Terms of use
The terms for this website. Engagements have their own.
Last updated September 2026. These terms cover your use of cyentrix.com, including the free tools. Any paid work — a cyber review or an ITGC audit — is governed by the written scope you approve before it starts, which takes precedence over this page.
1. Who we are and what this covers
Cyentrix provides security services to companies. This website describes those services and offers some free tools: a free external exposure review and free self-assessments. By using the site you agree to these terms. If you do not agree, please do not use it.
2. The free tools
The self-assessments produce a score and guidance from the answers you give; they are a directional read, not an audit. The free exposure review is a limited external look at what is publicly visible about the domain you nominate, carried out only where you confirm you are authorised to ask for it. Both are provided as-is, free of charge, with no warranty and no obligation on either side to go further.
3. Paid engagements
Every paid engagement starts with a written scope (or statement of work) that sets out the targets, the testing window, what is in and out of bounds, deliverables, fees, confidentiality and data retention. Nothing starts until you approve it in writing. Where these website terms and a written scope differ, the written scope applies to that engagement. We will sign your NDA or provide ours before scoping if you prefer.
4. Not professional advice; no certification
Website content, self-assessment results and the free exposure review are informational and do not constitute legal, regulatory, insurance or audit advice. Cyentrix does not issue SOC 2, ISO 27001 or any other certificate or attestation; those come from the relevant accredited body. Where we say a finding is verified, we mean we reproduced it with evidence at the time of testing; security posture changes, and a clean result is not a guarantee against future compromise.
5. Authorisation
You may only ask us to look at, test or assess systems you own or are authorised to have tested. By submitting a domain or a target list you confirm that authorisation. We will stop and tell you if anything suggests otherwise.
6. Acceptable use of the site
Do not do anything illegal, malicious or destructive with this site. Do not scrape it at volume, attempt to compromise it, or use it to attack others. Do not pretend to be us. Security researchers are welcome to report issues responsibly — see Security & data handling.
7. Your content
Comments and anything else you submit to the site remain yours. By submitting, you grant Cyentrix a non-exclusive licence to display, store and moderate that content as part of the site. Material shared during an engagement is confidential and governed by the written scope, not by this clause.
8. Intellectual property
The site, its text, design and the Cyentrix name and logo are ours. Reports and evidence packs we deliver under an engagement are yours to use for your business, including sharing with buyers, insurers and auditors; you may not resell them or present them as your own testing.
9. Liability
To the maximum extent permitted by law, Cyentrix is not liable for indirect, incidental or consequential losses arising from your use of this website or the free tools, including decisions made on the basis of self-assessment results or a free review. Liability for paid engagements is set out in the written scope.
10. Changes
We may update these terms; the date at the top reflects the current version. Continuing to use the site after a change means you accept the updated terms. Changes to these website terms never alter a scope you have already approved.