1About these Terms
These Terms of Service govern access to and use of the CyberEssentia website, CyberEssentia Scanner and associated cybersecurity assessment and compliance services ("Services").
By creating an account, connecting an organisation to CyberEssentia or using the Services, you agree to these Terms.
If you use CyberEssentia on behalf of an organisation, you confirm that you have authority to act on behalf of that organisation.
2The CyberEssentia service
CyberEssentia provides automated and assisted cybersecurity assessment tools intended to help organisations identify potential security risks, configuration issues and compliance requirements.
CyberEssentia may analyse information supplied by users and information obtained from authorised third-party platforms, including Microsoft 365 and Microsoft Entra ID.
3Authority to perform scans
You must only connect, scan or assess systems, tenants, networks, devices or accounts that you own or for which you have explicit authority to conduct cybersecurity assessments.
You must not use CyberEssentia to obtain unauthorised access to another person's or organisation's systems or information.
4Microsoft integration
Where you connect CyberEssentia Scanner to Microsoft services, CyberEssentia may request Microsoft Graph permissions required to perform security and compliance checks.
The permissions requested will be presented through Microsoft's consent process.
An authorised administrator is responsible for reviewing and approving these permissions.
CyberEssentia will use information obtained through Microsoft APIs only to provide and secure the CyberEssentia Services and associated customer support.
5Customer responsibilities
You are responsible for:
- providing accurate information
- ensuring that you have authority to connect systems to CyberEssentia
- maintaining the security of your account credentials
- reviewing permissions before granting them
- protecting reports and security information produced by CyberEssentia
- determining whether and how to implement recommendations
You must notify us promptly if you believe your CyberEssentia account has been compromised.
6Cyber Essentials assessments
CyberEssentia may help organisations assess their readiness against Cyber Essentials requirements and other cybersecurity standards.
Unless expressly stated otherwise, automated CyberEssentia results are not themselves Cyber Essentials certification and do not guarantee that an organisation will pass an official Cyber Essentials or Cyber Essentials Plus assessment.
Final certification decisions are made by the relevant authorised certification or assessment body.
7Security recommendations
Cybersecurity assessment involves judgement and technology changes continuously.
CyberEssentia therefore cannot guarantee that an assessment will identify every vulnerability, threat, configuration problem or security risk.
A successful assessment does not guarantee that an organisation will not experience a cybersecurity incident.
Recommendations should be evaluated by appropriately qualified personnel before significant changes are made to production systems.
8Acceptable use
You must not use CyberEssentia to:
- gain unauthorised access to systems or information
- conduct malicious security testing
- interfere with another organisation's systems
- distribute malware
- circumvent security controls
- violate applicable law
- attempt to compromise the CyberEssentia platform
We may suspend access where we reasonably believe the Services are being abused or used unlawfully.
9Availability
We aim to provide a reliable service but do not guarantee uninterrupted or error-free availability.
We may temporarily restrict access for maintenance, security incidents, upgrades or circumstances beyond our reasonable control.
10Intellectual property
CyberEssentia and its licensors retain ownership of the CyberEssentia platform, software, assessment methodologies, branding and other intellectual property.
Customers retain ownership of their own information and data.
Subject to these Terms, customers receive a limited right to use CyberEssentia for their internal business and cybersecurity purposes.
11Confidentiality
We recognise that cybersecurity assessments may contain commercially sensitive information.
CyberEssentia will take reasonable measures to protect confidential customer information and will not disclose it except as required to provide the Services, where authorised by the customer, or where required by law.
12Data protection
Our processing of personal information is described in the CyberEssentia Privacy Notice.
Where CyberEssentia acts as a processor of personal data on behalf of a customer, additional data-processing terms may apply.
13Third-party services
CyberEssentia may integrate with third-party services including Microsoft products and APIs.
Those services remain subject to their respective providers' terms and availability. CyberEssentia is not responsible for outages or changes made by third-party providers that are outside our control.
14Fees and subscriptions
Where Services are provided on a paid basis, applicable prices, subscription periods and payment terms will be displayed or agreed with the customer before purchase.
Additional commercial terms may apply to particular subscriptions or enterprise agreements.
15Limitation of liability
To the fullest extent permitted by law, CyberEssentia will not be liable for indirect or consequential losses arising from use of the Services, including loss of profits, business interruption or losses resulting from cybersecurity incidents.
Nothing in these Terms excludes or limits liability where doing so would be unlawful, including liability for fraud or fraudulent misrepresentation.
Any specific contractual liability limits applicable to paid Services may be set out in the customer's order or subscription agreement.
16Termination
You may stop using CyberEssentia and revoke connected application permissions at any time.
CyberEssentia may suspend or terminate access where these Terms are materially breached, where required by law, or where continued access presents a material security risk.
17Changes to these Terms
We may update these Terms to reflect changes to our Services, applicable law or security requirements.
Material changes will be communicated where reasonably appropriate.
18Governing law
These Terms are governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction over disputes arising in connection with these Terms, subject to any mandatory rights that apply under applicable law.
19Contact
Questions concerning these Terms can be sent to:
CyberEssentia
Email: info@cyberessentia.com
Website: cyberessentia.com