Terms of Service
These Terms govern your use of the website all-secure.co.uk operated by All-Secure Consultancy Ltd (“All-Secure”, “we”, “us”). Our penetration testing, red team and other security services are supplied under a separately agreed Statement of Work (and any Master Services Agreement), which governs those services and takes precedence over these Terms in relation to them.
1. Who we are
All-Secure Consultancy Ltd, a company registered in England & Wales, provides cybersecurity consulting including penetration testing, red team operations, and adversarial security assessments. Contact: [email protected].
2. Order of precedence
Where more than one document applies, the following order of precedence resolves any conflict, highest first:
- the Statement of Work;
- any Master Services Agreement;
- our Data Processing Agreement;
- these Terms of Service;
- our Privacy Policy (an informational notice rather than contractual terms).
3. Eligibility
You must be at least 18 years old and legally able to enter into a contract to use our services. Engagements are offered to organisations, not individuals, unless expressly agreed.
4. Engagement of services and authorisation
Security services are delivered under a Statement of Work. In relation to any engagement:
- Authorisation. The Customer confirms that it owns, controls, or has obtained all necessary authority and permissions to authorise All-Secure to perform the services against all systems, applications, infrastructure and third-party or cloud-hosted assets identified in the Statement of Work, and accepts responsibility for obtaining any permissions required from third parties before testing begins.
- Cooperation. The Customer agrees to provide, in good time, the access, credentials and information reasonably required to perform the services. Delays caused by the Customer may affect the schedule and fees.
- Scope changes. Requests outside the agreed scope may require a revised quotation or Statement of Work before the additional work is carried out.
5. Access to reports and deliverables
We do not provide customer-facing software or accounts. The points below cover the limited access that may pass between us during an engagement.
- Where we give you secure access to your reports or other deliverables (for example a protected download link or one-time credentials), you are responsible for keeping that access confidential and not sharing it outside your organisation.
- Tell us promptly at [email protected] if you believe access to a report or deliverable has been lost or compromised.
- Any systems, credentials or access you provide to us for a test are used solely to carry out the authorised work set out in the relevant statement of work, and are handled in line with that agreement and our Privacy Policy.
6. Acceptable use
You agree not to:
- Use our site or services for any unlawful purpose or in breach of any applicable regulation;
- Attempt to gain unauthorised access to our systems, networks or data;
- Attempt to interfere with, probe, or disrupt our infrastructure without prior written authorisation;
- Reverse engineer, scrape, or resell our website or its content;
- Upload malware or content you don’t have the right to share;
- Impersonate any person or misrepresent your affiliation.
Security testing of All-Secure systems requires explicit written permission. Unauthorised access to, or interference with, our systems is likely to constitute an offence under the Computer Misuse Act 1990 and may be reported to the relevant authorities. Responsible disclosure is welcomed at [email protected].
7. Intellectual property
The site, its content, and our deliverables are our intellectual property or licensed to us. All intellectual property in our methodologies, testing techniques, scripts, templates and reports remains vested in All-Secure. On full payment, the Customer receives a non-exclusive, non-transferable licence to use the engagement deliverables solely for its internal business, audit and compliance purposes, as set out in the relevant Statement of Work.
8. Fees and payment
Services are quoted per engagement at our standard day rate (currently £850 per day, exclusive of VAT) unless otherwise agreed in writing. The number of days is scoped and confirmed in the applicable statement of work, which also sets out payment terms. The public website is provided free of charge.
Expenses. Engagements requiring attendance on-site (for example internal network, physical or social engineering testing) may incur reasonable travel, accommodation and subsistence costs. Where applicable these are agreed in advance and recharged at cost, in addition to the day rate.
Free retest. The complimentary retest applies to UK-based engagements only. Where included, each engagement provides one complimentary retest of the findings rated critical or high in the report, provided it is requested within 30 days of report delivery. The free retest is limited to one retest per engagement and to those critical and high findings; it is delivered remotely and does not include any on-site attendance or associated expenses, which, if required, are quoted separately. Re-testing of medium or lower findings, repeat retests, or testing of new or changed systems is treated as a new engagement. The Customer must confirm that the reported vulnerability has been remediated before a complimentary retest is performed. Engagements based outside the UK do not include a complimentary retest unless expressly agreed in writing.
9. Confidentiality
We handle all client information as confidential and do not publish engagement details, client names, or findings without prior written consent. Confidentiality obligations are governed by the Statement of Work, any applicable non-disclosure agreement, or, where none exists, by the confidentiality terms in our engagement documentation.
10. Reporting
Our reports represent our professional opinion based on the evidence observed during the agreed testing window. They describe findings observable at that time and do not guarantee the absence of other vulnerabilities, nor the future security of the tested systems.
11. Disclaimers and website
The website is provided “as is” without warranties of any kind. Although we make reasonable efforts to keep website content accurate, it is provided for general information only and is not professional advice. We do not guarantee uninterrupted availability of the website and may suspend access for maintenance or security reasons. We are not responsible for third-party websites linked from this site.
12. Limitation of liability
To the maximum extent permitted by law, All-Secure shall not be liable for indirect, incidental, or consequential losses arising from use of the website. Liability under a paid engagement is capped as set out in the applicable statement of work. The limitations in this clause do not affect any liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, or for fraud.
13. Force majeure
We shall not be liable for any delay or failure to perform caused by events beyond our reasonable control, including internet or power outages, cyber attacks, industrial action, or acts of God.
14. Termination
We may suspend or terminate access if these Terms are breached, or if we are required to do so by law. You may stop using the site at any time. Termination does not affect any rights or obligations accrued before it. Sections that by their nature should survive (IP, confidentiality, liability) will do so.
15. Changes
We may update these Terms. Material changes will be posted here with a revised “last updated” date. Continued use of the website after revised Terms are posted constitutes acceptance.
16. Governing law
These Terms are governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the English courts.
17. Contact
All-Secure Consultancy Ltd
Registered in England & Wales, Company No. 17276857
Registered office: 128 City Road, London, EC1V 2NX
[email protected]