Aegis — Terms of Service

Prepared as a technically-accurate starting point describing what the service actually does. A qualified lawyer in your jurisdiction (Ontario/Canada, plus any customer jurisdictions you sell into) must review and adapt this before it takes effect. Bracketed items [LIKE THIS] are decisions only you or your counsel can make.

Provider: Backbone Solutions Ltd. ("Backbone", "we", "us") Service: Aegis automated security testing platform ("Aegis", "the Service") Effective date: [DATE] · Version: [1.0]


1. Agreement

By creating an account, you agree to these Terms, the Acceptable Use Policy and the Rules of Engagement, which together form the agreement between you and Backbone. If you are agreeing on behalf of an organisation, you confirm you are authorised to bind it.

2. What the Service is

Aegis performs automated security testing against targets you nominate and prove you control. It produces reports describing what its automated checks observed.

Aegis is not a manual penetration test performed by human security consultants. It does not replicate the creativity, intuition or context-specific reasoning of a skilled human tester.

3. Your authorisation and ownership of targets — the central obligation

You may only submit a target that you own or are expressly authorised in writing to test.

Before any test runs you must: 1. prove control of the target domain via the DNS verification we issue; 2. accept the Rules of Engagement for the tier you have selected; 3. confirm you have complied with your hosting, cloud and CDN providers' policies.

Testing computer systems without authorisation is a criminal offence in most jurisdictions (in Canada, s.342.1 of the Criminal Code; comparable provisions exist elsewhere, e.g. the US Computer Fraud and Abuse Act and the UK Computer Misuse Act). You are solely responsible for ensuring you hold the necessary authority. You indemnify Backbone against any claim arising from your submission of a target you were not authorised to test.

DNS verification proves control of a domain. It does not prove you are authorised by every party with an interest in the underlying systems (for example a hosting provider, a landlord of shared infrastructure, or a client whose data you process). That remains yours to establish.

4. Accounts

You are responsible for your credentials and for all activity under your account. Notify us promptly of any suspected compromise. We may suspend an account we reasonably believe is being used in breach of this agreement or unlawfully.

5. Service tiers and inherent risk

Tier Nature Constraint
Baseline Unauthenticated, non-destructive, low rate Permitted against production
Authenticated Signs in with credentials you supply; non-destructive Permitted against production
Aggressive assurance State-changing; writes data Non-production targets only

Security testing sends real network traffic to real systems. Even non-destructive testing may surface latent faults, trigger rate limiting, generate alerts, fill logs or cause unexpected application behaviour. Aggressive testing modifies data by design.

You are responsible for: maintaining backups; having a rollback plan; selecting an appropriate testing window; nominating a contact reachable during testing; and ensuring the target is appropriate for the tier selected. An emergency stop control is provided and it is your responsibility to use it if you observe adverse effects.

6. Fees

Fees are as published at sign-up. Subscriptions renew automatically for successive periods until cancelled. [REFUND POLICY — e.g. no refunds for partial periods; 14-day cooling-off where required by consumer law]. Taxes are additional where applicable. We may change pricing on [30] days' notice, effective at your next renewal.

7. Your data and our confidentiality

You retain ownership of your data, findings and reports. We store them encrypted, scoped to your workspace, and redact evidence server-side before storage. We will not disclose your findings to third parties except as required by law or as you direct. See the Privacy Policy [LINK] and Data Processing Agreement [LINK].

You may export or delete your data at any time. On termination we delete or return your data within [30] days, save for backups purged on their ordinary cycle and records we must retain by law.

We may use aggregated, anonymised statistics that do not identify you or your systems to improve the Service.

8. Reports are not certifications

Reports support a defensible security process and may be shared with your auditors and customers under confidentiality. They are not a certification against SOC 2, ISO 27001, PCI DSS or any other standard, and are not legal advice. Whether a report satisfies a particular obligation is a matter for your auditor or regulator.

9. No warranty — and what a clean report means

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT, TO THE MAXIMUM EXTENT PERMITTED BY LAW.

We expressly do not warrant that the Service will identify all vulnerabilities. No automated testing can prove the absence of vulnerabilities. A report containing no findings means the checks performed did not detect an issue — it does not mean your systems are secure. You must not represent to any third party that Aegis certifies your security.

10. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, BACKBONE IS NOT LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, NOR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS INTERRUPTION OR SYSTEM DOWNTIME, HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY.

BACKBONE'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT IS LIMITED TO THE FEES YOU PAID FOR THE SERVICE IN THE [TWELVE (12)] MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

Nothing limits liability that cannot be limited by law (including fraud, or death or personal injury caused by negligence). [COUNSEL: consumer-protection statutes may override these limits for non-business customers; consider a business-customers-only restriction.]

11. Indemnity

You will indemnify and hold harmless Backbone against claims, losses and reasonable legal costs arising from: (a) testing a target you were not authorised to test; (b) your breach of this agreement or the Acceptable Use Policy; (c) your failure to comply with a provider policy or applicable law; or (d) your use or distribution of a report.

12. Suspension and termination

You may cancel at any time, effective at the end of the current period. We may suspend immediately where we reasonably believe unauthorised testing is occurring, where the Service is being used unlawfully, or where testing threatens the stability of third-party infrastructure. We may terminate for material breach not cured within [14] days.

13. Changes

We may amend these Terms on [30] days' notice for material changes. Continued use after the effective date constitutes acceptance.

14. Governing law

Governed by the laws of [Ontario, Canada], with exclusive jurisdiction in the courts of [Ontario]. [COUNSEL: consider arbitration and a class-action waiver where enforceable.]

15. Contact

[legal@backbonesolutions.ca] · Backbone Solutions Ltd., [REGISTERED ADDRESS]