Terms and conditions governing penetration testing and security assessment engagements with Vincent Cyber Defence Ltd.
Vincent Cyber Defence Limited · Company No: 16335932 · Effective: 1 June 2026
Penetration testing involves controlled, authorised security testing of your systems, networks, applications, and environments.
By its nature, testing may cause disruption, service interruption, or unexpected system behaviour. These Terms set out the legal basis on which testing is conducted and the obligations that apply to both parties.
Please read these Terms carefully before placing an Order. By placing an Order or making payment, you confirm you have read and agree to be bound by them.
These Terms cover all penetration testing and security assessment services offered by Vincent Cyber Defence Limited, including infrastructure testing, web application testing, cloud security reviews, MDM reviews, PCI DSS penetration testing, and build reviews.
IMPORTANT: Penetration testing without proper authorisation is a criminal offence under the Computer Misuse Act 1990. By placing an Order, you confirm you have obtained all necessary legal authority to permit testing of every target in scope. This is your responsibility - not ours.
1.1 In these Terms, the following definitions apply:
1.2 Clause headings do not affect interpretation. Words in the singular include the plural and vice versa. A reference to a statute includes any amendment or re-enactment. Any words following "including", "such as", or "for example" are illustrative and do not limit the preceding words.
2.1 These Terms govern the provision of all penetration testing and security assessment services by us. They take precedence over any inconsistent terms in your purchase order, confirmation of order, or specification, or implied by law, trade custom, or course of dealing.
2.2 Your Order is formed when you make payment, confirm acceptance of these Terms in writing, or instruct us to commence scoping or testing - whichever occurs first. These Terms are incorporated into your Order by reference.
2.3 No testing will commence until: (a) the Scoping Document and Rules of Engagement have been agreed in writing by both parties; (b) written Authority to Test has been received covering all Targets; and (c) all applicable Fees have been received in cleared funds. These conditions are absolute prerequisites and are not waived by any other provision of this Agreement.
2.4 You acknowledge that penetration testing services have not been developed to meet your individual requirements in their entirety. It is your sole responsibility to ensure that the scope described in the Scoping Document meets your needs, satisfies any applicable compliance requirement, and covers all relevant Targets before testing commences.
2.5 Where there is any conflict between these Terms and your Order or Scoping Document, the Scoping Document prevails on technical scope matters and the Order prevails on fee and delivery matters. On all other matters, these Terms prevail.
Penetration testing is governed by serious criminal legislation in the UK. Both parties must understand their legal obligations before testing begins.
3.1 Computer Misuse Act 1990. Unauthorised access to computer systems is a criminal offence under the Computer Misuse Act 1990, carrying penalties including unlimited fines and imprisonment. Testing is only lawful where explicit written authorisation has been obtained from the legal owner of every Target. You are solely responsible for ensuring that this authorisation exists before placing your Order and before testing commences.
3.2 Human Rights Act 1998. Where testing may involve monitoring of network traffic, interception of communications, or assessment of systems that process personal data, Article 8 of the Human Rights Act 1998 (right to privacy) is engaged. You are responsible for ensuring that any such monitoring or interception is lawful, including under the Investigatory Powers Act 2016 where applicable, and that all necessary notices and consents are in place.
3.3 UK General Data Protection Regulation & Data Protection Act 2018. Testing may involve access to or incidental exposure to personal data. You are responsible for ensuring that any processing of personal data arising from the testing is lawful under the UK GDPR and Data Protection Act 2018. You must ensure that appropriate technical and organisational measures are in place and that the testing is documented as part of your information security programme.
3.4 Authority to Test. By placing your Order, you provide us with formal written Authority to Test all Targets identified in the Scoping Document. You warrant and represent that:
3.5 Third-party systems. Where any Target is hosted, managed, or controlled by a third party, you must obtain written authorisation from that third party before testing commences. We will not commence testing of any third-party system on the basis of your authority alone. Evidence of third-party authorisation must be provided to us before testing of those Targets begins.
3.6 Cloud environments. Major cloud providers (including AWS, Azure, and Google Cloud) have their own penetration testing policies and may require advance notification before testing. You are responsible for complying with all applicable cloud provider policies and for obtaining any required permissions or notifications before testing commences. We accept no liability arising from your failure to comply with cloud provider policies.
3.7 Notification of employees and third parties. Where testing may affect systems used by your employees, contractors, or third-party suppliers, you are responsible for notifying those parties to the extent required by law or contract. You must advise us in writing of any individuals or systems that must not be tested or affected.
3.8 Changes to authorisation. If at any point during testing the Authority to Test is withdrawn, suspended, or becomes uncertain in respect of any Target, you must notify us immediately in writing. We will pause testing of the affected Target on receipt of such notification and await your written confirmation before resuming.
4.1 Before testing commences, you must:
4.2 During testing, you must:
4.3 You represent and warrant that all information you provide in connection with the Scoping Document, the Order, and the Authority to Test is accurate, complete, and not misleading, and that you have the legal authority to enter into this Agreement and to grant the Authority to Test.
4.4 If we are prevented or delayed in performing our obligations by any act or omission of yours, we shall not be liable for any resulting delay or failure, and shall be entitled to an extension of time and recovery of any additional costs reasonably incurred as a result.
5.1 We will perform the Services using reasonable skill and care in accordance with generally accepted penetration testing industry standards and methodologies, including OWASP and PTES (Penetration Testing Execution Standard), adapted to your specific environment and risk profile.
5.2 We will conduct all testing within the scope defined in the Scoping Document and Rules of Engagement. We will not test Targets outside the agreed scope without your prior written consent.
5.3 We will use reasonable endeavours to minimise disruption to your systems and services during testing. However, you acknowledge that the nature of penetration testing means that some disruption, degradation, or unexpected system behaviour may occur notwithstanding the care taken by our testers.
5.4 We will notify you immediately if we discover a critical or urgent vulnerability during testing that, in our reasonable opinion, poses an immediate and serious risk to your organisation, so that you can take interim protective action if required.
5.5 We will deliver the Report within the timeframe agreed in the Scoping Document or Order. Time for delivery is an estimate only and is not of the essence. Delivery timelines are materially dependent on the complexity of the engagement and your responsiveness during testing.
5.6 We will maintain professional indemnity insurance with a reputable insurer for the duration of this Agreement and will provide evidence of such insurance upon reasonable written request.
5.7 We may engage subcontractors to assist in performing the Services. We remain fully responsible for the quality and delivery of the Services and ensure all subcontractors are bound by confidentiality and authorisation obligations equivalent to those in these Terms.
5.8 We will keep all information obtained during testing strictly confidential and will not disclose it to any third party except as required by law or as permitted by these Terms.
6.1 The Scoping Document and Rules of Engagement form the operational boundaries of the Engagement. Testing will be conducted strictly within these boundaries. Any finding, technique, or target not covered by the agreed scope is outside the Engagement.
6.2 Any change to the scope of the Engagement after the Scoping Document has been agreed - including the addition of new Targets, test types, or testing windows - must be agreed in writing by both parties before the change is implemented. We reserve the right to issue a revised Invoice for any agreed scope increase before additional work commences.
6.3 Where we identify, during testing, that the agreed scope appears to be incomplete or that additional Targets may be relevant to the assessment, we will notify you in writing. We will not extend scope unilaterally. Any agreed extension will be separately scoped and invoiced.
6.4 Out-of-scope findings. Where we identify a vulnerability or issue in a system or component that falls outside the agreed scope, we will note it in the Report for your awareness. This does not constitute testing of that system and creates no obligation on us to investigate further.
6.5 Emergency stop. The Rules of Engagement will include an emergency contact procedure and a defined emergency stop mechanism. Where you invoke the emergency stop, we will cease all active testing immediately on receipt of written notification. You acknowledge that immediate cessation of testing may leave the environment in an intermediate state and that you are responsible for restoring it to a secure configuration.
6.6 Concurrent testing. You must disclose in the Scoping Document any other penetration testing, vulnerability scanning, security tooling, or third-party security activity that is running or planned to run concurrently with our Engagement. Where we become aware of undisclosed concurrent testing during an Engagement, we reserve the right to pause testing immediately until the position is clarified. We accept no liability for findings, incidents, or system impacts that may result from the interaction of our testing with undisclosed concurrent activity.
6.7 Out-of-hours testing. Where you request testing outside normal business hours (09:00 to 18:00 on Business Days), this must be specified in the Scoping Document and agreed in writing before testing commences. You accept that out-of-hours testing may carry an elevated risk of disruption due to reduced availability of your technical staff, and that any additional costs or risks arising from out-of-hours testing are your responsibility.
6.8 Penetration testing and vulnerability scanning. Penetration testing is a manual, expert-led assessment and is not equivalent to an automated vulnerability scan. The Engagement will identify vulnerabilities within the agreed scope using the techniques and time available. It does not and cannot guarantee the identification of every vulnerability present in your environment. You should not treat the Report as a complete inventory of all security weaknesses in your systems.
6.9 Social engineering exclusion. We do not offer social engineering, phishing simulation, or any other services involving the deception of your employees, contractors, or third parties. Any request for social engineering services is outside the scope of all Engagements and will not be undertaken.
Penetration testing involves controlled but active probing of your systems. By its nature, it carries risk of disruption. You must have verified backups in place before testing begins.
7.1 You acknowledge and accept that penetration testing is inherently disruptive by nature and that:
7.2 To the fullest extent permitted by law, we shall not be liable for any system downtime, service interruption, data loss, data corruption, system instability, or any other operational impact arising from the performance of the Services within the agreed scope and Rules of Engagement, except where caused by our failure to exercise reasonable skill and care under Clause 5.1.
7.3 We do not guarantee that testing will be uninterrupted or that all vulnerabilities will be identified. Penetration testing is a point-in-time assessment conducted using the techniques and information available at the time. It cannot guarantee the discovery of all vulnerabilities, weaknesses, or attack vectors present in your environment.
7.4 Following completion of the Engagement, you are responsible for implementing all remediation actions identified in the Report. We accept no responsibility for any breach, attack, or security incident occurring after the Completion Date, including incidents arising from vulnerabilities identified in the Report that were not remediated.
7.5 Pre-existing compromise. Where we discover during testing that a system or environment appears to have been compromised by a third party prior to or during our Engagement - including evidence of active malware, backdoors, unauthorised access, or active data exfiltration not attributable to our testing - we will pause testing of the affected system immediately and notify you. We accept no liability for any pre-existing compromise or for any impact on findings or system integrity arising from it. You are responsible for engaging an incident response provider to address any active compromise before testing of the affected system resumes.
7.6 Live breach discovery. Where we encounter what appears to be an active live breach or ongoing data exfiltration during testing, we will cease active testing on the affected systems immediately, notify you as soon as practicable, and provide a written summary of what was observed. We will not take any action to intervene in, remediate, or contain the breach - incident response is outside the scope of all Engagements. We accept no liability for any loss arising from a live breach discovered during testing, including any delay caused by our notification and cessation of testing.
8.1 Fixed-price engagements. Where the Order specifies a fixed price, that price is agreed following scoping and applies to the scope defined in the Scoping Document. The fixed price will not change unless the scope changes in accordance with Clause 6.2.
8.2 Day-rate engagements. Where the Order specifies a day rate, Fees are calculated based on the number of consultant days required to complete the Engagement as agreed in the Scoping Document. Where additional days are required due to scope changes agreed under Clause 6.2, these will be invoiced separately at the agreed day rate.
8.3 All Fees are payable in full in cleared funds before we commence testing, unless otherwise agreed in writing on the Order. No testing will begin until payment has been received.
8.4 All Fees are exclusive of VAT, which shall be payable at the prevailing rate where applicable.
8.5 All Fees are payable in British Pounds (GBP). You are responsible for all bank charges, intermediary fees, and currency conversion costs.
8.6 If you fail to pay any amount due by the due date, we reserve the right to: (a) charge interest at 8% per annum above the Bank of England base rate under the Late Payment of Commercial Debts (Interest) Act 1998, accruing daily; (b) suspend all testing without liability until payment is received; and (c) recover fixed-sum compensation and reasonable debt recovery costs permitted by that Act.
8.7 All payments are independent of any third-party payment schedules or "paid-when-paid" arrangements.
9.1 You may cancel or reschedule a confirmed Engagement subject to the following charges:
9.2 Where specialist resources, tools, or third-party licences have been procured specifically for your Engagement, the cost of those resources is non-refundable regardless of the notice period given.
9.3 Where you fail to provide required access, credentials, or information on the agreed testing date through no fault of ours, the full Fees are payable and a rebooking fee of 50% of the original Fees may be charged for any rescheduled date.
9.4 We reserve the right to reschedule an Engagement with reasonable notice where required by operational necessity. No cancellation or rebooking fee applies where rescheduling is initiated by us.
9.5 Where testing is suspended or terminated during an Engagement at your request for reasons other than our material breach, Fees for work completed to the date of suspension or termination are payable in full. We will issue an Invoice for completed work immediately.
9.6 If you fail to engage, provide access, or respond to our requests for a period of 30 days following the agreed testing window, the Engagement will be deemed cancelled and all Fees paid will be forfeited. All associated data and findings will be securely purged.
10.1 Every Engagement includes a free 30-day retest window beginning on the date the final Report is delivered. The Retest covers re-assessment of the specific findings identified in the original Report following your remediation of those findings.
10.2 The Retest does not cover:
10.3 To initiate the Retest, you must notify us in writing before the expiry of the 30-day window, confirming which findings have been remediated and requesting a retest date. We will use reasonable endeavours to schedule the Retest within the 30-day window following your notification. Where the 30-day window expires without notification from you, the Retest entitlement lapses and no extension or credit applies.
10.4 Following the Retest, we will issue a retest attestation confirming which findings have been verified as remediated. The attestation is based solely on the evidence available at the time of retesting and is a point-in-time confirmation only.
10.5 Where findings remain unremediated at the time of the Retest, we will note this in the attestation. We accept no liability for any breach, attack, or security incident arising from unremediated findings.
10.6 Two hours of engineer walkthrough time is included in every Engagement to assist your IT team or developers in understanding the findings and remediation steps. This time is available within the 30-day Retest window and must be requested in writing. It does not roll over beyond the Retest window.
11.1 The Report is prepared on the basis of the testing conducted within the agreed scope and Rules of Engagement. It is accurate as at the date of testing only. The security posture of your environment may change after the Completion Date and the Report does not reflect any changes made after testing concluded.
11.2 The Report is prepared for your use in connection with the purpose stated in the Order (which may include compliance evidence, internal security management, or satisfying a third-party requirement). It is not a guarantee of security, a certification of compliance, or a warranty that your environment is free from vulnerabilities.
11.3 Third-party use. You may share the Report with third parties (including enterprise customers, regulators, auditors, QSAs, or insurers) for your legitimate business purposes, subject to the following conditions: (a) sharing is on a strictly "as is" basis; (b) you do not remove any disclaimers or limitations contained in the Report; (c) we have no liability to any third party to whom the Report is disclosed; and (d) third parties may not rely on the Report as if it were prepared for them.
11.4 We do not warrant that the Report will satisfy any specific compliance requirement, be accepted by any particular auditor, QSA, regulator, or enterprise customer, or meet any specific vendor questionnaire or framework requirement. We will use reasonable endeavours to format the Report in line with your stated compliance purpose, but acceptance is at the discretion of the receiving party.
11.5 All findings in the Report are based on the information available and techniques applied during the testing window. We accept no responsibility for vulnerabilities not identified during testing. The absence of a finding in the Report does not mean no vulnerability exists.
11.6 Credential handling. Where you provide us with credentials, access tokens, VPN configurations, API keys, or other authentication material in connection with the Engagement, we will: (a) use those credentials solely for the purposes of the Engagement; (b) not share them with any person outside the testing team; and (c) securely destroy all credentials as soon as practicable following delivery of the Report. You must change all credentials provided to us upon completion of the Engagement. We accept no liability for any loss arising from your failure to rotate credentials after testing concludes.
11.7 Prohibition on weaponising findings. The Report, including all vulnerability details, proof-of-concept code, exploit chains, and attack path descriptions, is provided solely to enable you to remediate identified weaknesses. You must not use, adapt, share, or permit the use of any finding, proof-of-concept, or exploit contained in the Report for any offensive, aggressive, or unlawful purpose, or to test, probe, or attack any system other than your own. Breach of this clause constitutes a material breach of this Agreement and may constitute a criminal offence under the Computer Misuse Act 1990 or other applicable legislation. You shall indemnify us fully against any claim, loss, or liability arising from any such misuse.
11.8 Responsible disclosure. Where we identify during testing a vulnerability that, in our reasonable opinion, affects third parties beyond your environment - including vulnerabilities in third-party software, shared infrastructure, or cloud platform components - we reserve the right to make a responsible disclosure to the affected vendor or authority following agreed industry practice. We will notify you before making any such disclosure. You must not suppress, delay, or interfere with any responsible disclosure we consider necessary.
11.9 Use in legal or regulatory proceedings. Where you intend to use, or are required to produce, the Report in any legal proceedings, regulatory investigation, arbitration, or formal complaint, you must notify us in writing as soon as practicable before doing so. This notification allows us to protect our position and ensure the Report is not mischaracterised or used out of context. This clause does not prevent you from complying with any legal obligation to disclose the Report, but we ask to be informed wherever it is lawful to do so.
12.1 The following provisions set out the entire liability of Vincent Cyber Defence Limited (including any liability for the acts or omissions of our employees, officers, agents, representatives, assessors, and subcontractors) to you arising out of or in connection with this Agreement. Any reference to liability means any liability whether in contract, tort (including negligence), misrepresentation, breach of statutory duty, or otherwise.
12.2 We will perform the Services using reasonable skill and care in accordance with generally accepted penetration testing industry standards.
12.3 Nothing in these Terms excludes or limits our liability for: (a) death or personal injury caused by our negligence; or (b) fraud or fraudulent misrepresentation.
12.4 You acknowledge that: (a) penetration testing is inherently disruptive and carries risk of system impact; (b) you have assessed and accepted those risks by placing your Order; (c) the Fees charged reflect the nature, scope, and risk profile of the Services; (d) you had the opportunity to seek independent advice before entering into this Agreement; and (e) you could have obtained similar services from alternative providers. You confirm that the limitations and exclusions in this clause are reasonable and represent a fair allocation of risk.
12.5 Subject to Clause 12.3, all warranties, representations, conditions, and other terms implied by statute or common law are, to the fullest extent permitted by law, excluded from this Agreement, including any implied warranties of merchantability, satisfactory quality, or fitness for a particular purpose. The Services and Deliverables are provided on an "as is" basis.
12.6 We shall have no liability for any loss, damage, or liability: (a) caused by inaccurate, incomplete, or misleading information you provide in connection with the Scoping Document, Order, or Authority to Test; (b) arising from your failure to maintain adequate, verified, and restorable backups of all Targets before testing; (c) arising from your failure to notify us of systems, services, or data that must not be affected; (d) arising from unauthorised testing resulting from inaccurate scope information you provide; (e) arising from your failure to obtain all necessary third-party authorisations before testing; or (f) arising from your failure to implement remediation actions identified in the Report.
12.7 By engaging us to perform the Services within the agreed scope and Rules of Engagement, you positively consent to us conducting the testing described therein and agree not to bring any action or claim against us arising from the conduct of testing within those boundaries. We shall not be liable for any losses incurred as a result of testing within the agreed scope, including losses or damage caused to your systems, documents, data, information, networks, or business, except to the extent it would be unlawful for us not to be liable.
12.8 We shall not be liable for any security breach, data loss, cyber attack, or security incident: (a) occurring during the testing window but not caused by our testing activities; (b) occurring after the Completion Date; or (c) arising from vulnerabilities identified in the Report that you failed to remediate.
12.9 We shall not be liable for any loss of profits, loss of business, loss of opportunity, loss of contract, loss of data, depletion of goodwill, or any indirect, special, punitive, exemplary, or consequential loss or damage, howsoever arising, even if we have been advised of the possibility of such loss.
12.10 Our total aggregate liability to you arising out of or in connection with any Engagement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall in all circumstances be strictly limited to the total Fees paid under the specific Invoice to which the claim relates. You expressly acknowledge that: (a) this cap may represent a modest sum relative to the value of your environment; (b) it is proportionate to the Fees charged for the Services; and (c) you have accepted this cap as a fair and reasonable allocation of commercial risk.
12.11 Your sole and exclusive remedy in respect of the Services is against Vincent Cyber Defence Limited in its corporate capacity. To the fullest extent permitted by law, we shall have no liability for any act, omission, negligence, error, or failure of any individual employee, officer, agent, assessor, or subcontractor engaged in connection with the Services.
12.12 Any legal action or claim arising under this Agreement must be commenced within 12 months of the Completion Date. After this period, all claims are absolutely time-barred.
13.1 You shall defend, indemnify, and hold harmless Vincent Cyber Defence Limited and its employees, officers, agents, assessors, and subcontractors against any and all claims, liabilities, losses, damages, expenses, and costs (including reasonable legal fees and enforcement costs) arising out of or in connection with:
14.1 We retain ownership of all Intellectual Property Rights in the Services, Deliverables, and all materials we create in connection with this Agreement, including methodologies, tools, scripts, report templates, and testing techniques. Nothing in this Agreement transfers any Intellectual Property Rights from us to you.
14.2 Upon full payment of all Fees, we grant you a non-exclusive, non-sublicensable, non-transferable, worldwide licence to use the Report and Deliverables for your reasonable internal business purposes and for the compliance or commercial purpose stated in the Order.
14.3 You own all rights in the information and materials you provide to us. You grant us a non-exclusive licence to use, review, and copy those materials to the extent necessary to perform the Services.
14.4 We retain the right to use anonymised, aggregated, and non-attributable findings, techniques, and statistical information from Engagements for the purposes of research, professional development, and improvement of our methodology. No client-identifiable information will be used or disclosed.
14.5 To the extent you provide any feedback or ideas regarding our methodologies, tools, or processes, you hereby assign all intellectual property rights in such feedback to us.
15.1 Each party agrees to keep confidential all technical, commercial, and business information disclosed by the other in connection with the Services, including vulnerability findings, system architecture details, credentials, Report content, and Client Materials.
15.2 We will not disclose any information obtained during testing to any third party without your prior written consent, except: (a) to our employees, contractors, and subcontractors involved in the Engagement, on a need-to-know basis; (b) where disclosure is required by law, regulation, or order of a competent authority; or (c) where we are required to disclose findings to law enforcement or a regulatory authority as a result of discovering evidence of criminal activity during testing.
15.3 Where we discover evidence of criminal activity, a serious data breach affecting third parties, or other matter that we are legally or professionally obliged to report during the course of testing, we reserve the right to make such disclosures as are required by law or professional obligation. We will notify you before making any such disclosure where it is lawful to do so.
15.4 This obligation does not apply to information that is publicly available (other than through breach), independently developed, or lawfully received from a third party.
15.5 These confidentiality obligations survive termination of this Agreement for five (5) years.
16.1 Both parties shall comply with all applicable data protection laws, including the UK GDPR and the Data Protection Act 2018.
16.2 Penetration testing may result in incidental exposure to personal data held in your systems. We will handle any such data with appropriate care and will not retain, copy, or process personal data beyond what is strictly necessary for the purposes of the Engagement.
16.3 We will notify you without undue delay (and in any event within 72 hours) upon becoming aware of any personal data breach or significant security incident affecting data held by us in connection with the Engagement.
16.4 We will securely destroy all temporary technical data, testing artefacts, captured credentials, working files, and proof-of-concept code as soon as practicable following delivery of the final Report and in any event within 30 days of the Completion Date, subject to any legal, regulatory, or insurance retention requirement.
16.5 We will retain your Invoice, Scoping Document, Rules of Engagement, and Authority to Test for 6 years from the Completion Date for legal, regulatory, and insurance purposes. This retention is strictly for maintaining a legal record of the Authority to Test in accordance with the Limitation Act 1980 and our Professional Indemnity insurance requirements.
16.6 Final Reports will be retained for 12 months from the Completion Date to allow for client download and remediation support. After that period, Reports will be permanently purged from our systems.
17.1 Either party may terminate this Agreement immediately if the other: (a) commits a material breach that remains uncured for 14 days after written notice; or (b) becomes insolvent or unable to pay its debts as they fall due.
17.2 We reserve the right to suspend or terminate testing immediately and without notice if we reasonably believe: (a) that continuing testing would exceed the agreed Authority to Test or Scoping Document; (b) that you have provided false or misleading information about the scope or authorisation; (c) that continuing testing poses an immediate and serious risk of harm to systems, data, or third parties; or (d) that criminal activity has been discovered that requires us to cease testing and make a mandatory report.
17.3 On termination: (a) all outstanding Fees for work completed to the date of termination become immediately due; (b) we will cease all testing immediately; (c) each party shall return or securely destroy the other's confidential information on written request, except where retention is required by law; and (d) Clauses 12, 13, 14, 15, 16, and 18 survive termination.
18.1 Governing Law & Jurisdiction. These Terms are governed by the laws of England and Wales. The parties irrevocably agree that the courts of England and Wales have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms, regardless of your country of residence, incorporation, or the location of the Targets being tested.
18.2 Dispute Resolution. Before commencing court proceedings (except for urgent interim relief), the parties agree to first attempt good faith negotiation for 14 days, then mediation administered by the Centre for Effective Dispute Resolution (CEDR) for up to 30 days. If unresolved, either party may commence court proceedings.
18.3 Invoice Disputes. If you dispute any invoice, you must notify us in writing within 7 days of receipt, setting out the grounds and specific amount disputed. Failure to do so constitutes acceptance of the invoice. You must pay all undisputed amounts by the due date regardless of any dispute.
18.4 Variation. No variation to these Terms is effective unless agreed in writing and signed by both parties.
18.5 Entire Agreement. These Terms, together with your Order, Scoping Document, and Rules of Engagement, constitute the entire agreement between us and supersede all prior arrangements, representations, or understandings. You confirm you have not relied on any representation or warranty not set out in these Terms.
18.6 Severability. If any provision is found unenforceable, the remaining provisions remain in full force.
18.7 Waiver. No failure or delay to exercise any right or remedy constitutes a waiver of that right or remedy.
18.8 Assignment. You may not assign or transfer your rights or obligations without our prior written consent. We may assign or transfer this Agreement at any time.
18.9 No Partnership. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties. We are an independent contractor.
18.10 Third Party Rights. These Terms do not confer any rights on any third party. The Contracts (Rights of Third Parties) Act 1999 does not apply to this Agreement.
18.11 Notices. Any notice under these Terms must be in writing and sent by email to the address provided in your Order. Email notices are deemed received at 9am on the next Business Day following transmission.
18.12 Non-Solicitation. You agree not to solicit, hire, or engage any of our employees or contractors involved in your Engagement for 12 months following the Completion Date. If you breach this clause, you shall pay us a sum equal to 50% of that individual's annual gross salary or fees as liquidated damages.
18.13 Force Majeure. Neither party is liable for delays or failures caused by events beyond their reasonable control. If such an event continues for more than 30 days, either party may terminate. You remain liable for all Fees for Services already delivered or work already completed.
By placing an Order, making payment, or signing the Scoping Document, you confirm that:
We reserve the right to update these Terms at any time. The version in force at the date of your Order applies to that Order.
Vincent Cyber Defence Limited · Company No: 16335932 · Registered in England and Wales