1. Scope and definitions
These terms apply to every quote, agreement and delivery by Chain Cybersecurity (KvK 96165278, Setheweg 8, 7942 LB Meppel, Netherlands), referred to below as "we" or "us". The other party is referred to as "the client".
Our services are offered to organisations acting in a professional or business capacity. We do not offer services to consumers.
- Engagement — the specific piece of work described in a signed quote, statement of work or order confirmation.
- Deliverable — any report, roadmap, policy, dashboard, training material or other output we provide.
- Testing — any activity in which we actively probe systems, people or processes, including penetration testing, red teaming and simulated phishing.
The client's own purchasing terms do not apply and are expressly rejected, unless we accept them in writing. Where these terms conflict with a signed engagement document, the engagement document prevails.
2. Quotes and formation of an agreement
- Quotes are valid for 30 days unless stated otherwise and are based on the information available to us at the time.
- An agreement is formed when the client accepts a quote in writing, including by email, or when we begin work at the client's request.
- Obvious errors in a quote do not bind us.
- Estimates of effort are estimates. Where scope changes materially, we will agree a revised quote before continuing.
3. The services
We perform each engagement to the standard of a competent professional in our field, using recognised methodologies. Our obligation is one of effort and diligence, not of achieving a specific result, unless a result is explicitly agreed in writing.
We may engage qualified subcontractors. These terms apply equally to their work, and we remain the client's counterparty.
Advisory output is based on the environment, documentation and information available during the engagement. Findings describe a point in time; environments and threats change.
4. Authorisation for security testing
We do not test anything without written authorisation. Before any testing begins, the client must sign a scope and rules-of-engagement document confirming that the client owns the systems in scope or has obtained the owner's written permission, and naming the people authorised to approve and to stop the work.
- The client warrants that it is entitled to authorise testing of everything in scope, including assets hosted by third parties such as cloud, hosting or SaaS providers, and that any required provider notifications or permissions are in place.
- Testing carries inherent risk. Although we work cautiously and exclude destructive techniques unless expressly authorised, testing can cause degraded performance or interruption. The client is responsible for backups and for a rollback plan.
- Either party may pause testing immediately. Contact details for out-of-hours escalation are agreed before work starts.
- We report critical findings to the client's named contact as soon as we confirm them, rather than holding them for the final report.
- If the client authorises testing it was not entitled to authorise, the client indemnifies us against resulting third-party claims.
5. What we need from you
- Timely, complete and accurate information, access and credentials as agreed.
- A named contact empowered to make decisions during the engagement.
- Any internal approvals, staff notifications or works-council consultation your organisation requires — particularly for awareness programmes and simulations involving employees.
- A safe and lawful working environment for any work performed on site.
Where delay or missing information is attributable to the client, agreed timelines shift accordingly and we may charge for reasonable standby time at the agreed rate.
6. Fees, invoicing and payment
- Fees are stated excluding VAT and excluding travel, accommodation and third-party costs unless the quote says otherwise.
- Fixed-scope engagements are invoiced 50% on commencement and 50% on delivery. Recurring services are invoiced monthly in advance. Work performed on a time basis is invoiced monthly in arrears.
- Invoices are payable within 14 days of the invoice date.
- If an invoice is not paid on time, statutory commercial interest under Article 6:119a of the Dutch Civil Code and reasonable collection costs become due, and we may suspend work after written notice.
- The client may not set off or withhold payment on the basis of a disputed item without our written agreement.
- Rates may be adjusted once per calendar year with two months' notice. For adjustments above inflation the client may terminate recurring services with effect from the adjustment date.
7. Confidentiality
Each party keeps the other's confidential information confidential, uses it only for the engagement, and protects it with at least the care it applies to its own confidential information. This obligation continues indefinitely after the engagement ends. Where a separate non-disclosure agreement exists, that agreement prevails.
Vulnerability details, findings and evidence relating to the client's environment are treated as strictly confidential and are never disclosed to third parties or used in marketing. We may reference the engagement in anonymised, non-attributable form only, and will only name the client as a reference with prior written permission.
Disclosure is permitted where required by law or by a competent authority. Where we may lawfully do so, we will inform the client first.
8. Intellectual property and deliverables
- We retain all intellectual property in our methodologies, tools, templates, training content and know-how.
- On full payment, the client receives a perpetual, non-exclusive licence to use the deliverables for its own internal purposes.
- Deliverables may not be published, resold, or provided to third parties as assurance about the client's security posture without our written permission. Sharing a report with the client's auditor, insurer or a specific customer under confidentiality is permitted.
- Reports must be shared in full, not in extracts that change their meaning.
- We may use anonymised, aggregated data about threats and trends to improve our services.
9. No guarantee of absolute security
Security work reduces risk; it cannot eliminate it. We do not warrant that an assessment identifies every vulnerability, that recommendations will prevent every incident, or that systems are or will remain free of compromise. A clean report is evidence of what was found within the agreed scope, time and method — not a certificate of invulnerability.
We do not issue certifications. Where an engagement supports certification or attestation, the decision rests with the accredited body concerned.
10. Liability
- Our total liability per engagement is limited to the fees the client paid for that engagement in the 12 months preceding the event, up to a maximum of EUR 50,000.
- We are not liable for indirect or consequential loss, including lost profit, lost savings, business interruption, loss of goodwill, or loss or corruption of data, except where caused by our intent or deliberate recklessness.
- We are not liable for damage arising from information the client provided that was incorrect or incomplete, from the client's decision not to implement a recommendation, or from an incident caused by a third party.
- A claim lapses unless it is notified to us in writing within 12 months of the client becoming aware of the damage.
- Nothing in these terms limits liability that cannot be limited under Dutch law.
11. Force majeure
Neither party is liable for failure to perform caused by circumstances beyond its reasonable control, including a cyber attack on its own infrastructure, failure of a critical supplier, power or network outage, government measures, or illness of key personnel. Where force majeure lasts longer than 60 days, either party may terminate the affected engagement in writing, and we will invoice work already performed.
12. Duration and termination
- Fixed-scope engagements end on delivery. Recurring services run for the agreed term and renew for the same term unless cancelled with one month's written notice before the renewal date.
- Either party may terminate immediately in writing if the other materially breaches these terms and fails to remedy the breach within 30 days of notice, or on insolvency or suspension of payments.
- We may terminate immediately if continuing would require us to act unlawfully or unethically, or if the client withdraws authorisation necessary for the work.
- On termination, work performed up to that point is payable.
13. Personal data
Where we process personal data on the client's behalf — for example participant data in an awareness programme, or data encountered during incident response — we act as processor and the parties enter into a data processing agreement before that processing begins. Our own processing as a controller is described in our privacy statement.
14. Use of this website
- The content of this website is general information, not advice for a specific situation, and creates no client relationship.
- Figures shown in illustrative dashboards and sample reports are examples, not client data or a promise of results.
- You may not scrape the site at volume, attempt to disrupt it, or use it to distribute unlawful content. Security researchers are welcome — please follow our responsible disclosure policy.
- We may change or withdraw website content at any time.
15. Complaints
Tell us within 30 days of noticing a problem, at support@chainsecurities.org, describing the issue and the outcome you are looking for. We acknowledge within 5 business days and aim to resolve within 30 days. Submitting a complaint does not suspend payment obligations.
16. Governing law and disputes
These terms and every agreement to which they apply are governed by Dutch law. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Disputes we cannot resolve between us are submitted to the competent court of Rechtbank Noord-Nederland, without prejudice to our right to bring proceedings before the court with jurisdiction over the client's registered seat.
If any provision is or becomes invalid, the remainder stays in force and the parties will replace the invalid provision with one that matches its purpose as closely as possible.