These Terms and Conditions govern the provision of cybersecurity services by Sentova. They apply from the moment you engage us, sign a Statement of Work, or use our website. Several provisions in this document concern the authorization of security testing and the inherent risks of such work, and they carry real legal and operational weight. We ask that you read them in full before any engagement begins. By proceeding, you agree to be bound by these Terms.
1. Introduction and Acceptance
These Terms constitute the agreement between Sentova (“we”, “us”, “our”) and the organization engaging us (“you”, “the Client”). They apply together with any Statement of Work and our Privacy Policy. Where a Statement of Work and these Terms conflict on a specific project matter, the Statement of Work governs that matter. You represent that you are at least 18 years of age and that you have authority to bind your organization to this agreement.
2. Definitions
For the purposes of these Terms:
- “Services” means our cybersecurity consulting, including risk assessment, security architecture, tool implementation, integration, automation, penetration testing, incident response, migration, training, and managed security services.
- “Statement of Work” or “SOW” means the executed brief setting out the scope, deliverables, authorized targets, timing, and price for an engagement.
- “Deliverables” means the assessments, reports, configurations, policies, playbooks, integrations, and documentation we produce.
- “In-Scope Assets” means the systems, networks, applications, accounts, and other assets expressly authorized for testing or assessment in the SOW or an authorization form.
- “Testing” means penetration testing, vulnerability scanning, simulated attacks, and any other active assessment of In-Scope Assets.
- “Security Information” means sensitive material generated or accessed during the engagement, including vulnerability findings, network diagrams, configurations, credentials, and incident data.
- “Confidential Information” means non-public information disclosed by either party, including Security Information, business plans, and internal processes.
3. Scope of Security Services
Our work covers security strategy and planning, implementation, integration, detection automation, migration, and managed services. The precise scope for your engagement is set out in the SOW. We determine the methods, tools, and techniques used to perform the work, in accordance with recognized professional and industry standards, unless the SOW provides otherwise. We may engage vetted specialist subcontractors where an engagement requires it. Where we do so, we remain responsible for the work and bind those subcontractors to the same confidentiality, security, and data protection obligations we owe to you.
4. Authorization, Consent, and Scope of Testing
This section is a condition of any engagement that involves Testing, and it operates regardless of any other provision.
4.1 Written Authorization Required
We perform Testing only within the scope, against the targets, and during the windows expressly authorized in writing in the SOW or a separate authorization form. We will not exceed that authorized scope without further written approval.
4.2 Your Warranties of Ownership and Authority
You represent and warrant that you own, or hold full legal authority to authorize the Testing of, every In-Scope Asset. Where any In-Scope Asset is hosted, operated, or controlled by a third party, including a cloud or hosting provider, you are responsible for obtaining that third party’s authorization for the Testing before it begins, and for providing evidence of such authorization on request.
4.3 Exclusions and Revocation
You are responsible for identifying any systems, data, or time periods that must be excluded from Testing. You may revoke authorization at any time by written notice, on receipt of which we will cease the relevant Testing as soon as reasonably practicable.
4.4 Reliance and Legal Compliance
You acknowledge that Testing conducted without proper authorization may constitute a violation of computer misuse, unauthorized access, and related laws. We rely entirely on the authorization and warranties you provide under this section, and we act solely as your authorized agent in performing Testing. You are responsible for any claim arising from your failure to hold or obtain the necessary authority.
5. Acknowledgment of Inherent Security Risks
Active security work carries risks that cannot be fully eliminated, and you accept these risks as a condition of the engagement. Testing, scanning, and exploitation activities may cause unintended effects, including system instability, performance degradation, service interruption, and, in rare cases, the loss or corruption of data.
You must maintain complete and verified backups of all relevant systems and data before any active Testing begins. We strongly recommend that high-risk or production systems be tested only where this has been expressly accepted in writing in the SOW.
We take reasonable care to plan and conduct Testing so as to limit disruption. Subject to that standard of care, we are not liable for incidental disruption, downtime, or data loss arising from Testing that was properly authorized and performed with reasonable skill and care.
6. No Guarantee of Security or Breach Prevention
No security measure is impenetrable, and no provider can guarantee that an environment will not be compromised. Our Services are designed to reduce risk; they do not eliminate it. We do not warrant that we will identify or prevent every vulnerability, threat, intrusion, or security incident.
The threat environment changes continuously, and a configuration that is secure at the time of our work may later be exposed by new techniques, new vulnerabilities, or changes you make to your environment. You remain responsible for your overall security posture, including the security of systems and decisions outside the scope of our engagement.
7. Client Responsibilities and Cooperation
The effectiveness of a security engagement depends materially on your participation. You agree to:
- Provide accurate information about your environment and the access we require to perform the Services.
- Maintain current backups and a tested recovery capability throughout the engagement.
- Designate a single decision-maker authorized to approve work, grant authorizations, and respond to escalations promptly.
- Implement the security measures necessary to operate your environment safely, including those we recommend.
- Maintain the licences and seats your environment requires on the security platforms we configure.
Where information or access is provided late, incompletely, or inaccurately, timelines may be extended, the value of our findings may be reduced, and costs may increase. We are not liable for any deficiency arising from such information.
8. Vulnerability Findings and Remediation
Our assessments identify vulnerabilities that are known and detectable at the time of the work using reasonable methods. A security assessment is a point-in-time exercise and is not exhaustive; the absence of a finding does not constitute a warranty that no vulnerability exists.
We provide findings and recommendations. Unless your SOW expressly includes managed remediation, you are responsible for deciding which recommendations to implement and for implementing them. We are not liable for any harm arising from a vulnerability you elected not to remediate, that fell outside the authorized scope, or that was not reasonably detectable at the time of the work.
9. Incident Response Services
Where the SOW includes incident response, we apply reasonable professional skill and care to assist you in containing, investigating, and remediating a security event. The outcome of incident response is inherently uncertain. We do not guarantee full recovery of data or systems, the complete removal of a threat, the identification of an attacker, or the prevention of further harm.
We are not responsible for the underlying incident or for losses arising from it, including business interruption, data loss, regulatory exposure, or ransom demands. Decisions such as whether to pay a ransom, notify regulators, or notify affected individuals are yours alone, and you should take your own legal advice on them.
10. Managed Security and Monitoring Services
Where the SOW includes managed services such as monitoring or threat hunting, the coverage hours, scope, and response targets are defined in that SOW. Monitoring and detection are conducted on a reasonable-efforts basis. We do not guarantee that every threat or anomaly will be detected, and you acknowledge that false positives and false negatives are inherent to detection technology. Response targets describe the time within which we will begin to act on a qualifying alert, and are not a guarantee of resolution.
11. Compliance and Regulatory Support
Where we assist with frameworks such as ISO 27001, SOC 2, HIPAA, PCI DSS, or the GDPR, we configure tools and prepare documentation to support your compliance objectives. We do not guarantee that you will achieve or maintain certification, pass any audit, or satisfy any regulator. Certification and audit outcomes are determined by independent auditors and certifying bodies whose decisions are outside our control. Nothing we provide constitutes legal or regulatory advice, and you should obtain advice from qualified professionals on your obligations.
12. Confidentiality and Handling of Sensitive Information
Each party shall protect the other’s Confidential Information and use it only for the purposes of the engagement. This obligation does not extend to information that is or becomes public through no fault of the receiving party, was already known to it, was independently developed, or was lawfully obtained from a third party without restriction.
Security Information warrants particular care. We store it securely, restrict access to personnel who require it, and apply least-privilege principles to our handling of your environment. You acknowledge that our reports and findings describe weaknesses in your environment and that their disclosure could increase your exposure. You are responsible for protecting any Security Information we provide to you and for limiting its distribution. The confidentiality obligations survive for two years following the end of the engagement, and indefinitely in respect of any trade secret or live vulnerability information.
13. Data Protection
In delivering the Services, we may access or process personal data within your environment. Where we do so on your behalf, we act as your processor and handle that data in accordance with applicable data protection law, including the GDPR and the CCPA where they apply. You act as the controller and remain responsible for the lawful basis for that processing and for any required consents and notices. Where a data processing agreement is required between the parties, we will enter into one, and it shall apply alongside these Terms.
14. Third-Party Platforms and Threat Intelligence
We configure and operate third-party security platforms, such as CrowdStrike, Palo Alto Networks, Fortinet, Splunk, and SentinelOne, but we do not own or control them. Those vendors set their own pricing, modify their features, and may experience outages, in each case outside our control. We do not warrant the accuracy, completeness, or timeliness of any third-party threat intelligence feed. Where a vendor changes or withdraws functionality on which a configuration depends, any resulting remediation constitutes additional work rather than a defect in our Deliverables.
15. Fees and Payment
Fees are set out in the SOW or invoice prior to the commencement of work. Additional scope is quoted separately and provided before such work begins. Invoices are due within fourteen days of the invoice date unless the SOW provides otherwise, and any deposit, where it applies, is non-refundable. Overdue invoices accrue interest at 1.5% per month, or the maximum rate permitted by law if lower. We may suspend the Services on any account more than fifteen days past due, although we will not knowingly suspend active monitoring in a manner that leaves you exposed without first giving you reasonable written notice. Payments are non-refundable once work has commenced. You are responsible for all applicable taxes and for any pre-approved out-of-pocket expenses we incur.
16. Intellectual Property and Deliverables
Our frameworks, testing methodologies, tooling, and methods remain our exclusive property and are not transferred to you. Upon receipt of payment in full, you are granted a perpetual, non-exclusive, non-transferable licence to use the final Deliverables for your internal security purposes. Your data and pre-existing materials remain yours, and you grant us a limited licence to use them solely to perform the Services. You agree not to use any Deliverable, tool, or technique we provide for any unlawful purpose or against any system you are not authorized to access. We may reference the engagement in anonymized form for our portfolio unless you instruct us otherwise in writing.
17. Limitation of Liability
To the maximum extent permitted by law, our total aggregate liability arising out of or in connection with these Terms, any SOW, or the Services shall not exceed the fees paid by you to us in the twelve months preceding the event giving rise to the claim, or one hundred US dollars where no fees have been paid.
We shall not be liable for any indirect, incidental, special, or consequential loss, including loss of profit, loss of revenue, loss or corruption of data, business interruption, regulatory fines, or reputational harm, even if advised of the possibility of such loss. In particular, and without limiting the foregoing, we shall not be liable for losses arising from a security breach, intrusion, or incident that our Services did not cause, nor for the acts of any threat actor. Where applicable law prohibits these limitations, our liability shall be limited to the minimum extent permitted by that law.
18. Disclaimers and Warranties
Our website and any digital resources we provide are offered on an “as is” and “as available” basis, without warranty of any kind. To the maximum extent permitted by law, we disclaim all implied warranties, including those of merchantability, fitness for a particular purpose, and non-infringement. We warrant only that the Services will be performed with reasonable skill and care in accordance with recognized professional standards, and this is your sole and exclusive warranty in respect of the Services.
19. Indemnification
You agree to indemnify and hold harmless us, our personnel, and our subcontractors against any claim, loss, or cost, including reasonable legal fees, arising out of your use of the Services or Deliverables, your failure to hold or obtain the authority required under Section 4, your decisions regarding remediation or incident response, your breach of these Terms, or any infringement of third-party rights by materials or instructions you provide.
20. Term and Termination
These Terms take effect upon your first use of the Services or first executed SOW and continue until all active SOWs have been completed, unless terminated earlier. Either party may terminate an engagement on thirty days’ written notice, in which case you shall pay for all completed work and committed costs. Either party may terminate immediately, on written notice, if the other materially breaches these Terms and fails to cure within fifteen days of notice, or becomes insolvent or ceases to trade.
On termination, we will, at your written request made within thirty days, provide a reasonable handover and securely return or destroy the Security Information in our possession, save where retention is required by law. We will confirm any destruction on request. The provisions relating to authorization, intellectual property, confidentiality, data protection, limitation of liability, indemnification, and dispute resolution survive termination.
21. Non-Solicitation and Independent Contractor Status
For twelve months following the end of an engagement, neither party shall directly solicit the personnel of the other who were involved in it, without prior written consent. General public advertisements are excluded from this restriction. We act as an independent contractor, and nothing in these Terms creates an employment, partnership, or agency relationship between the parties, except in respect of the limited authorized-agent role described in Section 4.
22. Force Majeure
Neither party shall be liable for any delay or failure to perform caused by circumstances beyond its reasonable control, including natural disasters, pandemics, government action, war, civil unrest, labor disputes, power or network failures, large-scale cyberattacks affecting infrastructure beyond your environment, or outages affecting the security platforms on which we rely. The affected party shall notify the other promptly and take reasonable steps to limit the impact.
23. Governing Law and Dispute Resolution
These Terms are governed by and construed in accordance with the laws of [Insert Governing State / Country], without regard to its conflict-of-laws principles. The parties shall first seek to resolve any dispute through good-faith negotiation. If the dispute is not resolved within thirty days of written notice, it shall be referred to binding arbitration at [Insert Arbitration Location] under the rules of the relevant arbitration body. The prevailing party shall be entitled to recover its reasonable legal fees and costs.
24. General Provisions
If any provision of these Terms is held unenforceable, the remaining provisions shall remain in full force and the affected provision shall be modified to the minimum extent necessary to render it enforceable. A failure to enforce any right shall not constitute a waiver of it. You may not assign your rights without our prior written consent, although we may assign ours to a successor entity. These Terms, together with any SOW and our Privacy Policy, constitute the entire agreement between the parties and supersede all prior understandings on the same subject matter. We may amend these Terms from time to time and will provide at least thirty days’ notice of any material change; continued use of the Services constitutes acceptance. Where we provide a translation, the English version shall prevail.
25. Contact Us
For any question concerning these Terms, please contact us:
Email: [email protected] | Web: sentovasecurity.com
