Terms of Service

Last updated: January 2025

1. Acceptance of Terms

By accessing or using the Cyber Pantheon website (the "Site") at cyberpantheon.us and any associated services (collectively, "Services"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, please do not use our Site or Services.

These Terms apply to all visitors, users, clients, and others who access or use the Services, including prospective clients who submit engagement applications.

2. Description of Services

Cyber Pantheon provides offensive cybersecurity services including but not limited to:

  • Penetration Testing: Authorized simulated cyberattacks to identify security vulnerabilities
  • Vulnerability Assessments: Systematic review of security weaknesses in IT environments
  • Security Architecture Review: Analysis and recommendations for security design
  • Threat Intelligence: Analysis of potential threats relevant to client environments
  • Security Training: Educational services for development teams and technical staff
  • Advisory Services: Strategic cybersecurity consulting

⚠️ CRITICAL NOTICE: All security testing services require explicit, written authorization through a signed Statement of Work (SOW), Rules of Engagement (RoE), and Non-Disclosure Agreement (NDA) BEFORE any testing begins. Cyber Pantheon will NEVER conduct testing without proper authorization.

3. Use of Website

3.1 Permitted Use

You may use our website to:

  • Learn about our services and expertise
  • Submit legitimate engagement inquiries or applications
  • Contact us for professional purposes
  • Access publicly available resources and content
  • Link to our site with appropriate attribution

3.2 Prohibited Conduct

You agree NOT to:

  • Attempt unauthorized testing of our website or connected networks
  • Use automated scripts, bots, or scrapers without permission
  • Attempt to gain unauthorized access to any portion of the Site
  • Interfere with or disrupt the Site's functionality
  • Impersonate Cyber Pantheon personnel or misrepresent your affiliation
  • Use the Site for any unlawful purpose
  • Reverse engineer any aspects of the Site
  • Upload malicious code, viruses, or harmful content

3.3 Responsible Disclosure

If you discover a security vulnerability on our website, please email security@cyberpantheon.us with details. We commit to:

  • Acknowledging receipt within 48 hours
  • Providing status updates every 7 days
  • Crediting researchers who follow responsible disclosure (if desired)
  • Not pursuing legal action against good-faith security researchers

4. Engagement Terms

4.1 Application and Qualification

Submission of an engagement application does not constitute acceptance. We reserve the right to:

  • Decline engagements that conflict with our ethical guidelines
  • Request additional information before accepting an engagement
  • Verify client identity and legitimacy before proceeding
  • Refuse services to entities involved in illegal activities

4.2 Scope and Authorization

All engagements require:

  1. Signed SOW: Detailed scope, timeline, deliverables, and pricing
  2. Rules of Engagement: Explicitly permitted targets, methods, timing, and constraints
  3. NDA: Mutual confidentiality commitments
  4. Authorization Letter: Written confirmation from authorized client representative

4.3 Client Responsibilities

Clients must:

  • Provide accurate, complete information about target systems
  • Designate points of contact for the engagement
  • Obtain necessary internal approvals before authorizing testing
  • Inform relevant stakeholders (IT teams, cloud providers, etc.) about scheduled testing
  • Not entrap or attempt to deceive testers during engagements
  • Maintain backups before any testing begins

4.4 Limitation of Liability

While we exercise professional care in all engagements, clients acknowledge that security testing involves inherent risks:

  • We are not liable for temporary service disruptions caused during testing
  • We are not liable for vulnerabilities we fail to discover
  • Our liability is limited to fees paid for the specific engagement
  • We recommend clients maintain separate cybersecurity insurance

5. Intellectual Property

5.1 Website Content

All content on this website—including text, graphics, logos, images, software, tools, and methodologies—is the property of Cyber Pantheon or its licensors and is protected by intellectual property laws.

5.2 Deliverables and Reports

Unless otherwise specified in the SOW:

  • Final reports: Licensed to client for internal use only
  • Methodologies and tools: Remain proprietary to Cyber Pantheon
  • Custom scripts: Ownership specified in SOW; typically transferred to client upon payment
  • Findings data: Belongs to client; we retain right to use anonymized aggregate data

6. Payment Terms

  • Pricing: As quoted in the accepted proposal or SOW
  • Deposit: Typically 50% due before engagement commencement
  • Balance: Due upon delivery of final report
  • Late payments: 1.5% monthly interest on overdue amounts
  • Expenses: Pre-approved travel/expenses billed at cost
  • Refunds: Prorated refunds available if engagement cancelled before completion

7. Confidentiality

Both parties agree to maintain strict confidentiality regarding:

  • Existence of the engagement (unless publicly disclosed by client)
  • All findings, vulnerabilities, and security weaknesses discovered
  • Client's technical environment, architecture, and security posture
  • Business information shared during the engagement

Confidentiality obligations survive termination of these Terms for a period of three (3) years.

8. Disclaimer of Warranties

OUR SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, INCLUDING BUT NOT LIMITED TO:

  • WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE
  • WARRANTIES THAT SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE
  • WARRANTIES THAT TESTING WILL DISCOVER ALL VULNERABILITIES

Note on Security Testing: Penetration testing is inherently limited by scope, time, technique, and the evolving nature of threats. No security assessment can guarantee complete protection. Our findings represent a point-in-time snapshot.

9. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

  • CYBER PANTHEON'S TOTAL LIABILITY SHALL NOT EXCEED FEES PAID IN THE PRECEDING 12 MONTHS
  • WE SHALL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES
  • WE ARE NOT LIABLE FOR BUSINESS INTERRUPTION, DATA LOSS, OR SECURITY INCIDENTS OCCURRING AFTER OUR ENGAGEMENT CONCLUDES

10. Termination

10.1 By Client

Clients may terminate engagements with 7 days' written notice (prorated refund for unused portion) or immediately for material breach by Cyber Pantheon.

10.2 By Cyber Pantheon

We may terminate if client fails to pay when due, violates RoE, provides false information, or engages in illegal activities.

10.3 Effect of Termination

  • All fees accrued become immediately due
  • Confidentiality obligations survive termination
  • Deliverables completed before termination remain subject to IP terms

11. Governing Law and Dispute Resolution

These Terms are governed by the laws of the State of Alabama, United States, without regard to conflict of law principles.

Dispute Resolution:

  1. Good faith negotiation between parties (30 days)
  2. Mediation through mutually agreed mediator (if negotiation fails)
  3. Binding arbitration in Madison County, Alabama (if mediation fails)

12. Contact Us

For questions about these Terms, contact us at:

Cyber Pantheon

General Inquiries: hello@cyberpantheon.us

Security Issues: security@cyberpantheon.us

Response Time: Within 5 business days

Built with v0