1. Acceptance and B2B eligibility
By accessing or using SecuTest, you agree to these Terms & Conditions and the Privacy Policy. These terms apply exclusively to companies, public bodies, independent professionals and other persons acting for business or professional purposes. SecuTest does not offer paid reports to consumers.
You represent that you are acting for business or professional purposes and have authority to bind the organisation on whose behalf you use or purchase the service.
2. Operator, seller and hosting
SecuTest is operated and invoiced by CYBER CLUSTER LLC, a New Mexico limited liability company.
| Legal name | CYBER CLUSTER LLC |
|---|---|
| Legal form | New Mexico limited liability company (LLC) |
| State of formation | New Mexico, United States |
| Company filing number | 3070559 |
| Registered business address | 1209 MOUNTAIN ROAD PL NE STE R Albuquerque, NM 87110 |
| General contact | Contact form |
The website and service are hosted by OVH SAS, 2 rue Kellermann, 59100 Roubaix, France, telephone +33 9 72 10 10 07.
3. Service scope
SecuTest provides automated, point-in-time external security posture assessments based on public DNS data, normal TCP connections, standard TLS handshakes, public HTTP responses and other publicly observable signals. Coverage is bounded and may differ by target, provider availability, timeout, network condition and technical limitation.
A SecuTest result is not a penetration test, certification, compliance audit, insurance product, legal opinion, warranty or guarantee of security. Automated findings must be reviewed by a qualified human before material decisions are made.
SecuTest does not perform credential attacks, vulnerability exploitation, persistence, destructive testing or unauthorised access.
5. Acceptable use
Use SecuTest only for lawful, defensive and professionally legitimate purposes.
Permitted uses
- Internal security posture review.
- Authorised supplier or customer assessment.
- Pre-sales assessment where the target owner has authorised it.
- Defensive remediation planning and verification.
- Education using targets you control or have permission to test.
Prohibited uses
- Harassment, intimidation, extortion, doxxing or coercive disclosure.
- Credential attacks, brute force, exploitation, payload delivery or attempts to gain access.
- Scanning intended to prepare, enable or conceal unlawful intrusion.
- Evasion of rate limits, target blocks, technical restrictions or payment controls.
- Automated mass scanning beyond product limits or repeated scanning designed to burden a target.
- Submitting credentials, private keys, access tokens, malware or unnecessary personal data.
- Misrepresenting a report as a certification, penetration test or proof of compromise.
- Publishing sensitive findings without appropriate coordination and authority.
- Reselling, white-labelling or removing attribution without written permission or an applicable partner agreement.
- Using the service in violation of sanctions, export controls or applicable law.
Sensitive targets
Do not assess emergency services, critical infrastructure, healthcare systems, election systems, military systems or other high-impact environments unless you have explicit written authority and the activity is lawful. SecuTest may block such targets.
You must respect published and enforced limits. Creating multiple identities, source addresses or sessions to bypass limits is prohibited.
6. Access, report links and submitted information
SecuTest may provide access without an account. Checkout sessions, access tokens and report links are confidential credentials. You must protect them and notify us promptly if they are exposed.
You grant CYBER CLUSTER LLC a limited right to process submitted domains, URLs and related information solely to provide, secure, maintain and improve the service, comply with law and enforce these terms. Do not submit passwords, private keys, authentication tokens, regulated secrets or unnecessary personal data.
7. Availability and third-party systems
We may change, suspend, rate-limit or discontinue any part of the service. We do not guarantee uninterrupted availability or that every check will complete. We may preserve partial results where a bounded deadline is reached.
Results may rely on DNS resolvers, certificate infrastructure, blocklists, payment processors, hosting providers and other third-party systems. We do not control their availability, accuracy or policies.
8. Paid reports and contract formation
A direct purchase covers one point-in-time automated report for each selected domain or hostname. The report may include findings, evidence, inventories, scoring, coverage limitations and remediation guidance in HTML and PDF formats. It reflects signals available at scan time and is not continuous monitoring.
The website displays the selected target, quantity and price before redirecting to Stripe Checkout. A contract forms when Stripe confirms successful payment and SecuTest records the paid session. We may refuse or cancel an order where the target is prohibited, the payment is fraudulent, the order violates these terms or fulfilment would be unlawful.
Stripe Checkout requires acceptance of the applicable terms and records the legal-document version in session metadata.
9. Price, taxes, payment and invoices
Unless checkout states otherwise, displayed prices exclude applicable sales, use, value-added, withholding or similar taxes. Taxes may be collected at checkout where configured and legally required. Where reverse charge or self-assessment applies, the customer remains responsible for its obligations.
The customer must provide accurate company, billing-address and tax-identification information. Pricing may change prospectively but does not alter a completed order.
Payment is processed by Stripe. Supported methods are those displayed at checkout. One-time invoices are generated through Stripe where technically available. The customer authorises the charge shown at checkout and must not use an unauthorised payment method.
For invoiced amounts not paid through immediate checkout, overdue amounts accrue interest at the lower of 1.5% per month or the maximum rate permitted by law, plus reasonable recovery costs. Mandatory local late-payment rules prevail where applicable.
10. Delivery and report access
Reports are normally available after payment verification. Temporary preparation may be required for PDF or bundle archives. We will use commercially reasonable efforts to remedy a delivery failure.
Download access is provided for at least 30 days after purchase unless access is revoked due to refund, chargeback, fraud, abuse or legal requirement. Customers must retain their own copy. Report data may be retained longer under the Privacy Policy.
11. Refunds and chargebacks
We will provide a replacement, remediation or refund where we confirm a duplicate charge for the same order; successful payment with no report access because of a SecuTest failure; a corrupted or unreadable delivered file that we cannot replace; an incorrect quantity charged because of a SecuTest checkout error; or where law requires a refund.
A refund is normally not available solely because the customer disagrees with a technically supportable score or finding; the target changes after the point-in-time scan; disclosed timeout, provider, DNS, blocklist or coverage limitations apply; the customer submitted the wrong target or lacked authority; the customer failed to download or retain the report during the access period; or the order involved misuse, breach, fraud, sanctions or chargeback abuse.
Submit a refund request within 14 calendar days of payment through the contact form, select “Billing or refund”, and include the purchaser email, Stripe receipt or session reference, affected domain and reason. Do not send full payment-card data. We normally acknowledge requests within five business days and may request reasonable evidence.
Approved refunds are returned through Stripe to the original payment method. Processing time depends on Stripe, the card network and the customer's financial institution. Contact us before initiating a chargeback so we can investigate. A refund, dispute or chargeback may revoke access to associated reports and archives.
12. Ownership, report licence and white-labelling
CYBER CLUSTER LLC retains all rights in SecuTest and its underlying software, methodology, templates, report structure, texts, graphics and original content.
Subject to these terms, free output may be used for internal professional purposes. After full payment, we grant the customer a perpetual, non-exclusive, worldwide licence to use and reproduce the purchased report internally and to share it with employees, professional advisers, insurers, auditors and the owner of the assessed target.
Public publication, resale, white-labelling, removal of SecuTest attribution or incorporation into a commercial product requires separate written permission or an applicable partner agreement.
13. Customer responsibilities and confidentiality
The customer must verify authority to assess each target, review findings before acting, maintain backups and change controls, avoid treating the score as a certification, protect report links and downloaded files, and avoid disclosing sensitive report content to unauthorised persons.
Each party must protect non-public information received from the other using reasonable care. Reports are not automatically confidential to third-party target owners; customers must determine whether they are authorised to receive and distribute them.
14. Warranty disclaimer
To the maximum extent permitted by law, SecuTest and its reports are provided “as is” and “as available”. We disclaim warranties of merchantability, fitness for a particular purpose, non-infringement, completeness, accuracy and uninterrupted operation. No automated assessment can identify every vulnerability or prove absence of compromise.
15. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, consequential, incidental, special, exemplary or punitive damages, lost profits, lost revenue, lost data, business interruption or reputational loss.
CYBER CLUSTER LLC's aggregate liability relating to free use is limited to USD 100. Its aggregate liability arising from a purchased report or bundle will not exceed the fees actually paid for the affected report or bundle. These caps do not apply to fraud, wilful misconduct or liability that cannot lawfully be limited.
16. Indemnification
You will defend and indemnify CYBER CLUSTER LLC against third-party claims arising from unauthorised scanning, unlawful use, misleading publication, misuse of reports, resale without permission, infringement of third-party rights or violation of these terms.
17. Enforcement, suspension and target blocks
We may reject requests, block targets or clients, revoke report access, cancel orders, preserve relevant evidence and cooperate with competent authorities where we reasonably suspect abuse, fraud, security risk or legal violation.
Protect findings and validate them before remediation or disclosure. Do not use findings to threaten a target owner, make knowingly false claims or imply an affiliation that does not exist.
To report abuse or request a target block, use the contact form, select “Abuse or target-block request”, and provide the target, relevant timestamps, evidence of control where appropriate and the reason for the request.
18. Force majeure
Neither party is liable for delay caused by events beyond reasonable control, including provider outages, internet failures, DNS disruption, natural disasters, war, labour disputes, government action or widespread security incidents.
19. Governing law, venue and precedence
These terms are governed by the laws of the State of New Mexico, without regard to conflict-of-law rules. The state and federal courts located in Bernalillo County, New Mexico, have exclusive jurisdiction, except where mandatory law requires otherwise.
A signed order form or partner agreement prevails over these terms for conflicting commercial provisions. The Partner Terms supplement these Terms & Conditions for the white-label partner service.
20. Changes and contact
We may update these terms prospectively. The effective date and version identify the applicable text. Material changes apply prospectively unless law requires otherwise.
Questions about these terms, invoices, payments or refunds may be submitted through the contact form. Security vulnerabilities affecting SecuTest must be submitted under the vulnerability disclosure policy.