Skip to content
Legal

Terms of service

How engagements are scoped and run, what each side is responsible for, and how confidentiality, liability and payment work.

Last updated

5 September 2026

These terms apply to the website and to services delivered under them. Where a signed statement of work or engagement letter says something different, that document takes precedence.

1. Introduction

These terms of service (“terms”) govern your use of the Cybersecly website and the penetration testing, vulnerability assessment and cybersecurity consulting services provided byCybersecly LLC (“Cybersecly”, “we”, “us” or “our”). By engaging our services, you agree to these terms.

2. Services

Cybersecly provides cybersecurity assessment services including but not limited to:

  • Penetration testing of web, mobile, API, network, cloud, Active Directory and thick client applications.
  • Vulnerability assessment and security auditing.
  • Red teaming and adversary simulation.
  • Phishing simulation and security awareness testing.
  • Dark web and credential exposure monitoring.
  • Secure code review.
  • Compliance and consulting services covering ISO 27001, PCI DSS, SOC 2, SWIFT CSCF, NCA ECC and related frameworks.

All services are delivered according to a written statement of work or engagement letter agreed by both parties before testing begins.

3. Rules of engagement

Every penetration testing engagement is governed by a mutually agreed rules of engagement document that defines:

  • The scope of systems, applications and networks to be tested.
  • Systems and IP ranges explicitly excluded from testing.
  • Testing windows and permitted hours of activity.
  • Authorised testing techniques and any prohibited methods.
  • Escalation contacts and communication protocols.
  • Data handling and confidentiality requirements.

We will not test any system, application or network outside the agreed scope. We will not perform denial-of-service testing, destructive testing, or any activity outside the rules of engagement without explicit written approval.

4. Client responsibilities

To enable us to deliver services effectively, you are responsible for:

  • Providing accurate and complete information about the systems and assets in scope.
  • Obtaining all necessary authorisations and permissions to conduct security testing on the target systems.
  • Ensuring you have the legal right to authorise penetration testing on all in-scope assets.
  • Notifying relevant internal teams, such as DevOps, SOC and IT, of scheduled testing windows.
  • Providing test credentials and access as agreed during scoping.
  • Backing up critical data and systems before testing begins.

5. Confidentiality

We treat all client data, findings and engagement information as strictly confidential:

  • All findings, reports and engagement data are shared only with designated client contacts.
  • We will not disclose your engagement, findings or vulnerability information to any third party without your explicit written consent, except as required by law.
  • Test credentials, architecture diagrams and internal documentation are stored encrypted and purged at engagement close.
  • We may use anonymised, aggregated data for internal quality improvement and methodology development.
  • Where engagement data contains personal data of people in the European Union or United Kingdom, we act as your data processor. We will enter into a Data Processing Agreement incorporating the EU Standard Contractual Clauses, with the UK Addendum where it applies, on request and at no charge.

6. Intellectual property

All findings, reports and deliverables produced during an engagement are the property of the client upon full payment. Cybersecly retains ownership of its testing methodologies, tools, templates and pre-existing intellectual property used to deliver services.

7. Limitation of liability

Penetration testing inherently carries risk. While we take every precaution to conduct testing safely, including rate-limited scanning, non-destructive techniques and agreed testing windows, no testing methodology can guarantee zero impact on production systems.

Our liability is limited to the fees paid for the specific engagement giving rise to the claim. We are not liable for:

  • Indirect, consequential or incidental damages.
  • System downtime or service disruption within testing windows disclosed and agreed in advance.
  • Vulnerabilities discovered by third parties after engagement completion.
  • Issues arising from systems or applications outside the defined scope of work.

8. Payment terms

Unless otherwise agreed in writing:

  • Fees are quoted as fixed-price per engagement, based on the scope defined in the statement of work.
  • Payment is due within 30 days of invoice date.
  • Late payments may incur interest at 1.5% per month or the maximum permitted by law.
  • All fees are exclusive of applicable taxes.

9. Termination

Either party may terminate an engagement with 14 days written notice. If an engagement is terminated by the client before completion, fees are payable for work completed up to the termination date plus any non-refundable costs incurred. If we terminate due to safety concerns, scope changes or client non-cooperation, the same terms apply.

10. Website use

By using our website, you agree not to:

  • Use the site for any unlawful purpose.
  • Attempt to gain unauthorised access to any part of the site.
  • Interfere with or disrupt the site or its servers.
  • Scrape, crawl or automatically extract data from the site without permission.

11. Third-party services

Our website is served by a cloud hosting provider and uses Resend for email delivery. Where page analytics and the scheduling calendar are enabled, those are third parties too. Each has its own terms and privacy policy, and we are not responsible for the availability or practices of third-party services. Our privacy policy lists what each one receives.

12. Governing law

These terms are governed by the laws of the State of New Mexico, United States, without regard to its conflict-of-law rules. Any dispute arising from these terms or our services is subject to the exclusive jurisdiction of the state and federal courts located in New Mexico, except that either party may seek injunctive relief in any court of competent jurisdiction.

Where a signed statement of work with a client in the European Union or United Kingdom specifies a different governing law or venue, that statement of work prevails for that engagement.

13. Changes to these terms

We may update these terms from time to time. Material changes are communicated to active clients by email. Continued use of our services after changes take effect constitutes acceptance of the updated terms.

14. Contact

For questions about these terms of service, contact us at [email protected]. We are based in Albuquerque, New Mexico.

Our privacy policy covers what we collect and how engagement data is stored, retained and deleted.