jssh Terms of Service
Last updated: July 23, 2026
Summary (plain language; the full Terms below control). jssh is a remote-access service for devices you enroll. The core rule: you may only connect to devices and systems that you own or are authorized to access. Session traffic is end-to-end encrypted between the jssh CLI on your machine and the agent on your device, on every path and for every protocol — not just SSH — so we cannot read it. What we can still see is metadata: which operator reached which device, when, which service, and how much. And encryption keeps us out of your sessions, not out of the decision of who may open one: we sign the authorizations that say which operator key may reach which device, so a compromise of our systems could open a new session even though it could not decrypt sessions you already had (Section 3.2). We may suspend or terminate accounts that abuse the Service. The Service is provided "as is," our liability is capped, and these Terms are governed by Delaware law.
1. Agreement and Acceptance
These Terms of Service (the "Terms" or this "Agreement") are a binding agreement between Tanor LLC ("jssh," "we," "us") and the person or entity that accepts them ("Customer," "you"). You accept these Terms by clicking to accept at signup, by creating an account, or by accessing or using the Service. If you do not agree, do not use the Service.
The jssh Privacy Policy and, where jssh processes personal data on your behalf, the jssh Data Processing Agreement (the "DPA") are incorporated into this Agreement by reference.
We may update these Terms from time to time. For material changes, we will give you advance notice by email to your account email address or by prominent notice in the Service, and the updated Terms will take effect no earlier than the date stated in the notice. Your continued use of the Service after the effective date constitutes acceptance of the updated Terms. If you do not agree to an update, stop using the Service and terminate your account under Section 16.
2. Definitions
- "Service" means the jssh remote-access service, including the relay infrastructure, dashboard and web application at app.jssh.io, APIs, documentation, and the Software.
- "Software" means the jssh client software we make available, including the device agent ("Agent") and the operator command-line client ("CLI"), and updates to them.
- "Customer" means the person or entity that accepts these Terms and owns one or more Organizations.
- "Organization" means a tenant within the Service under which Devices are enrolled, users are managed, and access rules are configured. A Customer may have, or (as a managed service provider) manage, multiple Organizations.
- "Device" means a computer or other system on which the Agent is installed and that is enrolled in an Organization.
- "Operator" means an individual authorized by Customer to access Devices through the Service, using the CLI, the dashboard, or compatible tooling.
- "Customer Data" means data that Customer or its Operators submit to the Service or transmit through it, including Device names, tags, and configuration, declared services, and the content of sessions relayed through the Service.
- "Session Metadata" means metadata about the use of the Service, including the acting user, Device identifier, action taken (such as enrollment, approval, token issuance, session open, service changes, revocation), service names accessed, timestamps and durations, denied service-level access attempts within a session, and client IP addresses. Session Metadata does not include the content of any session.
3. The Service
3.1 Description. The Service provides remote access to Customer's enrolled Devices. Each Device runs the Agent, which establishes an outbound, encrypted connection to our relay; Devices do not need to accept inbound connections. Operators open point-in-time sessions to individual Devices — over SSH or other services the Device exposes — subject to the access rules configured in the Organization. Connections are carried either through our relay data-plane or, where network conditions allow, over a peer-to-peer or TURN path negotiated directly between the CLI and the Agent, in which case our relay carries only signaling. The Service records Session Metadata for auditing.
3.2 Encryption; what we can and cannot see. Session traffic is end-to-end encrypted between the jssh CLI and the agent on your Device, on every path (peer-to-peer, TURN, and our own relay) and independently of the protocol carried inside — SSH, RDP, VNC, HTTP, databases or generic TCP alike. The session keys are derived between those two endpoints and never exist on our servers, so we cannot read session content or credentials, and could not produce them if compelled. Each Device authenticates with the key it generated at enrolment and never discloses; the CLI pins that key and refuses a session if it changes. "End-to-end" here means between the jssh CLI and the agent, not between your application and the service on the Device: on both machines the final hop is a local loopback connection in the clear, exactly as with an SSH port-forward. Two limits we state plainly rather than leave implied. First, encryption prevents us from reading sessions; it does not remove us from the decision of who may open one. We publish the Device keys the CLI trusts and sign the authorizations naming which operator key may reach which Device, so a compromise of our systems could authorize a key the attacker controls and open a new session — it could not decrypt sessions already conducted. Each authorization we issue is signed with a key the Device verifies independently and retains, and the CLI pins each Device key on first use, so both forms of substitution leave evidence rather than occurring silently. Second, we still see metadata (Section 3.1), and traffic timing and volume can reveal which protocol a session carries. Section 7.3 describes how we treat session content.
3.3 No service-level commitment. The Service is provided without any uptime, availability, or support commitment or service-level agreement. Section 13 (Disclaimer of Warranties) applies.
3.4 Changes to the Service. We are continually improving the Service and may add, modify, or remove features. We may discontinue material features, or the Service as a whole, with reasonable advance notice.
4. Accounts and Registration
4.1 Accurate information. You must provide accurate, current, and complete registration information and keep it up to date, including a valid email address that you control.
4.2 Authority; organizations. If you accept these Terms on behalf of a company or other entity, you represent that you have authority to bind that entity, and "Customer" refers to it. A user who creates or administers an Organization on behalf of an entity binds that entity to these Terms.
4.3 Responsibility for access. You are responsible for all activity under your account and Organizations, including the acts and omissions of your Operators, members, and (if you are a managed service provider) the users of Organizations you manage, and for safeguarding all credentials, enrollment tokens, API tokens, and devices used to authenticate to the Service. Notify us promptly at security@jssh.io of any suspected unauthorized access.
4.4 Age. The Service is a business tool and is not directed to children. You may not use the Service if you are under 13 years of age (or under 16, or such higher age as applicable law sets for consenting to online services, where you live).
5. Authorized Use
5.1 Your representation of authorization. This is the core condition of the Service. You represent and warrant that you own, or have all necessary rights, consents, and authorizations from the owner of, every Device you enroll and every system, network, and service you access or make accessible through the Service. If you are a managed service provider or otherwise act for others, this includes current authorization from each end client whose devices or systems you enroll or access. You must cease access, and unenroll the affected Devices, immediately if any such authorization ends.
5.2 Prohibited uses. You will not, and will not permit any Operator or third party to, use the Service or Software to:
- access or attempt to access any device, account, system, network, or data without authorization, or exceed authorized access;
- violate the U.S. Computer Fraud and Abuse Act or any analogous law of any jurisdiction;
- probe, scan, penetrate, or attack systems you are not authorized to test, or conduct security testing of third-party systems without written authorization from their owner;
- create, distribute, or operate malware, or use the Service for command-and-control of compromised systems, botnets, or any similar infrastructure;
- traffic in illegal content or use the Service in furtherance of any illegal activity;
- abuse the relay for cryptocurrency mining or similar resource-consuming schemes;
- circumvent or attempt to circumvent any usage limits, access controls, or security measures of the Service;
- resell, sublicense, or make the Service available to third parties as a service, except that a managed service provider may use the Service to manage Organizations for its own clients in accordance with these Terms (including Section 5.1);
- interfere with or disrupt the Service or its infrastructure, or degrade its use by other customers; or
- use the Service to develop a competing product, or scrape or systematically extract data from the Service other than your own Customer Data and Session Metadata.
5.3 Your systems remain yours. The Service is a remote-access tool. You remain solely responsible for your Devices, the systems and physical equipment they control, what your Operators do over sessions, and compliance with all laws applicable to your use — including computer-misuse, privacy, employee-monitoring, and telecommunications laws in the places where you and your Devices are located.
5.4 Managed service providers. If you use the Service to manage Organizations for end clients, you will (a) impose on each end client written terms that disclaim jssh's liability and warranties to at least the extent of Sections 13 and 14, and (b) indemnify jssh under Section 15 against any claim by an end client or other person for whom you manage Organizations.
6. Enforcement
We may investigate suspected violations of these Terms. We may suspend, throttle, restrict, or terminate access to the Service — for an account, an Organization, a Device, or a session — with or without notice, at our discretion, where we believe in good faith that it is necessary to address a violation of these Terms, to protect the Service, other customers, or the public, or to comply with law. We will use reasonable efforts to notify you of enforcement action and, where the issue is curable and does not present an ongoing risk, to give you an opportunity to cure. We will lift a suspension promptly once the grounds for it are resolved, and suspension of a paid Organization for more than 30 days (other than for your breach) entitles you to a pro-rata refund of prepaid fees for the suspended period. We have no obligation to monitor use of the Service, and no failure to act is a waiver.
Report abuse involving the Service to abuse@jssh.io.
7. Customer Data and Privacy
7.1 Ownership. As between the parties, you own Customer Data. You grant us the rights to host, transmit, and process Customer Data, and to display Customer Data other than session content in the dashboard, solely as necessary to provide and secure the Service, to comply with law, and as otherwise permitted by this Agreement.
7.2 Privacy Policy and DPA. We process personal data as described in the Privacy Policy. Where we process personal data contained in Customer Data on your behalf (for example, Device names or metadata that identify your end clients' assets), we do so as your processor under the DPA.
7.3 Session content and Session Metadata. We record Session Metadata for security, auditing, abuse prevention, and operation of the Service. We do not record or store the content of sessions on any path, and we cannot inspect it: session keys are derived between the CLI and the agent and never exist on our systems (Section 3.2). Earlier versions of these Terms reserved the right to run automated abuse detection over traffic that was not end-to-end encrypted. That reservation no longer has an object and we do not carry it forward. We do operate automated abuse detection on connection and Session Metadata, to detect and prevent violations of Section 5 and to protect the Service, our customers, and the public.
7.4 Your responsibility for Customer Data. You are responsible for Customer Data, including its legality and your right to transmit it through the Service, and for providing any notices to and obtaining any consents from your Operators and end users that are required by law.
8. Legal Process and Protective Disclosures
We may access, preserve, and disclose your account information, Session Metadata, and stored Customer Data — we do not record or retain session content, so we have no stored session content to disclose — if required to do so by applicable law, or if we believe in good faith that such access, preservation, or disclosure is reasonably necessary to: (a) comply with legal process or a lawful governmental request; (b) enforce this Agreement; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or personal safety of jssh, our customers, or the public. Where legally permitted and practicable, we will notify you of a legal demand for your data before disclosure so that you may seek protective measures — unless we are legally prohibited from giving notice or we believe in good faith the request involves an emergency threatening death or serious injury — and we will direct requesters to obtain data directly from you where appropriate. If a prohibition on notice later lapses, we will notify you where permitted.
9. Fees and Payment
9.1 Paid plans. Certain features require a paid subscription. Fees, plan contents, and billing periods are stated at purchase. Payments are processed by Stripe under Stripe's own terms; we do not receive or store your card details. You authorize recurring charges for your subscription until cancelled.
9.2 Taxes. Fees are exclusive of taxes. You are responsible for all applicable taxes, duties, and withholdings other than taxes on our income.
9.3 Non-payment. If a payment fails or is overdue, we will notify you, and may suspend the affected Organizations' access to paid features (or, for continued non-payment, the Service) if the amount remains unpaid a reasonable time after notice.
9.4 Price changes; trials. We may change prices with at least 30 days' notice; changes apply from your next billing period after the notice period. Free tiers and trials are offered at our discretion and may be modified or withdrawn at any time. Material reductions or withdrawal of free-tier features will apply to existing accounts only with at least 30 days' notice.
9.5 No refunds. Fees are non-refundable except where required by law or as expressly provided in this Agreement (including Sections 6 and 16.4).
10. Intellectual Property
10.1 Our IP. jssh and its licensors own the Service and the Software, including all associated intellectual property rights. Except for the limited rights expressly granted in this Agreement, no rights in the Service or Software are granted to you.
10.2 License to the Software. Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, non-sublicensable (except to your Operators and, for managed service providers, to the Organizations you manage) license to install and run the Agent on your Devices and the CLI on your Operators' machines, solely to use the Service. You may not reverse engineer, decompile, or disassemble the Software except to the extent this restriction is prohibited by applicable law. The Software is licensed, not sold.
10.3 Feedback. If you give us feedback, suggestions, or ideas about the Service, we may use them without restriction or obligation to you.
10.4 Trademarks; publicity. Your names and trademarks remain yours. Neither party will use the other's name or marks publicly (including in customer lists or marketing) without the other's prior written consent.
11. Software and Automatic Updates
The Software may check for and install updates automatically; on Linux, the Agent installs cryptographically signed updates by default. You may disable automatic updates using the Software's installation options, but unsupported or outdated versions may stop working with the Service and may lack security fixes, and we may require a minimum Software version to connect. Updates are part of the Software and are licensed under Section 10.2.
12. Export Compliance and Sanctions
The Software is subject to the U.S. Export Administration Regulations ("EAR"), and the Service and Software are subject to U.S. sanctions laws administered by OFAC. You represent and warrant that you and your Operators (a) are not located in, organized under the laws of, or ordinarily resident in any country or region subject to a comprehensive U.S. embargo or listed in EAR Country Groups E:1 or E:2 — as in effect at the time of use, and including the Crimea region and the so-called DNR and LNR regions of Ukraine — and (b) are not identified on, and are not owned 50% or more, individually or in the aggregate, by one or more persons identified on, any U.S. government restricted-party list. You will not export, re-export, or transfer the Software, or access or permit access to the Service, in violation of U.S. export control or sanctions laws, including the additional EAR and OFAC restrictions applicable to Russia and Belarus, and you will comply with all such laws applicable to your use.
13. Disclaimer of Warranties
THE SERVICE AND SOFTWARE ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS AND WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY LAW, JSSH DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. JSSH DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE, THAT DEFECTS WILL BE CORRECTED, OR THAT ANY DEVICE WILL BE REACHABLE AT ANY PARTICULAR TIME.
THE SERVICE IS NOT FAULT-TOLERANT. IT IS DESIGNED FOR REMOTE ADMINISTRATION, MAINTENANCE, AND SUPPORT OF DEVICES, INCLUDING INDUSTRIAL AND EMBEDDED DEVICES. IT IS NOT DESIGNED OR LICENSED FOR USE AS A REAL-TIME CONTROL, SAFETY, OR EMERGENCY-RESPONSE CHANNEL — ANY USE IN WHICH THE AVAILABILITY OR REAL-TIME OPERATION OF THE SERVICE IS ITSELF RELIED UPON TO PREVENT DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL, PROPERTY, OR ENVIRONMENTAL DAMAGE (E.G., LIFE-SUPPORT OPERATION, EMERGENCY-STOP OR INTERLOCK PATHS, NUCLEAR, AIRCRAFT, OR WEAPONS CONTROL). REMOTE ADMINISTRATION OF EQUIPMENT IN SUCH ENVIRONMENTS IS PERMITTED ONLY WHERE THE EQUIPMENT'S SAFE OPERATION DOES NOT DEPEND ON THE SERVICE BEING AVAILABLE. THE SERVICE IS A REMOTE-ACCESS TOOL ONLY: CUSTOMER REMAINS SOLELY RESPONSIBLE FOR THE SAFETY, MONITORING, AND OPERATION OF ITS DEVICES AND OF ANY INDUSTRIAL, PHYSICAL, OR OTHER SYSTEMS THEY CONTROL, AND MUST NOT RELY ON THE AVAILABILITY OF THE SERVICE FOR THE SAFE OPERATION OF ANY SUCH SYSTEM.
14. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) IN NO EVENT WILL JSSH BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST DATA, LOSS OF GOODWILL, OR COST OF SUBSTITUTE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; AND (B) JSSH'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICE WILL NOT EXCEED THE GREATER OF (I) ONE HUNDRED U.S. DOLLARS (US$100) OR (II) THE FEES YOU PAID TO JSSH FOR THE SERVICE IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
THESE LIMITATIONS APPLY REGARDLESS OF THE THEORY OF LIABILITY (CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE) AND EVEN IF A LIMITED REMEDY FAILS OF ITS ESSENTIAL PURPOSE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF CERTAIN DAMAGES OR WARRANTIES; IN THOSE JURISDICTIONS, THE ABOVE EXCLUSIONS AND LIMITATIONS APPLY TO THE MAXIMUM EXTENT PERMITTED BY LAW, AND NOTHING IN THIS AGREEMENT LIMITS LIABILITY THAT CANNOT BE LIMITED BY LAW. NOTHING IN THIS SECTION LIMITS LIABILITY FOR A PARTY'S FRAUD, WILLFUL MISCONDUCT, OR GROSS NEGLIGENCE, OR CUSTOMER'S PAYMENT AND INDEMNIFICATION OBLIGATIONS.
15. Indemnification
You will defend, indemnify, and hold harmless jssh and its members, officers, employees, and agents from and against any third-party claim, demand, or proceeding, and all resulting damages, penalties, costs, and reasonable attorneys' fees, arising out of or relating to: (a) your use of the Service or Software in breach of this Agreement; (b) Customer Data; (c) your breach of Section 5 (Authorized Use), including any claim that you accessed a device, system, or network without authorization; or (d) your violation of law — except, in each case, to the extent a claim arises from jssh's breach of this Agreement or its gross negligence or willful misconduct. We will promptly notify you of any such claim (late notice relieves you of your obligations only to the extent you are prejudiced by it) and will reasonably cooperate at your expense. You have sole control of the defense and settlement of the claim; we may participate in the defense with our own counsel at our own expense, and you may not settle any claim in a way that imposes obligations or admissions on jssh without our prior written consent.
16. Term and Termination
16.1 Term. This Agreement applies from your acceptance until terminated.
16.2 Termination by you. You may stop using the Service at any time and may cancel paid subscriptions through the billing portal. An Organization owner may permanently delete an Organization and its data from the dashboard's settings. To delete your account entirely, or for any remaining personal data, contact privacy@jssh.io; we will honor deletion requests as described in the Privacy Policy and DPA.
16.3 Termination by us. We may terminate this Agreement or your access to the Service (a) for material breach that remains uncured 30 days after notice, (b) immediately and without notice, but only in these cases: breach of Section 5 (Authorized Use) or Section 12 (Export Compliance), unlawful use of the Service, use that presents an ongoing risk to the Service, other customers, or the public, or where we are legally compelled to do so, or (c) upon discontinuation of the Service under Section 3.4.
16.4 Effect of termination. Upon termination, your license to the Software and your right to use the Service end, and outstanding fees become due. If we terminate under Section 16.3(c), discontinue the Service, or you terminate because you do not accept a material update to these Terms, we will refund the pro-rata portion of prepaid fees for the unused period. We will delete Customer Data and personal data as provided in the DPA — in general within 60 days of account deletion, except for data in routine backups (which is overwritten in the ordinary course within 90 days) and data we must retain to comply with law, resolve disputes, or enforce this Agreement.
16.5 Survival. Sections 2, 5.3, 5.4, 7.1 (as to accrued rights), 8, 9 (as to amounts owed), 10.1, 10.3, 10.4, 12, 13, 14, 15, 16.4, 16.5, and 18 survive termination.
17. Beta and Early-Access Features
We may offer alpha, beta, preview, or early-access features, identified as such. They are provided AS IS, without any commitment of continuity, support, or fitness, are excluded from any obligations in this Agreement that conflict with this Section, and may be changed or discontinued at any time without notice.
18. General
18.1 Governing law; venue; dispute resolution. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules. Before filing any claim arising out of or relating to this Agreement (other than a claim for injunctive or equitable relief), the parties will first attempt in good faith to resolve the dispute through negotiation for at least 30 days after written notice of the dispute. The state and federal courts located in Delaware have exclusive jurisdiction over any dispute arising out of or relating to this Agreement, and the parties consent to personal jurisdiction and venue there — except that either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property or confidential information. TO THE EXTENT PERMITTED BY LAW, EACH PARTY WAIVES ITS RIGHT TO A TRIAL BY JURY, AND ALL CLAIMS MUST BE BROUGHT IN THE PARTIES' INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING.
18.2 Notices. We may give you notice by email to your account email address or through the Service; notice is deemed given when sent. You may give us notice by email to legal@jssh.io or by mail to 21 SE 1st Avenue, 3rd Floor, Miami, FL 33131, United States; legal notices to jssh are deemed given on receipt. Keep your account email current.
18.3 Assignment. You may not assign this Agreement without our prior written consent, except to a successor in connection with a merger, acquisition, or sale of all or substantially all of your assets, with notice to us. We may assign this Agreement to an affiliate or to a successor in connection with a merger, acquisition, or sale of all or substantially all of our assets. Any other attempted assignment is void.
18.4 Entire agreement. This Agreement (including the Privacy Policy and DPA) is the entire agreement between the parties regarding the Service and supersedes all prior or contemporaneous agreements on that subject. Terms in your purchase orders or vendor forms have no effect. In case of conflict regarding the processing of personal data, the DPA controls.
18.5 Severability; waiver. If any provision of this Agreement is held unenforceable, it will be enforced to the maximum extent permissible and the remainder will remain in effect. A failure to enforce a provision is not a waiver of it; waivers must be in writing.
18.6 Force majeure. Neither party is liable for delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, labor disputes, governmental action, utility or internet failures, or failures of upstream infrastructure providers.
18.7 No third-party beneficiaries. This Agreement creates no rights in any third party, except as provided in the DPA and the Standard Contractual Clauses it incorporates.
18.8 Independent contractors. The parties are independent contractors; this Agreement creates no partnership, joint venture, or agency.
18.9 Headings. Headings and the summary box are for convenience only and do not affect interpretation.
18.10 Claims period. To the extent permitted by law, any claim arising out of or relating to this Agreement or the Service — except claims for unpaid fees or for infringement or misappropriation of a party's intellectual property — must be filed within one (1) year after the claim accrued, or it is permanently barred.
Questions about these Terms: legal@jssh.io. Abuse reports: abuse@jssh.io. Security issues: security@jssh.io. Privacy requests: privacy@jssh.io.