Terms of Service
The terms and conditions governing your use of our website and services.
Effective date: July 27, 2026 · Last updated: July 27, 2026
1. Agreement to Terms
By accessing or using the website at lorikeetsecurity.com (the "Site"), the client or partner portal, our API and MCP server, or the cybersecurity services provided by Lorikeet Security ("we," "us," or "our"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, you must not access or use our Site or services. If you accept these Terms on behalf of an organization, you represent that you have authority to bind that organization.
These Terms incorporate by reference our Privacy Policy and our AI Usage Policy.
We reserve the right to modify these Terms. Non-material changes are effective on posting to the Site. Material changes affecting active clients will be notified to account contacts by email at least 30 days before taking effect. Your continued use of the Site or services after a change takes effect constitutes acceptance of the updated Terms.
Order of precedence
Where documents conflict, the following order controls: (1) a signed Master Services Agreement, (2) the applicable Statement of Work, (3) a signed Data Processing Agreement or NDA, (4) these Terms, (5) the AI Usage Policy and Privacy Policy.
2. Services
Lorikeet Security provides cybersecurity services, including but not limited to:
- Penetration testing (web application, API, network, cloud, mobile, thick client, wireless, IoT and hardware, physical)
- Security code reviews and blockchain audits
- Active Directory and identity security assessments
- AI agent security assessments
- Red team, purple team, and social engineering operations
- Phishing simulation and security awareness training
- Attack surface management and continuous AI-assisted testing
- Incident response, digital forensics, ransomware and business email compromise response, and threat hunting
- Virtual CISO, governance, risk and compliance advisory, and the Compliance Center
- Compliance-focused security testing (SOC 2, PCI-DSS, ISO 27001, HIPAA)
- The client portal, partner portal, API, and MCP server
All engagement services are provided subject to a separate Statement of Work ("SOW") or engagement agreement that defines the scope, timeline, deliverables, and fees for each engagement. These Terms apply in addition to any SOW or engagement agreement.
Not every service is available for every asset type. Where we lack the capability to test something meaningfully, we refuse the engagement rather than run it and report nothing. We will tell you which alternative applies.
3. AI-Assisted and Autonomous Services
Some of our services are delivered with or by Lory, our AI system. This section governs your use of them and is supplemented by our AI Usage Policy, which forms part of these Terms.
What you are agreeing to
- Autonomous testing. Where you request an AI-assisted engagement, our engine selects targets within your declared scope and executes tools against them without per-action human approval. Scope is enforced in code, tools run in non-destructive modes, and budgets are hard-capped, but testing is performed by software acting autonomously within those bounds.
- Human review of output. Every AI-generated finding is held in a pending-review state and is invisible to you until a Lorikeet penetration tester approves it. A human decides whether a finding is released and at what severity.
- Third-party model providers. Content you submit to any AI feature — chat, phone, email, portal, API, or engagement context — is transmitted to third-party model providers in the United States for inference. Under our agreements, that data is not used to train their models. If you cannot permit this, tell us and we will arrange a human-only engagement instead.
- Conversational output is not binding. Statements made by our AI assistant about pricing, scope, timelines, availability, or contractual terms are informational only and do not bind us until confirmed in writing by a person.
- Recording. Calls with our voice agent are recorded, with disclosure before recording begins.
Acceptable use of AI features
You will not: submit targets you do not own or have documented authority to have tested; submit regulated or third-party confidential data beyond what the engagement requires and permits; attempt to jailbreak, manipulate, or prompt-inject our systems outside an authorized test of Lorikeet itself; use our AI features to develop or operate malware or unauthorized-access tooling; represent unreviewed AI output as a human-performed assessment or attestation; or scrape, resell, or redistribute our AI features or their output as a competing service. We may suspend AI feature access without notice where we reasonably believe this clause is being breached, and we will tell you why.
Limits on AI output
AI output may be incomplete, inaccurate, or wrong. It is not legal, regulatory, or compliance advice and is not an attestation that any system is secure. An engagement that did not test something does not imply that thing is clean; coverage is recorded and surfaced to you per engagement. Our AI is not immune to prompt injection, and we do not claim that it is.
You can stop AI testing at any time. Call +1 (888) 652-6479, option 5, answered within 15 minutes 24/7, or use "Stop engagement" in the portal. You do not need to justify the request or diagnose the cause first. If an AI engagement causes an outage, we do not bill for it.
4. Authorization and Scope
All security testing activities performed by Lorikeet Security are conducted only with explicit written authorization from the client. You represent and warrant that you have the legal authority to authorize testing of any systems, applications, or infrastructure included in the scope of an engagement, including where those systems are hosted or operated by a third party.
Testing will be performed strictly within the scope defined in the SOW. Any changes to scope require written agreement from both parties. Lorikeet Security will not intentionally access systems or data outside the authorized scope. For AI-assisted engagements, scope is recorded as machine-readable rules and enforced at the point of every tool call; discovering an asset does not bring it into scope.
We will immediately suspend or terminate an engagement if we discover that authorization is absent, incomplete, or misrepresented. Fees for work performed up to that point remain payable.
5. Confidentiality
We take confidentiality seriously. All information obtained during an engagement, including vulnerabilities discovered, data accessed, credentials obtained, and report contents, is treated as strictly confidential.
We will not disclose any client information, findings, or engagement details to any third party without your prior written consent, except to the subprocessors listed in our Privacy Policy who process data on our behalf under contract, or as required by law. Where disclosure is legally compelled, we will notify you in advance unless prohibited from doing so.
Test credentials are deleted within 7 days of an engagement relationship ending, and immediately on request. Other client data is retained according to the schedule published in our Privacy Policy, which reflects the audit and retest obligations of security work; you may request earlier deletion and we will tell you specifically what we must retain and why.
We are willing to sign mutual Non-Disclosure Agreements ("NDAs") and Data Processing Agreements prior to any engagement.
6. Client Responsibilities
As a client, you agree to:
- Provide accurate information about the systems and applications in scope, and keep your declared asset inventory current
- Ensure you have the legal authority to authorize security testing on all in-scope systems
- Notify relevant third parties (such as cloud providers or hosting companies) of the testing, if required by their terms of service
- Provide necessary access, credentials, and documentation as outlined in the SOW, and use dedicated test accounts rather than production accounts belonging to real people wherever possible
- Designate a point of contact who is available during the testing window
- Acknowledge that security testing carries inherent risks, including potential service disruption, and maintain appropriate backups and a rollback plan
- Tell us promptly if you observe anything during a testing window that concerns you, and use the stop paths in Section 3 rather than waiting
- Not use a production environment for testing where a representative staging environment is available and you would prefer we not touch production
Where you supply credentials, you are responsible for provisioning them at the privilege level you intend us to exercise. We act as the identity you give us.
7. Deliverables and Reports
Upon completion of an engagement, Lorikeet Security will deliver a detailed report as specified in the SOW. Reports typically include an executive summary, detailed findings with severity ratings, evidence and reproduction steps, remediation recommendations, and a record of coverage — which vectors were tested and which were not.
Reports are provided for the client's internal use only and may not be shared with third parties without our written consent, except as needed to remediate findings (e.g., sharing with your development team) or to meet compliance requirements (e.g., sharing with auditors, insurers, or a prospective acquirer under confidentiality).
Free retesting of remediated findings is included within the timeframe specified in the SOW.
A report reflects a point in time. It does not certify that a system is secure, and it is not an attestation, warranty, or guarantee of compliance with any standard. Findings not reported may still exist. Coverage gaps are recorded rather than implied to be clean, and you should not present an untested area as tested.
8. Fees, Payment, and Subscriptions
Fees for services are set forth in the applicable SOW or engagement agreement. Unless otherwise specified:
- A deposit may be required prior to the start of an engagement
- Invoices are due within 30 days of receipt
- Late payments may incur interest at a rate of 1.5% per month, or the maximum permitted by law if lower
- Fees are exclusive of taxes; you are responsible for any applicable sales, use, VAT, or withholding taxes
- We reserve the right to suspend or terminate services for non-payment after written notice
Subscriptions and recurring plans
Subscription plans, retainers, and continuous testing packages are billed in advance for each term through our payment processor, Stripe. Card details are handled by Stripe and do not transit our systems.
- Subscriptions renew automatically at the end of each term at the then-current rate unless cancelled before the renewal date
- You may cancel at any time from the client portal or by contacting us; cancellation takes effect at the end of the current paid term and access continues until then
- Fees already paid are non-refundable except where required by law or where we fail to deliver a contracted engagement
- We will give at least 30 days' notice of a price increase affecting your renewal
Disputed invoices should be raised in writing within 15 days of receipt; we will not treat a good-faith disputed amount as delinquent while it is being resolved.
9. Warranties and Disclaimers
We warrant that our services will be performed in a professional and workmanlike manner consistent with generally accepted industry practice, by personnel with appropriate skill, and in accordance with the applicable SOW.
Except as expressly stated in these Terms or a signed agreement, the Site, the portals, the API, the AI features, and all deliverables are provided "as is" and "as available," without warranties of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and uninterrupted or error-free operation.
We do not warrant that all vulnerabilities will be discovered, that AI-generated output will be accurate or complete, that findings will be free of false positives, or that testing will not cause unexpected effects on your systems. We do not warrant that your use of our services will result in compliance with, or certification under, any standard or regulation.
Some jurisdictions do not allow the exclusion of certain warranties; in those jurisdictions the exclusions above apply to the maximum extent permitted.
10. Limitation of Liability
Security testing is inherently complex and involves risk. While we take every reasonable precaution to avoid disruption to your systems, we cannot guarantee that testing will not cause unexpected issues.
To the maximum extent permitted by law, Lorikeet Security's total aggregate liability arising from or related to any engagement shall not exceed the fees paid by the client for that specific engagement. In no event shall we be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, goodwill, or business opportunities, even if advised of the possibility.
We do not guarantee that all vulnerabilities will be discovered during an engagement. Security testing provides a point-in-time assessment based on the scope, methodology, and time allocated. We are not liable for loss arising from a vulnerability we did not find, from a third party's exploitation of your systems, or from your decision not to remediate a finding we reported.
These limits do not apply to liability that cannot be limited under applicable law, including fraud, willful misconduct, gross negligence, or death or personal injury caused by negligence.
If we cause impact
Separately from and without limiting the above: if our testing causes or may have caused impact to your systems, we stop testing, tell you the same day in plain language including the parts we do not yet understand, preserve the activity log before remediation, help you recover at our cost, and provide a written account within five business days. We do not bill for an engagement that caused an outage.
11. Intellectual Property
All tools, methodologies, scripts, AI skill libraries, models, prompts, platform software, and frameworks developed by Lorikeet Security remain our intellectual property. Clients receive full ownership of the deliverables (reports, findings) produced specifically for their engagement, subject to our retained rights in the underlying methodology and templates.
You retain all rights in the data, systems, and content you provide to us. You grant us a limited licence to process it solely to deliver the services you have requested.
We may use anonymized, aggregated data from engagements for research, benchmarking, and improving our services, provided no client-identifiable information is disclosed. We do not use client data to train AI models, our own or a third party's.
We will not name you as a client publicly, or use your logo, without your written permission.
12. Website Use
By using our Site, you agree not to:
- Use the Site for any unlawful purpose or in violation of any applicable laws
- Attempt to gain unauthorized access to any part of the Site, its servers, or any connected systems
- Interfere with or disrupt the Site or any connected networks
- Reproduce, duplicate, or exploit any part of the Site for commercial purposes without our written permission
Content on the Site, including blog posts, articles, and educational materials, is provided for informational purposes only. It does not constitute professional advice and should not be relied upon as a substitute for a professional security assessment.
13. Portals, API, and MCP Access
Access to the Lorikeet Security client portal, partner portal, API, and MCP server is provided to authorized users only. You are responsible for maintaining the confidentiality of your login credentials and API tokens, and for all activities that occur under your account. You must notify us immediately if you suspect any unauthorized use.
When using our API or MCP server, you additionally agree not to exceed published rate limits or circumvent them, not to use the API to access data belonging to another tenant, and not to use it to submit targets outside your authorized scope. API tokens are scoped to a single organization and we enforce that boundary server-side; attempting to cross it is a breach of these Terms.
Free tools offered on the Site are provided for informational use against systems you own or are authorized to test. Running them against systems you do not control is prohibited.
We reserve the right to suspend or terminate portal, API, or MCP access at any time for security reasons or if these Terms are violated, and we will tell you why.
14. Indemnification
You agree to indemnify, defend, and hold harmless Lorikeet Security, its officers, employees, and contractors from any claims, damages, losses, or expenses (including reasonable legal fees) arising from your breach of these Terms, your misuse of our services, AI features, or reports, your failure to obtain proper authorization for security testing, or a third party's claim arising from our testing of a system you told us you were authorized to have tested.
15. Term and Termination
Either party may terminate an engagement with written notice as specified in the applicable SOW. In the event of early termination, the client is responsible for payment of all services rendered up to the termination date.
We reserve the right to immediately suspend or terminate an engagement if we discover that the client does not have proper authorization for the systems being tested, or if continuing the engagement would violate any applicable law.
On termination
- Test credentials are deleted within 7 days
- Findings and reports remain available for 12 months so you can request copies, then are deleted; you may request immediate deletion instead and we will confirm what that removes
- Engagement records are retained per the schedule in our Privacy Policy to meet our audit and contractual obligations
- Portal access ends at the close of the current paid term
Sections covering confidentiality, intellectual property, payment obligations accrued before termination, warranties and disclaimers, limitation of liability, indemnification, governing law, and these general provisions survive termination.
16. Governing Law and Dispute Resolution
These Terms shall be governed by and construed in accordance with the laws of the State of Delaware and the applicable federal law of the United States, without regard to conflict-of-law principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Any dispute arising from these Terms or our services shall first be raised in writing and the parties shall attempt to resolve it through good-faith negotiation for 30 days. If negotiation fails, the dispute shall be resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before a single arbitrator, seated in Delaware, conducted in English. Judgment on the award may be entered in any court of competent jurisdiction.
Either party may seek injunctive relief in a court of competent jurisdiction to protect confidential information or intellectual property without first completing the process above. Disputes are resolved on an individual basis; class and representative actions are waived to the extent permitted by law. Where mandatory local law gives you the right to bring proceedings in your own jurisdiction or before a consumer body, these Terms do not remove that right.
17. General Provisions
- Entire agreement. These Terms, together with any SOW, MSA, NDA, DPA, and the policies incorporated by reference, are the entire agreement between the parties on this subject and supersede prior discussions.
- Severability. If any provision is held unenforceable, it is modified to the minimum extent necessary or severed, and the remainder stays in force.
- No waiver. Failure to enforce a provision is not a waiver of it.
- Assignment. Neither party may assign these Terms without the other's written consent, except in connection with a merger, acquisition, or sale of substantially all assets, on written notice.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, war, civil unrest, labour action, government action, internet or utility failure, or a large-scale outage at a hosting or model provider. Payment obligations are not excused.
- Independent contractors. Nothing here creates a partnership, joint venture, agency, or employment relationship.
- Subcontractors. We may use qualified subcontractors and remain responsible for their performance and for their compliance with the confidentiality obligations in these Terms.
- Notices. Legal notices to us go to support@lorikeetsecurity.com marked for the attention of Legal. Notices to you go to the account contact email on file. Notice is effective on delivery.
- Export and sanctions. You represent that you are not located in, and will not use our services on behalf of anyone in, a country or entity subject to U.S. embargo or sanctions, and that you will comply with applicable export control laws.
- Non-solicitation. During an engagement and for 12 months afterwards, neither party will knowingly solicit for employment personnel of the other who were directly involved in the engagement. General public advertising is not solicitation.
- Third-party beneficiaries. There are none.
18. Contact Us
If you have questions about these Terms of Service, please contact us at:
- Sales and contracts: sales@lorikeetsecurity.com
- Support and legal notices: support@lorikeetsecurity.com
- Security, privacy, and data protection: security@lorikeetsecurity.com
- Billing: billing@lorikeetsecurity.com
- Stop testing immediately (24/7): +1 (888) 652-6479, option 5
- Website: lorikeetsecurity.com