Terms of Service
Terms covering use of this website, and the basis on which we provide security testing services.
1. About these terms
These terms apply to your use of this website and describe the general basis on which CyberCache provides security testing services. They are not themselves a contract for services.
Any engagement is governed by a separate written agreement — a proposal, a statement of work, and rules of engagement — signed by both parties. Where those engagement documents differ from this page, the engagement documents prevail.
2. Use of this website
You may read this website, and print or download extracts for your own reference or to share internally when evaluating our services. You may not republish our content as your own, present it as originating from another party, or use it to imply any endorsement or relationship that does not exist.
You must not attempt to compromise this website or the infrastructure it runs on. If you believe you have found a vulnerability, the disclosure route is set out in our Authorized Testing Policy, and we would rather hear from you than not.
3. Information on this website is general
The content here is provided for general information. It describes our services and our approach, and it is not security advice for your specific circumstances. Nothing on this website should be relied upon as a substitute for a scoped engagement, and no statement here forms a warranty about the security of any system.
Any commercial figures, ranges, or indications shown on this website are indicative only. Fees for an engagement are those stated in the signed engagement documents.
Our sample report is a fictional illustration. It does not represent a real client, product, engagement, or vulnerability.
4. How engagements are formed
Nothing on this website is an offer capable of acceptance. Submitting an enquiry or a scope review request does not create a contract, does not oblige either party to proceed, and does not authorize any testing of any system.
An engagement begins only when:
- the scope, approach, deliverables, timescales, and fees are agreed in writing;
- you have provided written authorization for each in-scope asset, from a person entitled to grant it;
- rules of engagement have been agreed and signed by both parties.
The requirements in our Authorized Testing Policy apply to every engagement and cannot be waived by commercial arrangement, including success-based engagements.
5. Your responsibilities
When engaging us, you are responsible for:
- ensuring you have the authority to authorize testing of every asset you place in scope, and obtaining any third-party permissions required;
- providing accurate information about the environment, its architecture, and its dependencies;
- providing the access, accounts, and roles agreed in the engagement documents;
- maintaining adequate backups and the ability to restore service, since any change to a live system carries residual risk;
- informing us of any constraint, fragility, or dependency that could make testing unsafe;
- remediating findings, which remains your responsibility; we test, report, advise, and verify.
If information you provide about authorization or ownership proves to be inaccurate, we may suspend or terminate the engagement, and we are not liable for consequences arising from that inaccuracy.
6. Our responsibilities
We will perform services with reasonable skill and care, in accordance with the scope and the methodology published on this website, and within the boundaries recorded in the rules of engagement.
We will report findings honestly, including the limitations of what we tested. We will tell you promptly about findings that present an immediate and serious risk rather than holding them for the report.
7. No guarantee of security
Security testing is an examination of a defined scope during a defined period. It cannot prove the absence of vulnerabilities.
We do not warrant that any system is secure, that all vulnerabilities have been identified, or that a system is compliant with any standard or regulation. We do not issue certificates, seals, or accreditation, and no deliverable we provide should be presented as one.
8. Confidentiality
Information you disclose to us in connection with an engagement is confidential. Findings, reports, and evidence are confidential to you, and we will not publish, disclose, or reference them without your written permission.
We will not identify you as a client, use your name or logo, or describe your engagement publicly without your written permission.
We expect reciprocal treatment of our methodology, report templates, and any proprietary material we share with you.
9. Intellectual property
We retain ownership of our methodology, tooling, templates, and know-how. On payment of the agreed fees, you receive a perpetual licence to use the deliverables produced for you for your own internal purposes, including sharing them with your customers, auditors, insurers, and advisers where relevant.
You may not present our deliverables as certification, as an endorsement, or as evidence of any accreditation.
10. Fees and payment
Fees, payment terms, currency, and any applicable taxes are stated in the engagement documents. Where an engagement is on a success basis, the criteria that trigger payment are recorded in writing before testing begins, as described on our No Hack, No Pay page.
Cancellation and refund arrangements are set out in our Refund and Cancellation Policy.
11. Liability
Nothing in these terms excludes or limits liability where it cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.
Subject to that, and to the extent permitted by law, we are not liable for indirect or consequential loss, loss of profit, loss of revenue, loss of anticipated savings, loss of business opportunity, or loss of or damage to data arising from your use of this website.
Liability arising from an engagement is governed by the limitation of liability agreed in the engagement documents for that engagement. Where you require a specific liability position or evidence of insurance, raise it during scoping so it can be addressed before the engagement begins.
12. Links to other websites
Where we link to external resources, we do so because we consider them useful. We do not control them and are not responsible for their content, their availability, or their handling of your data.
13. Changes
We may update these terms. The effective date above reflects the current version, and the version in force when an engagement is signed applies to that engagement.
14. Governing law
To be completed before publication. The governing law and jurisdiction for these terms depend on the registered legal entity, which has not been supplied. This clause must state a single named jurisdiction before this page is published or relied upon. See TBD_REGISTER.md item T-01. Until then, the governing law of any engagement is that stated in its signed engagement documents.
15. Contact
Questions about these terms can be sent to info@cybercache.cc.