HebridesCyber
← Back to home

Terms of Service

Last updated: 27 August 2026

1. Who we are and acceptance of these terms

Hebrides Cyber (“we”, “us”, “our”) is based in the Isle of Lewis, Scotland, UK. By creating an account, purchasing a subscription, or engaging us for a one-off audit or penetration test, you (“Customer”, “you”) agree to these Terms. If you don't agree, please don't use the service.

2. The service

We provide:

  • Automated Security Score subscriptions (Basic/Pro/Agency) — scheduled automated scanning, a scored report, and remediation guidance, per the plan tier described on /pricing.
  • One-off audits (Small Website Audit / Standard Web App Audit / Full SaaS Audit) — a mix of automated scanning and, at the higher tiers, manual testing, delivered as a written report.
  • Manual penetration-test engagements and other add-ons, priced per engagement.

The service identifies indicators of security weakness. It is not a guarantee that a target system is secure, free of vulnerabilities, or compliant with any particular standard — see §7 (Disclaimers).

3. Accounts

You must provide accurate registration information and keep your credentials confidential. You're responsible for activity under your account. Notify us immediately at hello@hebridescyber.co.uk if you suspect unauthorised access.

4. Authorisation to scan

This is the most important clause in these Terms for a service that runs active security testing against infrastructure you specify.

By submitting any URL, domain, or system for scanning — automated or manual — you represent and warrant that:

  • you own the target, or
  • you have explicit, current authorisation from the owner to conduct security testing against it, including active/intrusive testing (port scanning, vulnerability probing, SQL injection testing, cross-site-scripting testing, and the other techniques our extended scanning tier and manual engagements use).

We verify domain ownership via a DNS or file-based check before running scheduled or on-demand automated scans (see our Privacy Policy), but this verification does not itself constitute legal authorisation to test, and manual/one-off engagements may rely on your representation alone.

You agree to indemnify and hold us harmless from any claim, loss, or liability arising from your submission of a target you were not authorised to test. We reserve the right to suspend or terminate your account and refuse service if we reasonably believe a submitted target was not authorised.

5. Acceptable use

You will not:

  • use the service to test a target you're not authorised to test (§4);
  • use the service to develop or launch attacks against third parties outside the scope of a specific, authorised engagement;
  • attempt to circumvent rate limits, plan restrictions, or access another customer's data;
  • resell or provide the service to a third party outside a specifically contracted white-label/agency arrangement (Agency plan).

We may suspend accounts that violate this section without refund.

6. Fees, billing, and cancellation

  • Monthly subscription plans are billed via Stripe on a recurring basis at the price shown on /pricing at signup. You can cancel at any time via the billing portal; cancellation takes effect at the end of the current billing period, with no partial refund for the remainder.
  • One-off audits are invoiced 50% upfront, remainder on delivery, per /pricing.
  • We may change prices for future billing periods with notice; changes don't apply retroactively to a period already paid for.

7. Disclaimers

The service is provided “as is.” Automated and manual security testing can never guarantee the discovery of every vulnerability, and a clean or high-scoring report is not a certification that a target is secure. We make no warranty, express or implied, of merchantability, fitness for a particular purpose, or that the service will be uninterrupted or error-free.

Cyber Essentials / compliance-framework references in reports are automated indicators only, never a certification.

8. Limitation of liability

To the maximum extent permitted by law, our total liability to you arising out of or related to these Terms or the service is limited to the fees you paid us in the 12 months preceding the claim. We are not liable for indirect, incidental, special, consequential, or lost-profit damages. Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded or limited under UK law.

9. Intellectual property

Scan reports and findings we generate for you are yours to use for your own security purposes. We retain ownership of our underlying tooling, scanner logic, and report templates. You grant us a licence to process the target/scan data you submit solely to provide the service.

10. Termination

Either party may terminate a subscription per §6. We may terminate or suspend access immediately for a breach of §4 or §5, or if required by law.

11. Data protection

Personal data is handled per our Privacy Policy — retention periods, data-subject rights, and our processor list live there, not duplicated here.

12. Governing law

These Terms are governed by the law of Scotland, and the Scottish courts have exclusive jurisdiction over any dispute arising from them.

13. Changes to these Terms

We may update these Terms from time to time. The “Last updated” date at the top will reflect any changes. Material changes will be communicated by email to registered users.

14. Contact

Hebrides Cyber
Isle of Lewis, Scotland, UK
hello@hebridescyber.co.uk