Legal

Terms and Conditions

The terms on which CIPHER KNIGHTS LTD provides cyber security, compliance and IT services. Please read them alongside your engagement agreement.

PROVIDER
CIPHER KNIGHTS LTD
CO. NUMBER
16141995
GOVERNING LAW
England & Wales
CONTACT
support@cipherknights.com
In short

What terms govern Cipher Knights services?

Services are provided by CIPHER KNIGHTS LTD (company number 16141995) under a written engagement agreement that sets out scope, fees and timescales, read together with these terms. The agreement takes precedence where the two differ. English law governs, and the courts of England and Wales have jurisdiction.

1. Who we are and how these terms apply

These terms apply to services provided by CIPHER KNIGHTS LTD, a company registered in England and Wales under company number 16141995, with its principal place of business in Leicester, United Kingdom ("we", "us", "Cipher Knights").

They should be read together with the written engagement agreement, proposal or statement of work agreed for your specific services. Where a term of that agreement conflicts with these terms, the engagement agreement takes precedence.

2. Scope of services

We will provide the services described in the engagement agreement with reasonable skill and care, and in accordance with generally accepted professional standards. Work outside that described scope is not included and will be quoted separately and agreed in writing before it is carried out.

Security assessment findings reflect the systems, configurations and information available during the agreed testing window. They are not a guarantee that no other vulnerabilities exist, and they do not remain accurate as your environment changes.

3. Authorisation for security testing

Where an engagement involves vulnerability assessment, penetration testing or any other active security testing, you confirm that you own the systems in scope or have authority from the owner to authorise testing of them, and that any relevant third party — including hosting providers and cloud platforms — has been notified where their terms require it.

No active testing will begin until a written authorisation or rules of engagement document has been signed by a person with authority to give it. We may suspend or terminate testing immediately if authorisation is withdrawn or found to be inadequate.

4. Your responsibilities

You agree to provide accurate information about the systems in scope, to give timely access where the engagement requires it, to nominate a contact with authority to make decisions, and to maintain current backups of any system that will be tested or changed.

Delays or additional work caused by inaccurate scoping information, unavailable access or unavailable contacts may affect timescales and fees, and we will tell you before any additional charge arises.

5. Fees and payment

Fees are as stated in the engagement agreement. Project work is quoted as a fixed price for the agreed scope; managed services are charged monthly per supported user. Fees exclude VAT and any third-party costs such as certification body fees, which are stated separately and passed through without mark-up.

Invoices are payable within the period stated in the engagement agreement. We reserve the right to charge statutory interest on late payment under the Late Payment of Commercial Debts (Interest) Act 1998, and to suspend services where an account is materially overdue.

6. Confidentiality

Each party will keep the other's confidential information confidential, use it only for the purposes of the engagement, and disclose it only to personnel who need it and who are bound by equivalent obligations.

We treat all assessment findings, reports and evidence relating to your systems as confidential. We will not identify you as a client or publish any case study referring to your engagement without your prior written consent.

7. Intellectual property

On payment in full, you own the reports and deliverables prepared specifically for you. We retain ownership of our underlying methodologies, tools, templates and general know-how, and of any pre-existing material incorporated into a deliverable, for which you receive a non-exclusive licence to use it for your internal business purposes.

You may share a deliverable with your auditors, insurers, regulators and professional advisers. Wider publication requires our written consent, which will not be unreasonably withheld.

8. Liability

Nothing in these terms limits or excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited.

Subject to that, our total aggregate liability arising out of or in connection with an engagement is limited to the total fees paid by you for that engagement in the twelve months preceding the claim, and we are not liable for loss of profit, loss of business, loss of anticipated savings or any indirect or consequential loss. We maintain professional indemnity insurance, details of which are available on request.

9. Data protection

Where we process personal data on your behalf we do so as a processor and you remain the controller. A data processing agreement setting out the subject matter, duration, nature and purpose of processing, the categories of data and data subjects, and our security obligations, forms part of the engagement.

Our handling of personal data in our own right — for example, contact details of the people we deal with — is described in our Privacy Policy.

10. Termination

Either party may terminate a managed service by giving the notice period stated in the engagement agreement. Either party may terminate immediately on written notice if the other commits a material breach that is not remedied within 30 days of being notified, or becomes insolvent.

On termination you will pay for services properly performed up to the termination date. We will return or securely destroy your confidential information in accordance with the agreed retention period, and will provide reasonable assistance with transition to another provider on our standard rates.

11. Governing law

These terms and any dispute arising out of them are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Questions about these terms should be sent to support@cipherknights.com.

Frequently asked questions

Terms & Conditions — your questions answered

Which document takes precedence if my contract differs from these terms?
Your signed engagement agreement, proposal or statement of work takes precedence wherever it conflicts with these general terms.
Can I share your penetration test report with my customers?
You may share deliverables with auditors, insurers, regulators and professional advisers as a matter of course. Wider publication needs our written consent, which we do not unreasonably withhold — an attestation letter is usually the better document for that purpose.
Do you need written authorisation before testing our systems?
Yes, always. Active security testing without written authorisation from someone with authority over the systems would breach the Computer Misuse Act 1990. We will not begin until that document is signed.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about terms & conditions?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.