Legal

Terms of Service

CompanyTouchpoint Security, LLC.
Websitetp-security.com
Effective dateSeptember 2026
Last reviewedSeptember 2026
Governing lawState of [Delaware / your state], United States

These Terms of Service ("Terms") govern your access to and use of all services provided by Touchpoint Security, LLC. ("Touchpoint Security", "we", "us"). By accessing our website, platform, or services, you agree to these Terms. If you are acting on behalf of a company or other legal entity, you represent that you have authority to bind that entity. If you do not agree, do not use our services.

1. Definitions

  • "Agreement" means these Terms together with any signed Order Form, Statement of Work (SOW), Service Level Agreement (SLA), Data Processing Agreement (DPA), or other written agreement between the parties.
  • "Services" means all cybersecurity services provided by Touchpoint Security, including without limitation: Managed Detection and Response (MDR); Exposure Monitoring; Threat Intelligence; Compliance and GRC services; Cloud API and compliance monitoring; Cloud Security (Azure, AWS, GCP, and other platforms); Cyber Consultancy (including vCISO advisory, network security, OT/ICS security, penetration testing, and vulnerability assessments and monitoring); Incident Response; Security Awareness Training; and Phishing Investigations.
  • "Platform" means the Touchpoint Security web-based portal and APIs through which Services are accessed and managed.
  • "Client Data" means all data, logs, alerts, configurations, telemetry, and other information submitted to or generated within the Platform by or on behalf of Client.
  • "Authorised Users" means Client's employees, contractors, and agents granted access to the Platform under Client's account.
  • "Deliverables" means reports, assessments, recommendations, and other written outputs produced by Touchpoint Security specifically for Client under an engagement.
  • "Order Form" means a mutually executed document specifying the Services, fees, and term.
  • "SOW" means a Statement of Work specifying the scope, deliverables, timeline, and fees for a professional services engagement.

2. Services

2.1 Managed Detection and Response (MDR)

We will provide continuous 24/7/365 security monitoring, threat detection, alert triage, and response across your endpoints, network, and cloud environments using our SIEM, EDR, and threat intelligence capabilities. Response actions will be agreed in advance in a Playbook or SOW and will not exceed the scope of actions you have authorised.

2.2 Exposure Monitoring

We will continuously monitor your external attack surface, including internet-facing assets, domain exposure, credential leaks, and dark web mentions, and provide prioritised findings and remediation guidance through the Platform.

2.3 Threat Intelligence

We will provide tactical, operational, and strategic threat intelligence relevant to your industry, geography, and technology stack, including adversary profiling, IoC feeds, and threat briefings.

2.4 Compliance and GRC / Cloud API Monitoring

We will assess and continuously monitor your compliance posture against applicable frameworks (including SOC 2, ISO 27001, NIST CSF, CIS Controls, PCI-DSS, HIPAA, DORA, and others as agreed) using read-only API integrations to your cloud and SaaS environments. We provide findings, evidence collection, and remediation tracking , we do not provide legal or audit opinions.

2.5 Cloud Security (Azure / AWS / GCP)

We will review and continuously monitor your cloud environment configurations, IAM policies, network controls, and security baselines. Engagements are scoped in an Order Form or SOW. All access is read-only unless explicit written authorisation to remediate is granted.

2.6 Cyber Consultancy

Consultancy engagements , including vCISO advisory, network security reviews, OT/ICS security assessments, penetration testing, and vulnerability assessments and monitoring , are governed by individual SOWs specifying scope, methodology, rules of engagement, deliverables, and timelines. Penetration testing is conducted only within the explicitly authorised scope. Out-of-scope access or testing is strictly prohibited.

2.7 Incident Response

Incident Response retainers and ad-hoc engagements are governed by an IR Retainer Agreement or SOW. Response is initiated upon your written or verbal (subsequently confirmed in writing) authorisation. Forensic data is handled under strict chain-of-custody procedures. We are not a legal firm and Incident Response services do not create attorney-client privilege.

2.8 Security Awareness Training

We will provide security awareness training content and delivery, and conduct phishing simulation campaigns as directed by you. You are responsible for obtaining all necessary employee consents required under applicable employment law in your jurisdiction before simulations are launched. Results are reported to you as the controller.

2.9 Phishing Investigations

We will investigate reported phishing emails and related threat actor infrastructure on your behalf, providing attribution analysis, IoC extraction, and recommended response actions. Investigations are limited to the artefacts you submit.

2.10 Service modifications

We may modify Services with 30 days' written notice where changes do not materially diminish core functionality. Material changes require your written consent or entitle you to terminate on 30 days' notice without penalty.

3. Platform access and accounts

  • You are responsible for all activity conducted under your account and the accounts of your Authorised Users.
  • You must implement reasonable access controls, including MFA, as required by the Platform.
  • You must promptly notify security@tp-security.com of any suspected unauthorised access to your account.
  • You must not share credentials or grant access to non-Authorised Users.
  • We reserve the right to suspend access where we reasonably believe an account is compromised or being used in violation of these Terms.

4. Client obligations

You agree to:

  • Provide accurate and complete information when contracting and throughout the Agreement.
  • Deploy agents, configure log forwarding, and grant API access as specified in onboarding documentation or SOWs to enable service delivery.
  • Obtain all necessary authorisations, rights, and consents before submitting Client Data to the Platform, including any required under applicable data protection, employment, and privacy law.
  • Ensure Authorised Users comply with these Terms and any applicable acceptable use policy.
  • Maintain a named point of contact responsible for security decisions and response authorisation.
  • For penetration testing and vulnerability assessments: provide written authorisation for all in-scope systems, including any third-party systems (cloud, co-location, SaaS) that require provider consent. You are solely responsible for obtaining such consent.
  • For OT/ICS security engagements: acknowledge that testing in operational technology environments carries inherent risk of disruption; agree the rules of engagement and any downtime windows in advance.
  • For Security Awareness Training: confirm compliance with applicable employment law and obtain employee notification or consent as required in your jurisdiction.

5. Acceptable use

You agree not to:

  • Use the Services or Platform for any unlawful purpose.
  • Attempt to gain unauthorised access to systems, networks, or data beyond the agreed scope of any engagement.
  • Introduce malware, disruptive code, or attack tooling into the Platform.
  • Resell, sublicense, or white-label the Services without a separate written reseller agreement.
  • Use threat intelligence or vulnerability data provided by Touchpoint Security to target or attack third parties.
  • Interfere with the availability or integrity of the Platform or other clients' environments.
  • Circumvent authentication or security controls.

6. Fees, billing, and payment

  • Fees are as specified in the applicable Order Form or SOW.
  • Recurring service fees are invoiced monthly or annually in advance as agreed.
  • Professional services (consultancy, IR, pen testing) are invoiced on milestones or on completion as specified in the SOW.
  • Invoices are due within 30 days of issue.
  • Overdue amounts accrue interest at 1.5% per month (or the maximum rate permitted by applicable law, whichever is lower).
  • All fees are exclusive of applicable taxes (sales tax, VAT, GST). Where Touchpoint Security is required to collect tax, it will be added to invoices. Clients outside the US may be responsible for self-assessing applicable taxes.
  • We may increase recurring fees on 90 days' written notice. If the increase exceeds 5% above the US CPI for the prior 12 months, you may terminate the affected service on 30 days' notice without early termination fees.
  • Disputed invoices must be raised in writing within 15 days of receipt. Undisputed portions remain due.

7. Intellectual property

7.1 Touchpoint Security IP

All intellectual property in the Platform, software, detection rules, algorithms, methodologies, threat intelligence models, training content, and Documentation is owned by or licensed to Touchpoint Security. Nothing in these Terms transfers ownership of our IP to you.

7.2 Licence to use

We grant you a limited, non-exclusive, non-transferable, revocable licence to access and use the Platform and Services during the term of your Agreement, solely for your internal business security operations.

7.3 Client Data

You retain all rights in Client Data. You grant Touchpoint Security a limited licence to process Client Data solely to deliver the Services and as otherwise described in our DPA. We will not use Client Data for any other purpose without your written consent.

7.4 Deliverables

Deliverables produced specifically for you under an SOW (e.g. penetration test reports, CISO advisory reports) are licensed to you for your internal use upon full payment of applicable fees. Underlying methodologies, tools, and frameworks remain our IP.

7.5 Aggregate and anonymised data

We may use anonymised, aggregated, and de-identified data derived from the Services , with no ability to identify you or any individual , to improve our detection capabilities, threat intelligence, and platform, and to publish industry research and benchmarks.

7.6 Feedback

If you provide feedback or suggestions about our Services, we may use it without restriction or compensation to you.

8. Confidentiality

Each party will hold the other's Confidential Information in strict confidence, using the same degree of care it uses for its own confidential information (not less than reasonable care), and will not disclose it to third parties or use it other than for the purposes of the Agreement. "Confidential Information" means all non-public information marked as confidential or which a reasonable party would understand to be confidential, including pricing, technical data, security findings, client lists, and business plans.

Exceptions: confidentiality obligations do not apply to information that: (a) is or becomes publicly known without breach of this clause; (b) was independently known before disclosure; (c) is independently developed without use of Confidential Information; or (d) must be disclosed by law or regulatory order (with prompt written notice where permitted).

Confidentiality obligations survive termination of the Agreement for 5 years, or indefinitely for trade secrets.

9. Data protection

To the extent Touchpoint Security processes personal data on your behalf as a data processor, processing is governed by our Data Processing Agreement (DPA), incorporated by reference into this Agreement. The DPA sets out roles, subprocessors, data subject rights, security measures, breach notification, and transfer mechanisms. A copy of the DPA is available at tp-security.com/legal/dpa or on request.

As a data controller, you are responsible for ensuring you have the legal right to share personal data with us for processing.

10. Service levels

Platform availability targets, incident response times, escalation procedures, and credits for service failures are set out in the Service Level Agreement (SLA) applicable to your subscription tier. SLA credits are the exclusive remedy for availability failures. SLAs do not apply to: scheduled maintenance (with prior notice), events caused by your actions or third parties outside our control, or force majeure events.

11. Warranties

11.1 Our warranties

Touchpoint Security warrants that:

  • We will perform Services with reasonable skill and care consistent with industry standards.
  • Services will materially conform to the Documentation and agreed SOW.
  • We will comply with all applicable laws in the provision of Services.
  • Our personnel hold relevant qualifications and certifications appropriate to the Services they deliver.

11.2 Disclaimer

Except as expressly stated, Services are provided "as is". Cybersecurity involves inherent and evolving risk. WE DO NOT WARRANT THAT: (A) THE SERVICES WILL DETECT OR PREVENT EVERY SECURITY THREAT OR INCIDENT; (B) THE PLATFORM WILL BE UNINTERRUPTED OR ERROR-FREE; (C) ANY VULNERABILITY ASSESSMENT OR PENETRATION TEST WILL IDENTIFY EVERY VULNERABILITY. NO MONITORING OR SECURITY SERVICE CAN GUARANTEE COMPLETE PROTECTION. WE DISCLAIM ALL IMPLIED WARRANTIES INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW.

12. Limitation of liability

To the maximum extent permitted by applicable law:

  • NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH LOSS.
  • TOUCHPOINT SECURITY'S TOTAL AGGREGATE LIABILITY UNDER OR IN CONNECTION WITH ANY AGREEMENT (WHETHER IN CONTRACT, TORT, NEGLIGENCE, OR OTHERWISE) SHALL NOT EXCEED THE GREATER OF: (A) THE TOTAL FEES PAID BY YOU IN THE 12 MONTHS PRECEDING THE CLAIM; OR (B) USD $50,000.

Nothing limits liability for: (a) gross negligence or wilful misconduct; (b) fraud or fraudulent misrepresentation; (c) death or personal injury caused by our negligence; (d) indemnification obligations under Section 13; or (e) any liability that cannot be excluded by applicable law.

13. Indemnification

13.1 By Client

You will indemnify, defend, and hold harmless Touchpoint Security and its officers, directors, employees, agents, and subcontractors from any third-party claims, damages, losses, and costs (including reasonable attorneys' fees) arising from: (a) your breach of these Terms; (b) your violation of applicable law; (c) any third-party claims relating to Client Data; (d) use of the Services by Authorised Users in violation of these Terms; or (e) your failure to obtain required consents for penetration testing or Security Awareness Training.

13.2 By Touchpoint Security

Touchpoint Security will indemnify, defend, and hold harmless Client from third-party claims that the Platform, as used in accordance with these Terms, infringes a third-party's intellectual property rights, provided that: (a) you notify us promptly in writing; (b) you grant us sole control of the defence; and (c) you cooperate reasonably. This indemnity does not apply to claims arising from your modifications, Client Data, or use outside the permitted scope.

14. Term and termination

14.1 Term

The Agreement commences on the date of your first Order Form or platform access and continues for the initial subscription term, renewing automatically unless terminated in accordance with this section.

14.2 Termination for convenience

Either party may terminate a subscription service by giving 90 days' written notice prior to the end of the then-current term. Professional services SOWs may be terminated on 30 days' notice subject to payment for work completed and non-cancellable costs incurred.

14.3 Termination for cause

Either party may terminate immediately on written notice if the other: (a) commits a material breach that is incapable of remedy, or fails to remedy a remediable breach within 30 days of written notice; (b) becomes insolvent, makes an assignment for the benefit of creditors, or has a receiver, administrator, or liquidator appointed; or (c) commits fraud or wilful misconduct in connection with the Agreement.

14.4 Effect of termination

On termination: (a) all licences immediately cease; (b) each party will promptly return or certifiably destroy the other's Confidential Information; (c) we will make Client Data available for export for 30 days, after which it will be securely deleted; (d) you will pay all fees accrued to the termination date; (e) provisions that by their nature survive (confidentiality, IP, liability, indemnification, governing law) will remain in effect.

15. Export compliance

The Services and associated technology may be subject to US export control laws, including the Export Administration Regulations (EAR) and Office of Foreign Assets Control (OFAC) sanctions. You represent that you are not located in, or a national or resident of, any country subject to US trade sanctions, and that you will not use the Services in violation of export control laws.

16. Governing law and disputes

These Terms are governed by the laws of the State of [Delaware / your state], United States, without regard to its conflict of law principles. For clients outside the United States, mandatory consumer protection laws of your jurisdiction may also apply.

Disputes: the parties will attempt to resolve disputes through good-faith negotiation within 30 days of written notice. If unresolved, disputes will be submitted to binding arbitration under the American Arbitration Association (AAA) Commercial Arbitration Rules, with proceedings in [City, State]. Judgment on the award may be entered in any court of competent jurisdiction. Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to protect IP or Confidential Information.

Class action waiver: to the extent permitted by law, you waive the right to participate in any class action or class-wide arbitration.

EU / UK clients: notwithstanding the above, EU and UK clients retain the right to bring claims before their local courts as provided under mandatory applicable law, including EU consumer law where applicable.

17. General

  • Entire agreement: the Agreement constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior representations, negotiations, and understandings.
  • Order of precedence: in the event of conflict , DPA, then Order Form / SOW, then these Terms.
  • Amendments: we may amend these Terms with 30 days' notice. Continued use after the effective date constitutes acceptance. Material changes to existing Order Forms require mutual written agreement.
  • Waiver: failure to enforce any provision does not constitute a waiver of future enforcement.
  • Severability: if any provision is found invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable; remaining provisions continue in full force.
  • Assignment: you may not assign these Terms without our prior written consent. We may assign to an affiliate or in connection with a merger, acquisition, or asset sale, with notice to you.
  • Force majeure: neither party is liable for delay or failure due to causes beyond its reasonable control, including natural disasters, acts of government, cyberattacks on critical infrastructure, pandemics, or internet outages , provided the affected party gives prompt notice and uses reasonable efforts to mitigate.
  • Notices: legal notices must be in writing and sent to legal@tp-security.com (for notices to us) or to the email address on your Order Form (for notices to you), with confirmation of delivery.
  • Independent contractors: the parties are independent contractors. Nothing creates an employment, partnership, joint venture, or agency relationship.
  • No third-party beneficiaries: these Terms do not create rights in any third party.
  • Language: in the event of any conflict between a translated version of these Terms and the English version, the English version prevails.