Legal / Risk Notice

Cybersecurity Services Disclaimer

Effective Date: September 30, 2025 Company: 1012 Capri, LLC

This Disclaimer explains the inherent limitations of cybersecurity consulting and assessments, including the absence of any guarantee of complete protection, complete vulnerability discovery, or incident prevention.

Purpose and application

This Cybersecurity Services Disclaimer applies to cybersecurity consulting, risk assessments, audits, vulnerability reviews, website and cloud security reviews, access-control reviews, data protection guidance, policy development, employee training, incident response planning, backup reviews, and ongoing advisory services provided by 1012 Capri, LLC.

Cybersecurity involves evolving technology, human behavior, third-party dependencies, incomplete information, and active threats. Professional services can reduce uncertainty and support better decisions, but they cannot eliminate all risk.

No guarantee of complete security

We do not guarantee that any organization, system, website, cloud environment, network, application, account, policy, process, backup, or device is completely secure. A favorable assessment or the absence of a reported critical finding does not mean that no vulnerability, weakness, misconfiguration, threat, or unauthorized activity exists.

No guarantee that every vulnerability will be discovered

Assessments are limited by the written scope, authorized methods, time, evidence, access, system state, third-party restrictions, available documentation, and information provided by the client.

A weakness may be intermittent, newly introduced, dependent on conditions not present during review, concealed by another control, located outside the authorized scope, or undetectable through the agreed method. We do not guarantee identification of every vulnerability, defect, control failure, or compromise.

Point-in-time findings

Findings generally describe conditions observed during a defined period. Environments change through software updates, configuration changes, new integrations, employee turnover, vendor changes, new accounts, new vulnerabilities, and attacker behavior.

A prior report should not be treated as a permanent statement of security. Material changes may require reassessment.

No guarantee of incident prevention

Recommendations, controls, training, plans, and remediation can reduce risk but cannot guarantee prevention, detection, containment, or recovery from every incident. Threat actors, software defects, credential exposure, employee actions, supply-chain compromise, physical events, unknown vulnerabilities, and third-party failures may bypass controls.

Reliance on client information

Services depend on the accuracy and completeness of information, access, representations, and documentation supplied by the client. Missing, delayed, inaccurate, or restricted information may affect findings and recommendations.

The client is responsible for identifying relevant assets, dependencies, known incidents, constraints, third-party ownership, regulated information, and operational sensitivities.

Operational and testing risk

Even authorized defensive activity may produce alerts, log volume, temporary access restrictions, performance effects, vendor notifications, or interaction with automated security controls. The agreed scope and safeguards are intended to reduce operational risk, not eliminate it.

The client should maintain current backups, recovery capabilities, monitoring, continuity plans, and qualified personnel during material assessment activity.

Remediation and implementation

Unless expressly included in a signed agreement, our role is advisory. The client remains responsible for deciding whether, when, and how to implement recommendations and for testing changes before production deployment.

Remediation may affect availability, compatibility, warranties, contracts, data, integrations, insurance, or compliance. The client should involve appropriate technical, legal, regulatory, insurance, and business professionals.

Compliance and legal matters

Unless a signed agreement expressly states otherwise, services do not constitute legal advice, a regulatory certification, an audit opinion, a formal attestation, an insurance approval, or a guarantee of compliance with any law, standard, contract, or framework.

References to frameworks or industry practices are contextual guidance and do not by themselves establish compliance.

Incident response planning

An incident response plan improves preparation but does not guarantee that a real incident will follow the anticipated sequence or that systems, evidence, personnel, communications, vendors, or decision-makers will be available.

An actual incident may require legal counsel, cyber insurance, forensic specialists, law enforcement, regulators, public-relations support, identity-protection providers, and other third parties. Those services are not included unless expressly stated.

Backups and recovery

A backup review evaluates the information and evidence available during the engagement. It does not guarantee that every backup is complete, uncompromised, restorable, current, or sufficient for every recovery scenario.

The client remains responsible for maintaining backups, testing restoration, protecting backup credentials, separating backup systems where appropriate, and documenting recovery priorities.

Third-party products and providers

References to a product, vendor, platform, control, or service are based on the relevant context and do not constitute a warranty, endorsement, or guarantee. Third-party functionality, pricing, licensing, availability, security, and support may change without our control.

Continuing responsibility

The client remains responsible for governance, patching, monitoring, identity management, backups, staff practices, vendor oversight, incident readiness, compliance, and ongoing risk management. Cybersecurity is a continuing process rather than a one-time project.

Legal and business contact

Contact 1012 Capri

Use these details for policy questions, privacy requests, billing concerns, formal notices, or questions about an authorized cybersecurity engagement. Do not send passwords, private keys, authentication codes, or other live credentials through ordinary email.

Company 1012 Capri, LLC
Email security@1012capri.com
Phone +1 303-888-5131
Business hours Monday–Friday, 9:00 AM–5:00 PM Mountain Time
Legal and business address 5309 Silver Feather Cir, Broomfield, CO 80023, United States