Legal
Terms & Conditions
Rules and responsibilities for using CMS Inspect.
Effective date: 27 August 2026
1. Parties and agreement
CMS Inspect is operated by Revibe Digital Limited, a New Zealand company (company number 8188883, NZBN 9429049339697). Registered office: 127 Te Hono Street, Maungatapu, Tauranga 3112, New Zealand. In these Terms, “CMS Inspect”, “we”, “us”, and “our” mean Revibe Digital Limited.
The service is cmsinspect.com, app.cmsinspect.com, and the WordPress plugin and Joomla extension agents. By creating an account, connecting a site, or using the service, you agree to these Terms and our Privacy Policy. If you use CMS Inspect for an organisation, you confirm you have authority to bind that organisation.
2. Definitions
Account means the CMS Inspect login you create. Site means a website you connect. Agent means the WordPress plugin or Joomla extension installed on a Site. Active Site means a connected Site with paid Operations enabled for that billing period, billed at the then-current per-site rate (currently NZD 1 per month). Free inventory and check-in Sites are not Active Sites and are not billed. Operations is the billed product (versus Free). Each connected Site also has a mode: Monitor (read-only), Maintain, or Secure. Site Data means information the Agent or a Connected Service sends us about a Site. Backup means a database dump and, if you enable it, a files backup we upload to your cloud. Connected Service means a third party you or we use to run the product, including Stripe, Google, Dropbox, and Cloudflare. Processors are listed in the Privacy Policy.
3. What the service is (and is not)
CMS Inspect is a SaaS dashboard plus an Agent. Billing is Free (inventory) or Operations (NZD 1 per Active Site per month). Each Site is then set to Monitor, Maintain, or Secure. Monitor Sites are read-only: they must not receive write, update, file, or remote-login commands.
It is not a guarantee of security, uptime, or compliance. It is not a substitute for your own hosting, backups, or security programme. It is not a web application firewall, a pentest, a security operations centre, an incident-response retainer, or a malware-cleanup desk. Cleanup, if needed, is referred to a partner.
4. Licence
We grant you a non-exclusive, revocable, non-transferable right to use the service for your authorised Sites. You must not reverse-engineer the service, resell it except through an approved host or affiliate programme, or use it to attack or scan Sites you do not control.
5. Authority and agency
The Account holder is the customer. You warrant that you own or are authorised by the Site owner to install the Agent, run updates and scans, and send database dumps and files backups off the server. If you manage third-party Sites (for example as an agency), you warrant you have that authority from each Site owner. Connecting a Site you do not control is a material breach. You indemnify us for claims from the real Site owner, host, or users if you connected without authority.
6. Agent and remote commands
You authorise the Agent to run privileged commands on connected Sites, as that Site’s Monitor / Maintain / Secure mode allows. Today that can include: queue updates, install packages, run pattern and permission scans, take a database dump, take a files backup, read a file, restore a core file, roll back an update, and create a short-lived one-click admin login to WordPress or Joomla. Secure mode can also delete a file. Monitor mode does not get those write, update, file, or login commands. A command is only current if it is shown in your dashboard for that Site. You install the Agent, must keep it updated, and are responsible for every action your users queue. We may refuse or rate-limit commands.
You can disconnect a Site. On disconnect we invalidate the site credential and stop commands. We are not responsible if you hide, rename, or leave a stale Agent on a Site.
7. Updates
You should take a restorable backup before you apply an update. A CMS Inspect database dump restores the database only, not plugin, theme, or core files, and is not a full rollback. We do not warrant that a Site will work after an update. We are not liable for plugin, theme, core, or extension conflicts, a white screen of death, data loss, or lost revenue. We are a messenger and operator, not the vendor of the code being updated. Snapshot, health-check, or rollback features, if offered, are best-effort and do not guarantee the Site returns identical. We do not auto-apply patches unless your plan and settings say so.
8. Security scanning
Scans are automated pattern and permission checks. They are not a pentest, not a malware-cleanup guarantee, and not a WAF. False positives and false negatives will happen. Findings are informational. You decide what to ignore or fix. We do not promise we will catch every issue or every infection.
9. Backups
Backups upload to your Google Drive or Dropbox if you connect those accounts. A database dump is always a dump of the database only. It can include your content, your customers’ personal information, commenters, users, orders, password hashes, and configuration. If the Site is on Maintain or Secure and you queue it, the Agent can also take a files backup. Neither kind is an archival warranty, and a database dump is not a full-site rollback.
You own the cloud account and must test restore. We are not liable if Drive or Dropbox is unavailable, over quota, or you delete the folder. We do not promise complete, consistent, or restorable copies. If you restore a dump onto a live Site, that can overwrite the live database; you confirm any restore you run. You remain responsible for your own off-platform backups. We may refuse to handle content that is illegal or that we reasonably believe is stolen. On disconnect we stop new backups and rotate the site secret immediately. Files already in your Drive or Dropbox stay under your control. Any leftover database dump we still hold is a copy of the database (users, orders, comments, password hashes, config), not the filesystem, and is deleted within 30 days. A leftover files backup, if one was taken, can include site files (see the Privacy Policy).
10. Monitoring
Uptime checks and history are monitoring tools, not an availability SLA, unless we agree one in writing. We do not guarantee we will detect every outage.
11. Credentials and secrets
We do not ask you to store WordPress or Joomla admin passwords in CMS Inspect. Access is through the Agent credential, signed commands, and short-lived tokens. We do store the Agent site secret and, if you connect them, OAuth tokens for Google, Dropbox, or similar. How we store those is described in the Privacy Policy. Treat them as root-equivalent. If a secret is compromised, disconnect the Site, rotate immediately, and email support@cmsinspect.com.
One-click admin login (Maintain or Secure) is a remote privilege grant into that Site’s WordPress or Joomla administrator, not into the CMS Inspect dashboard: short-lived, logged, and plan-gated. You accept that risk. Cloud backup tokens belong to your cloud account. We are not the cloud provider.
12. Support access and two-factor authentication
Staff impersonation opens your CMS Inspect dashboard from a staff admin session so we can diagnose a problem. It is not the same as one-click admin login, which opens the customer’s WordPress or Joomla administrator. The staff session is tied to the account that started it. You authorise this when you open a ticket, or if your plan includes it. Impersonation does not grant extra Site powers or upgrade a plan. You can email support@cmsinspect.com to ask which staff accessed your Account.
Use a unique password and turn on 2FA when we offer it. Keep the site secret private. Uninstall the Agent when you sell or drop a Site. Tell support@cmsinspect.com if you think a secret leaked. We can reset 2FA after identity checks we define, and we may disable an Agent or rotate a secret to contain abuse. Revoke staff who leave your organisation promptly. Do not share logins.
13. Customer obligations
Keep Site URLs accurate. Connect only Sites you control or are authorised to manage. Keep account 2FA on if we offer it. Do not share the Account, reseller tokens, or site secrets. Promptly revoke users who leave.
14. Acceptable use
You must not connect or scan Sites without authority; use the product as an open scanner, exploit proxy, spam tool, or botnet; host malware; share login, reseller tokens, or site secrets; or interfere with other tenants, Agent authentication, or billing. We may suspend immediately for abuse, non-payment, legal risk, or suspected compromise.
15. Incidents
If we confirm a breach of our systems that is likely to cause serious harm, or that exposes customer site secrets, backups, or payment data, we will notify affected customers at the Account email without undue delay. If the New Zealand Privacy Act 2020 requires a notifiable privacy breach, we will also notify the Office of the Privacy Commissioner. support@cmsinspect.com is the contact.
You must notify us promptly if your dashboard, Agent, or a connected Site is compromised. We may revoke secrets, disable Agents, or force disconnect to contain an incident. We do not commit to public incident posts or CVE credits.
16. Fees, GST, and Stripe
Free is inventory and basic visibility. Free Sites are not billed. Operations is billed through Stripe at NZD 1 per Active Site per month, or the then-current rate shown at checkout. An Active Site is a connected Site with Operations enabled for that billing period. Prices are in NZD and exclusive of GST unless we say otherwise. You pay GST, VAT, or similar taxes that apply.
Failed payment can suspend Operations (no updates or backups) after a grace period we set. Cancellation stops renewal; paid access continues to the end of the current paid period. Fees are generally non-refundable except where the Consumer Guarantees Act 1993 requires, or we approve a refund in writing. We do not refund downtime caused by your Site, host, or a requested update. Material billing changes will be notified more clearly than routine wording tweaks.
17. Cancellation, data on exit, and leftovers
You may cancel at any time. We may suspend or terminate for non-payment, abuse, legal risk, or a security incident, and we may terminate immediately for breach. After close you may request an export of dashboard data for 30 days. We then delete tenant data we hold, subject to legal hold and the Privacy Policy. You must uninstall the Agent. We are not liable for an abandoned plugin left on a Site. In-flight backups stop; files already in your Drive or Dropbox remain yours.
18. Intellectual property and confidentiality
We own the app, Agents, and related IP. You own Site Data and Backup contents. You grant us a limited licence to process Site Data only to provide the service.
Each party must keep the other’s confidential information confidential. Findings, logs, and Backup contents are confidential, except where disclosure is required by law or these Terms.
19. Third parties
The service uses third parties, including Stripe, Postmark, Cloudflare, optional Google sign-in, Google Drive, Dropbox, Google Analytics if you link a property (your GA property, not cmsinspect.com analytics), and our hosting provider (DigitalOcean in Sydney, provisioned with Laravel Forge). Their outages and terms apply. We are not those companies. The current processor list is in the Privacy Policy.
20. Your indemnity
You indemnify us against claims arising from unauthorised Site connections or Agent use, content on your Sites, your clients’ or end-users’ claims, illegal content in backups, or your failure to patch after we flagged an issue you ignored.
21. Limitation of liability and Consumer Guarantees Act
To the fullest extent permitted by law, we are not liable for indirect or consequential loss, lost profits, lost data, reputational loss, third-party CMS bugs, or third-party claims on your Site, including claims from failed updates, missed malware, unrestorable backups, one-click login misuse, support impersonation, or an outage at a Connected Service.
Our total liability in any 12-month period is limited to the fees you paid us in that period, or NZD 100 if you are on a free plan. This cap does not apply to fraud or wilful misconduct by us, or to rights that cannot be excluded under New Zealand law.
If you are in trade and you acquire the service for the purposes of a business, you agree that the Consumer Guarantees Act 1993 does not apply. If you are a consumer acquiring the service for personal, domestic, or household use, the CGA applies and cannot be contracted out of. CMS Inspect is generally supplied as a business-to-business service.
22. No professional advice
CMS Inspect is a software tool. We are not your lawyer, auditor, or security consultant. Scan findings and reports are not professional advice.
23. Changes, law, and assignment
We may change these Terms with notice in-app or by email. Continued use after the effective date is acceptance. These Terms are the entire agreement for the service. If a clause is unenforceable, the rest still applies. You may not assign these Terms without our consent. We may assign them in a sale of the business.
These Terms are governed by New Zealand law and are in English. The New Zealand courts have exclusive jurisdiction, except that we may seek injunctive relief anywhere.
24. Contact
Notices: support@cmsinspect.com. Postal / registered office: Revibe Digital Limited, 127 Te Hono Street, Maungatapu, Tauranga 3112, New Zealand.

