//Legal
Terms of Service
Last updated: 9 August 2026
These terms govern your use of this website and set out the general basis on which Theosec (Pty) Ltd ("Theosec", "we", "us") provides professional services. They are not themselves an engagement contract.
1. These terms and your engagement contract
Any engagement is governed by a separate written contract — including a statement of work, rules of engagement, and a mutual non-disclosure agreement — signed by both parties. Where these terms conflict with a signed engagement contract, the engagement contract prevails.
2. Website content
The content of this website is provided for general information about our services. It does not constitute security, legal or compliance advice, and should not be relied upon as such. Descriptions of services are indicative; actual scope is defined in the statement of work for each engagement.
3. Authorisation is a precondition
Security testing is only lawful with the authorisation of the party entitled to give it. Accordingly:
- we require signed written authorisation identifying the systems in scope before any testing activity begins, without exception;
- you warrant that you own the in-scope systems or are otherwise authorised to commission testing against them, including obtaining any necessary permission from hosting providers or third parties;
- we will decline or immediately suspend any engagement where authorisation is absent, unclear, or appears to have been given without authority.
Requesting testing against systems you do not control or are not authorised to test may constitute a criminal offence, including under the Cybercrimes Act 19 of 2020 in South Africa and equivalent legislation elsewhere.
4. Nature of security testing
You should understand and accept the following before commissioning any engagement:
- No assurance of completeness. Testing is conducted within an agreed scope and timeframe. The absence of a finding is not evidence that a vulnerability does not exist, and no engagement can guarantee that all vulnerabilities have been identified.
- Point-in-time validity. Findings reflect the state of systems during the testing window. Subsequent changes may introduce new vulnerabilities.
- Inherent risk of disruption. Active testing carries an inherent risk of service disruption, performance degradation or unexpected system behaviour. We take reasonable care to minimise this and agree testing windows in advance, but the risk cannot be eliminated entirely. You are responsible for maintaining current backups.
- No guarantee of compliance. Our reports may support your compliance obligations, but we do not certify compliance with any standard or regulation.
5. Reports and intellectual property
On full payment, you receive ownership of the report produced for your engagement. We retain ownership of our underlying methodologies, tools, templates and know-how, and of any general knowledge or skill acquired during the engagement.
Reports are prepared for you and for your stated purpose. They should not be republished, distributed publicly, or relied upon by third parties without our prior written consent.
6. Confidentiality
Both parties treat information disclosed during an engagement as confidential. We do not disclose your identity as a client, publish your logo, or reference your findings — including in anonymised form — without your express written permission. Specific confidentiality obligations are set out in the mutual non-disclosure agreement signed before scoping.
7. Your responsibilities
- provide accurate scope information, including any systems that must be excluded from testing;
- notify relevant internal teams and third-party providers where required;
- maintain current, tested backups of in-scope systems;
- nominate a point of contact who is reachable during agreed testing windows;
- act on findings — we identify and explain risk, but remediation remains your responsibility.
8. Fees
Fees, payment terms and any expenses are set out in the applicable statement of work. Complimentary offerings — including the Reconnaissance Briefing — are provided at our discretion, carry no contractual service commitment, and may be declined or withdrawn.
9. Limitation of liability
Nothing in these terms excludes or limits liability where such exclusion is not permitted by law, including liability for death or personal injury caused by negligence, or for fraud.
Subject to that, and except where a signed engagement contract provides otherwise: we are not liable for indirect, incidental, special or consequential loss, including loss of profits, revenue, data, anticipated savings, or business interruption; and our total aggregate liability arising from an engagement is limited to the fees paid by you for that engagement.
We are not liable for loss arising from your failure to act on findings, from vulnerabilities outside the agreed scope, or from changes made to systems after the testing window.
10. Governing law
These terms are governed by the laws of the Republic of South Africa, and the parties submit to the jurisdiction of the South African courts. An engagement contract may specify a different governing law or forum, in which case that contract prevails.
11. Changes
We may amend these terms at any time by posting an updated version on this page. Amendments do not affect engagements already contracted.
12. Contact
Questions about these terms can be sent to daniel@theosec.com.