Terms of Service
These terms govern access to the NovaShield Cyber platform and the security services we perform for our customers. Please read them before ordering services or creating an account.
1. Acceptance of Terms
These Terms of Service (the “Terms”) are an agreement between NovaShield Cyber (“NovaShield”, “we”) and the organization that orders our services or uses our platform (“Customer”, “you”). They apply when you create an account, sign an order form, or otherwise access the platform.
If you accept these Terms for a company, you confirm you have authority to bind it. Where we have signed a master services agreement, it controls to the extent it conflicts with these Terms.
2. Scope of Services
Depending on what you order, our services may include:
- AI-assisted threat detection and monitoring of systems you connect to the platform;
- Zero Trust architecture design and implementation support;
- Managed SOC services, including alert triage and incident response coordination;
- Vulnerability assessments and security testing of environments you authorize;
- Cloud security across AWS, Azure, Google Cloud, hybrid and on-premise environments;
- Compliance readiness: gap analysis, control mapping and evidence preparation.
The services we owe you are those listed in your order form or SOW.
3. Orders and Statements of Work
Each engagement is defined by an order form or statement of work (“SOW”) identifying the services, environments in scope, deliverables, term and fees. Scope changes require a written change order and may be billed separately.
Service levels, such as target response times, apply only if written into a signed service level agreement — for example, an SOW might commit us to acknowledge critical alerts within a stated window. Absent such an agreement, no response time is promised, and figures on our website are illustrative only.
4. Customer Responsibilities
Our work depends on the access and information you give us. You agree to:
- provide accurate information about your environment, including asset inventories;
- maintain the credentials, API keys and agents the services need to function;
- keep your own backups — we do not back up your systems unless an SOW says so;
- act on our findings, and apply patches and configuration changes yourself;
- designate a contact who can approve testing windows and receive incident notices;
- secure the accounts your personnel use, and tell us if one is compromised.
You remain responsible for the security of your systems. NovaShield supports your security program; it does not replace it or take control of your infrastructure.
5. Authorization for Security Testing
Vulnerability assessments, penetration testing and similar active work touch live systems. Before we begin, you represent and warrant that:
- you own the systems, networks, applications and accounts in scope, or you hold current written permission from the owner to have them tested;
- you have any consent required from hosting providers, cloud providers and other third parties whose infrastructure is in scope;
- the scope you give us is accurate and includes no assets belonging to anyone who has not authorized the testing.
We will not test any system without authorization. If we believe an in-scope asset is not authorized, we pause the work until the authorization is documented. Active testing also carries inherent risk, so keep backups current.
Testing without authorization is prohibited. If you instruct us to test an asset you do not own and cannot show written permission for, that instruction is a material breach of these Terms. We may suspend the engagement immediately, and you are responsible for any claims, penalties or costs arising from your misrepresentation of scope.
6. Acceptable Use of the Platform
The platform is licensed for your internal security operations during your subscription. You agree not to:
- use it to monitor, scan or attack systems you are not authorized to assess;
- resell or sublicense it to third parties without our written consent;
- reverse engineer or derive our detection logic or models, except where that restriction is unenforceable by law;
- circumvent usage limits, share credentials, or exceed your order form entitlements;
- use it in violation of applicable law, including export control and sanctions rules.
We may suspend access without notice if we detect use that threatens the platform or other customers.
7. Fees and Payment
Fees are stated in your order form. Unless it says otherwise:
- subscriptions are invoiced in advance each period; professional services as delivered;
- invoices are payable within thirty (30) days of the invoice date, in U.S. dollars;
- fees exclude sales, use, VAT and similar taxes, which are yours;
- overdue amounts may accrue interest at 1.5% per month, or the legal maximum if lower;
- fees are non-refundable unless these Terms or an SOW provide otherwise.
If an invoice is more than thirty (30) days past due, we may suspend the services after written notice and a chance to cure.
8. Intellectual Property
NovaShield retains all rights in the platform, our detection models, methodologies and report templates. Subject to payment, we grant you a non-exclusive, non-transferable right to use the platform and our deliverables internally.
You retain all rights in your data. You grant us a limited right to process it to deliver the services and improve our detection capabilities, provided anything we derive is aggregated and does not identify you.
9. Confidentiality
Security work is unusually sensitive: our reports describe how your systems can be attacked, and our platform holds telemetry about your environment.
The receiving party will use the other's confidential information only to perform under these Terms and limit access to personnel who need it. These duties survive termination for three (3) years, and indefinitely for trade secrets and reports describing unremediated vulnerabilities.
10. Third-Party Cloud Services
The services often run on or connect to infrastructure operated by third parties, including Amazon Web Services, Microsoft Azure and Google Cloud. Those providers operate under their own terms, and their availability and security are outside our control.
You are responsible for your accounts with them and for their acceptable use and testing policies. Some restrict or require notice for penetration testing; where that applies, you must obtain permission. We are not liable for incidents caused by a third-party provider.
11. Warranties and Disclaimers
We warrant that we will perform the services in a professional and workmanlike manner, consistent with generally accepted practice in the cybersecurity industry.
We do not warrant that all threats will be detected or prevented. No security product, service or team can identify every vulnerability, block every attack, or guarantee that your systems will not be compromised. Detection depends on the data available, on models that are necessarily imperfect, and on attacker techniques that change constantly. An assessment reflects your environment during the testing window, using the methods in the SOW; a clean report is not proof that no vulnerability exists.
Compliance readiness is not certification. Our compliance work helps you map controls, close gaps and prepare evidence for frameworks such as SOC 2, HIPAA, ISO 27001 and PCI DSS. It does not make you certified or compliant. Certification and attestation can only be issued by an independent auditor or qualified assessor after their own examination, and we do not control or predict that outcome.
Except for the express warranty above, the platform and services are provided “as is”. To the maximum extent permitted by law, we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement.
12. Limitation of Liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or business interruption.
Each party's total aggregate liability under these Terms is limited to the fees you paid or owed for the services giving rise to the claim in the twelve (12) months before the event. These limits do not apply to your payment obligations, to either party's breach of Section 9, or to your breach of Section 5.
13. Term and Termination
These Terms apply while you hold an active subscription or open SOW. Either party may terminate for material breach not cured within thirty (30) days of written notice. We may terminate immediately for a breach of Section 5 or Section 6.
On termination, your access ends and accrued fees become due. You may export your data during the term and for thirty (30) days afterward. Sections on intellectual property, confidentiality, fees, disclaimers, liability and governing law survive.
14. Governing Law
These Terms are governed by the laws of the Commonwealth of Massachusetts, United States, without regard to its conflict of law rules.
Both parties submit to the exclusive jurisdiction of the state and federal courts in Suffolk County, Massachusetts. Either party may still seek injunctive relief in any court of competent jurisdiction to protect its confidential information or intellectual property.
15. Changes to These Terms
We may update these Terms as our services and the law change, and will revise the “Last updated” date above when we do. For changes that materially reduce your rights, we will give notice at least thirty (30) days before they take effect.
16. Contact
Questions about these Terms, or an engagement's scope, go to [email protected], or by mail:
NovaShield Cyber
200 Clarendon Street
Boston, MA 02116
United States
See also our Privacy Policy and Cookie Policy.