Terms
Last updated: September 2026
These Terms and Conditions ("Terms") govern your use of the StrikeCyber website at strikecyber.com, our client portal and platform, and, where applicable, the provision of services by StrikeCyber Inc. ("StrikeCyber", "we", "us", "our"). By accessing this website or using our services, you agree to these Terms. If you do not agree, do not use the site or the services.
Where you engage us to perform services, those services are also governed by a separate written agreement, statement of work and rules of engagement. To the extent of any inconsistency relating to the services, that engagement documentation takes precedence over these Terms.
Use of the website and platform
You may use this website and our client portal for their intended purposes: to learn about our services, to contact us, and, if you are an authorized user, to access engagement materials. You may not attempt to gain unauthorized access to any part of the site or platform, interfere with its operation, or use it in any way that breaches our Acceptable Use Policy.
Authorization for security testing
This is the most important term on this page.
We perform security testing only where we hold clear, current, written authorization from a party entitled to give it. That authorization is recorded in a signed engagement agreement, statement of work and rules of engagement identifying the systems in scope, the permitted techniques, the testing window and the points of contact.
Unauthorized access to a computer system is a criminal offense under the Computer Fraud and Abuse Act and under state computer crime statutes. Nothing on this website constitutes authorization to test any system, and no employee of StrikeCyber may commence testing on the basis of an informal request, an email exchange, or a verbal instruction alone.
If you engage us, you represent and warrant that:
- You own the systems in scope, or you hold documented authority from the owner to authorize testing of them;
- You have obtained any consent required from third parties whose systems, data or infrastructure may be affected, including hosting providers, cloud providers, managed service providers and landlords;
- You have complied with the testing policies of any cloud or platform provider whose infrastructure is in scope; and
- The person signing the engagement documentation has authority to bind your organization.
We may suspend or terminate testing immediately if authorization is withdrawn, becomes unclear, or appears to have been given without proper authority.
Our platform and AI-assisted delivery
Our methodology is AI-augmented. Automated tooling performs reconnaissance, correlation and repetitive validation and assists in drafting findings; a qualified human operator reviews and confirms every finding before it is reported. We describe this openly because it changes what you should expect: broader coverage and faster reporting, with human judgment applied to what matters.
Where we use third-party AI services in delivering an engagement, we do so under enterprise agreements that prohibit training on our inputs and provide zero data retention.
Client responsibilities
You are responsible for:
- Providing accurate scope information, and telling us about systems that are fragile, safety-related, clinical, or operating under change freezes;
- Maintaining current backups before testing begins;
- Nominating a contact reachable during the testing window, including for critical findings raised in real time;
- Acting on findings. We identify and demonstrate risk; remediation is yours to implement unless separately agreed.
Intellectual property
The content of this website, our reports, methodologies, tooling and platform are owned by StrikeCyber or our licensors and are protected by intellectual property law. On payment in full, you receive a perpetual, non-exclusive license to use the report we deliver for your internal business purposes, including sharing it with your auditors, regulators, insurers and, under confidentiality, your customers. You may not resell it, publish it, or represent it as your own work product.
We retain ownership of our methodologies, tooling and any general knowledge, skills and experience gained during an engagement.
Third-party content
Our website and research may link to or reference third-party sites, tools and materials. We do not control them and are not responsible for their content, accuracy or availability. References to third-party products or standards do not imply endorsement by, or affiliation with, their owners.
No warranties
Security testing is a point-in-time assessment performed within an agreed scope and time period. It cannot identify every vulnerability, and it does not guarantee that your systems are secure or that a breach will not occur. Environments change, and new vulnerabilities are discovered continuously.
To the fullest extent permitted by law, the website, platform and services are provided "as is" and "as available", and we disclaim all warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, title and non-infringement.
Limitation of liability
To the fullest extent permitted by law, StrikeCyber will not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for loss of profits, revenue, data, goodwill or business opportunity, arising out of or relating to the website, the platform or the services, whether in contract, tort, strict liability or otherwise, and whether or not we were advised of the possibility of such damages.
Our total aggregate liability arising out of or relating to an engagement is limited to the fees paid by you to us for that engagement.
Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud, willful misconduct, or death or personal injury caused by negligence.
Indemnity
You will indemnify and hold harmless StrikeCyber, its officers, employees and contractors, against any claim, loss, liability or expense arising from your breach of these Terms, your breach of the Acceptable Use Policy, or your failure to hold valid authorization for systems you asked us to test.
Confidentiality and privacy
Each party will keep the other's confidential information confidential and use it only for the purposes of the engagement. Our handling of personal information is described in our Privacy Policy. Where we act as a service provider, business associate or subcontractor under sector-specific law, the applicable agreement governs.
Export control
Our services, tooling and technical outputs may be subject to United States export control laws, including the Export Administration Regulations and, where applicable, the International Traffic in Arms Regulations. You will not export, re-export or disclose any deliverable in violation of those laws. Where an engagement involves controlled technical data, we will confirm operator eligibility before testing begins, and you will identify the controlled material to us during scoping.
Suspension and termination
We may suspend or terminate access to the website or platform, or cease testing, where authorization is withdrawn or unclear, where these Terms or the Acceptable Use Policy are breached, or where continuing would expose either party to legal or safety risk. Termination does not affect rights accrued before it takes effect.
Changes to these Terms
We may update these Terms from time to time. The current version is always available at this page, and the date it was last updated appears above. Continued use after a change constitutes acceptance of the updated Terms.
Governing law and venue
These Terms are governed by the laws of the State of Texas, without regard to its conflict of laws principles. The parties submit to the exclusive jurisdiction of the state and federal courts located in Dallas County, Texas.
Contact
Questions about these Terms can be sent to info@strikecyber.com, or by mail to StrikeCyber Inc., 3723 Greenville Ave STE 55230, Dallas, TX 75206.
