Terms of Service

Last Updated: June 17, 2026

Effective Date: June 17, 2026

1. Introduction and Acceptance

Welcome to CoreCyber, a self-service cyber risk quantification and management platform (the "Platform") operated by Covenant Security Solutions International ("Covenant," "Company," "we," "us," or "our"). These Terms of Service ("Terms") form a legally binding agreement between you (and, if you use the Platform on behalf of an organization, that organization) and Covenant, and govern your access to and use of the Platform, the website at corecyber.io, and all related products, tools, content, and services (collectively, the "Services").

By creating an account, clicking "I agree" (or a similar control), signing an order or assessment authorization, making a payment, or otherwise accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by these Terms and by our Privacy Policy, which is incorporated by reference. If you do not agree to these Terms, you must not access or use the Services.

If you accept these Terms on behalf of an organization, you represent and warrant that you are an authorized representative of that organization with legal authority to bind it, and "you" refers to both you individually and that organization.

IMPORTANT: These Terms limit our liability (Sections 20-21), require you to indemnify us in certain circumstances (Section 22), and - except where prohibited by law - require disputes to be resolved by binding individual arbitration and waive your right to a jury trial and to participate in class actions (Section 24). Please read these sections carefully.

Company Information

Company Name: Covenant Security Solutions International

Platform / Service Name: CoreCyber

Address: 30 N. Gould St., STE 9374, Sheridan, Wyoming 82801, United States of America

General / Legal Contact: legal@corecyber.io

2. Definitions

Capitalized terms have the meanings given where they first appear or as set out below:

  • "Account" means the account you register to access the Services.
  • "AI Outputs" means any risk scores, financial-impact estimates (including Expected Annual Loss, Value-at-Risk, and Conditional Value-at-Risk figures), confidence intervals, risk drivers, forecasts, benchmarks, compliance gap analyses, plans of action and milestones (POA&Ms), recommendations, draft documents, and other results generated by the Platform's automated, statistical, machine-learning, or artificial-intelligence models.
  • "Applicable Law" means all laws, regulations, and binding governmental orders applicable to a party's use or provision of the Services, including data-protection, export-control and sanctions, anti-corruption, and consumer-protection laws.
  • "Connector" means an integration that, with your authorization, allows the Platform to retrieve data from a third-party service (for example, AWS, Bitdefender GravityZone, Google Workspace, Microsoft 365, Shopify, or Splunk).
  • "Customer Data" means all data, information, files, responses, configurations, target identifiers (such as IP addresses, domains, and hostnames), credentials, and other content that you or your users submit to, or authorize the Platform to retrieve for, the Services.
  • "External Security Assessment" or "vPenTest" means the optional add-on penetration-testing and external vulnerability-assessment service delivered through our third-party provider (Vonahi/Kaseya) and ingested into the Platform.
  • "Subscription" means a paid plan (for example, Professional or Enterprise), an IP-counted vulnerability-assessment plan, an add-on module, or the External Security Assessment add-on.
  • "User" means any individual you authorize to access the Services under your Account.

3. Eligibility and Account Registration

3.1 Eligibility

You must be at least 18 years old (or the age of majority in your jurisdiction) and have the legal capacity to enter into binding contracts. The Services are intended for business and professional use only and are not offered for personal, household, or consumer purposes. By using the Services you represent and warrant that you meet these requirements and that all registration information you provide is accurate, current, and complete.

3.2 Account Security

You agree to: (a) provide accurate, current, and complete information and keep it updated; (b) maintain the confidentiality of your credentials and enable multi-factor authentication (MFA) where available; (c) accept responsibility for all activity under your Account; (d) not share credentials or create accounts by automated means; and (e) notify us immediately at legal@corecyber.io of any suspected unauthorized access. You are responsible for your Users' compliance with these Terms.

3.3 Account Recovery

Certain security features (including MFA and encrypted storage of sensitive material) mean we may be unable to recover access to, or the contents of, an Account if you lose your credentials and recovery codes. You are responsible for securely retaining your backup recovery codes.

4. Nature of the Service - Self-Service ("Do-It-Yourself")

The Services are a self-service software platform. They are not a master services agreement, a managed service, a consulting or advisory engagement, a professional security audit, a legal or compliance opinion, or insurance. Except where you separately purchase the optional External Security Assessment add-on (Section 13) or another service we expressly agree in a signed writing to provide, Covenant does not perform services on your behalf, does not direct or supervise your use of the Platform, and does not review, validate, or verify the information you enter.

You operate the Platform yourself, choose what data to provide and what systems to connect, and decide how to interpret and act on the AI Outputs. Because the Services are self-directed, you - and not Covenant - are responsible for the configuration, inputs, authorizations, and decisions associated with your use of the Services, as further described in Sections 6, 8, and 9.

If your organization requires a scoped, supervised, contracted professional engagement (including a Statement of Work, service levels, or deliverables for which Covenant assumes responsibility), that engagement must be governed by a separately executed Master Services Agreement and Statement of Work - not by these Terms.

5. Description of the Platform

CoreCyber provides AI-assisted tools to help organizations identify, quantify, and manage cyber risk on a self-service basis. Depending on your Subscription tier and add-ons, the Platform may include:

  • Cyber risk assessments - multi-phase questionnaires (Phase 1 foundational, Phase 2 technical deep-dive, and optional Phase 3 specialty modules) across multiple industry sectors and compliance frameworks.
  • AI risk quantification - automated models that estimate financial cyber risk (such as Expected Annual Loss and loss-distribution / value-at-risk ranges), identify risk drivers, forecast trends, and aggregate supply-chain risk (see Section 9).
  • Compliance tooling - framework mapping, gap analysis, plans of action and milestones (POA&Ms), and cyber-insurance readiness checks.
  • Connectors - optional, read-only integrations that retrieve security signals from supported third-party services (Section 12).
  • Vendor portal - token-based questionnaires that let you collect self-reported security information from third-party vendors (Section 14).
  • Reports - generated PDF/DOCX/CSV reports and, on eligible tiers, scheduled reports.
  • External Security Assessment (vPenTest) add-on - optional penetration testing and external vulnerability assessment (Section 13).

5.1 Subscription Tiers and Add-Ons

The Services are offered in tiers (for example, a no-cost or limited Starter experience, Professional, and Enterprise) with differing feature entitlements, usage limits (assessments, users, connectors, vendors, report formats), and support levels, together with usage-based and add-on options (including IP-counted vulnerability-assessment plans, individual Phase 3 modules, and the External Security Assessment add-on). The specific entitlements, limits, and prices applicable to a given tier or add-on are presented in the Platform and on our pricing pages at the time of purchase and are incorporated into these Terms. Features behind a higher tier or add-on are not available unless and until the corresponding Subscription is active. We may add, modify, suspend, or discontinue features at any time and will use reasonable efforts to give advance notice of material adverse changes to paid features.

6. Explicit Authorization Requirement (Authorized Testing Only)

USE OF THE SERVICES TO ASSESS, SCAN, TEST, OR CONNECT ANY SYSTEM REQUIRES PRIOR, EXPLICIT AUTHORIZATION FROM THE OWNER OR AUTHORIZED CONTROLLER OF THAT SYSTEM.

Before initiating any assessment, vulnerability scan, penetration test, or Connector integration, and before submitting any target identifier (such as an IP address, domain, hostname, account, or store), you must hold all necessary authorizations and consents. By using the Services, you represent, warrant, and covenant on a continuing basis that:

  • you own, or have obtained explicit written authorization from the owner or authorized controller of, every system, network, application, account, or asset that you assess, scan, test, connect, or identify through the Services;
  • you are authorized to provide every credential, token, and data set you submit or that you authorize a Connector to retrieve;
  • you will not use the Services to test, scan, access, or assess any system, network, application, or data for which you lack such authorization;
  • you understand that unauthorized access to, or testing of, computer systems may violate civil and criminal laws (including, in the United States, the Computer Fraud and Abuse Act, and comparable laws worldwide); and
  • you will provide proof of authorization promptly upon our reasonable request or the request of a competent authority.

Where the Platform requires you to affirm authorization and provide a signature, consent, or attestation (including the authorization step in the assessment workflow and the scope attestation for the External Security Assessment add-on), that affirmation is a representation by you on which Covenant relies. You - and not Covenant - bear full responsibility and liability for any use of the Services that lacks proper authorization. Failure to obtain proper authorization may result in immediate suspension or termination of your Account, forfeiture of fees, legal action, and referral to law-enforcement or regulatory authorities.

7. Acceptable Use Policy

You shall not, and shall not permit any User or third party to, use the Services to:

  • violate any Applicable Law, regulation, or third-party right (including intellectual-property, privacy, contractual, or export-control rights);
  • conduct any unauthorized security testing, scanning, or access, or target any system you are not authorized to assess (Section 6);
  • upload, transmit, store, or distribute malware, ransomware, exploits, or other malicious code, except for legitimate, authorized testing of your own systems within the Platform's intended functionality;
  • interfere with, disrupt, overload, or impair the integrity or performance of the Services or any connected systems or networks, or attempt to gain unauthorized access to the Services or other accounts;
  • circumvent or attempt to circumvent usage limits, tier gating, authentication, rate limiting, or geographic/export restrictions (including by use of VPNs, proxies, or falsified location);
  • impersonate any person or entity, or misrepresent your identity, affiliation, or authorization;
  • submit information you know or should know to be false, misleading, or fraudulent;
  • reverse engineer, decompile, disassemble, scrape, or attempt to derive the source code, models, or underlying ideas of the Services, except to the extent this restriction is prohibited by Applicable Law;
  • resell, sublicense, time-share, or make the Services available to any third party except as expressly permitted, or use the Services to build a competing product or for competitive benchmarking;
  • use the Services for any unlawful, harmful, harassing, defamatory, infringing, or unethical purpose; or
  • use any AI Output to make decisions that produce legal or similarly significant effects on individuals without appropriate human review, or in any manner prohibited under Applicable Law (including any prohibited practice under the EU AI Act).

We may, without limiting our other remedies, issue warnings, suspend access immediately for serious or suspected violations, terminate for material or repeated violations, and report illegal activity to authorities. We will use reasonable efforts to notify you before acting, except where immediate action is necessary.

8. Accuracy of Inputs and Customer Responsibility

The Services produce outputs based on the information you provide and the data sources you connect. The quality, reliability, and usefulness of every AI Output depend entirely on the accuracy, completeness, currency, and good faith of your inputs. You acknowledge and agree that:

  • you are solely responsible for all Customer Data, including the truthfulness, accuracy, completeness, and lawfulness of your questionnaire responses, target identifiers, configurations, and uploaded materials, and for the data retrieved through Connectors you authorize;
  • inaccurate, incomplete, outdated, or misrepresented inputs will produce inaccurate or misleading outputs ("garbage in, garbage out"), and Covenant is not responsible for any output, decision, loss, or consequence arising from such inputs;
  • the Platform may display data-quality and model-agreement indicators (for example, a Data Quality Score and a Model Agreement Index) to signal the reliability of an estimate; you are responsible for reading and heeding these indicators and any accompanying warnings;
  • you are responsible for maintaining your own independent records and for verifying any output before relying on it; and
  • you must not rely on the Services as your sole basis for any security, compliance, financial, insurance, legal, or operational decision.

Covenant disclaims all liability for any loss, damage, regulatory exposure, or other consequence that results from inaccurate, incomplete, unlawful, or unethical Customer Data or from your failure to use the Services in accordance with these Terms.

9. Automated Analysis, AI Outputs, and No Professional Advice

9.1 How the Platform Generates Outputs

The Platform uses statistical and machine-learning models - which may include FAIR-style Bayesian networks, loss-distribution/probabilistic models, gradient-boosted feature-importance (SHAP) analysis, time-series (LSTM/transformer) forecasting, supply-chain Bayesian aggregation, causal-inference estimation, and ensemble methods - to generate AI Outputs from your inputs and connected data.

9.2 Estimates, Not Guarantees

AI Outputs are probabilistic estimates and informational aids, expressed with inherent uncertainty (including confidence intervals and agreement indices). You acknowledge that: (a) AI Outputs may be inaccurate, incomplete, or biased; (b) financial-impact figures (such as Expected Annual Loss, Value-at-Risk, and Conditional Value-at-Risk) are modeled estimates and not predictions, valuations, or guarantees of actual loss; (c) risk-driver and causal outputs indicate statistical association and modeled effect, not proof of causation; (d) results are point-in-time and depend on inputs and data quality; and (e) models require human review and may change over time.

9.3 Not Professional Advice; Not an Audit or Certification

The Services and all AI Outputs do not constitute professional, legal, financial, insurance, accounting, or security-audit advice, and do not constitute a certification, attestation, accreditation, or guarantee of compliance with any law, standard, or framework. Compliance gap analyses, POA&Ms, and generated draft documents (such as system security plans, assessment reports, or data-protection impact assessments) are self-service drafts and working aids for your internal use only; they are not official audits, certifications, or filings, and do not replace assessment by a qualified, independent professional or accredited assessor. You are responsible for engaging qualified professionals and for all decisions you make based on the Services.

9.4 No Guarantee of Security

No security assessment, scan, or test can identify all vulnerabilities or guarantee future security. Implementing recommendations from the Services will not eliminate all risk or prevent all breaches. You remain solely responsible for the security of your own systems and data.

9.5 Human Oversight

You agree to maintain appropriate human oversight of AI Outputs and not to use them for automated decisions affecting individuals' legal rights, employment, creditworthiness, or access to essential services without appropriate human review and safeguards.

9.6 Improvement of the Services and Your Opt-Out

We may process Customer Data and usage data to operate, secure, maintain, and improve the Services, including improving our models. Where we use data to develop or improve models for the benefit of other customers, we use aggregated and/or de-identified data that does not identify you or any individual.

You may opt out of having your organization's data used to improve our models and Services at any time using the data-sharing control in your account settings ("Data & Privacy" / incognito mode). When opted out, your organization's data is excluded from product- and model-improvement processing on a going-forward basis. This opt-out does not affect processing necessary to provide, secure, and operate the Services for you, or processing required by Applicable Law.

10. Subscriptions, Fees, Billing, and Payment

10.1 Fees and Plans

Fees, currencies, billing cycles (monthly or annual), tiers, usage limits, and add-on prices are those displayed in the Platform or on our pricing pages at the time of your purchase, which are incorporated into these Terms. Prices may vary by region (purchasing-power-parity pricing) and are presented with the applicable currency at checkout. Certain limited features may be offered at no charge; we may change or discontinue any no-cost offering at any time.

10.2 Payment Processor; Identity Verification

Payments are processed by Stripe, and certain flows use Stripe Identity for identity verification and fraud prevention. By paying or verifying through Stripe, you agree to Stripe's applicable terms and authorize the charges. We do not store full payment-card details. See Section 11 for identity verification.

10.3 Auto-Renewal

Unless otherwise stated at purchase, paid Subscriptions renew automatically at the end of each billing period at the then-current price, until cancelled. You authorize us (through Stripe) to charge your payment method for each renewal. You may cancel auto-renewal at any time through your billing settings or by contacting us; cancellation takes effect at the end of the current paid period.

10.4 Price Changes

We may change prices. For Subscriptions, price changes take effect at your next renewal, and we will provide at least thirty (30) days' advance notice of any increase. Continuing your Subscription after a price change takes effect constitutes acceptance of the new price.

10.5 No Refunds

Except where required by Applicable Law, all fees for the Platform and Services are non-refundable, and cancelling does not entitle you to a refund or credit for the unused portion of a paid period; you retain access through the end of the period already paid. One-time and usage-based charges (including IP-counted assessment plans, module add-ons, and the External Security Assessment add-on) are non-refundable once the corresponding service has been initiated or delivered. This no-refund policy applies to the fullest extent permitted by Applicable Law and does not limit any non-waivable statutory rights you may have.

10.6 Taxes

All fees are exclusive of taxes. You are responsible for all applicable sales, use, value-added (VAT/GST), withholding, and similar taxes, excluding taxes on our net income. If we are required to collect such taxes, they will be added to your charges.

10.7 Late or Failed Payment

If a payment fails or is overdue, we may suspend or downgrade access until amounts are paid, charge interest on undisputed overdue amounts at the lower of 1.5% per month or the maximum rate permitted by law, and recover reasonable costs of collection. We will provide notice before suspension where practicable.

10.8 Disputed Charges

If you dispute a charge in good faith, notify us within fifteen (15) days of the charge with details; you must pay undisputed amounts when due, and the parties will work in good faith to resolve the dispute promptly.

11. Identity Verification

Certain features (including aspects of the assessment and External Security Assessment workflows) require identity verification through Stripe Identity, which may collect government-issued identification and biometric/selfie data and process it for verification, fraud prevention, and compliance. This processing is governed by Stripe's terms and privacy policy and by our Privacy Policy. Verification sessions may time out and require re-verification. We may suspend or refuse access where identity verification fails or cannot be completed.

Stripe Privacy Policy

12. Third-Party Connectors and Integrations

12.1 You Authorize Each Connection

Connectors retrieve data from third-party services only when you connect them and grant the necessary authorization (via OAuth grant or by providing an API key/token). Connectors are designed to use read-only access appropriate to their purpose. By connecting a service, you represent that you are authorized to grant that access and to allow the Platform to retrieve the associated data.

12.2 Credential Handling and Revocation

Credentials and tokens you provide are stored in encrypted form and used only to provide the Services. You may disconnect a Connector and revoke access at any time through the Platform and/or the third-party service's own controls. You are responsible for managing and rotating your credentials.

12.3 Third-Party Services Are Outside Our Control

Connectors and the third-party services they access are provided by independent third parties under their own terms and privacy policies. We are not responsible for the availability, accuracy, security, or acts/omissions of those third-party services, and your use of them is at your own risk. Some Connectors require a prerequisite license or module from the third-party provider; you are responsible for maintaining the necessary entitlements.

13. External Security Assessment (Penetration Testing) Add-On

13.1 Nature of the Add-On

The External Security Assessment / vPenTest add-on is an optional, separately purchased service in which penetration testing and external vulnerability assessment are performed through our third-party provider (Vonahi/Kaseya), with findings ingested into the Platform. It requires an active External Security Assessment subscription and is available across tiers as an add-on.

13.2 Mandatory Scope Authorization

Before any test is performed, you must define the scope (such as specific external IP addresses, domains, and web applications) and expressly attest that you own or are fully authorized to authorize testing of every in-scope target, that the testing window is authorized, and that you have all legal authority required. This attestation is a material representation on which Covenant and its provider rely. You are solely responsible for the accuracy of the scope and for any testing of targets you were not authorized to include.

13.3 Testing Limitations and Exclusions

Penetration testing is inherently intrusive and carries risk, including the possibility of service disruption. You acknowledge that: (a) you are responsible for backups and for notifying your own stakeholders and hosting/cloud providers as required by their terms; (b) testing is point-in-time and will not identify all vulnerabilities; and (c) tests will not knowingly be used to perform denial-of-service attacks, destroy data, or violate Applicable Law. Findings are provided for your internal remediation use and are confidential.

13.4 Allocation of Responsibility

Covenant is not liable for disruption, damage, or loss to your or any third party's systems arising from an External Security Assessment conducted on targets you were not authorized to include in scope, or arising from inaccurate scope information you provided. Your indemnification obligations in Section 22 apply to such matters.

14. Vendor Portal and Third-Party Submissions

The vendor portal lets you invite third-party vendors to complete security questionnaires via time-limited tokens and to submit self-reported responses and evidence. You are responsible for the lawful use of the vendor portal, for the invitations you send, and for your handling of vendor submissions. Vendor responses are self-reported by the vendor; Covenant does not audit, verify, or validate vendor submissions, and the Platform's aggregation of vendor data (including supply-chain risk outputs) reflects only the information vendors provide. You are responsible for any independent due diligence. Vendors who submit information represent that their submissions are accurate; Covenant is not responsible for vendor misrepresentation.

15. Intellectual Property

15.1 Platform Ownership

The Platform, including all software, code, models, algorithms, methodologies, user interfaces, designs, report templates, documentation, and all related intellectual-property rights, is owned by Covenant or its licensors and is protected by United States and international law. Except for the limited rights granted below, no rights are transferred to you.

15.2 Limited License to You

Subject to your compliance with these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Services for your internal business purposes during your Subscription term. You may not (a) modify, copy, or create derivative works of the Services; (b) reverse engineer or attempt to derive source code or models; (c) remove proprietary notices; (d) use the Services for competitive analysis or to build a competing product; or (e) resell or sublicense access.

15.3 Your Content and Outputs

As between the parties, you retain all rights in Customer Data. You grant us a non-exclusive, worldwide license to host, process, transmit, display, and analyze Customer Data and to generate AI Outputs solely to provide, secure, and improve the Services as described in these Terms and the Privacy Policy (subject to your opt-out in Section 9.6). Subject to your payment of applicable fees and compliance with these Terms, you may use the reports and AI Outputs we provide for your internal business and security purposes. You may not publicly disclose, publish, resell, or distribute our proprietary methodologies, models, scoring techniques, or report templates without our prior written consent.

15.4 Feedback

If you provide feedback, suggestions, or ideas about the Services ("Feedback"), you grant us a perpetual, irrevocable, worldwide, royalty-free, fully sublicensable license to use and incorporate the Feedback without restriction, attribution, or compensation.

15.5 Trademarks

"CoreCyber," "Covenant Security Solutions International," and related logos are trademarks of Covenant. You may not use them without our prior written permission. Other marks are the property of their respective owners.

15.6 Third-Party and Open-Source Components

The Services may incorporate third-party and open-source components governed by their own licenses; nothing in these Terms limits your rights under, or grants rights superseding, any applicable open-source license.

16. Confidentiality

Each party may receive non-public information of the other that is marked or reasonably understood to be confidential ("Confidential Information"), including the non-public features of the Platform, your Customer Data, and the terms of any non-public order. The receiving party will: (a) use Confidential Information only to exercise its rights and perform its obligations under these Terms; (b) protect it using at least reasonable care; and (c) not disclose it except to personnel, advisors, or subprocessors bound by confidentiality obligations and with a need to know, or as required by law (with notice where legally permitted). Confidential Information excludes information that is or becomes public without breach, was lawfully known before disclosure, is independently developed, or is lawfully received from a third party without restriction. These obligations survive for five (5) years after disclosure, except that obligations regarding trade secrets and personal data continue as long as required by Applicable Law.

17. Data Protection and Privacy

Our collection and use of personal data are described in our Privacy Policy. Where we process personal data on your behalf as a processor/service provider, a Data Processing Addendum (DPA) - incorporating Standard Contractual Clauses and other transfer mechanisms as applicable - is available and, where executed or incorporated by reference, governs that processing. You are the controller of personal data you submit and are responsible for having a lawful basis and all necessary notices and consents for the data you provide and the systems you connect. Each party will comply with applicable data-protection laws (including, where applicable, the GDPR, UK GDPR, and US state privacy laws). In the event of a personal-data breach affecting Customer Data within our control, we will notify you in accordance with the DPA and Applicable Law. The Services involve transfer and storage of data in the United States and other countries; by using the Services you acknowledge such transfers, subject to the safeguards described in the Privacy Policy and DPA.

18. Export Controls, Sanctions, and ITAR

The Services, and any technical data or software made available through them, are subject to United States export-control and sanctions laws, including the Export Administration Regulations (EAR), the International Traffic in Arms Regulations (ITAR), and the economic sanctions and embargoes administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), as well as comparable export-control and sanctions laws of other jurisdictions (including the EU and UK). Because CoreCyber is a global platform, the following restrictions apply to all users regardless of location.

18.1 Prohibited Jurisdictions

The Services may not be accessed, used, exported, re-exported, or made available, directly or indirectly, in or to any country, region, or territory that is the target of comprehensive U.S. or other applicable sanctions or embargoes (currently including, without limitation, Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine), or otherwise in violation of any export-control or sanctions law.

OFAC Sanctions Programs and Country Information

18.2 Restricted and Denied Parties

You represent and warrant that you, your organization, your Users, and any system, target, or beneficiary of your use of the Services are not: (a) located in, organized under the laws of, or ordinarily resident in a prohibited jurisdiction; (b) owned or controlled by, or acting on behalf of, any sanctioned or restricted party; or (c) listed on any restricted-party list, including OFAC's Specially Designated Nationals (SDN) List, the U.S. Commerce Department's Denied Persons or Entity List, or any equivalent list maintained by a competent authority.

18.3 No Circumvention

You will not use VPNs, proxies, falsified location, or any other means to access the Services from, or provide the Services to, a prohibited jurisdiction or restricted party, or otherwise to circumvent export or sanctions controls. We may verify location and compliance (including by IP analysis and payment/identity information) and may suspend or terminate access we reasonably believe violates this Section.

18.4 ITAR-Controlled Data Prohibited

The Services are not authorized, designed, or intended for the storage, processing, transmission, or generation of ITAR-controlled defense articles, defense services, or technical data, or of EAR-controlled "600-series" or other controlled military/dual-use technical data requiring a license for export, unless and until Covenant expressly agrees in a signed writing and the parties implement the controls required by Applicable Law. You must not upload, connect, or otherwise introduce ITAR- or export-controlled technical data into the Services, and you must not use the Services in any manner that would result in an unauthorized export or re-export of controlled technical data, including any release of such data to a foreign person. You are solely responsible for classifying your data and for ensuring your use of the Services complies with all export-control and sanctions obligations.

18.5 Your Compliance Responsibility

You are responsible for obtaining any licenses or authorizations required for your use of the Services and for complying with all export-control and sanctions laws. You will promptly notify us if you become a restricted party or if your use would otherwise violate this Section. Breach of this Section is a material breach permitting immediate suspension or termination and may be reported to authorities.

19. Representations and Warranties

19.1 Mutual

Each party represents and warrants that it has the authority to enter into and perform these Terms and that its performance will comply with Applicable Law.

19.2 Your Warranties

You represent, warrant, and covenant on a continuing basis that: (a) you have all authorizations required to assess, scan, test, connect, and submit every system, target, and data set you use with the Services (Section 6); (b) all Customer Data is provided lawfully and, to the best of your knowledge, accurately and completely (Section 8); (c) you have all rights, consents, and a lawful basis to provide Customer Data and to authorize its processing, including any personal data; (d) your use of the Services complies with these Terms, the Acceptable Use Policy, export-control and sanctions laws (Section 18), and all other Applicable Law; and (e) you will not use the Services for any unlawful or unethical purpose.

19.3 Anti-Corruption; Modern Slavery; Sanctions

Each party will comply with applicable anti-corruption laws (including the U.S. FCPA and UK Bribery Act), modern-slavery and anti-trafficking laws, and export-control and sanctions laws, and will not take any action that would cause the other party to violate such laws.

20. Disclaimers

THE SERVICES, INCLUDING ALL CONTENT, SOFTWARE, FEATURES, AND AI OUTPUTS, ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, COVENANT DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

WITHOUT LIMITING THE FOREGOING, COVENANT DOES NOT WARRANT THAT: (A) THE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE; (B) ANY AI OUTPUT, ASSESSMENT, ESTIMATE, FINDING, OR RECOMMENDATION WILL BE ACCURATE, COMPLETE, OR RELIABLE, OR WILL IDENTIFY ALL VULNERABILITIES OR ENSURE COMPLIANCE OR SECURITY; OR (C) RESULTS GENERATED FROM YOUR INPUTS WILL MEET YOUR REQUIREMENTS. YOU ACKNOWLEDGE THAT THE ACCURACY OF OUTPUTS DEPENDS ON YOUR INPUTS, AND THAT YOUR USE OF THE SERVICES AND RELIANCE ON ANY OUTPUT IS AT YOUR SOLE RISK. NO SYSTEM CAN BE GUARANTEED 100% SECURE.

Some jurisdictions do not allow the exclusion of certain warranties; in such cases, the above exclusions apply to the maximum extent permitted by Applicable Law.

21. Limitation of Liability

21.1 Exclusion of Indirect Damages

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, GOODWILL, USE, OR DATA, ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

21.2 Cap

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, COVENANT'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES WILL NOT EXCEED THE TOTAL FEES YOU PAID TO COVENANT FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE LIABILITY OR, WHERE NO FEES WERE PAID, ONE HUNDRED U.S. DOLLARS ($100).

21.3 Customer Responsibility Carve-Out

The limitations in this Section operate in addition to, and do not diminish, the allocation of responsibility elsewhere in these Terms. Covenant has no liability whatsoever for loss or damage to the extent arising from (a) inaccurate, incomplete, unlawful, or unethical Customer Data; (b) your use of the Services without required authorization; (c) your violation of the Acceptable Use Policy or export-control/sanctions obligations; or (d) your decisions or actions based on AI Outputs. These matters are your responsibility and, where applicable, are subject to your indemnification obligations in Section 22.

21.4 Basis of the Bargain; Essential Purpose

The limitations in this Section reflect a reasonable allocation of risk, are a fundamental basis of the bargain, and apply regardless of the theory of liability and even if a limited remedy fails of its essential purpose.

21.5 Jurisdictional Variations

Nothing in these Terms excludes or limits liability that cannot be excluded or limited under Applicable Law (such as liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation). Where Applicable Law prohibits any limitation in this Section, that limitation applies only to the extent permitted.

22. Indemnification

You will defend, indemnify, and hold harmless Covenant and its affiliates, and their respective officers, directors, employees, and agents, from and against any third-party claims, and any resulting losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees), arising out of or related to:

  • your Customer Data, including any inaccuracy, misrepresentation, or unlawful content;
  • your use of the Services without required authorization, or your assessment, scanning, testing, or connection of any system you were not authorized to access (Sections 6 and 13);
  • your violation of these Terms, the Acceptable Use Policy, or Applicable Law (including export-control, sanctions, privacy, and anti-corruption laws);
  • your violation of any third-party right; or
  • your use of, or reliance on, any AI Output.

We will give you prompt notice of the claim, reasonable cooperation (at your expense), and sole control of the defense (provided you may not settle in a manner that imposes obligations or admissions on us without our consent).

23. Term, Suspension, and Termination

23.1 Term

These Terms apply for as long as you have an Account or use the Services. Subscriptions continue for their stated period and renew as described in Section 10.

23.2 Termination by You

You may stop using the Services and close your Account at any time through your settings or by contacting legal@corecyber.io. The no-refund policy in Section 10.5 applies on cancellation.

23.3 Suspension or Termination by Covenant

We may suspend or terminate your access immediately, with or without notice, for: violation of these Terms or the Acceptable Use Policy; suspected unauthorized testing, fraud, or security risk; non-payment; access from a prohibited jurisdiction or by a restricted party; or as required by Applicable Law. We may also terminate for convenience on reasonable notice. Except as required by Applicable Law, fees are non-refundable on termination (Section 10.5).

23.4 Effect of Termination

On termination, your license and right to access the Services cease. We will make Customer Data available for export for a limited period and then delete it in accordance with our retention practices and the Privacy Policy/DPA, except as required to be retained by Applicable Law. Provisions that by their nature should survive - including Sections 8, 9, 15, 16, 17, 18, and 20-25 - survive termination.

24. Dispute Resolution; Arbitration; Class Action Waiver

PLEASE READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS, INCLUDING YOUR RIGHT TO SUE IN COURT AND TO A JURY TRIAL. IT DOES NOT APPLY TO THE EXTENT PROHIBITED BY APPLICABLE LAW, AND DOES NOT APPLY TO EEA/UK/SWISS RESIDENTS FOR DISPUTES THAT MANDATORY LOCAL LAW REQUIRES TO BE HEARD IN LOCAL COURTS.

24.1 Informal Resolution

Before initiating mediation or arbitration, the parties will attempt in good faith to resolve any dispute through informal negotiation. Either party may begin this process by written notice describing the dispute; within fifteen (15) business days, representatives with authority to settle will meet (in person, by telephone, or by video conference) to attempt resolution.

24.2 Mediation

If the dispute is not resolved through informal negotiation within thirty (30) days of the initial notice, either party may initiate non-binding mediation administered by the American Arbitration Association (AAA) under its Commercial Mediation Procedures, seated in Sheridan, Wyoming (or by video conference if the parties agree). The parties will share the mediator's fees equally.

24.3 Binding Arbitration

If the dispute is not resolved through mediation within sixty (60) days of the mediation request, either party may initiate final and binding arbitration administered by the AAA under its Commercial Arbitration Rules (or Consumer Arbitration Rules where those apply), before a single arbitrator with expertise in technology and commercial contracts. The seat shall be Sheridan, Wyoming, conducted in English; hearings may be held by video conference. Judgment on the award may be entered in any court of competent jurisdiction.

24.4 Exceptions

Notwithstanding the foregoing: (a) either party may seek injunctive or equitable relief from a court of competent jurisdiction to protect intellectual property or Confidential Information or to prevent unauthorized use of the Services; (b) disputes involving amounts less than Fifty Thousand United States Dollars ($50,000) may, at the electing party's option, be resolved through litigation in the courts identified in Section 25; and (c) either party may bring a qualifying claim in small-claims court.

24.5 Class Action Waiver

YOU AND COVENANT AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING. The arbitrator may not consolidate claims or preside over any class or representative proceeding. This waiver does not apply where prohibited by law.

24.6 Opt-Out

You may opt out of this arbitration agreement by emailing legal@corecyber.io within thirty (30) days of first accepting these Terms, stating your name, account, and intent to opt out. Opting out does not affect any other part of these Terms.

25. Governing Law and Venue

These Terms are governed by the laws of the State of Wyoming, United States, without regard to conflict-of-laws principles, and excluding the U.N. Convention on Contracts for the International Sale of Goods. To the extent litigation is permitted under Section 24, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Sheridan County, Wyoming, except that either party may seek enforcement of an award or judgment in any court of competent jurisdiction. Mandatory consumer- or data-protection rights and venue provisions of your local law continue to apply where Applicable Law so requires.

26. Jurisdiction-Specific and Regional Provisions

Because CoreCyber is a global platform, the following apply where relevant and supplement (and, where mandatory local law requires, override) the foregoing:

  • EU/EEA: the GDPR and the DPA (incorporating EU Standard Contractual Clauses) apply to personal-data processing; mandatory consumer-protection and statutory-warranty rights are unaffected; the EU AI Act's prohibited-practice restrictions apply to AI Outputs.
  • United Kingdom: the UK GDPR, the Data Protection Act 2018, and the UK IDTA/Addendum apply as relevant.
  • United States: applicable state privacy laws (e.g., CCPA/CPRA, Virginia, Colorado) and sector-specific laws apply where relevant; the export-control obligations in Section 18 apply.
  • Other regions (including Canada, Australia, Asia-Pacific, Latin America, and Africa): local data-protection and consumer laws apply where mandatory and prevail over conflicting provisions to the extent required.

Nothing in these Terms deprives a consumer of mandatory protections of the law of their country of residence where such protections apply.

27. General Provisions

27.1 Modifications to the Terms

We may modify these Terms. For material changes we will update the "Last Updated" date, post notice in the Services, and where appropriate notify you by email and/or require acceptance before continued use. Changes take effect as stated in the notice; your continued use after the effective date constitutes acceptance. If you do not agree, you must stop using the Services.

27.2 Force Majeure

Neither party is liable for failure or delay (other than payment obligations) caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, pandemics, government action, cyberattacks on infrastructure, or failures of third-party services or utilities.

27.3 Assignment

You may not assign these Terms without our prior written consent, except to a successor in a merger or sale of substantially all assets that is not a competitor of Covenant and that agrees to be bound. We may assign these Terms to an affiliate or in connection with a corporate transaction. Any non-permitted assignment is void.

27.4 Entire Agreement; Order of Precedence

These Terms, the Privacy Policy, any DPA, and the order/pricing details presented at purchase constitute the entire agreement regarding the Services and supersede prior agreements on the subject matter. If you and Covenant have a separately executed Master Services Agreement covering the same subject matter, that agreement controls to the extent of any conflict for the services it covers.

27.5 Severability; Waiver

If any provision is held unenforceable, it will be modified to the minimum extent necessary or severed, and the remaining provisions remain in effect. No failure or delay in exercising any right is a waiver, and no waiver is effective unless in writing.

27.6 Independent Contractors; No Third-Party Beneficiaries

The parties are independent contractors; nothing creates a partnership, joint venture, agency, or employment relationship. Except for the indemnified parties in Section 22, these Terms confer no rights on third parties.

27.7 Notices

We may provide notices via the Services, email to your Account address, or posting. Notices to us must be sent to legal@corecyber.io and, for formal legal notices, to Covenant Security Solutions International, 30 N. Gould St., STE 9374, Sheridan, Wyoming 82801, USA.

27.8 Language

These Terms are made available in English, Spanish, and French. The English version controls in the event of any conflict, except where Applicable Law requires otherwise.

28. Contact

Questions about these Terms may be sent to:

Covenant Security Solutions International - CoreCyber, 30 N. Gould St., STE 9374, Sheridan, Wyoming 82801, United States. Email: legal@corecyber.io (subject line: "Terms of Service Inquiry").

29. Acknowledgment and Acceptance

BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THESE TERMS OF SERVICE AND THE PRIVACY POLICY.

YOU FURTHER ACKNOWLEDGE THAT (A) THE SERVICES ARE SELF-SERVICE TOOLS WHOSE OUTPUTS DEPEND ON THE ACCURACY OF YOUR INPUTS; (B) YOU ARE SOLELY RESPONSIBLE FOR OBTAINING ALL AUTHORIZATIONS BEFORE ASSESSING, SCANNING, TESTING, OR CONNECTING ANY SYSTEM AND FOR USING THE SERVICES LAWFULLY AND ETHICALLY; AND (C) YOU WILL COMPLY WITH ALL EXPORT-CONTROL AND SANCTIONS RESTRICTIONS, INCLUDING ITAR. IF YOU DO NOT AGREE, YOU MUST NOT ACCESS OR USE THE SERVICES.

© 2026 Covenant Security Solutions International. All rights reserved. CoreCyber is a trademark of Covenant Security Solutions International.