Terms of Service
Last updated: January 2025
1. Acceptance of Terms
By accessing or using the Cyber Pantheon website (the "Site") at cyberpantheon.us and any associated services (collectively, "Services"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, please do not use our Site or Services.
These Terms apply to all visitors, users, clients, and others who access or use the Services, including prospective clients who submit engagement applications.
2. Description of Services
Cyber Pantheon provides offensive cybersecurity services including but not limited to:
- Penetration Testing: Authorized simulated cyberattacks to identify security vulnerabilities
- Vulnerability Assessments: Systematic review of security weaknesses in IT environments
- Security Architecture Review: Analysis and recommendations for security design
- Threat Intelligence: Analysis of potential threats relevant to client environments
- Security Training: Educational services for development teams and technical staff
- Advisory Services: Strategic cybersecurity consulting
⚠️ CRITICAL NOTICE: All security testing services require explicit, written authorization through a signed Statement of Work (SOW), Rules of Engagement (RoE), and Non-Disclosure Agreement (NDA) BEFORE any testing begins. Cyber Pantheon will NEVER conduct testing without proper authorization.
3. Use of Website
3.1 Permitted Use
You may use our website to:
- Learn about our services and expertise
- Submit legitimate engagement inquiries or applications
- Contact us for professional purposes
- Access publicly available resources and content
- Link to our site with appropriate attribution
3.2 Prohibited Conduct
You agree NOT to:
- Attempt unauthorized testing of our website or connected networks
- Use automated scripts, bots, or scrapers without permission
- Attempt to gain unauthorized access to any portion of the Site
- Interfere with or disrupt the Site's functionality
- Impersonate Cyber Pantheon personnel or misrepresent your affiliation
- Use the Site for any unlawful purpose
- Reverse engineer any aspects of the Site
- Upload malicious code, viruses, or harmful content
3.3 Responsible Disclosure
If you discover a security vulnerability on our website, please email security@cyberpantheon.us with details. We commit to:
- Acknowledging receipt within 48 hours
- Providing status updates every 7 days
- Crediting researchers who follow responsible disclosure (if desired)
- Not pursuing legal action against good-faith security researchers
4. Engagement Terms
4.1 Application and Qualification
Submission of an engagement application does not constitute acceptance. We reserve the right to:
- Decline engagements that conflict with our ethical guidelines
- Request additional information before accepting an engagement
- Verify client identity and legitimacy before proceeding
- Refuse services to entities involved in illegal activities
4.2 Scope and Authorization
All engagements require:
- Signed SOW: Detailed scope, timeline, deliverables, and pricing
- Rules of Engagement: Explicitly permitted targets, methods, timing, and constraints
- NDA: Mutual confidentiality commitments
- Authorization Letter: Written confirmation from authorized client representative
4.3 Client Responsibilities
Clients must:
- Provide accurate, complete information about target systems
- Designate points of contact for the engagement
- Obtain necessary internal approvals before authorizing testing
- Inform relevant stakeholders (IT teams, cloud providers, etc.) about scheduled testing
- Not entrap or attempt to deceive testers during engagements
- Maintain backups before any testing begins
4.4 Limitation of Liability
While we exercise professional care in all engagements, clients acknowledge that security testing involves inherent risks:
- We are not liable for temporary service disruptions caused during testing
- We are not liable for vulnerabilities we fail to discover
- Our liability is limited to fees paid for the specific engagement
- We recommend clients maintain separate cybersecurity insurance
5. Intellectual Property
5.1 Website Content
All content on this website—including text, graphics, logos, images, software, tools, and methodologies—is the property of Cyber Pantheon or its licensors and is protected by intellectual property laws.
5.2 Deliverables and Reports
Unless otherwise specified in the SOW:
- Final reports: Licensed to client for internal use only
- Methodologies and tools: Remain proprietary to Cyber Pantheon
- Custom scripts: Ownership specified in SOW; typically transferred to client upon payment
- Findings data: Belongs to client; we retain right to use anonymized aggregate data
6. Payment Terms
- Pricing: As quoted in the accepted proposal or SOW
- Deposit: Typically 50% due before engagement commencement
- Balance: Due upon delivery of final report
- Late payments: 1.5% monthly interest on overdue amounts
- Expenses: Pre-approved travel/expenses billed at cost
- Refunds: Prorated refunds available if engagement cancelled before completion
7. Confidentiality
Both parties agree to maintain strict confidentiality regarding:
- Existence of the engagement (unless publicly disclosed by client)
- All findings, vulnerabilities, and security weaknesses discovered
- Client's technical environment, architecture, and security posture
- Business information shared during the engagement
Confidentiality obligations survive termination of these Terms for a period of three (3) years.
8. Disclaimer of Warranties
OUR SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, INCLUDING BUT NOT LIMITED TO:
- WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE
- WARRANTIES THAT SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE
- WARRANTIES THAT TESTING WILL DISCOVER ALL VULNERABILITIES
Note on Security Testing: Penetration testing is inherently limited by scope, time, technique, and the evolving nature of threats. No security assessment can guarantee complete protection. Our findings represent a point-in-time snapshot.
9. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
- CYBER PANTHEON'S TOTAL LIABILITY SHALL NOT EXCEED FEES PAID IN THE PRECEDING 12 MONTHS
- WE SHALL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES
- WE ARE NOT LIABLE FOR BUSINESS INTERRUPTION, DATA LOSS, OR SECURITY INCIDENTS OCCURRING AFTER OUR ENGAGEMENT CONCLUDES
10. Termination
10.1 By Client
Clients may terminate engagements with 7 days' written notice (prorated refund for unused portion) or immediately for material breach by Cyber Pantheon.
10.2 By Cyber Pantheon
We may terminate if client fails to pay when due, violates RoE, provides false information, or engages in illegal activities.
10.3 Effect of Termination
- All fees accrued become immediately due
- Confidentiality obligations survive termination
- Deliverables completed before termination remain subject to IP terms
11. Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Alabama, United States, without regard to conflict of law principles.
Dispute Resolution:
- Good faith negotiation between parties (30 days)
- Mediation through mutually agreed mediator (if negotiation fails)
- Binding arbitration in Madison County, Alabama (if mediation fails)
12. Contact Us
For questions about these Terms, contact us at:
Cyber Pantheon
General Inquiries: hello@cyberpantheon.us
Security Issues: security@cyberpantheon.us
Response Time: Within 5 business days
