BackstopCyber Start a conversation

Legal

Terms of use

Version [FILL: version] · Effective [FILL: effective date] · Last updated [FILL: last updated date]

Draft — requires attorney review before launch.

This is a plain-English first draft describing how this website is intended to work. It has not been reviewed by a lawyer and is not legal advice. The limitation of liability, warranty disclaimer, governing law and dispute resolution sections in particular are jurisdiction-specific and must be adapted by counsel — as drafted, some of them may be unenforceable where you operate. Do not publish this page as-is.

1. Accepting these terms

These terms are an agreement between you and [FILL: registered legal entity name] (“Backstop Cyber”, “we”, “us”), and they govern your use of backstopcyber.com and everything served from it. By using the site you accept them. If you do not accept them, please stop using the site.

If you use this site on behalf of an organisation, you confirm that you are authorised to accept these terms for that organisation, and “you” means that organisation.

2. What this website is

This site is marketing material. It describes services we offer, how we prefer to work, and how to start a conversation with us. It is a description of a practice, not a specification of a deliverable.

3. It is not advice, and it is not an engagement

Nothing on this site is security advice, compliance advice, legal advice, audit opinion, or a professional recommendation for your particular environment. Security and compliance decisions depend entirely on facts this website does not know about you.

Reading this site, submitting the contact form, or exchanging emails with us does not create a consulting relationship, a client relationship, or any duty of care. A relationship begins only when both parties sign a written engagement agreement or statement of work. Until that document exists and is signed, nothing said in either direction is binding on either of us, and you should not act in reliance on it.

Where an executed engagement agreement exists and conflicts with these terms, the engagement agreement controls for that engagement.

4. We are not an auditor or a certifying body

Backstop Cyber prepares organisations for audits and assessments. We are not a CPA firm, not a licensed SOC 2 auditor, not a CMMC Third-Party Assessment Organization (C3PAO), not a PCI Qualified Security Assessor, and not an ISO 27001 certification body — and we do not represent ourselves as any of them. Independence rules mean that in most cases we could not be both your readiness partner and your assessor even if we wanted to be. You will need to engage the relevant certified party separately. [FILL: if the entity or any individual does in fact hold one of these accreditations, state it precisely here and correct the paragraph above — do not overstate it]

5. No guarantee of outcomes

We do not guarantee that you will pass an audit, obtain a certification, satisfy a regulator, satisfy a customer’s security review, avoid a security incident, or avoid loss. No competent security practice can promise those things. Our obligation, once engaged, is to perform the work described in the engagement agreement with reasonable skill and care.

Any figures, timelines or examples that appear on this site are illustrative. They are not a commitment, a quote, or a forecast for your situation.

6. Using the contact form

When you use the contact form, you agree that the information you provide is accurate, that you are entitled to provide it, and that you will not use the form to send unsolicited commercial messages.

Do not send us confidential or sensitive information through this form. It delivers an ordinary email. Do not send credentials, secrets, personal health information, government identifiers, payment details, or unredacted findings from a live incident. Information you send us before an engagement exists is not covered by a confidentiality agreement unless we have signed one with you. If you need a confidentiality agreement in place first, say so in your message and we will arrange one before you send anything further.

How we handle what you submit is described in our privacy notice.

7. Acceptable use

You agree not to:

  • use the site for any unlawful purpose, or in violation of any applicable regulation;
  • attempt to gain unauthorised access to the site, its hosting environment, or any connected system;
  • interfere with the site’s availability, including by denial-of-service, flooding the contact form, or circumventing the rate limiting or bot protection on it;
  • scrape, harvest or automatically extract content from the site at a volume that burdens it;
  • misrepresent your identity or your affiliation with any person or organisation;
  • use the site or its content to build or train a competing service or a machine-learning model without our written permission.

8. Security research and testing

We appreciate good-faith reports of security issues in this website. Please report them through the contact form or the address in §17 rather than disclosing them publicly, and give us a reasonable opportunity to fix the issue.

Please do not run automated scanners, fuzzers, or denial-of-service tests against this site or its hosting infrastructure without written permission — the infrastructure is shared, and that testing affects other people. Testing that stays within the acceptable-use rules in §7 and does not degrade availability for others is welcome. [FILL: decide whether to offer a formal safe-harbour statement here — counsel should draft it if so]

9. Intellectual property

The content, design, code, copy and marks on this site are owned by us or used with permission, and are protected by copyright and trade mark law. You may read the site, print pages for your own reference, and share links to it. You may not republish, sell, or present our content as your own, or use our name or marks in a way that implies a relationship or endorsement that does not exist.

Framework names such as SOC 2, HIPAA, CMMC, PCI DSS, ISO 27001 and the NIST Cybersecurity Framework belong to their respective owners. We reference them descriptively to say what we work on. Their appearance on this site does not imply that any of those bodies endorse, accredit or are affiliated with us.

10. Third-party links and services

Where we link to a third-party site, we do not control it and are not responsible for its content, its security, or its privacy practices.

This site loads one third-party service at runtime: Cloudflare Turnstile, the bot check on the contact form. Your use of it is subject to Cloudflare’s own terms and privacy policy.

11. Availability

We make no promise that this site will be available, uninterrupted, or error-free. We may change, suspend, or withdraw any part of it at any time without notice. In particular, the contact form depends on third-party services and may occasionally fail. If you send something important and do not hear back, please call the number listed on the contact section rather than assume the message arrived.

12. Disclaimer of warranties

To the fullest extent permitted by law, this site and its content are provided “as is” and “as available”, without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement.

Some jurisdictions do not allow the exclusion of certain warranties, and nothing here excludes liability that cannot lawfully be excluded. [FILL: counsel to align this section with the consumer-protection rules of the governing jurisdiction]

13. Limitation of liability

To the fullest extent permitted by law, we are not liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, lost revenue, lost data, business interruption, or loss of goodwill, arising out of or connected with your use of this website — whether the claim is in contract, tort, statute, or otherwise, and whether or not we were advised such loss was possible.

Our total aggregate liability arising out of or connected with your use of this website is limited to [FILL: e.g. USD 100].

This section limits liability arising from the website. Liability arising from work we perform under a signed engagement agreement is governed by that agreement, which will contain its own liability terms. [FILL: counsel to confirm the cap is enforceable in the governing jurisdiction and consistent with the professional liability insurance in place]

14. Indemnity

You agree to indemnify and hold us harmless from any claim, loss or expense (including reasonable legal fees) arising from your breach of these terms or your misuse of this website.

15. Governing law and disputes

These terms are governed by the laws of [FILL: governing state or country], without regard to its conflict-of-laws rules. The courts of [FILL: venue] have exclusive jurisdiction over any dispute arising from them, and both parties submit to that jurisdiction. [FILL: counsel to decide whether to add an arbitration clause, a class-action waiver, or an informal-resolution period, and to confirm enforceability for non-US visitors]

If any provision of these terms is found unenforceable, the rest remain in force and the unenforceable provision is applied to the maximum extent permitted. Our failure to enforce a provision is not a waiver of it.

16. Changes to these terms

We may update these terms. When we do, we will change the version and the date at the top of this page. Continuing to use the site after a change means you accept the updated terms. If you do not, please stop using the site.

17. How to reach us

Questions about these terms can go through the contact form, or to [FILL: legal contact address, written as plain text — see the note in README about mailto: links and Cloudflare Email Address Obfuscation], or by post to [FILL: postal address].