVE" and related program names or marks are the property of their respective owners. CVE Scorecard is an independent operator and is not affiliated with, sponsored by, or endorsed by MITRE, the CVE Program, or any sponsoring agency. CVE Scorecard uses such terms only descriptively to identify the publicly available vulnerability records to which the Content relates.
10.5. No Endorsement. Nothing on the Site constitutes or implies any endorsement, sponsorship, certification, review, or approval of CVE Scorecard or the Site by any vendor or mark owner, or of any vendor or product by CVE Scorecard.
10.6. Copyright Complaints (DMCA). CVE Scorecard respects intellectual property rights and responds to notices of alleged copyright infringement under the Digital Millennium Copyright Act (DMCA), 17 U.S.C. § 512. If you believe material on the Site infringes your copyright, send a written notice containing the information required by 17 U.S.C. § 512(c)(3) to our designated agent using the contact form on the Site (subject line "DMCA Notice"). We provide a counter-notification process and, in appropriate circumstances, terminate the access of repeat infringers. Full agent registration and notice details are to be completed and published before go-live.
10.7. Feedback. If you send us suggestions, ideas, or other feedback about the Site, you grant us a non-exclusive, worldwide, royalty-free, perpetual, irrevocable license to use and incorporate that feedback without restriction or obligation to you. This license applies only to feedback about the Site and not to any other materials or personal information you may submit.
11. Vendor Data and Corrections Process
11.1. CVE Scorecard presents the Content in good faith and endeavors to reflect public data sources accurately. We recognize that public data, and our processing of it, can contain errors or omissions, and we welcome corrections.
11.2. Any vendor, user, or other interested party who believes that Content is inaccurate, out of date, misattributed, or misleading may submit a correction request by contacting us using the contact form on the Site with the subject line "Data Correction Request." To help us evaluate a report efficiently, please include, where possible: (a) the specific page, vendor, product, figure, or record at issue (a link is ideal); (b) a description of what you believe is inaccurate or misleading, and why; (c) the correct information, if known, and any supporting reference to primary sources (for example, a relevant NVD, CISA, or advisory record or release note); and (d) a contact name and email for follow-up.
11.3. We will acknowledge a correction request that provides enough detail for us to locate the item at issue within a commercially reasonable time, and in any event we aim to acknowledge within five (5) business days. We will review good-faith reports promptly. Where we determine that a data point we control is materially inaccurate or misattributed, or that a Characterization is not adequately supported by its stated basis, we will correct, update, add context to, or remove the item within a commercially reasonable time appropriate to the nature of the issue, and we will log the request, our review, and the action taken. Where source data has changed at NVD, CISA, or another provider, an update at the source will be reflected on the Site following our normal refresh cycle, and we may refer you to that source for issues that originate there and that we do not control. We may decline to make a change where the item accurately reflects the public source, where it reflects our documented methodology and is fairly presented, or where the request is not adequately supported, and we will explain the basis for a decline where practicable.
11.4. Submitting or reviewing a correction request is a good-faith process offered for accuracy. It does not, by itself, create a warranty, a contract, or an admission of liability or of falsity, and it does not alter the disclaimers and limitations in these Terms. We may retain and use correction reports, and records of our review and response, to improve the Site and to document our handling of such requests.
12. Third-Party Links and Services
12.1. The Site may contain links to, or integrations with, third-party websites, resources, data sources, and services that CVE Scorecard does not own or control, including primary vulnerability sources and third-party form, email, analytics, and hosting providers.
12.2. CVE Scorecard provides these links and integrations for convenience only and does not endorse and is not responsible for the availability, accuracy, content, products, services, practices, or policies of any third party. Your access to and use of any third-party website or service is at your own risk and is subject to that third party's own terms and privacy policies. CVE Scorecard is not liable for any loss or damage arising from your use of any third-party website, resource, or service.
13. Privacy
13.1. Your use of the Site is also governed by our Privacy Policy, which describes how we collect, use, and disclose information, including information collected through accounts, email-alert subscriptions, embedded forms, analytics, and cookies. The Privacy Policy is incorporated into these Terms by reference. By using the Site, you consent to the practices described in the Privacy Policy. In the event of a conflict between these Terms and the Privacy Policy regarding the handling of personal information, the Privacy Policy controls as to that subject.
14. Changes to the Site and to These Terms
14.1. CVE Scorecard may modify, suspend, or discontinue the Site or any part of the Content at any time, with or without notice, and is not liable to you or any third party for doing so.
14.2. We may revise these Terms from time to time. When we do, we will update the "Effective Date" above and post the revised Terms on the Site. For material changes, we will provide reasonable advance notice before the changes take effect, by a prominent notice on the Site and, for account holders, by email to the address associated with the account where practicable. Changes apply prospectively only and do not apply to any dispute that arose before their effective date.
14.3. Your continued access to or use of the Site after the effective date of revised Terms constitutes your acceptance of the revised Terms. If you do not agree to the revised Terms, you must stop using the Site and may close your account. We will not apply a new dispute-resolution term retroactively, and where applicable law requires affirmative consent to a material change, we will seek it before that change applies to you.
15. Governing Law and Venue
15.1. These Terms and any dispute arising out of or relating to these Terms, the Site, or the Content are governed by the laws of the State of Texas, without regard to its conflict-of-laws principles, and by applicable U.S. federal law. This choice of law does not deprive you of the protection of any non-waivable provision of the law of the jurisdiction in which you reside.
15.2. Subject to Section 16, you and CVE Scorecard agree that the exclusive venue for any permitted court action will be the state or federal courts located in Travis County, Texas. You and CVE Scorecard consent to the personal jurisdiction of those courts and waive any objection to venue in those courts on grounds of inconvenient forum.
15.3. Each party retains all rights, defenses, privileges, and immunities available to it under applicable law, including any applicable constitutional protections and any statutes protecting speech, petition, or publication on matters of public concern, including statutes providing for the early dismissal of, and the recovery of attorneys' fees and costs for, claims targeting such speech (so-called "anti-SLAPP" statutes). Nothing in these Terms waives or limits any such right, defense, privilege, or immunity, and this Section is not a substitute for confirming, with counsel, that the chosen jurisdiction provides such protection.
16. Dispute Resolution
16.1. Informal Resolution First. Before initiating any formal proceeding, you agree to contact us using the contact form on the Site and provide a written description of the dispute and the relief you seek. You and CVE Scorecard will attempt in good faith to resolve the dispute informally for a period of at least sixty (60) days from the date of that notice. Any contractual limitations period under Section 16.3 is tolled (paused) for the duration of this informal-resolution period. This informal-resolution requirement does not apply where it would prevent a party from meeting a deadline set by applicable law, from seeking timely equitable relief under Section 16.4, or from bringing a claim in small-claims court.
16.2. Forum. If the dispute is not resolved through informal resolution, it will be resolved in the courts identified in Section 15.2, except where applicable law provides otherwise.
16.3. Time Limit. To the fullest extent permitted by applicable law, any claim arising out of or relating to these Terms, the Site, or the Content must be filed within one (1) year after the claim accrues, except where applicable law requires a longer period or prohibits shortening the period, in which case the minimum period permitted by that law applies. This Section does not apply to any claim that applicable law does not permit to be contractually shortened.
16.4. Equitable Relief. Notwithstanding the foregoing, either party may seek injunctive or other equitable relief in a court of competent jurisdiction to protect its intellectual property or confidential information or to prevent unauthorized access to or misuse of the Site.
17. Severability
17.1. If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision will be enforced to the maximum extent permissible so as to give effect to the intent of the parties, or, if it cannot be so enforced, it will be severed and the remaining provisions of these Terms will remain in full force and effect. The invalidity of a provision in one jurisdiction does not affect its validity in any other jurisdiction.
18. General Provisions
18.1. Entire Agreement. These Terms, together with the Privacy Policy and any additional terms expressly incorporated by reference, constitute the entire agreement between you and CVE Scorecard regarding the Site and supersede all prior or contemporaneous understandings, communications, and agreements, whether written or oral, regarding that subject matter.
18.2. No Waiver. CVE Scorecard's failure to enforce any provision of these Terms is not a waiver of that provision or of any other provision, and no waiver is effective unless in writing and signed by an authorized representative of CVE Scorecard.
18.3. Assignment. You may not assign or transfer these Terms or any of your rights or obligations under them without CVE Scorecard's prior written consent, and any attempted assignment in violation of this section is void. CVE Scorecard may assign these Terms in connection with a merger, acquisition, reorganization, or sale of assets, or to an affiliate, provided the assignee agrees to be bound by these Terms.
18.4. No Third-Party Beneficiaries. Except for the Covered Parties identified in Sections 7 and 8, who are intended beneficiaries of the provisions that protect them, these Terms do not create any third-party beneficiary rights.
18.5. Relationship of the Parties. Nothing in these Terms creates any partnership, joint venture, agency, employment, or fiduciary relationship between you and CVE Scorecard.
18.6. Force Majeure. CVE Scorecard is not liable for any delay or failure to perform resulting from causes beyond its reasonable control, including acts of God, natural disasters, labor disputes, internet or utility failures, third-party service outages, governmental actions, and cyberattacks.
18.7. Survival. Any provision that by its nature should survive termination of your access to the Site will survive, including Sections 2 through 13 and 15 through 18.
18.8. Headings and Interpretation. Section headings are for convenience only and do not affect interpretation. The words "including" and "for example" are illustrative and not limiting.
18.9. Electronic Communications. You consent to receive communications from CVE Scorecard electronically, and you agree that electronic communications satisfy any legal requirement that a communication be in writing.
19. Accessibility
19.1. CVE Scorecard aims to make the Site usable by as many people as possible and works toward conformance with the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. If you encounter an accessibility barrier, please contact us using the contact form on the Site so we can address it. This statement is a good-faith commitment and not a warranty of conformance.