CyberGrid
Pen testing SOC 2 Pricing Blog Sample report Methodology Verify Help Sign in Start a scan

Service agreement

Template version 1.0 · May 19, 2026

Draft notice: This service agreement is a template. Before relying on it for any signed customer engagement, the founders intend to commission a review by qualified counsel. The structure below mirrors industry-standard agreements for vulnerability assessment services.

1. Services

CyberGrid will perform automated security scanning services as set forth in the Customer's selected plan ("Services"). Services consist of: automated vulnerability scanning, TLS configuration analysis, network port and service discovery, asset enumeration, and report and attestation generation, as applicable to the selected plan.

2. Authorization

Customer represents and warrants that it owns or has explicit written authorization from the owner of each target registered for scanning. Customer agrees to verify target ownership via the DNS-based verification mechanism provided by CyberGrid before any scan is executed.

3. Assumptions and risk

Customer acknowledges:

  • Automated security scanning may, in rare cases, cause unintended service disruption, even when destructive checks are disabled
  • CyberGrid is not responsible for interruptions, errors, or losses arising from Services performed in accordance with this Agreement
  • The Services may improve Customer's security posture but cannot identify or eliminate all security risks
  • The Services are not a penetration test and do not satisfy requirements that specifically mandate manual security testing

CyberGrid's separate Penetration Testing service (methodology-based, per-engagement) is governed by an engagement-specific Statement of Work executed at kickoff and is outside the scope of this Service Agreement. See /penetration-testing.

CyberGrid's separate SOC 2 Readiness service (consulting engagement, 90-day program — see /soc2) is similarly governed by an engagement-specific Statement of Work executed at kickoff and is outside the scope of this Service Agreement. The SOC 2 audit itself is performed and the report issued by an independent licensed CPA firm engaged directly by the Customer; CyberGrid is not a CPA firm, performs no audit work, and issues no SOC 2 opinion. CPA audit fees and any third-party GRC platform license fees (e.g., Sprinto, Drata, Vanta, Secureframe) are paid directly by the Customer to those vendors and are not included in any CyberGrid fee.

4. Deliverables

CyberGrid will provide:

  • A PDF Assessment Report containing findings, severity ratings, evidence, and remediation guidance
  • A PDF Attestation document with a public verification URL
  • Access to the dashboard for the duration of the active plan

5. Compensation

Customer pays the fees set forth in the Customer's selected plan, billed annually in advance via Stripe.

6. Confidentiality

CyberGrid and Customer agree to keep confidential any non-public information shared in connection with the Services, including findings, internal documentation, and methodology specifics. This obligation survives termination.

7. Data rights

Customer retains all rights to data submitted to the Service and to the findings generated by the Service. CyberGrid retains rights to the underlying methodology, software, and infrastructure.

8. Disclaimer of warranty

EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICES ARE PROVIDED "AS IS." CYBERGRID DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. CYBERGRID MAKES NO WARRANTY AS TO THE COMPLETENESS, ACCURACY, OR USEFULNESS OF FINDINGS OR REPORTS.

9. Limitation of liability

CYBERGRID'S AGGREGATE LIABILITY ARISING FROM OR RELATED TO THIS AGREEMENT IS LIMITED TO THE AMOUNT PAID BY CUSTOMER IN THE TWELVE MONTHS PRECEDING THE CLAIM. NEITHER PARTY IS LIABLE FOR INDIRECT, CONSEQUENTIAL, OR PUNITIVE DAMAGES.

10. Termination

Either party may terminate this Agreement upon thirty (30) days' written notice. CyberGrid retains the right to immediate termination for material breach (unauthorized scanning, non-payment).

11. Survival

Sections 6 (Confidentiality), 7 (Data rights), 8 (Disclaimer), and 9 (Limitation of liability) survive termination.

12. Entire agreement

This Service Agreement, together with the Terms of Service and Privacy Policy in effect at the time of signup, constitutes the entire agreement between the parties with respect to the Services.

CyberGrid

CyberGrid is an honest security-and-compliance practice for SaaS teams. We run a $1,999/yr automated assessment, ship manual penetration tests at a flat $4,999, and bundle both as Continuous Security ($999/mo). For audit-ready customers we also run a 90-day SOC 2 readiness program from $5,999 — policies, controls, evidence, and a referred CPA audit firm. What you read on this site is what you'll get — no upsells, no relabeling, no surprises in your auditor's inbox.

Services

Automated assessment Penetration testing SOC 2 readiness Pricing Blog Sample report

Procurement

Trust package Compliance mapping Methodology Verify attestation

Help

Help center Blog Contact About Security

Legal

Terms of service Privacy policy Service agreement Disclaimers
© 2026 CyberGrid · An honest scan, by design.