0%

Terms of Service

Last updated: 21 May 2026

Introduction

These Terms of Service govern the purchase and use of cybersecurity, cloud security, compliance, advisory, assessment and managed security services provided by Vernovi Cyber Ltd.

In these Terms, “Vernovi Cyber,” “we,” “us” and “our” refer to Vernovi Cyber Ltd. “Client,” “you” and “your” refer to the individual or organisation purchasing, receiving or using our Services.

By ordering, accepting or using any of our Services, you agree to these Terms.

These Terms apply together with any proposal, quotation, order form, subscription agreement or Statement of Work issued by Vernovi Cyber. Where there is a conflict, the signed Statement of Work will take priority for the relevant engagement.

Definition of Terms

Services

Cybersecurity, cloud, compliance, monitoring, advisory, assessment or related services supplied by Vernovi Cyber.

Client Data

Information, records, credentials, system data, logs, documents or personal data provided by the Client.

Deliverables

Reports, policies, assessments, recommendations, findings, plans, dashboards or other work products agreed as part of the Services.

Authorised Systems

Systems, applications, networks, devices, APIs, domains or cloud environments that the Client has authorised Vernovi Cyber to access, monitor, assess or test.

Statement of Work

A document describing the agreed scope, fees, timescales, responsibilities and Deliverables for a particular engagement.

Binding Agreement

  • These Terms are contractually binding between Vernovi Cyber and the Client.
  • A person accepting these Terms for an organisation confirms that they have authority to bind that organisation.
  • Services may not begin until the relevant proposal or Statement of Work has been accepted, required access has been provided and any required payment has been received.

Our Services

Cyber Security for SMEs

Cybersecurity support for small and medium-sized organisations, which may include assessments, policies, vulnerability management, compliance support, security monitoring and ongoing advice.

Managed Services

Ongoing cybersecurity support, which may include SOC monitoring, vulnerability management, alert triage, incident escalation, security reporting and management of agreed security controls.

Virtual CISO

On-demand strategic cybersecurity leadership, including governance, risk management, security strategy, compliance oversight, board reporting and security programme planning.

Vulnerability Assessment and Penetration Testing

Authorised assessment and testing of agreed applications, networks, APIs, cloud environments, devices or other systems to identify security weaknesses.

Free Consultation

A complimentary introductory session providing high-level cybersecurity assessment and recommendations based on the information supplied during the session.

The precise scope, Deliverables, exclusions and service levels will be stated in the applicable proposal or Statement of Work.

Scope and Changes

The scope of each engagement is defined in the applicable proposal, order form or Statement of Work. Changes to scope must be agreed in writing, and additional work may be quoted and charged separately.

Vernovi Cyber may update these Terms from time to time. The version in force at the date of the applicable Statement of Work applies to that engagement.

Client Responsibilities

  • Provide accurate, complete and timely information, access and cooperation reasonably required to deliver the Services.
  • Ensure appropriate backups of systems and data are in place before any testing or changes.
  • Maintain the confidentiality of credentials issued for the engagement and notify us promptly of any suspected compromise.
  • Obtain any third-party consents needed for Vernovi Cyber to access systems hosted or managed by others.
  • Remain responsible for decisions made and actions taken based on the Deliverables.

Authorised Testing and System Access

  • Testing is performed only on Authorised Systems, within the scope, dates and methods agreed in writing.
  • The Client confirms it owns the Authorised Systems or has the right to authorise testing on them.
  • Security testing carries inherent risk. We take reasonable care to avoid disruption, but Vernovi Cyber is not liable for degradation or outages arising from authorised testing performed with reasonable skill and care.
  • Either party may pause testing where a material risk to production systems is identified.

Managed Monitoring and Detection

  • Monitoring services operate on the systems, log sources and hours defined in the Statement of Work.
  • Alerting, triage and escalation follow the agreed playbooks and service levels.
  • Monitoring reduces, but cannot eliminate, the risk of a security incident. The Client remains responsible for its own environment, patching and end-user practices except where expressly agreed.

Free Consultation

The free consultation is a high-level advisory session only. It does not constitute a full assessment, audit or engagement, creates no ongoing obligations, and its recommendations are based solely on the information supplied during the session.

One free consultation is available per organisation unless we agree otherwise.

Fees and Payment

  • Fees are stated in the applicable proposal, order form or Statement of Work and are exclusive of applicable taxes unless stated otherwise.
  • Unless agreed otherwise, invoices are payable within 14 days of the invoice date.
  • Late payment may result in suspension of Services and may attract statutory interest.
  • Expenses agreed in advance, such as travel, are recharged at cost.

Subscriptions

  • Subscription Services renew automatically for successive periods equal to the initial term unless cancelled before the renewal date.
  • Subscription fees may be revised at renewal with at least 30 days notice.
  • Cancelling mid-term does not entitle the Client to a refund of fees already paid unless the Statement of Work says otherwise.

Cancellation and Rescheduling

  • Scheduled work, including testing windows and consultations, may be rescheduled with at least 5 business days notice at no charge.
  • Cancellations with less notice may be charged up to the full fee for the reserved time.
  • Either party may terminate an engagement for material breach that remains unremedied 14 days after written notice.

Service Availability

We aim to deliver Services during the days and hours stated in the Statement of Work. Target response and resolution times, where offered, are service levels and not guarantees unless expressly stated.

Planned maintenance affecting monitored or hosted components will be notified in advance where reasonably practicable.