Siemphony
Terms of Service
Last updated 30 August 2026
1. Agreement, eligibility, and who “we” are
By creating an account or otherwise using Siemphony (the Service), you accept these Terms. If you do not accept them, do not use the Service. If you are using it for an organisation, you confirm you are authorised to bind that organisation, and “you” means both you and it.
“Operator” the individual who provides Siemphony, established in the United States, contactable at the Operator's legal contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live). “We”, “us” and “our” mean the Operator.
“Content” anything you submit to the Service: rules, translations, tags, lessons, comments, verdicts, reactions, field reports, profile information and anything attached to any of them.
“Rule” a detection rule authored in Sigma and published on the Service, together with its metadata and generated backend queries.
You must be 18 or older. The Service is built for security professionals and is not directed to children. We do not knowingly maintain accounts for anyone under 18, and we will close one if we learn of it.
2. Every rule here is unverified. Test it before you deploy it.
No rule published on Siemphony has been executed against production telemetry in your environment, or in any environment resembling it. The reference corpus was machine-authored from the MITRE ATT&CK detection layer and reviewed by another model. Where a rule carries a verification badge, that badge means it fired on a specific public attack capture in our lab and nothing more — it is evidence, not a fitness assessment for your estate.
The four SIEM queries on a rule page are produced by our own translator rather than by pySigma, and are previews. They may be syntactically valid and semantically wrong for your data model, your field mappings or your log sources.
A detection taken from here is a starting point. Read it, understand what it matches, test it against your own data, and tune it before it goes anywhere near production. Deploying one untested is how you end up with an alert that never fires, or one that fires on your backup software every night until people stop reading alerts. You are solely responsible for what you deploy and for the consequences of a detection that misses, misfires or floods.
3. Your account
One account per person. You are responsible for everything done under your account and for keeping your credentials confidential. Tell us at the Operator's security contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live) promptly if you believe it has been compromised.
A confirmed email address is required to publish, comment or leave a verdict. Certain handles are reserved — those colliding with routes, and the system account owning the reference corpus — and the Service will refuse them.
You may not share, sell or transfer an account, register one by automated means, or create a new one to evade a suspension.
4. Beta software
Siemphony is pre-release. Features appear, change and are withdrawn; data models change; interfaces break. We may modify, suspend or discontinue any part of the Service at any time. We do not promise availability, and we do not promise that Content will survive a migration — keep your own copies of anything that matters to you. Every rule you author is downloadable as Sigma from its own page, and you should use that.
5. Your work stays yours — and what publishing licenses
You keep ownership of your Content. Nothing here transfers copyright to us.
Licence to us. You grant the Operator a non-exclusive, worldwide, royalty-free, sublicensable licence to host, store, reproduce, cache, transmit, adapt for formatting, and display your Content, solely to operate, secure and improve the Service and to make it available as you have directed through your own visibility settings. “Sublicensable” covers our hosting and delivery providers doing the same on our behalf; it is not permission to license your work to anyone else. The licence ends when you delete the Content or your account, except for backups pending deletion and for copies others have already lawfully taken.
Licence to everyone else, when you publish a Rule. Publishing a Rule licenses it to the public under the Detection Rule License 1.1 — the licence SigmaHQ applies to its own corpus. In short: others may use, copy, modify and redistribute your published Rules, including commercially, provided they credit you as the author and keep the licence notice with the rule. You warrant that you are entitled to license the Rule on those terms.
This licence is deliberate and it is the point of the corpus. It is also irrevocable as to copies already taken: unpublishing a Rule stops us distributing it, and does not reach into anyone’s repository. If you do not want work licensed this way, keep it as a draft or keep your profile private.
Comments, verdicts and field reports are not Rules and are not covered by that licence. They remain yours under the licence to us above.
Feedback. If you send us suggestions about the Service, we may use them without restriction and without owing you anything. This does not apply to your Content.
6. What you must not publish
Do not publish anyone else’s work as your own, or anything that infringes a copyright, trademark, trade secret or other right.
Do not paste telemetry you are not permitted to disclose. Real log events carry hostnames, usernames, internal addresses and sometimes credentials, and anything you attach to a field report is public. Redact before you submit. You are responsible for confidential and personal data you choose to publish, including under your employer’s policies and any data-protection law that applies to it.
Detection content is inherently dual-use and that is fine — a rule describes an attack in order to catch it. Malware, working exploit code, credential dumps, and material whose purpose is to cause harm rather than to detect it are not detection content and do not belong here.
Nothing unlawful, no harassment, no impersonation, and nothing that would put the Operator in breach of a law or a provider’s terms.
7. What you must not do to the Service
Do not probe, scan, disrupt or circumvent the Service or its access controls; do not attempt to read Content you are not authorised to read; do not flood it with automated writes; do not publish a rule crafted to consume server resources rather than to detect anything. Write rate limits are enforced at the database and abuse ends an account.
Automated access — crawling, scraping, bulk export — is permitted only within robots.txt and at a rate that does not degrade the Service for others. Do not use the Service or its Content to train a machine-learning model without our written permission, other than as the DRL 1.1 permits for published Rules.
Authorised testing only
You warrant that you are authorised to run any detection, query or technique you take from Siemphony against every system you run it against. Nothing on this Service is permission to test, scan or attack infrastructure you do not own or do not have documented authority over. Security research is lawful; doing it to someone else’s estate without authorisation generally is not, and that is your responsibility alone.
8. Export control and sanctions
The Service is operated from the United States and is subject to its export control and sanctions laws. You may not access or use it if you are located in, ordinarily resident in, or organised under the laws of a country or region subject to comprehensive U.S. sanctions, or if you are on a restricted-party list maintained by the U.S. government. You may not export or re-export Content from the Service in breach of those laws.
9. Copyright complaints
If you believe Content on Siemphony infringes your copyright, write to the Operator's copyright contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live) with: your contact details; identification of the work; the URL of the Content complained of; a statement that you believe in good faith the use is unauthorised; a statement, under penalty of perjury, that your notice is accurate and you are the owner or authorised to act for them; and your signature, electronic or physical.
We remove Content we determine to be infringing and we terminate the accounts of repeat infringers. If your Content is removed and you believe that was wrong, you may send a counter-notice to the same address.
10. Third-party standards and trademarks
Sigma is a community standard maintained by SigmaHQ. ATT&CK is a registered trademark of The MITRE Corporation; technique names and descriptions on this Service come from ATT&CK under CC BY 4.0 and are neither reviewed nor endorsed by MITRE. Siemphony is not affiliated with, endorsed by or sponsored by SigmaHQ, MITRE, Microsoft, Splunk, Elastic or Wazuh, and references to their products describe compatibility only. All trademarks belong to their owners.
11. Disclaimer of warranties
Read this one
THE SERVICE AND ALL CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTY OF ANY KIND. To the fullest extent permitted by law, we disclaim all warranties, express or implied, including the implied warranties of merchantability, fitness for a particular purpose, title and non-infringement, and any warranty arising from course of dealing or trade usage.
We do not warrant that the Service will be available, secure or error-free; that a rule will detect any particular activity; that a translated query is correct for your backend; or that any Content is accurate, complete or fit for your purpose.
That disclaimer is not us hiding a known problem. It is section 2 restated in the form the law recognises: this Service tells you, on every rule page, that nothing here is verified. Treated as a starting point it is useful; treated as a vetted ruleset it will let you down.
Some jurisdictions do not allow the exclusion of certain warranties. Where that is so, the exclusions above apply only as far as that law permits, and you may have rights that these Terms cannot remove.
12. Limitation of liability
Limits on what we owe you
To the fullest extent permitted by law, we are not liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, lost revenue, lost data, business interruption, or the cost of substitute services — including any loss arising from a detection that failed to fire, fired wrongly, or was deployed untested.
Our total aggregate liability arising out of or relating to the Service is limited to the greater of the amount you paid us in the twelve months before the claim, or one hundred United States dollars (US$100). Siemphony is currently free, so for most users that figure is US$100.
These limits apply regardless of the theory of liability and even if a remedy fails of its essential purpose. They allocate risk between us, and the Service is provided free on the strength of that allocation.
Nothing in these Terms excludes liability that cannot lawfully be excluded — including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for gross negligence or wilful misconduct where the applicable law does not permit their exclusion. Some jurisdictions do not allow some of the limitations above; where that is so, they apply only as far as that law permits.
13. Your indemnity to us
You will defend, indemnify and hold harmless the Operator from any claim, demand, loss or expense — including reasonable legal fees — arising from your Content, your use of the Service, your breach of these Terms, your breach of any law, or your infringement of anyone else’s rights. We will tell you promptly of any such claim and will not settle it without your consent, which you will not unreasonably withhold.
14. Suspension, termination and what survives
You may stop using the Service at any time and ask us to delete your account by writing to the Operator's privacy contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live).
We may suspend or terminate an account that breaches these Terms, attacks the Service, or exposes us or other users to legal risk. Where it is reasonable and lawful to do so, we will say why and give you a chance to put it right first. We may remove Content that breaches section 6.
If we discontinue the Service, we will give reasonable notice and time to export your work.
Sections 5 (licences already granted), 6, 11, 12, 13, 15 and 16 survive termination. So does the DRL 1.1 licence on Rules you published while your account was open — see section 5.
15. Governing law and disputes
These Terms and any dispute arising out of them or the Service are governed by the federal laws of the United States and the laws of the state in which the Operator resides, without regard to conflict-of-law rules.
Talk to us first. Before filing anything, write to the Operator's legal contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live) describing the dispute and what you want. Most things end there, and we would both rather they did. If it is unresolved after thirty days, either of us may go to court.
You and we agree to the exclusive jurisdiction of the state and federal courts for the place in which the Operator resides, and each waives any objection to that venue. If you are a consumer, this does not deprive you of the protection of mandatory rules of the law where you live.
16. The rest
Changes. We may change these Terms. If a change is material we will say so on the Service before it takes effect and update the date at the top. Continuing to use the Service after that means you accept the new Terms; if you do not, stop using it and ask us to close your account.
Severability. If a provision is held unenforceable, it is limited or severed to the minimum extent necessary and the rest stays in force.
No waiver. Not enforcing a provision is not a waiver of it.
Assignment. You may not assign these Terms without our written consent. We may assign them to a successor in connection with a merger, acquisition or sale of assets.
Entire agreement. These Terms and the Privacy Policy are the whole agreement between us about the Service and replace anything said before. No third party has rights under them.
Notices. We contact you at your account email address. You contact us at the Operator's legal contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live).