Terms & Conditions
1. Definitions and interpretation
In these Terms & Conditions:
- “Nanorisk” means Nanorisk Limited.
- “Client” or “Customer” means the organisation purchasing Services from Nanorisk.
- “Contract” means the agreement formed between Nanorisk and the Client, comprising these Terms & Conditions, the applicable Statement of Work, and the associated Quote.
- “Services” means the security assessment and related services provided by Nanorisk as defined in a Statement of Work.
- “Statement of Work” (SOW) means a statement of work describing the Services to be provided, made available and executed electronically or in writing, including via the Nanorisk Security Portal.
- “Quote” means a project quotation setting out commercial terms, made available electronically, including via the Nanorisk Security Portal.
- “Nanorisk Security Portal” means Nanorisk’s secure online platform used to facilitate administration, execution, and delivery of Services.
- “Deliverables” means any reports, findings, or other outputs produced by Nanorisk as part of the Services, as defined in the applicable Statement of Work.
2. Contract formation
2.1 A Contract is formed when the Client accepts a Quote and/or Statement of Work, whether electronically via the Nanorisk Security Portal or by other written or electronic means.
2.2 These Terms & Conditions apply to all Services provided by Nanorisk unless expressly varied in writing.
2.3 In the event of conflict, the order of precedence shall be:
- The applicable Statement of Work
- These Terms & Conditions
- The Quote
3. Scope of services
3.1 Nanorisk shall provide the Services strictly in accordance with the applicable Statement of Work.
3.2 Any services not expressly defined in the Statement of Work are out of scope unless agreed in writing.
3.3 Nanorisk does not provide legal, regulatory, or compliance advice unless explicitly stated in the Statement of Work.
4. Authorisation and lawful testing
4.1 Where the Services include security testing activities that may constitute offences under the Computer Misuse Act 1990 if unauthorised, the Client grants consent for such activities to be performed strictly in accordance with the applicable Statement of Work.
4.2 The Client confirms that it has authority over the in-scope systems and any associated data and that all required third-party permissions have been obtained.
4.3 Nanorisk shall not perform testing outside the authorised scope and reserves the right to suspend Services if authorisation is absent, unclear, or withdrawn.
5. Client responsibilities
5.1 The Client shall:
- provide accurate and complete information required for delivery of the Services
- provide timely access, credentials, and documentation
- notify relevant stakeholders of authorised testing activity
- maintain appropriate backups of systems and data
5.2 Delays or failures caused by incomplete or inaccurate information may result in rescheduling or additional charges.
6. Fees and payment
6.1 Fees are as set out in the applicable Quote.
6.2 Unless otherwise stated, invoices are payable within 30 days of issue.
6.3 Nanorisk reserves the right to suspend Services for overdue payments.
6.4 All fees are exclusive of VAT unless stated otherwise.
7. Cancellation and rescheduling
7.1 Cancellation terms are defined in the applicable Statement of Work.
7.2 Nanorisk may treat rescheduling as cancellation where delivery impact or resource allocation is affected.
8. Data protection and confidentiality
8.1 Each party shall comply with applicable data protection legislation, including the Data Protection Act 2018 and UK GDPR.
8.2 Nanorisk shall handle Client data securely and solely for the purposes of delivering the Services.
8.3 Both parties shall treat confidential information as confidential and shall not disclose it to third parties except as required by law.
8.4 Confidentiality obligations survive termination of the Contract.
See also our Privacy Notice.
9. Reports and deliverables
9.1 Reports and deliverables are provided for the Client’s internal use unless otherwise agreed.
9.2 Reports reflect a point-in-time assessment and do not guarantee the absence of vulnerabilities.
9.3 Nanorisk retains ownership of its methodologies, tools, and intellectual property.
10. Limitation of liability
10.1 Nanorisk shall not be liable for:
- indirect or consequential loss
- loss of profits, revenue, or business
- loss arising from reliance on findings beyond their intended purpose
10.2 Nanorisk’s total liability under any Contract shall be limited to the total fees paid for the applicable Services, except where liability cannot be excluded under law.
11. Warranties and disclaimers
11.1 Nanorisk warrants that Services will be provided with reasonable skill and care.
11.2 No warranty is given that all vulnerabilities will be identified.
11.3 The Client acknowledges that security testing carries inherent technical and operational risks.
12. Suspension and termination
12.1 Either party may terminate a Contract for material breach not remedied within a reasonable period.
12.2 Nanorisk may suspend Services immediately where continued delivery would be unlawful or unsafe.
13. Use of the Nanorisk Security Portal
13.1 The Nanorisk Security Portal may be used to facilitate the administration, execution, and delivery of Contracts.
13.2 Electronic acceptance and execution via the portal shall be deemed valid and binding.
13.3 Portal availability does not replace the contractual authority defined within the Statement of Work.
14. Force majeure
Neither party shall be liable for failure or delay caused by events beyond reasonable control.
15. Governing law and jurisdiction
These Terms & Conditions and any Contract shall be governed by the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction.
16. Entire agreement
The Contract constitutes the entire agreement between the parties and supersedes all prior discussions or agreements relating to the Services.
Download the signed PDF (NR-1, 187 KB)