Terms of Service
Last updated: February 8, 2026
1. Acceptance of Terms
By accessing or using Butterfly Security ("the Service"), you agree to be bound by these Terms of Service. If you do not agree to these terms, please do not use the Service.
2. Description of Service
Butterfly Security provides backup and disaster recovery services for identity infrastructure, currently marketed for Okta, Okta Workflows, and Auth0. The Service allows you to create backups of supported configuration data, including users, groups, applications, policies, workflow assets, and related resources.
2A. Service Availability and Support
The Service is generally available. Support commitments, retention periods, and remedies vary by plan, as described below and in any order form or agreement executed between the parties.
- Support – Standard and Business plans include email support with commercially reasonable response times. Formal service level agreements, including uptime commitments and associated remedies, are available under an Enterprise agreement.
- Backup completeness – backups depend on third-party identity provider APIs. Backups may be partial or delayed as a result of provider rate limits, API changes, permission scope changes, or network conditions outside our control. Backup status, including failures, is surfaced in the dashboard and in your activity log.
- Data retention – retention follows the period stated for your plan. We do not guarantee retention of backup data beyond that period.
- Changes to the Service – we may add, modify, or deprecate features. Where a change materially reduces functionality, we will provide reasonable advance notice.
- Provider and regional coverage – supported identity providers and regions are listed in our documentation. Coverage outside the documented list is not warranted.
Warranty disclaimers are set out in Section 4 and liability limits in Section 5. Nothing in this section expands the warranties given there.
3. Environment Types
3.1 Sandbox/Preview Environments (Recommended for Initial Testing)
We recommend initial testing with sandbox and preview environments, including:
- Okta Preview organizations (*.oktapreview.com) and Developer orgs (*.trexcloud.com)
- Okta Workflows environments associated with non-production Okta orgs
- Auth0 development tenants
3.2 Production Environment Usage
IMPORTANT: PRODUCTION ENVIRONMENT USE
Production identity provider environments may be connected to the Service. By doing so, you acknowledge the following risks and terms.
By connecting a production environment, you acknowledge and agree that:
- You assume all risk for any data loss, service disruption, security incidents, or other damages arising from use of the Service with your production environment
- Restore operations are irreversible and may modify, overwrite, or corrupt your production identity provider configuration
- Butterfly Security disclaims all liability for any direct, indirect, incidental, consequential, or punitive damages resulting from production use, regardless of cause
- No warranty of fitnessis provided for production use; the Service is provided "as is" without any guarantee of reliability, availability, or accuracy for production environments
- You have the authority to connect the production environment and accept these risks on behalf of your organization
- You have tested the Service in a non-production environment and understand its behavior before using it with production systems
3A. Workflows and Automation Platforms
The Service supports backup and restore of Okta Workflows automations. Additional terms apply:
- Cross-org restore: Workflows may be restored to a different Okta Workflows organization than the source. You are responsible for ensuring compatibility and proper configuration in the target environment.
- Connection credentials: API keys, OAuth tokens, and other credentials used by Workflow connections are NOT backed up. You must re-authenticate all connections after restoration.
- Connector Builder projects: Custom connector code and configurations are backed up, but authentication configurations must be reconfigured in the target environment.
- Production Workflows: Restoring Workflows to a production environment is subject to all production environment terms in Section 3.2.
4. Disclaimer of Warranties
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
We do not warrant that:
- The Service will meet your specific requirements
- The Service will be uninterrupted, timely, secure, or error-free
- Backups will be complete, accurate, or restorable
- Any errors in the Service will be corrected
5. Limitation of Liability
IN NO EVENT SHALL BUTTERFLY SECURITY, ITS OPERATORS, AFFILIATES, OR SERVICE PROVIDERS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING WITHOUT LIMITATION, LOSS OF PROFITS, DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES, RESULTING FROM YOUR USE OF THE SERVICE.
This includes, but is not limited to, damages arising from:
- Inability to use the Service or access backups
- Unauthorized access to or alteration of your data
- Data loss, corruption, or incomplete backups
- Failed restoration attempts
- Service interruptions or downtime
- Any impact to your identity provider environment, whether production or non-production
Our total liability to you for any claims arising from your use of the Service shall not exceed the amount you paid for the Service in the twelve (12) months preceding the claim.
6. Your Responsibilities
You agree to:
- Maintain the security of your account credentials and OAuth keys
- Use appropriate OAuth scopes and API permissions with the minimum required access
- Verify backups independently before relying on them for disaster recovery
- Test restoration procedures in non-production environments before applying to production
- Not use the Service for any unlawful purpose
- Comply with your identity provider's terms of service and acceptable use policies
7. Data Handling
By using the Service, you grant us permission to access your identity provider environment via the API credentials you provide, solely for the purpose of creating backups. We store:
- Your account information (email, OAuth provider ID)
- Encrypted API credentials (encrypted with AES-256 at rest)
- Backup files (stored encrypted in Cloudflare R2)
See our Privacy Policy and Security page for more details.
Enterprise customers may request a Data Processing Agreement (DPA) by contacting contact@butterflysecurity.org.
8. Free Trial and Paid Plans
The Service offers a free plan, a 30-day free trial, and paid plans with feature, connection, and retention limits described on the site and in current product documentation. We reserve the right to modify pricing and plan features at any time with reasonable notice.
9. Termination
You may terminate your account at any time by deleting your data from the Settings page in your dashboard. We reserve the right to suspend or terminate your access to the Service at any time for any reason, including violation of these Terms.
10. Changes to Terms
We may modify these Terms at any time. We will notify users of material changes by updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the modified Terms.
10A. Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Delaware, United States, without regard to conflict of law principles. Any disputes arising under these Terms shall be resolved in the state or federal courts located in Delaware.
Before initiating formal proceedings, both parties agree to attempt good-faith resolution through written communication for at least 30 days. Written notice of a dispute should be sent to contact@butterflysecurity.org.
11. Third-Party Services
Butterfly Security is not affiliated with or endorsed by Okta, Inc. or Auth0. All trademarks belong to their respective owners. The Service integrates with third-party services including Okta, Okta Workflows, Auth0, and supporting infrastructure providers described in our Privacy Policy, and your use of those services is subject to their respective terms.
With your consent, we use Google Analytics to collect anonymized website usage data. Google's use of this data is governed by the Google Privacy Policy. You may opt out of analytics cookies at any time via the cookie consent banner.
12. Contact
If you have questions about these Terms, please contact us at contact@butterflysecurity.org.