Cybersecurity Services Terms & Conditions
Baseline website and service terms for Hackabby cybersecurity, penetration testing, security validation, incident response and digital forensic engagements.
These website terms provide the baseline conditions applicable to our services. Engagement-specific terms may be contained in an accepted quotation, Statement of Work, Service Order, Master Services Agreement, Rules of Engagement, SLA, NDA or Data Processing Agreement. Where a signed or accepted engagement document conflicts with these website terms, the engagement document prevails to the extent of the inconsistency.
1. About Hackabby and Application of These Terms
Hackabby (Pty) Ltd, registration number 2026/591759/07, trading as Hackabby Cybersecurity ("Hackabby", "we", "us" or "our"), provides cybersecurity consulting, penetration testing, attack-surface assessment, security validation, incident response, threat intelligence, digital forensic and related professional services.
These Terms & Conditions apply to use of this website and, where incorporated or referenced, to cybersecurity services supplied by Hackabby. They operate together with the specific contractual documents accepted for an engagement.
2. Scope, Quotations, SOWs and Work Orders
Hackabby services are normally defined through an accepted quotation, proposal, Statement of Work (SOW), Service Order, Work Order, retainer or similar written engagement document. Those documents may specify scope, systems, deliverables, assumptions, exclusions, timelines, fees, payment milestones, testing windows, reporting obligations and client responsibilities.
Where a Master Services Agreement (MSA) has been concluded, the MSA governs future quotations, SOWs and work orders accepted under it unless the applicable engagement document expressly provides otherwise.
3. No Implied Authority to Test
These website terms, a general enquiry, quotation request or ordinary service contract do not by themselves authorise intrusive cybersecurity testing. Penetration testing, exploitation, red-team activity, social-engineering testing, vulnerability validation, forensic acquisition or similar activity will only be performed where the required written authority and agreed scope exist.
4. Rules of Engagement
Penetration-testing and offensive-security engagements should be governed by written Rules of Engagement (RoE). The RoE may define authorised systems, IP addresses, domains, applications, environments, permitted and prohibited techniques, testing periods, production restrictions, emergency contacts, escalation procedures, evidence requirements, data-handling rules and stop-testing conditions.
Anything not expressly authorised is treated as out of scope. Hackabby may suspend testing where continued activity could materially threaten system availability, evidence integrity, third-party systems, legal compliance or safety.
5. Client Authority and Third-Party Systems
The client is responsible for ensuring that it owns, controls or has sufficient lawful authority over each system, account, application, domain, network or other asset it instructs Hackabby to test or investigate.
Where infrastructure is owned or operated by a third party, including a cloud provider, ISP, hosting provider or business partner, the client must obtain any required third-party permission unless this responsibility is expressly allocated to Hackabby in writing.
6. Potential Operational Impact of Security Testing
Authorised penetration testing may intentionally simulate attacker behaviour. Depending on the agreed techniques, testing may generate security alerts, account lockouts, increased load, application errors, temporary instability or other unintended operational effects.
Hackabby will exercise reasonable professional care and follow the agreed Rules of Engagement to minimise unnecessary disruption. Production testing must be specifically authorised.
7. Client Responsibilities
The client must provide reasonable and timely cooperation required for the engagement, including authorised access, accurate technical information, appropriate contacts, agreed credentials and disclosure of material operational restrictions.
Unless expressly included in the contracted scope, the client remains responsible for maintaining current backups, recovery procedures, business continuity, disaster recovery, system availability and implementation of remediation recommendations.
8. Cybersecurity Findings are Point-in-Time
Cybersecurity is a continuously changing risk environment. Findings reflect the systems, scope, configurations, information and threat conditions reasonably observable during the agreed assessment period.
No penetration test, vulnerability assessment, scanner, security product or consultant can guarantee discovery of every vulnerability or ensure that a system will remain completely secure. Automated and manual tools may produce false positives, false negatives or findings requiring professional interpretation.
9. Warranties and Professional Standard
Hackabby will perform professional services with reasonable care, skill and diligence appropriate to the nature of the engagement. However, unless expressly agreed otherwise and subject to applicable law, Hackabby does not warrant that its services will prevent every cyberattack, identify every vulnerability, eliminate all security risk, guarantee regulatory compliance or make a system "hack-proof".
10. Confidentiality and Sensitive Security Information
Hackabby may obtain access to highly sensitive information such as network diagrams, IP addresses, security architecture, credentials, API keys, authentication data, source code, vulnerability information, forensic evidence, logs, personal information and incident records.
Such information is treated as confidential and used only for legitimate purposes connected with the authorised engagement, subject to applicable contractual and legal requirements. Access is restricted to personnel who reasonably require it for the engagement.
11. Client Credentials and Security Secrets
Credentials, tokens, keys or other security secrets supplied to or lawfully encountered by Hackabby will not intentionally be used outside the authorised engagement. Where appropriate, Hackabby may recommend that temporary testing credentials be revoked, rotated or disabled after completion of testing.
12. Secure Client Data Handling
Hackabby applies reasonable technical and organisational safeguards designed to protect engagement information against unauthorised access, disclosure, alteration, loss or destruction. Depending on the engagement, safeguards may include access control, encryption, multi-factor authentication, secure repositories, least-privilege access, logging, secure transfer and controlled retention or deletion.
Further information is available in our Privacy & POPIA Policy and Forensics & Data Handling Policy.
13. POPIA and Personal Information
Where the Protection of Personal Information Act 4 of 2013 (POPIA) applies, the parties must process personal information in accordance with their respective legal obligations. Where Hackabby acts as an operator processing personal information on behalf of a client, processing may be governed by a separate Data Processing / Operator Agreement.
Hackabby will process personal information only for legitimate engagement purposes and subject to appropriate confidentiality and security controls.
14. Digital Forensics and Evidence Handling
Digital forensic investigations require specific authority and careful evidence handling. Depending on the engagement, Hackabby may document evidence identifiers, acquisition details, cryptographic hashes, analyst activity, storage location, transfers and chain-of-custody information.
Where potential evidence may be required for disciplinary, civil, regulatory or criminal proceedings, the client should inform Hackabby as early as possible so that appropriate forensic procedures can be followed. Technical forensic services do not constitute legal representation or legal advice.
15. Incident Response and Critical Findings
If Hackabby identifies a critical vulnerability or indications of an active compromise during an authorised engagement, Hackabby may notify the designated client contact before delivery of the final report and may recommend immediate containment, remediation or activation of incident-response procedures.
Hackabby will not intentionally interfere with a suspected threat actor or third-party system unless this is expressly authorised and legally permissible.
16. Reports and Deliverables
Depending on the engagement, deliverables may include executive summaries, technical findings, evidence, severity ratings, CVE/CWE references, attack-path observations, business impact, remediation recommendations and retest results.
Penetration-testing and forensic reports should be treated as confidential security information because unauthorised disclosure could increase risk to the client environment.
17. Intellectual Property
Each party retains ownership of intellectual property it owned or developed independently of the engagement. Hackabby retains ownership of its pre-existing methodologies, templates, scripts, tools, processes, testing techniques, know-how and generic materials.
Subject to payment of applicable fees and the specific engagement terms, the client may use its final engagement-specific deliverables for legitimate internal business, security, audit, governance, risk and compliance purposes.
18. Third-Party Products and Services
Hackabby may use appropriate commercial, proprietary or open-source security tools. Third-party platforms, software and cloud services remain subject to their own licence, privacy, support and service terms. Hackabby does not control independent vendor availability, product operation or future product vulnerabilities.
19. Fees, Invoicing and Payment
Fees, deposits, milestones and invoice due dates are specified in the applicable quotation, SOW, Service Order or other commercial document. Where no alternative payment period has been expressly agreed, Hackabby may apply a standard payment period stated on the relevant invoice.
The client should promptly notify Hackabby of a bona fide invoice dispute and identify the disputed amount and reason. Undisputed amounts remain payable in accordance with the agreed terms.
Where an undisputed account remains overdue, Hackabby may, after appropriate notice and subject to applicable law, suspend non-critical services, decline to commence additional work or exercise lawful recovery remedies. Any interest or late-payment charge will only be applied where properly disclosed, contractually agreed and legally permissible.
20. Suspension and Termination
Engagement-specific termination rights are governed by the applicable MSA, SOW, retainer or Service Order. Hackabby may suspend affected services where continuing the work would reasonably involve unlawful activity, unauthorised access, testing outside the agreed scope, unacceptable risk to third-party systems, compromise of forensic evidence or a material security concern.
Termination does not automatically extinguish accrued payment, confidentiality, data-protection, evidence-handling, intellectual-property or other obligations intended to survive termination.
21. Limitation of Liability
Cybersecurity services reduce and manage risk but cannot eliminate all cyber risk. To the maximum extent permitted by applicable law, liability for a particular engagement is governed by the liability provisions and any agreed financial cap contained in the applicable MSA, SOW, quotation or Service Order.
Nothing in these website terms is intended to exclude or limit liability, rights or remedies that cannot lawfully be excluded or limited under South African law.
22. Consumer Protection Act
Where the Consumer Protection Act 68 of 2008 (CPA) applies to a transaction or client, these terms must be interpreted consistently with the CPA. Nothing in these terms is intended to unlawfully waive mandatory consumer rights, avoid mandatory supplier obligations, impose unfair, unreasonable or unjust terms, or exclude liability that may not lawfully be excluded.
23. Ethical and Lawful Use
Hackabby provides cybersecurity services only for lawful defensive, assurance, investigative and risk-management purposes. We may refuse or discontinue instructions reasonably suspected of involving unauthorised access, cybercrime, malicious surveillance, theft of information, unlawful interception, disruption of third-party services or other unlawful activity.
24. Responsible Vulnerability Disclosure
Security researchers are expected to act lawfully, minimise unnecessary access to data, avoid unnecessary disruption and coordinate disclosure responsibly. Our security and compliance framework is described on the Legal & Compliance page.
25. Electronic Communications
Where legally permissible, quotations, engagement documents, notices and other communications may be concluded or transmitted electronically. The parties remain responsible for maintaining accurate authorised contact details and protecting their own communications channels.
26. Governing Law and Disputes
Unless a signed agreement expressly states otherwise, these terms are governed by the laws of the Republic of South Africa. The parties should first attempt in good faith to resolve disputes through their authorised representatives before escalating the matter or pursuing formal remedies.
27. Order of Precedence
Where contractual documents conflict, the order of precedence stated in the applicable signed agreement will apply. In the absence of a specific order, a signed or formally accepted engagement-specific document will prevail over these general website terms to the extent of the inconsistency.
28. Changes to These Website Terms
Hackabby may update these website terms from time to time to reflect service, legal, regulatory or operational changes. Updates to website terms do not retrospectively amend a separately signed agreement unless the parties agree to the amendment in accordance with that agreement.
29. Related Policies
These terms should be read together with our Privacy & POPIA Policy, Forensics & Data Handling Policy, Legal & Compliance information and Website Disclaimer.
Hackabby — Decode. Defend. Dominate.
