Terms of Service
Last Updated: October 6, 2026
These Terms of Service constitute a legally binding agreement made between you, whether personally or on behalf of an entity ("you," "Customer," or "Client") and TESSA Security ("we," "us," "our," "Company," or "Provider"), concerning your access to and use of the https://tessa-sec.com website and any services purchased or subscribed to through the Site (collectively, the "Services").
By accessing the Site or subscribing to any Services (including but not limited to SOC-as-a-Service, penetration testing, continuous penetration testing, security audits, compliance advisory, or consulting services), you agree that you have read, understood, and agree to be bound by all of these Terms of Service. If you do not agree with all of these terms, then you are expressly prohibited from using the Site and Services and you must discontinue use immediately.
1. INTELLECTUAL PROPERTY RIGHTS
Unless otherwise indicated, the Site and Services are our proprietary property and all source code, databases, functionality, software, website designs, audio, video, text, photographs, graphics, monitoring tools, security intelligence, reports, and logos on the Site (collectively, the "Content") and the trademarks, service marks, and logos contained therein (the "Marks") are owned or controlled by us or licensed to us, and are protected by copyright and trademark laws and various other intellectual property rights.
The Content and Marks are provided on the Site and through the Services "AS IS" for your information and personal use only. No part of the Site, Services, or Content may be copied, reproduced, republished, transmitted, distributed, sold, licensed, or otherwise exploited for any commercial purpose whatsoever, without our express prior written permission.
2. USER REPRESENTATIONS
By using the Site and Services, you represent and warrant that:
- ›All registration information you submit will be true, accurate, current, and complete
- ›You will maintain the accuracy of such information and promptly update it as necessary
- ›You have the legal capacity and authority to agree to comply with these Terms of Service
- ›You are not a minor in the jurisdiction in which you reside
- ›You will not access the Site or Services through automated or non-human means, whether through a bot, script, or otherwise
- ›You will not use the Site or Services for any illegal or unauthorized purpose
- ›Your use of the Site and Services will not violate any applicable law or regulation
- ›If subscribing on behalf of an organization, you have the authority to bind that organization to these terms
3. SUBSCRIPTION SERVICES
3.1 SOC-as-a-Service Agreements
Our SOC-as-a-Service is provided under a Master Services Agreement (MSA) or specific Service Order. By engaging our services:
- ›Service Term: The initial term and renewal conditions are defined in your specific Service Agreement
- ›Service Levels: Service Level Agreements (SLAs), including monitoring scope and response times, are detailed in your contract
- ›Contract Signing: Services commence upon the execution of a Service Agreement, typically via electronic signature (DocuSign)
- ›Monitoring Starts: 24/7 security monitoring begins upon completion of the onboarding and integration phase
3.2 Payment Terms
Payment terms are governed by your Service Agreement/Invoice. Generally:
- ›Invoicing: Services are invoiced in advance on a monthly or annual basis as agreed
- ›Payment Methods: We accept payments via bank transfer (ACH/Wire) and major credit cards
- ›Taxes: You are responsible for all applicable taxes and duties
- ›Late Payments: Overdue payments may result in service suspension and/or interest charges as permitted by law
3.3 Penetration Testing Engagements
Penetration testing services are delivered under a scoped Statement of Work (SOW). By engaging this service:
- ›Authorized Scope: Testing is strictly limited to the systems, IP ranges, URLs, and applications explicitly defined in the agreed SOW. Testing outside this scope is prohibited
- ›Authorization Letter: You must provide written authorization confirming you own or have permission to test the in-scope systems before testing commences
- ›Rules of Engagement: Testing windows, blackout periods, and emergency stop procedures are agreed in advance and must be adhered to by both parties
- ›Report Delivery: A detailed findings report with risk ratings and remediation guidance will be delivered within the timeframe agreed in the SOW
- ›Confidentiality: All test findings, vulnerability details, and exploit data are strictly confidential and will not be disclosed to third parties
3.4 Continuous Penetration Testing
Continuous penetration testing services leverage automated platforms (e.g., RidgeBot, NodeZero, Pentera, Cymulate) on an ongoing subscription basis:
- ›Ongoing Authorization: Your subscription constitutes standing authorization for automated security testing within the agreed scope for the duration of the contract
- ›Platform Access: You may be granted access to a testing platform dashboard; credentials are personal and must not be shared
- ›Scope Changes: Changes to the testing scope must be submitted in writing and take effect after written confirmation from TESSA Security
- ›Remediation Responsibility: You are solely responsible for acting on identified vulnerabilities. TESSA Security is not liable for damages arising from unresolved findings
3.5 Compliance Advisory & Security Audits (DORA, NIS2, ISO 27001)
Compliance advisory and audit services are advisory in nature and subject to the following terms:
- ›Advisory Nature: Compliance assessments and gap analyses are advisory only. TESSA Security does not act as a formal certification body and cannot guarantee regulatory approval or certification outcomes
- ›Client Cooperation: You agree to provide accurate, complete documentation and access required for the audit or assessment in a timely manner
- ›Regulatory Changes: TESSA Security will endeavor to keep guidance current, but is not liable for changes in regulatory requirements that occur after delivery of services
- ›Confidentiality: All audit findings, gap analyses, and compliance documentation shared during the engagement are treated as strictly confidential
3.6 Cybersecurity Consulting & vCISO Services
Consulting engagements, including virtual CISO (vCISO) services, are governed by the following:
- ›Engagement Scope: The scope, deliverables, and timeline for consulting engagements are defined in a mutually agreed Statement of Work or consulting agreement
- ›Advisory Role: Our consultants provide strategic recommendations and guidance. Final implementation decisions and responsibility remain with your organization
- ›Intellectual Property: Deliverables (roadmaps, policies, frameworks) produced specifically for you become your property upon full payment; methodologies and tools remain our IP
- ›Personnel: We reserve the right to assign qualified personnel to your engagement. Named resource requests are subject to availability and must be specified in the SOW
3.7 Cancellation and Termination
- ›Cancellation: You may cancel services by providing written notice as specified in your Service Agreement (typically 30 or 60 days prior to renewal)
- ›No Refunds: Fees paid for the current service period are non-refundable unless otherwise stated in your agreement
- ›Service Termination: We reserve the right to suspend or terminate services for material breach of terms, non-payment, or illegal activities
4. PROHIBITED ACTIVITIES
You may not access or use the Site or Services for any purpose other than that for which we make them available. Prohibited activities include, but are not limited to:
- ›Attempting to bypass, disable, or interfere with security features of the Services
- ›Engaging in unauthorized framing of or linking to the Site
- ›Uploading or transmitting viruses, malware, or any other malicious code
- ›Engaging in any automated use of the system, such as scraping or data harvesting
- ›Attempting to impersonate another user or person
- ›Using the Services to violate any laws or regulations
- ›Interfering with, disrupting, or creating an undue burden on the Services
- ›Attempting to gain unauthorized access to other customers' data or accounts
5. SERVICE LEVEL AGREEMENT (SLA)
For SOC-as-a-Service subscriptions:
- ›Uptime: We guarantee 99.9% service uptime, excluding scheduled maintenance
- ›Response Time: Critical security alerts will receive an initial response within 5 minutes for Growth and Enterprise plans, and within 15 minutes for Starter plans
- ›Incident Response: Full incident response times vary by plan tier as specified in your Service Agreement
- ›SLA Credits: If we fail to meet the uptime guarantee, you may be eligible for service credits as outlined in your specific Service Agreement
6. DATA OWNERSHIP AND CONFIDENTIALITY
- ›Your Data: You retain all ownership rights to the data you provide to us and the data we collect on your behalf through monitoring Services. We will not access, use, or disclose your data except as necessary to provide the Services or as required by law
- ›Security Logs and Reports: All security event logs, incident reports, and analytics generated by our Services remain your property. We may use anonymized, aggregated data for improving our Services and threat intelligence
- ›Confidentiality: Both parties agree to maintain the confidentiality of any confidential information disclosed during the course of the Services
7. THIRD-PARTY SERVICES
Our Services may integrate with or rely on third-party services including but not limited to:
- ›Stripe: For payment processing
- ›DocuSign: For electronic contract signing
- ›Security Tools: Various SIEM, EDR, and security platforms (including RidgeBot, NodeZero, Pentera, Cymulate for continuous pen testing) as outlined in your Service Agreement
Your use of third-party services is governed by their respective terms of service and privacy policies. We are not responsible for the actions, policies, or practices of any third-party services.
8. DISCLAIMER OF WARRANTIES
THE SITE AND SERVICES ARE PROVIDED ON AN "AS-IS" AND "AS-AVAILABLE" BASIS. YOU AGREE THAT YOUR USE OF THE SITE AND SERVICES WILL BE AT YOUR SOLE RISK. TO THE FULLEST EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, IN CONNECTION WITH THE SITE, SERVICES, AND YOUR USE THEREOF.
While we strive to provide comprehensive security monitoring and threat detection, we make no warranties that:
- ›The Services will detect all security threats or vulnerabilities
- ›The Services will prevent all security breaches or incidents
- ›The Services will meet all your specific security requirements
- ›The Services will be uninterrupted, secure, or error-free
The information and services provided are for cybersecurity monitoring and advisory purposes only. You are responsible for implementing appropriate security controls and making final decisions regarding your security posture.
9. LIMITATION OF LIABILITY
TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT SHALL TESSA SECURITY, ITS DIRECTORS, EMPLOYEES, PARTNERS, AGENTS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR:
- ›Any indirect, incidental, special, consequential, or punitive damages
- ›Any loss of profits, revenue, data, or use
- ›Any damage resulting from security breaches, cyberattacks, or unauthorized access to your systems
- ›Any other loss arising out of or related to your use of or inability to use the Services
Whether based on warranty, contract, tort (including negligence), product liability, or any other legal theory, even if we have been advised of the possibility of such damages.
Our total liability to you for all claims arising out of or related to these Terms or the Services shall not exceed the amount you paid to us in the 12 months preceding the event giving rise to liability, or $100, whichever is greater.
10. INDEMNIFICATION
You agree to defend, indemnify, and hold us harmless, including our subsidiaries, affiliates, and all of our respective officers, agents, partners, and employees, from and against any loss, damage, liability, claim, or demand, including reasonable attorneys' fees, made by any third party due to or arising out of:
- ›Your use of the Site or Services
- ›Breach of these Terms of Service
- ›Any breach of your representations and warranties
- ›Your violation of the rights of a third party
- ›Your violation of any law or regulation
11. TERMINATION
These Terms of Service shall remain in full force and effect while you use the Site or maintain an active subscription to our Services. We reserve the right to:
- ›Suspend or terminate your access to the Site and Services immediately, without prior notice or liability, for any reason, including breach of these Terms
- ›Terminate subscriptions for non-payment after reasonable notice
- ›Refuse service to anyone for any reason at any time
Upon termination, your right to use the Services will immediately cease. All provisions of these Terms which by their nature should survive termination shall survive, including ownership provisions, warranty disclaimers, indemnity, and limitations of liability.
12. CHANGES TO TERMS
We reserve the right to modify or replace these Terms of Service at any time at our sole discretion. Material changes will be notified to active subscribers via email at least 30 days prior to the effective date. Your continued use of the Site or Services after such modifications constitutes acceptance of the updated terms.
13. GOVERNING LAW AND DISPUTE RESOLUTION
These Terms of Service are governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law principles.
Any disputes arising out of or relating to these Terms or the Services shall be resolved through:
- ›Informal Negotiation: First, by contacting us to seek an amicable resolution
- ›Binding Arbitration: If informal resolution fails, disputes shall be resolved by binding arbitration in accordance with the rules of the American Arbitration Association
- ›Class Action Waiver: You agree to resolve disputes on an individual basis and waive any right to participate in a class action lawsuit
14. CONTACT INFORMATION
To resolve a complaint regarding the Site or Services, or to receive further information, please contact us: