Terms of Service
Effective Date: September 30, 2025 Company: 1012 Capri, LLC
These Terms establish the operating boundary for website use and authorized defensive cybersecurity services, including client authorization, scope control, confidentiality, intellectual property, payment, and professional limitations.
Acceptance and relationship to other agreements
These Terms of Service govern use of this website and services provided by 1012 Capri, LLC. By accessing the website, submitting an enquiry, accepting a proposal, or using services, you agree to these Terms.
A proposal, statement of work, authorization document, data processing agreement, confidentiality agreement, invoice, or other signed engagement document may contain additional terms. If a signed engagement document conflicts with these website Terms, the signed document controls for that engagement.
Authorized defensive services only
Services are limited to lawful, defensive, and authorized cybersecurity activities. The client must own, operate, control, or have sufficient authority over every system, account, application, website, cloud environment, network, device, data source, and process included in the engagement.
No testing, access, validation, evidence collection, or technical review requiring authorization will begin until the parties have agreed on scope and the client has provided appropriate written authorization.
1012 Capri does not provide offensive hacking, unauthorized access, destructive activity, credential theft, unlawful surveillance, persistence, malware deployment, disruption, concealment, or testing against third parties without documented authority.
Scope and rules of engagement
The parties will define the objective, in-scope assets, excluded assets, permitted methods, timing, access arrangements, points of contact, escalation procedures, testing restrictions, data-handling requirements, and known operational limitations. Anything not expressly included is out of scope.
We may pause, limit, or refuse work if authority is unclear, the environment differs materially from the agreed assumptions, a third party objects, payment is overdue, the requested activity appears unsafe or unlawful, or continued work could create unreasonable risk.
Client responsibilities
The client is responsible for:
- Providing complete and accurate ownership, authorization, technical, and contact information.
- Obtaining required approvals from owners, vendors, hosting providers, employees, customers, insurers, and other affected parties.
- Identifying production, fragile, regulated, life-safety, industrial, medical, payment, or third-party systems before work begins.
- Maintaining current backups, recovery capabilities, continuity plans, monitoring, and qualified personnel.
- Providing access only through approved secure methods and revoking temporary access after use.
- Reviewing findings and making independent decisions about remediation, risk acceptance, vendors, and business operations.
- Notifying us promptly of material changes to systems, ownership, authorization, incidents, or the requested scope.
Credentials and access
Access must be limited to the minimum reasonably necessary for the authorized work. The client remains responsible for account approval, creation, monitoring, revocation, credential rotation, and restoration.
Passwords, private keys, recovery codes, authentication secrets, and similar information must not be submitted through a public website form. Where credentials are required, the parties should use an agreed secure method. We may refuse to receive or retain credentials through an insecure channel.
Deliverables and review
Deliverables may include reports, observations, risk ratings, recommendations, policies, plans, training materials, summaries, or technical notes. Findings reflect the systems, evidence, access, assumptions, methods, and time available during the engagement.
The client should review deliverables promptly and notify us of a material factual error within ten business days unless the applicable agreement specifies another period. A correction addresses an error in the agreed deliverable. A request that expands the objective, adds systems, requires new testing, or changes assumptions is additional work.
Confidentiality
Each party may receive confidential business, technical, security, financial, legal, or operational information. The receiving party will use confidential information only for the engagement, protect it with reasonable care, and disclose it only to personnel and providers who need it and are subject to appropriate obligations.
Confidentiality obligations do not apply to information that is lawfully public, previously known without restriction, independently developed without use of the confidential information, rightfully received from another source, or required to be disclosed by law. Where legally permitted, the receiving party should provide reasonable notice before compelled disclosure.
Intellectual property
Each party retains ownership of intellectual property owned or developed independently of the engagement. Upon full payment, the client receives a non-exclusive, non-transferable license to use final client-specific deliverables internally for the business purpose identified in the engagement.
Our pre-existing tools, methods, frameworks, checklists, templates, know-how, generic recommendations, code snippets, processes, and reusable materials remain our property. The client may not resell, publish, sublicense, distribute, remove proprietary notices from, or use deliverables to create a competing commercial service unless expressly authorized in writing.
The client retains ownership of client data and materials. The client grants us a limited right to use them only as necessary to perform the authorized engagement and meet legal or professional obligations.
Fees, expenses, and taxes
Fees, deposits, schedules, expenses, taxes, and payment milestones are stated in the applicable proposal, invoice, or service agreement. Published website prices are general ranges and do not constitute a binding quote.
Changes in scope, expedited work, additional meetings, inaccessible systems, repeated evidence requests, additional deliverables, or changed assumptions may require a revised fee and schedule. We are not required to perform additional work until the revised terms are accepted.
Professional limitations and no guarantee
Cybersecurity risk cannot be eliminated. Services do not guarantee complete protection, discovery of every vulnerability, prevention of every incident, uninterrupted operation, regulatory compliance, insurance coverage, or a particular business outcome.
Unless expressly stated in a signed agreement, services do not constitute a legal opinion, regulatory certification, audit attestation, penetration-test certification, insurance approval, or guarantee of compliance with any law, contract, or framework.
Limitation of liability
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, exemplary, punitive, or consequential damages, including lost profits, lost revenue, loss of goodwill, or loss of anticipated savings, arising from the website or services.
To the maximum extent permitted by law, our aggregate liability arising from a specific engagement will not exceed the fees actually paid to us for the specific services giving rise to the claim during the six months preceding the event. For claims arising only from website use and not a paid engagement, aggregate liability will not exceed one hundred United States dollars.
These limitations do not apply where prohibited by law or to liability that cannot lawfully be limited.
Indemnification
The client will defend, indemnify, and hold harmless 1012 Capri, its members, personnel, and service providers from third-party claims, losses, penalties, costs, and reasonable attorneys’ fees arising from the client’s lack of authority, unlawful instructions, inaccurate ownership representations, misuse of deliverables, violation of third-party rights, or failure to comply with the agreed scope.
Suspension and termination
We may suspend or terminate website access or services for nonpayment, unsafe conditions, unclear authority, lack of cooperation, abusive conduct, suspected illegality, misuse of deliverables, or material breach. The client may terminate services subject to the applicable cancellation and payment obligations.
Payment, confidentiality, intellectual property, limitation of liability, indemnification, dispute, and other provisions intended by their nature to survive will remain effective after termination.
Governing law and disputes
Unless a signed agreement states otherwise, these Terms are governed by the laws of the State of Colorado, without regard to conflict-of-law principles. Before filing a claim, the parties should attempt in good faith for at least thirty days to resolve the dispute through written notice and direct discussion.
Subject to mandatory law, disputes that cannot be resolved informally will be brought in a state or federal court having jurisdiction in Colorado. Each party waives objections based solely on inconvenient forum to the extent legally permitted.
Website use
You may use the website only for lawful business purposes. You may not interfere with website operation, attempt unauthorized access, scan or test the website without written permission, introduce malicious code, scrape content at unreasonable scale, impersonate another person, or use website content in a misleading or unlawful manner.
General provisions
If a provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions will continue. Failure to enforce a provision is not a waiver. Neither party may assign an engagement without consent, except in connection with a lawful merger, reorganization, or sale of substantially all relevant assets.
We may update these Terms for future website use and future engagements. Changes do not retroactively alter a signed agreement unless the parties agree in writing.
Contact 1012 Capri
Use these details for policy questions, privacy requests, billing concerns, formal notices, or questions about an authorized cybersecurity engagement. Do not send passwords, private keys, authentication codes, or other live credentials through ordinary email.