Skip to content
CIBHER
Terms License Refunds Privacy Invitee notice Cookies Legal notice

Contents

  1. The licence we grant you
  2. How many machines a licence activates
  3. The free tier
  4. Activation and hardware binding
  5. Moving a license to another machine
  6. Updates and support
  7. What you may not do
  8. Export control and sanctions
  9. No escrow, no recovery
  10. What an Audit Report does and does not evidence
  11. Platform requirements
  12. Limitation of the duress feature on Windows
  13. What we cannot assist with
  14. Warranty
  15. Liability
  16. Termination
  17. Capacity
  18. Governing law

End User License Agreement

Last updated 2026-09-03 · version 1.3
The Polish version of this document is the governing version. This English text is a translation provided for convenience; where the two differ, the Polish version prevails.

Key points

  • There is no escrow and no recovery of any kind. We hold no copy of your master password and no key that opens your vault without it, so if you lose it we cannot recover your data. There is no reset, no backdoor and no support path. This is a statement about our key design, not about everything we could be compelled to do — see “No escrow, no recovery” below.
  • On tiers Small to XL, a licence activates exactly one machine, bound to that machine’s hardware — a second machine needs a second licence. The Enterprise, Edu and Medical tiers are sold per seat: one subscription, whose seat count is the number of machines it may activate.
  • If the licensed machine becomes unusable before you generate a deactivation code, the license cannot be moved. Not by support, not by proving purchase, not by any procedure. Generate a deactivation code before you retire, wipe, repair or dispose of the machine.
  • An Audit Report is not third-party-verifiable and does not by itself certify compliance with any framework.
  • Paid tiers buy encryption quota, never a security capability. Every security feature is in every tier, including the free one.

The licence we grant you

When your subscription is active, we grant you a non-exclusive, non-transferable, revocable licence to install and use CIBHER on each machine your subscription licenses — one machine on tiers Small to XL, and one machine per seat on the Enterprise, Edu and Medical tiers — for the purposes described in our documentation, in accordance with this Agreement.

The software is licensed, not sold. We and our suppliers retain all rights not expressly granted.

How many machines a licence activates

On tiers Small, Small+, Medium, Large and XL, a licence activates exactly one machine — one Mac or one Windows PC — and a second machine needs a second licence. The Enterprise, Edu and Medical tiers are sold per seat: one subscription, whose seat count is the number of machines it may activate.

What a paid tier buys is quota: how many files you may encrypt during your subscription term, and how many sending addresses you may configure on each licensed machine. Sending itself is not metered on any tier.

TierEncryptionsSending addressesMachines
Freea fixed lifetime total1— no license needed
Smallper term101
Small+per term101
Mediumper term101
Largeper term101
XLper term101
Enterprise / Edu / Medicalper seat, per term1 per seat1 per seat

If two people use different accounts on the same physical computer, that is still one machine and one activation.

No activation moves between machines except by the transfer routes this Agreement discloses.

The free tier

CIBHER without a license is not a trial and does not expire. It is a full, unlimited decryptor: anyone can read what you send them without paying us anything, without creating an account, without activating, and without a network connection.

The free tier also generates keys, runs the recipient-verification gate, keeps the audit log and exports Audit Reports, all without limit. What it bounds is how many files you encrypt: a fixed number for the life of the installation, which does not refill. It bounds nothing else — sending is not limited on any tier, and there is no limit on the size of a document you encrypt.

Running out does not lock you out of anything you already have. Decryption stays unlimited on every tier, forever, and files you have already encrypted remain fully usable — you can send them, attach them, or copy them anywhere.

No security feature is behind a paywall. If a capability exists in CIBHER, it exists in the free tier too.

Activation and hardware binding

Activating a license contacts our activation service once and binds the license to that machine. After activation, validation happens offline against the machine itself; the software does not need to reach us to keep working within the period you have paid for.

While your subscription is active and the machine is online, the license file is refreshed silently so its expiry date moves forward. Exactly what activation and refresh transmit is enumerated in our Privacy Policy, and that list is closed.

Moving a license to another machine

This is the most important paragraph in this Agreement. Before you retire, wipe, sell, repair or dispose of the licensed machine, open CIBHER and generate a deactivation code. It is the only thing that frees the license.

If the licensed machine becomes unusable and you did not generate a deactivation code first, there is no transfer route. Not through support, not by proving you paid, not by any procedure we can perform. The license is lost, and this case is not refunded. We know this is harsh; we are telling you plainly rather than letting you discover it at the worst possible moment.

With a deactivation code, transfer is straightforward: submit the code through the support portal together with proof that you control the billing email on the subscription, and activate the new machine. A code stays usable until it is spent: we do not put an expiry on it, and a code you generated some time ago still works. Once we have first seen a code, re-presenting the same one is only accepted for a further 72 hours, which bounds retries and nothing else.

Some hardware changes to a machine that still works — an OS reinstall, a migration, a board repair, a TPM clear, or a panic key wipe — change the machine’s fingerprint. These are handled by self-service re-activation after a cooling period of 14 days, or immediately if you generate a deactivation code first. Each such event counts against your activation allowance.

Licenses are personal to you. You may not sell, sublicense, rent, lease or otherwise transfer a license to a third party without our written consent.

Updates and support

While your subscription is active you receive software updates and email support. Support is by email, with a target first response within five business days, Monday to Friday, 09:00–17:00 Europe/Warsaw, excluding Polish public holidays. That is a target, not a guarantee, and it does not vary by tier. Four things go through the support portal instead, never by email: offline activation requests, deactivation codes, licence-transfer requests, and evidence for Enterprise, Edu or Medical eligibility.

When a subscription lapses, your paid entitlement stops: support and the paid send quota end with the period you paid for. The software itself does not stop — the machine returns to the free tier and keeps working, and it remains a full decryptor.

Security updates are a separate clause, and they do not stop when your subscription does. For five years from the date of your purchase we publish security updates and defect fixes for the version sold, through the application’s update channel. That period runs whether or not your subscription is still active: if you cancel, you keep security updates for the remainder of the five years and you lose the paid send quota at the end of the period you paid for. This is an obligation to publish patched builds. It is not a commitment to keep any service running, and none is required — encrypting and decrypting on your own machine work offline and do not expire.

What you may not do

You may not:

  • copy or distribute the software except as needed for your own backup;
  • sell, rent, lease, sublicense or otherwise make the software available to a third party;
  • remove or alter any notice, licence key mechanism or hardware binding;
  • circumvent, or attempt to circumvent, the activation or quota mechanisms;
  • use the software to commit an offence, to infringe anyone’s rights, or in breach of applicable law.

Reverse engineering. You may not reverse engineer, decompile or disassemble the software, except to the extent that this restriction cannot lawfully be imposed on you. In the EU, Articles 5 and 6 of Directive 2009/24/EC give you rights to observe, study and test the software, and to decompile it for interoperability purposes; nothing here limits those rights. If you want interoperability information, ask us first — we would rather simply give it to you.

Independent security research on a copy you have lawfully licensed is welcome. Please report what you find to security@cibher.eu.

Export control and sanctions

Where CIBHER is sold, and one thing that follows from it. CIBHER is offered for sale in the European Union and is not offered to customers in the United States. In particular, we do not act as a business associate under HIPAA and we do not enter into Business Associate Agreements. A US covered entity should not use CIBHER for protected health information; the “Medical” tier name describes the customers it is priced for, not a HIPAA posture.

CIBHER is cryptographic software published from the European Union and may be subject to export control rules, including EU Regulation 2021/821 on dual-use items, and to applicable sanctions regimes.

You must not use, export or re-export the software in breach of those rules; in particular you may not make it available to a person, entity or territory subject to EU sanctions, and you confirm you are not yourself such a person or entity. If you are unsure whether a particular use is permitted, ask us before you proceed.

No escrow, no recovery

Your master password never leaves your device and is not stored anywhere — not by us, not by an administrator, not in a recovery file. There is no escrow, no reset, no backdoor and no administrative override.

If you lose it, we cannot recover your data. We hold no copy of your master password and no key that opens your vault without it, so no proof of identity or ownership changes that. Please keep a copy of your master password somewhere safe and independent of the machine.

Anyone who obtains a copy of your CIBHER data directory can try passwords against that copy offline, without limit and without lockout. Its only protection is the strength of your master password and nothing else.

This is a statement about CIBHER’s key design, not about everything we could be compelled to do. We operate services that hold pairing records and activation records, and we hold the key that signs pairing attestations. Legal process reaches those directly.

Legal process does not reach your vault, your documents or your master password, because we do not have them.

This is not the same thing as “zero-knowledge”, a term of art about server protocols that does not apply here, because for these operations there is no server.

What an Audit Report does and does not evidence

CIBHER keeps a local, append-only audit log and can export it as an Audit Report. The Report records what CIBHER did on your machine: which verification outcomes occurred, and when.

An Audit Report is not third-party-verifiable. It is a record produced by software on a machine you control, and it does not by itself certify compliance with GDPR, HIPAA, or any other framework. Which regimes apply to your practice, and what evidence each of them requires, remains your determination. Do not present an Audit Report as something it is not.

The Report deliberately omits the cryptographic digests of matched identifiers unless you explicitly opt in at the moment of export, so that a Report cannot leak the very data it exists to say was handled correctly.

Platform requirements

CIBHER requires macOS 13 or later on Apple Silicon, or Windows 11, or Windows 10 version 2004 or later. Intel Macs are not supported.

If you buy a subscription and your machine turns out not to meet these requirements, that is a refund case — see the Refund Policy.

On Windows, where no TPM 2.0 is available, the device key falls back to a software-protected key. Where hardware protection is unavailable the software tells you so.

Limitation of the duress feature on Windows

CIBHER offers a duress mode. The Windows build makes no claim that its use is indistinguishable from ordinary use at the level of on-disk metadata. If your threat model depends on an adversary being unable to tell that duress mode was used, do not rely on the Windows build for that property.

What we cannot assist with

It follows from the design that we cannot help you with any of the following, and no support agreement changes it:

  • recovering a lost master password, or any data protected by it;
  • decrypting a container for which you do not hold the key;
  • moving a license off a machine that became unusable without a deactivation code;
  • proving to a third party that an Audit Report is authentic.

We hold no key material, no vault and no recovery secret. This is the honest form of our warranty position: we are not declining to help, we are unable to.

Warranty

We warrant that the software will materially perform as described in our published documentation. To the fullest extent permitted by law, and except as stated in that sentence, the software is provided “as is” without warranties of any kind, whether express, implied or statutory, including any implied warranty of merchantability, fitness for a particular purpose or non-infringement.

If you are a consumer, your mandatory statutory rights in respect of digital content are not affected by this section.

Liability

The limitation of liability in section “Limitation of liability” of our Terms of Service applies to this Agreement, and in particular our aggregate liability in any twelve-month period is limited to the fees you paid for the subscription in that period.

Nothing limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.

Termination

This licence ends automatically when your subscription lapses, and the machine returns to the free tier. We may terminate the licence for a material breach of this Agreement that you do not remedy within 30 days of us asking you to.

A refunded or charged-back license serial is added to a deny-list, which reaches a machine the next time it checks for updates. We are explicit about the limit of that mechanism: a machine that never checks for updates keeps working. We do not claim revocation is immediate, because it is not.

Capacity

You must be at least 18 years old, and legally capable of entering into a binding contract, to accept this Agreement. If you accept it on behalf of an organisation, you confirm you are authorised to bind that organisation.

Governing law

This Agreement is governed by Polish law, and the jurisdiction and consumer-protection provisions in our Terms of Service apply to it in the same way.

  • Terms
  • License
  • Refunds
  • Privacy
  • Invitee notice
  • Cookies
  • Legal notice
  • Back to cibher.eu

CBPROJEKT sp. z o.o., Wschodnia 6/15, 20-015 Lublin, Poland · KRS 0001221768 · NIP (EU VAT) PL9462763671 · REGON 543893138 · share capital PLN 5,000. Registry court: Sąd Rejonowy Lublin-Wschód w Lublinie z siedzibą w Świdniku, VI Wydział Gospodarczy KRS.

  • English
  • Polski
  • Deutsch
  • Français
  • Español
  • 中文