Terms and Conditions
1. INTRODUCTION AND ACCEPTANCE OF TERMS
Welcome to Infosec Ventures. These Terms and Conditions ("Terms", "Agreement") govern your access to and use of the websites, software-as-a-service platforms, applications, and related services (collectively, the "Services") provided by Infosec Ventures and its portfolio companies, including but not limited to EmailAuth.io, HumanFirewall.io, BugsBounty.com, SecurityRating.com, Securathon.com, LiveHackShow.com, and CyberForceHQ.com.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by these Terms and our Privacy Policy. If you are accepting these Terms on behalf of an organisation, you represent and warrant that you have the authority to bind that organisation to these Terms.
If you do not agree to these Terms, you must not access or use our Services. We reserve the right to modify these Terms at any time, and such modifications shall be effective immediately upon posting. Your continued use of the Services following any modifications constitutes acceptance of the revised Terms.
2. DEFINITIONS
"Infosec Ventures", "we", "us", or "our" refers to Infosec Ventures and its affiliated portfolio companies, with registered offices in the United Kingdom (Unit 206, Comms House, Chiswick High Road, London W4 4HH), United Arab Emirates (Astrolabs Dubai, Cluster R, Jumeirah Lakes Towers, Dubai), and Singapore (1003 Bukit Merah Central, #07-04 Inno Centre, Singapore 159836).
"User", "you", or "your" refers to any individual or entity that accesses or uses our Services, including administrators, employees, contractors, and authorised representatives of subscribing organisations.
"Platform" refers to any of our software-as-a-service solutions, web applications, mobile applications, APIs, and related technology infrastructure.
"Customer Data" means all electronic data, information, or content submitted, uploaded, or processed through our Services by or on behalf of Users.
"Security Researcher" means any individual participating in vulnerability disclosure or bug bounty programmes through BugsBounty.com.
"Subscription" means the right granted to access and use specific Services for a defined period in exchange for payment of applicable fees.
3. DESCRIPTION OF SERVICES
Infosec Ventures provides enterprise-grade cybersecurity solutions designed to protect organisations from evolving digital threats. Our portfolio includes the following Services:
3.1 EmailAuth.io
EmailAuth.io provides Email Authentication as a Service, including DMARC (Domain-based Message Authentication, Reporting, and Conformance), SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and BIMI (Brand Indicators for Message Identification) management. The platform enables organisations to prevent email spoofing, protect against phishing attacks, and manage both inbound and outbound email authentication policies.
3.2 HumanFirewall.io
HumanFirewall.io is a comprehensive Human Cyber Risk Management and Mitigation platform. Services include security awareness training, phishing simulation campaigns, individual risk profiling, real-time threat reporting, incident remediation, and automated enterprise-wide blacklisting capabilities. The platform integrates with Microsoft 365, Google Workspace, Microsoft Exchange, and IBM Lotus Notes.
3.3 BugsBounty.com
BugsBounty.com is a SaaS-based vulnerability coordination and bug bounty platform offering public programmes, private programmes, and Securathon events. The platform connects organisations with a global community of ethical security researchers to identify and responsibly disclose security vulnerabilities.
SecurityRating.com provides continuous security monitoring, cyber risk measurement, and third-party risk assessment services. The platform enables organisations and cyber insurers to assess, score, and manage cybersecurity posture in near real-time.
3.5 Securathon.com
Securathon.com offers intensive red team testing services through competitive, time-limited security assessment events. These black-box penetration testing exercises are conducted by expert security professionals to identify critical vulnerabilities in target systems.
3.6 LiveHackShow.com
LiveHackShow.com provides live hacking demonstration events designed to raise cybersecurity awareness across organisations. These interactive sessions, lasting 60-90 minutes, are conducted by certified ethical hackers and demonstrate real-world attack scenarios to educate employees about security risks.
3.7 CyberForceHQ.com
CyberForceHQ.com is a cybersecurity skill assessment and training platform offering practical, hands-on evaluations, industry-recognised certifications, and professional development pathways for cybersecurity professionals.
4. ACCOUNT REGISTRATION AND SECURITY
To access certain features of our Services, you must create an account by providing accurate, current, and complete registration information. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account.
You agree to immediately notify us of any unauthorised use of your account or any other breach of security. We shall not be liable for any loss or damage arising from your failure to protect your account credentials.
You must be at least 18 years of age or the age of legal majority in your jurisdiction to create an account and use our Services. By creating an account, you represent and warrant that you meet these eligibility requirements.
We reserve the right to suspend or terminate accounts that violate these Terms, contain false information, or pose security risks to our platform or other users.
5. USER OBLIGATIONS AND ACCEPTABLE USE
You agree to use our Services only for lawful purposes and in accordance with these Terms. You shall not use the Services to engage in any activity that violates applicable laws, regulations, or third-party rights.
5.1 Prohibited Activities
You agree not to: (a) attempt to gain unauthorised access to any portion of the Services or any systems or networks connected to the Services; (b) use the Services to transmit malware, viruses, or other malicious code; (c) interfere with or disrupt the integrity or performance of the Services; (d) reverse engineer, decompile, or disassemble any aspect of the Services; (e) use automated means to access the Services except through our published APIs; (f) resell, sublicense, or redistribute the Services without our express written consent; (g) use the Services to conduct any form of illegal surveillance, harassment, or abuse; (h) submit false, misleading, or fraudulent information; or (i) violate the intellectual property rights of Infosec Ventures or any third party.
5.2 Responsible Disclosure (Security Researchers)
Security Researchers participating in bug bounty programmes through BugsBounty.com must adhere to responsible disclosure practices as specified in each programme's scope and rules. Researchers must not access, modify, or delete data belonging to other users; cause denial of service or performance degradation; conduct testing that could harm the availability, integrity, or confidentiality of systems; or publicly disclose vulnerabilities before they have been remediated and authorisation for disclosure has been granted.
6. SUBSCRIPTION, FEES, AND PAYMENT
Access to certain Services requires payment of subscription fees. Subscription terms, pricing, and feature access are specified in the applicable order form, quotation, or online subscription agreement.
6.1 Payment Terms
Unless otherwise specified, fees are due in advance on an annual or monthly basis as agreed. All fees are quoted exclusive of applicable taxes, which shall be added where required by law. You agree to provide accurate billing information and authorise us to charge your designated payment method for all applicable fees.
6.2 Renewal and Cancellation
Subscriptions shall automatically renew for successive periods of equal length unless either party provides written notice of non-renewal at least thirty (30) days prior to the end of the current subscription period. Cancellation requests must be submitted in writing to your account manager or through the designated cancellation process within each platform.
6.3 Refund Policy
Fees paid are generally non-refundable except as expressly stated in your subscription agreement or as required by applicable law.
6.4 Bug Bounty Rewards
Rewards for valid vulnerability submissions through BugsBounty.com are determined by the sponsoring organisation based on the severity, impact, and quality of the report. Reward amounts and eligibility criteria are specified in each programme's terms. Infosec Ventures facilitates reward payments but is not the ultimate payer for third-party programmes.
7. DATA PROTECTION AND PRIVACY
We are committed to protecting the privacy and security of your data. Our collection, use, and processing of personal data is governed by our Privacy Policy, which is incorporated into these Terms by reference.
7.1 Customer Data
You retain all ownership rights to Customer Data submitted through our Services. You grant us a limited, non-exclusive licence to host, copy, process, and display Customer Data solely for the purpose of providing and improving our Services. We shall implement appropriate technical and organisational measures to protect Customer Data against unauthorised access, loss, or destruction.
7.2 Data Processing
Where we process personal data on your behalf, we act as a data processor and you as the data controller. Upon request, we shall enter into a Data Processing Agreement that addresses the requirements of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws.
7.3 Data Retention and Deletion
We shall retain Customer Data for the duration of your subscription and for a reasonable period thereafter to allow for data export. Upon termination of your subscription, you may request deletion of your Customer Data, and we shall comply within thirty (30) days, except where retention is required by law or for legitimate business purposes as described in our Privacy Policy.
7.4 Security Measures
We maintain industry-standard security certifications and implement comprehensive security controls including encryption in transit and at rest, access controls, intrusion detection, regular security assessments, and incident response procedures. Details of our security practices are available upon request.
8. INTELLECTUAL PROPERTY RIGHTS
All intellectual property rights in and to the Services, including but not limited to software, algorithms, user interfaces, documentation, trademarks, and proprietary methodologies, are and shall remain the exclusive property of Infosec Ventures and its licensors.
You are granted a limited, non-exclusive, non-transferable, revocable licence to access and use the Services during your subscription period solely for your internal business purposes and in accordance with these Terms. This licence does not convey any ownership rights or rights to sublicense.
You may not remove, alter, or obscure any proprietary notices, trademarks, or copyright notices contained within the Services. The names EmailAuth.io, HumanFirewall.io, BugsBounty.com, SecurityRating.com, Securathon.com, LiveHackShow.com, CyberForceHQ.com, and Infosec Ventures, along with associated logos and designs, are registered trademarks or trademarks of Infosec Ventures and may not be used without our prior written consent.
9. SERVICE AVAILABILITY AND SUPPORT
We shall use commercially reasonable efforts to maintain the availability of our cloud-based Services. Target availability levels, planned maintenance windows, and service credits for unscheduled downtime, where applicable, are specified in the Service Level Agreement (SLA) provided with your subscription.
Technical support is provided according to the support tier included in your subscription. Support channels, response times, and escalation procedures are detailed in your subscription agreement. Emergency security support for critical vulnerabilities affecting our platform is provided to all customers.
We reserve the right to perform scheduled maintenance during designated maintenance windows with reasonable advance notice. Emergency maintenance may be performed without advance notice when necessary to address security vulnerabilities or critical system issues.
10. THIRD-PARTY INTEGRATIONS AND SERVICES
Our Services may integrate with or provide links to third-party services, applications, or websites. These integrations are provided for your convenience and do not constitute endorsement of any third-party products or services.
Your use of third-party services is subject to the terms and conditions and privacy policies of those third parties. We are not responsible for the availability, accuracy, or content of third-party services, nor for any loss or damage arising from your use of such services.
You acknowledge that integration with third-party services may require you to grant us access to certain accounts or data, and you represent that you have the necessary rights and authorisations to provide such access.
11. DISCLAIMERS AND WARRANTIES
THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
We do not warrant that the Services will be uninterrupted, error-free, or completely secure. While we employ industry-leading security practices, no system can guarantee absolute security against all threats, and you acknowledge that use of the Services carries inherent cybersecurity risks.
We do not warrant that the Services will detect or prevent all security threats, phishing attacks, vulnerabilities, or malicious activities. The effectiveness of security measures depends on multiple factors including user behaviour, configuration choices, and the evolving threat landscape.
Information, ratings, and assessments provided through SecurityRating.com are based on available data and methodologies at the time of assessment and should not be relied upon as the sole basis for security or business decisions.
12. LIMITATION OF LIABILITY
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL INFOSEC VENTURES, ITS AFFILIATES, DIRECTORS, OFFICERS, EMPLOYEES, OR AGENTS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, BUSINESS OPPORTUNITIES, GOODWILL, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR RELATED TO YOUR USE OF OR INABILITY TO USE THE SERVICES.
OUR TOTAL CUMULATIVE LIABILITY FOR ANY AND ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED THE GREATER OF (A) THE TOTAL FEES PAID BY YOU TO US DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED POUNDS STERLING (£100).
The limitations set forth in this section shall apply regardless of the form of action, whether in contract, tort, strict liability, or otherwise, and even if we have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of certain damages, so some of the above limitations may not apply to you.
13. INDEMNIFICATION
You agree to indemnify, defend, and hold harmless Infosec Ventures, its affiliates, and their respective directors, officers, employees, and agents from and against any and all claims, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or related to: (a) your use of the Services in violation of these Terms; (b) your violation of any applicable law or regulation; (c) your violation of any third-party rights, including intellectual property rights; (d) any Customer Data you submit through the Services; or (e) any unauthorised security testing or hacking activities conducted using our platforms.
We reserve the right to assume the exclusive defence and control of any matter subject to indemnification by you, and you agree to cooperate fully with our defence of such claims.
14. TERMINATION
These Terms shall remain in effect until terminated by either party. You may terminate your account at any time by following the account cancellation procedures within the applicable platform or by contacting our support team.
We may suspend or terminate your access to the Services immediately, without prior notice or liability, if you breach any provision of these Terms, fail to pay applicable fees when due, or if we reasonably believe that your use of the Services poses a security risk or may subject us to legal liability.
Upon termination, your right to access the Services shall immediately cease. We may, at our discretion, provide you with a reasonable period to export your Customer Data following termination. Provisions of these Terms that by their nature should survive termination shall survive, including but not limited to intellectual property provisions, disclaimers, limitations of liability, and indemnification obligations.
15. DISPUTE RESOLUTION
Any dispute arising out of or relating to these Terms or the Services shall first be attempted to be resolved through good-faith negotiation between the parties. If the dispute cannot be resolved through negotiation within thirty (30) days, either party may initiate formal dispute resolution proceedings.
For disputes involving claims of less than fifty thousand pounds sterling (£50,000), the parties agree to submit to binding arbitration administered by an internationally recognised arbitration institution, with arbitration to be conducted in London, United Kingdom.
Nothing in this section shall prevent either party from seeking injunctive or other equitable relief from any court of competent jurisdiction to prevent irreparable harm pending the outcome of arbitration.
16. GOVERNING LAW AND JURISDICTION
These Terms shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflict of law provisions. Subject to the dispute resolution provisions above, the courts of England and Wales shall have exclusive jurisdiction to adjudicate any dispute arising out of or relating to these Terms.
If you are accessing the Services from a jurisdiction with mandatory consumer protection laws that cannot be waived, nothing in these Terms shall affect your statutory rights under such laws.
17. GENERAL PROVISIONS
17.1 Entire Agreement
These Terms, together with our Privacy Policy, any applicable Data Processing Agreement, and any order forms or subscription agreements, constitute the entire agreement between you and Infosec Ventures regarding the Services and supersede all prior agreements and understandings.
17.2 Severability
If any provision of these Terms is found to be unenforceable or invalid by a court of competent jurisdiction, that provision shall be modified to the minimum extent necessary to make it enforceable while preserving its original intent, and the remaining provisions shall continue in full force and effect.
17.3 Waiver
Our failure to enforce any provision of these Terms shall not constitute a waiver of our right to enforce that provision or any other provision in the future.
17.4 Assignment
You may not assign or transfer these Terms or your rights under these Terms without our prior written consent. We may assign these Terms to any affiliate or in connection with a merger, acquisition, reorganisation, or sale of all or substantially all of our assets.
17.5 Force Majeure
Neither party shall be liable for any delay or failure to perform its obligations under these Terms due to events beyond its reasonable control, including but not limited to natural disasters, acts of war or terrorism, pandemics, government actions, or failures of third-party infrastructure or utilities.
17.6 Notices
We may provide notices to you via email to the address associated with your account, through in-platform notifications, or by posting notices on our websites. You may provide notices to us by email to the address specified in the Contact Information section below.
18. CONTACT INFORMATION
If you have any questions, concerns, or requests regarding these Terms, please contact us at:
Infosec Ventures
Email: hello@infosecventures.com