Aegis — Terms of Service
Prepared as a technically-accurate starting point describing what the service actually
does. A qualified lawyer in your jurisdiction (Ontario/Canada, plus any customer
jurisdictions you sell into) must review and adapt this before it takes effect. Bracketed
items [LIKE THIS] are decisions only you or your counsel can make.
Provider: Backbone Solutions Ltd. ("Backbone", "we", "us")
Service: Aegis automated security testing platform ("Aegis", "the Service")
Effective date: [DATE] · Version: [1.0]
1. Agreement
By creating an account, you agree to these Terms, the Acceptable Use Policy and the Rules of Engagement, which together form the agreement between you and Backbone. If you are agreeing on behalf of an organisation, you confirm you are authorised to bind it.
2. What the Service is
Aegis performs automated security testing against targets you nominate and prove you control. It produces reports describing what its automated checks observed.
Aegis is not a manual penetration test performed by human security consultants. It does not replicate the creativity, intuition or context-specific reasoning of a skilled human tester.
3. Your authorisation and ownership of targets — the central obligation
You may only submit a target that you own or are expressly authorised in writing to test.
Before any test runs you must: 1. prove control of the target domain via the DNS verification we issue; 2. accept the Rules of Engagement for the tier you have selected; 3. confirm you have complied with your hosting, cloud and CDN providers' policies.
Testing computer systems without authorisation is a criminal offence in most jurisdictions (in Canada, s.342.1 of the Criminal Code; comparable provisions exist elsewhere, e.g. the US Computer Fraud and Abuse Act and the UK Computer Misuse Act). You are solely responsible for ensuring you hold the necessary authority. You indemnify Backbone against any claim arising from your submission of a target you were not authorised to test.
DNS verification proves control of a domain. It does not prove you are authorised by every party with an interest in the underlying systems (for example a hosting provider, a landlord of shared infrastructure, or a client whose data you process). That remains yours to establish.
4. Accounts
You are responsible for your credentials and for all activity under your account. Notify us promptly of any suspected compromise. We may suspend an account we reasonably believe is being used in breach of this agreement or unlawfully.
5. Service tiers and inherent risk
| Tier | Nature | Constraint |
|---|---|---|
| Baseline | Unauthenticated, non-destructive, low rate | Permitted against production |
| Authenticated | Signs in with credentials you supply; non-destructive | Permitted against production |
| Aggressive assurance | State-changing; writes data | Non-production targets only |
Security testing sends real network traffic to real systems. Even non-destructive testing may surface latent faults, trigger rate limiting, generate alerts, fill logs or cause unexpected application behaviour. Aggressive testing modifies data by design.
You are responsible for: maintaining backups; having a rollback plan; selecting an appropriate testing window; nominating a contact reachable during testing; and ensuring the target is appropriate for the tier selected. An emergency stop control is provided and it is your responsibility to use it if you observe adverse effects.
6. Fees
Fees are as published at sign-up. Subscriptions renew automatically for successive periods
until cancelled. [REFUND POLICY — e.g. no refunds for partial periods; 14-day cooling-off
where required by consumer law]. Taxes are additional where applicable. We may change
pricing on [30] days' notice, effective at your next renewal.
7. Your data and our confidentiality
You retain ownership of your data, findings and reports. We store them encrypted, scoped to
your workspace, and redact evidence server-side before storage. We will not disclose your
findings to third parties except as required by law or as you direct. See the Privacy
Policy [LINK] and Data Processing Agreement [LINK].
You may export or delete your data at any time. On termination we delete or return your
data within [30] days, save for backups purged on their ordinary cycle and records we must
retain by law.
We may use aggregated, anonymised statistics that do not identify you or your systems to improve the Service.
8. Reports are not certifications
Reports support a defensible security process and may be shared with your auditors and customers under confidentiality. They are not a certification against SOC 2, ISO 27001, PCI DSS or any other standard, and are not legal advice. Whether a report satisfies a particular obligation is a matter for your auditor or regulator.
9. No warranty — and what a clean report means
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT, TO THE MAXIMUM EXTENT PERMITTED BY LAW.
We expressly do not warrant that the Service will identify all vulnerabilities. No automated testing can prove the absence of vulnerabilities. A report containing no findings means the checks performed did not detect an issue — it does not mean your systems are secure. You must not represent to any third party that Aegis certifies your security.
10. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, BACKBONE IS NOT LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, NOR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS INTERRUPTION OR SYSTEM DOWNTIME, HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY.
BACKBONE'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT IS
LIMITED TO THE FEES YOU PAID FOR THE SERVICE IN THE [TWELVE (12)] MONTHS PRECEDING THE
EVENT GIVING RISE TO THE CLAIM.
Nothing limits liability that cannot be limited by law (including fraud, or death or
personal injury caused by negligence). [COUNSEL: consumer-protection statutes may
override these limits for non-business customers; consider a business-customers-only
restriction.]
11. Indemnity
You will indemnify and hold harmless Backbone against claims, losses and reasonable legal costs arising from: (a) testing a target you were not authorised to test; (b) your breach of this agreement or the Acceptable Use Policy; (c) your failure to comply with a provider policy or applicable law; or (d) your use or distribution of a report.
12. Suspension and termination
You may cancel at any time, effective at the end of the current period. We may suspend
immediately where we reasonably believe unauthorised testing is occurring, where the
Service is being used unlawfully, or where testing threatens the stability of third-party
infrastructure. We may terminate for material breach not cured within [14] days.
13. Changes
We may amend these Terms on [30] days' notice for material changes. Continued use after
the effective date constitutes acceptance.
14. Governing law
Governed by the laws of [Ontario, Canada], with exclusive jurisdiction in the courts of
[Ontario]. [COUNSEL: consider arbitration and a class-action waiver where enforceable.]
15. Contact
[legal@backbonesolutions.ca] · Backbone Solutions Ltd., [REGISTERED ADDRESS]