Terms of Service
Last updated: March 2026
1. Definitions
In these Terms:
- "Trace37", "we", "us", "our" means Trace37 Ltd, a company registered in England and Wales.
- "Client", "you", "your" means the entity subscribing to the Service.
- "Service" means the Mastermind continuous offensive security service as described in the applicable Order Form.
- "Platform" means the Mastermind security testing platform deployed on your Dedicated Instance.
- "Dedicated Instance" means the isolated virtual private server provisioned exclusively for your use.
- "Rules of Engagement" or "RoE" means the document specifying the agreed scope, constraints, and authorisations for security testing.
- "Order Form" means the document specifying your selected Service Tier, pricing, scope, and contract term.
- "Findings" means validated security vulnerabilities discovered during testing, delivered with proof-of-concept evidence.
- "Subscription Period" means the period specified in the Order Form.
2. Service Description
2.1 Overview
Trace37 provides a continuous offensive security testing service. Subject to the agreed Rules of Engagement, we will:
- Deploy and maintain a Dedicated Instance for your organisation;
- Conduct continuous automated reconnaissance and monitoring of your agreed attack surface;
- Perform AI-assisted vulnerability triage and prioritisation;
- Where included in your Service Tier, conduct manual expert exploitation testing;
- Deliver findings with proof-of-concept evidence and remediation guidance.
2.2 Service tiers
The specific features and exploitation hours included in your subscription are defined in the Order Form and correspond to the Service Tier selected (Sentinel, Strike, or Adversary).
2.3 What the Service is not
The Service is not:
- A compliance audit or certification assessment;
- A guarantee that all vulnerabilities will be discovered;
- A managed security operations centre (SOC);
- A remediation or development service — we identify and evidence vulnerabilities; remediation is your responsibility.
3. Authorisation and Rules of Engagement
3.1 Written authorisation required
You warrant that you have the legal authority to authorise security testing against the systems defined in the Rules of Engagement. Testing will not commence until a signed RoE is in place.
3.2 Scope
All testing is strictly limited to the systems, applications, and IP ranges defined in the signed RoE. We will not test any system outside the agreed scope.
3.3 Changes to scope
Either party may request changes to the agreed scope during the Subscription Period. Scope changes must be documented in writing and signed by both parties before taking effect.
3.4 Emergency contacts
You must provide at least one emergency contact who can be reached during testing windows. If we observe unexpected system behaviour that may indicate an issue, we will cease testing and contact you immediately.
4. Client Obligations
You agree to:
- Provide accurate scope information: domains, IP addresses, applications, and any exclusions;
- Maintain valid authorisation: ensure you have and retain the legal right to authorise testing throughout the Subscription Period;
- Designate emergency contacts: provide at least one contact reachable during testing;
- Notify us of changes: inform us of significant changes to your infrastructure that may affect testing;
- Not hold us liable for findings discovered — vulnerabilities exist in your systems regardless of whether they are discovered by us;
- Pay invoices in accordance with Section 7.
5. Our Obligations
We agree to:
- Operate within the agreed RoE: all testing will be conducted strictly within the defined scope and constraints;
- Handle data responsibly: any data encountered during testing will be handled in accordance with our Privacy Policy and Data Processing Agreement;
- Report critical findings promptly: P1/P2 findings will be reported within 24 hours of validation;
- Maintain insurance: professional indemnity and cyber liability insurance throughout the engagement;
- Maintain confidentiality: all findings, reports, and client information are confidential (see Section 9);
- Securely destroy data on termination: see Section 8.
6. Intellectual Property
6.1 Client IP
All findings, reports, and deliverables produced for you are your property upon payment. You receive a perpetual, non-exclusive licence to use, reproduce, and distribute deliverables internally.
6.2 Trace37 IP
The Platform, tools, methodologies, and general security knowledge remain the intellectual property of Trace37 Ltd. We retain the right to use general techniques, patterns, and anonymised learnings in our operations.
6.3 No reverse engineering
You may not reverse-engineer, decompile, or attempt to extract the source code of the Platform or any tools used in the Service.
7. Pricing and Payment
7.1 Fees
The fees for your Service are specified in the Order Form. All prices are in GBP and exclusive of VAT.
7.2 VAT
VAT will be added to invoices at the applicable rate where required by law.
7.3 Billing
Invoices are issued quarterly in advance unless otherwise specified in the Order Form. Payment is due within 14 days of invoice date.
7.4 Late payment
We reserve the right to charge interest on overdue payments at 8% above the Bank of England base rate, in accordance with the Late Payment of Commercial Debts (Interest) Act 1998.
7.5 Additional hours
Exploitation hours beyond those included in your Service Tier may be purchased at £300/hour (excl. VAT), subject to availability.
8. Term and Termination
8.1 Minimum term
The minimum subscription period is 3 months from the Service commencement date unless otherwise specified in the Order Form.
8.2 Renewal
Subscriptions renew automatically at the end of each Subscription Period unless either party gives at least 30 days' written notice of non-renewal.
8.3 Termination for cause
Either party may terminate immediately by written notice if the other party:
- Commits a material breach that is not remedied within 14 days of written notice;
- Becomes insolvent, enters administration, or ceases trading.
8.4 Effect of termination
On termination:
- All testing ceases immediately;
- Outstanding deliverables for completed work will be provided;
- Your Dedicated Instance will be securely destroyed within 7 days;
- A certificate of destruction will be provided on request;
- Any prepaid fees for unused periods within the current quarter are non-refundable.
9. Confidentiality
9.1 Mutual obligation
Both parties agree to keep confidential all information received from the other party that is designated as confidential or that reasonably should be understood to be confidential.
9.2 Findings confidentiality
All security findings, reports, and vulnerability details are strictly confidential. We will not disclose your findings to any third party without your prior written consent.
9.3 Exceptions
Confidentiality obligations do not apply to information that:
- Is or becomes publicly available through no fault of the receiving party;
- Was already known to the receiving party before disclosure;
- Is required to be disclosed by law, regulation, or court order.
9.4 Anonymised references
We may reference the engagement in general terms (e.g., "continuous red teaming for a UK fintech") for marketing purposes, but will not identify you by name or disclose any findings without your prior written consent.
10. Data Protection
10.1 Data processing
Where personal data is processed during the Service, the parties agree that you are the Data Controller and Trace37 is the Data Processor. Processing will be governed by a separate Data Processing Agreement.
10.2 Data encountered during testing
Any personal data encountered during testing will be:
- Minimised to what is strictly necessary to evidence the vulnerability;
- Stored securely and encrypted at rest;
- Deleted within 30 days of the relevant finding being reported, or earlier on request;
- Processed on infrastructure located in the UK, EU, or US. The specific location will be disclosed on request. Data will not be transferred to jurisdictions outside these regions without your prior written consent.
10.3 ICO registration
Trace37 is registered with the Information Commissioner's Office as a data controller.
11. Limitation of Liability
11.1 Exclusion of indirect losses
To the maximum extent permitted by law, neither party shall be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, revenue, data, or business opportunity.
11.2 Cap on liability
Trace37's total aggregate liability under or in connection with this agreement shall not exceed the total fees paid by you in the 12 months preceding the claim.
11.3 Exclusions
Nothing in these Terms limits or excludes liability for:
- Death or personal injury caused by negligence;
- Fraud or fraudulent misrepresentation;
- Any other liability that cannot be limited or excluded by law.
11.4 Nature of security testing
You acknowledge that:
- Security testing may cause temporary disruption (e.g., increased load, triggered alerts);
- No testing methodology can guarantee discovery of all vulnerabilities;
- The existence of undiscovered vulnerabilities after testing does not constitute a breach of this agreement.
12. Warranties and Disclaimers
12.1 Our warranties
We warrant that:
- The Service will be performed with reasonable skill and care;
- We will comply with the agreed Rules of Engagement;
- We maintain appropriate professional indemnity insurance.
12.2 Disclaimer
Except as expressly stated in these Terms, the Service is provided "as is" without warranties of any kind, whether express or implied, including implied warranties of merchantability or fitness for a particular purpose.
13. Indemnification
13.1 Your indemnity
You agree to indemnify and hold harmless Trace37 against any claims, losses, or damages arising from:
- Your failure to maintain valid authorisation for testing;
- Inaccurate scope information provided by you;
- Your use of findings or deliverables.
13.2 Our indemnity
We agree to indemnify and hold harmless you against any claims, losses, or damages arising from our:
- Testing outside the agreed scope;
- Negligent handling of your data;
- Breach of confidentiality obligations.
14. Force Majeure
Neither party shall be liable for delays or failures in performance caused by circumstances beyond reasonable control, including natural disasters, government actions, cyberattacks on our own infrastructure, or interruption of essential third-party services.
15. General
15.1 Governing law
These Terms are governed by the laws of England and Wales.
15.2 Jurisdiction
The courts of England and Wales have exclusive jurisdiction over any disputes.
15.3 Entire agreement
These Terms, together with the Order Form, Rules of Engagement, and Data Processing Agreement, constitute the entire agreement between the parties.
15.4 Amendments
We may update these Terms from time to time. Material changes will be notified in writing at least 30 days before taking effect.
15.5 Severability
If any provision is found to be unenforceable, the remaining provisions shall continue in full force and effect.
15.6 Assignment
Neither party may assign this agreement without the other party's prior written consent.
15.7 Notices
Notices must be in writing and sent to the addresses specified in the Order Form, or by email to the designated contacts.