Terms of Use
Last updated:
These Terms of Use apply when you visit or use threatnest.com, contact the ThreatNest agency, or request or purchase its business services (together, the “Services”). They govern website use, service requests, written testing authorization, payment, reports, and Engagement Documents. By using the website or submitting a service request, you agree to these Terms.
Using the website
ThreatNest is an independent international cybersecurity agency. In these Terms, “ThreatNest,” “we,” “us,” and “our” refer to the ThreatNest agency, unless signed Engagement Documents identify another contracting service provider.
The website provides information about ThreatNest services, pricing, and the engagement process. It may be used only for lawful business purposes.
Do not interfere with the website, attempt unauthorized access, or misuse its content.
Website content is general information. It is not a binding offer, testing authorization, security guarantee, compliance certification, or legal, regulatory, or insurance advice.
Service requests
Services are offered to businesses, organizations, professional practices, and people acting for business purposes. A person making a request must be authorized to act for the organization identified in the request.
A request does not create an engagement or require acceptance. Work may be rejected when it is unsafe, unlawful, outside the available expertise, inadequately authorized, or inconsistent with these Terms.
The contracting service provider for paid work will be identified in the applicable proposal, invoice, Service Agreement, Statement of Work, or other Engagement Document.
Engagement documents
The standard Website Security Audit is governed by a signed Service Agreement that combines the service description, scope, methodology, payment terms, deliverables, confidentiality, liability, and Authorization to Test. A proposal, invoice, data processing terms, or other signed document may also apply. Together, these are the Engagement Documents.
If documents conflict, signed engagement-specific terms control, followed by the accepted proposal or invoice, these Terms, and then general website descriptions. Engagement Documents may change these Terms only for the engagement they cover.
Fees, cancellation, and refunds
The standard Website Security Audit fee is USD 2,000. Unless the Engagement Documents say otherwise, 50% is due upon signing and must clear before testing begins, and the remaining 50% is due when the final report is delivered. Payment instructions are provided by invoice.
Specific cancellation and refund terms in the Engagement Documents control. If they are silent, a client may cancel before testing starts and receive a refund less unrecoverable payment charges and approved preparatory work. Fees are not refundable after active testing begins, except where ThreatNest does not deliver the agreed final report.
The included retest may be withheld while the final balance remains unpaid, including when it is still unpaid 14 days after report delivery. Work may also be rescheduled, suspended, or cancelled when authorization, access, payment, safety, or legality becomes unclear.
Client responsibilities
The client is responsible for:
- providing accurate ownership, authority, scope, and technical information;
- obtaining required permission from system owners and third party providers;
- maintaining backups and recovery procedures;
- providing least-privilege test accounts, synthetic data where practical, and a reachable emergency contact;
- identifying operationally sensitive systems and reporting material changes;
- protecting credentials, reports, and evidence;
- reviewing and implementing remediation; and
- determining its own legal, regulatory, contractual, and insurance obligations.
Delivery dates may change when access, approvals, information, client personnel, or systems are not ready. The client is responsible for third party claims, losses, and costs caused by materially false authority statements, unauthorized scope, or misuse of a report. This does not cover loss caused by ThreatNest's intentional misconduct or material failure to follow the agreed scope.
Confidentiality
Nonpublic client identities, system details, credentials, findings, evidence, source code, reports, business records, and communications are treated as confidential. They are used only for the engagement, its administration, or a binding legal request.
Confidentiality does not cover information already known without restriction, independently developed, received from another lawful source, made public without a breach of duty, or subject to a binding disclosure order. The affected client will be notified before a required disclosure unless the order prohibits notice.
Client names, logos, testimonials, vulnerabilities, evidence, and reports are not published without permission.
Reports and intellectual property
After full payment, the client may use and share the final report for remediation, governance, and legitimate discussions with advisers, providers, insurers, auditors, and regulators, provided recipients protect its confidentiality.
ThreatNest retains its pre-existing methods, report structures, templates, tools, scripts, checklists, techniques, and general knowledge. Client-specific findings and evidence are not reused publicly without permission.
A report may not be resold, presented as another provider's work, or edited in a way that misrepresents the assessment.
Service limitations
An assessment is limited to the agreed scope and testing period. It may use automated tools for coverage, but reportable findings are manually reviewed. Security conditions can change after testing.
An assessment does not guarantee that every vulnerability will be found, that an application cannot be compromised, that remediation will be correct, or that future changes will remain secure. The client remains responsible for ongoing security, maintenance, monitoring, access control, patching, and risk management.
An assessment is not legal or insurance advice, continuous monitoring, a regulatory determination, HIPAA validation, or a legal, regulatory, or compliance certification.
Limitation of liability
To the fullest extent permitted by applicable law, ThreatNest is not liable for indirect, incidental, special, exemplary, punitive, or consequential loss, including lost revenue, opportunity, goodwill, savings, or information.
To the fullest extent permitted by applicable law, the total aggregate liability arising from a specific engagement will not exceed the amount paid for that engagement. The limits do not cover fraud, intentional misconduct, or liability that applicable law does not allow to be excluded or limited.
Ending an engagement
Testing may be paused or ended immediately if authorization is withdrawn or disputed, a system owner objects, unexpected operational risk appears, scope information is inaccurate, unlawful activity is suspected, payment is reversed, an emergency contact is unavailable, or continuing would be unsafe or professionally inappropriate.
The client may request an immediate pause through the emergency contact method stated in the signed Service Agreement. Work resumes only after the issue is resolved and authorization remains valid.
Governing law and disputes
The governing law, dispute process, and contracting provider for a paid engagement will be stated in the Service Agreement or Statement of Work.
If the Engagement Documents are silent, the parties will first try to resolve a dispute through written good-faith negotiation. These Terms do not limit rights or remedies that applicable law does not allow the parties to limit.
Changes to these Terms
Updated Terms apply to future website use and future engagements. An update does not replace signed terms for an existing engagement unless both parties agree in writing. The date at the top identifies the current version.
Questions or requests
Questions about these Terms or a proposed engagement can be sent to threatnest@threatnest.com.