Customer Terms and Conditions

Effective Date: 10/08/2026

1. Agreement

These Customer Terms govern Services supplied by Capture The Bug Limited (“CTB”) to the customer identified in an Order Form, Statement of Work, Proposal, Quote or other ordering document (“Customer”).

The agreement consists of:

  • the applicable Order Form or Statement of Work;
  • any agreed Rules of Engagement;
  • these Customer Terms;
  • the Data Processing Agreement, where applicable;
  • the SLA, where applicable; and
  • other documents expressly incorporated by reference.

If documents conflict, the above order applies unless expressly agreed otherwise.

2. Services

CTB may provide:

  • Penetration Testing as a Service;
  • web application penetration testing;
  • API penetration testing;
  • mobile application penetration testing;
  • external infrastructure testing;
  • internal infrastructure testing;
  • cloud security assessments;
  • network penetration testing;
  • vulnerability validation;
  • retesting;
  • vulnerability management;
  • security reporting;
  • remediation support; and
  • related professional services.

Specific Services will be identified in the applicable Order Form.

3. PTaaS Platform

CTB may provide access to a cloud-based platform through which authorised Customer users may:

  • request assessments;
  • manage scope;
  • track assessments;
  • communicate with CTB;
  • review vulnerabilities;
  • access evidence;
  • manage remediation;
  • request retests; and
  • download reports.

CTB grants Customer a non-exclusive, non-transferable right to use the Platform during the applicable subscription or engagement term.

4. Authorisation to test

Customer expressly authorises CTB and authorised CTB personnel to perform the security-testing activities described in the agreed scope.

Customer warrants that it:

  • owns the Target Systems; or
  • has sufficient authority from the owner to authorise testing.

Customer is responsible for obtaining third-party or hosting-provider approvals.

5. Scope

Testing will be limited to the Target Systems, techniques and testing window agreed between the parties.

Material scope changes may result in:

  • additional fees;
  • revised delivery dates;
  • additional testing effort; or
  • a replacement Order Form.

CTB is not required to test systems outside agreed scope.

6. Rules of Engagement

Testing will be performed under agreed Rules of Engagement.

Unless expressly included, testing does not include:

  • denial-of-service testing;
  • destructive testing;
  • social engineering;
  • physical security testing;
  • phishing;
  • persistent malware deployment; or
  • intentional disruption of production systems.

7. Testing methodology

CTB will use commercially reasonable penetration-testing methods appropriate to the engagement.

Testing may involve manual and automated techniques.

CTB does not warrant that every vulnerability will be identified.

Security conditions may change following completion of an assessment.

8. Personnel

CTB may assign appropriately qualified employees or contractors to engagements.

CTB remains responsible for delivery of the contracted Services.

Personnel with access to Customer Confidential Information will be subject to confidentiality obligations.

9. Customer responsibilities

Customer must:

  • provide accurate scope information;
  • identify critical systems;
  • provide required access;
  • provide suitable test accounts where necessary;
  • identify prohibited testing actions;
  • maintain backups;
  • obtain required approvals;
  • provide emergency contacts;
  • communicate material environment changes; and
  • respond reasonably promptly to testing queries.

Delays caused by Customer may affect delivery dates.

10. Testing in production

Where Customer authorises production testing, Customer acknowledges that penetration testing may create operational risk.

CTB will take reasonable measures to minimise disruption but cannot guarantee that authorised security testing will have no operational impact.

11. Emergency stop

Either party may request immediate suspension of testing where continued activity may reasonably create a material security, safety or availability risk.

Testing will resume after the parties agree it is appropriate to proceed.

12. Findings

CTB will classify vulnerabilities using its standard methodology or another agreed methodology.

Severity ratings reflect CTB's professional assessment at the time of testing.

Customer remains responsible for determining remediation priorities in the context of its own risk environment.

13. Critical vulnerabilities

Where CTB identifies a vulnerability reasonably assessed as requiring urgent attention, CTB will use reasonable efforts to notify the designated Customer contact promptly rather than waiting for the final report.

14. Reports

Unless otherwise agreed, Customer will receive a report describing:

  • scope;
  • testing approach;
  • identified findings;
  • severity;
  • evidence;
  • risk explanation; and
  • remediation recommendations.

Reports represent findings during the applicable assessment period.

15. Retesting

Where included in the Order Form, CTB will retest remediated findings within the applicable entitlement period.

Material changes to the affected system may require additional testing beyond ordinary retesting.

16. Fees

Customer will pay fees identified in the Order Form.

Unless otherwise stated:

  • fees are exclusive of applicable taxes;
  • invoices are payable within 30 days;
  • undisputed overdue amounts may accrue reasonable collection costs; and
  • CTB may suspend Services for materially overdue invoices after reasonable notice.

17. Subscriptions and renewal

Where Services are purchased as an annual subscription, the subscription period and renewal mechanism will be stated in the Order Form.

No automatic renewal applies unless stated in the applicable Order Form.

18. Confidentiality

Each party must protect the other party's Confidential Information using at least reasonable care.

Confidential Information includes:

  • penetration-testing reports;
  • vulnerability findings;
  • credentials;
  • architecture;
  • technical documentation;
  • security configurations;
  • non-public product information;
  • pricing;
  • commercial information; and
  • other information reasonably understood to be confidential.

A receiving party may disclose Confidential Information to personnel, contractors and professional advisers who need access and are bound by appropriate confidentiality duties.

Confidentiality obligations do not apply to information that:

  • is lawfully public;
  • was already lawfully known;
  • is independently developed;
  • is lawfully obtained without restriction; or
  • must be disclosed by law.

19. Customer Data

Customer retains ownership of Customer Data.

Customer grants CTB a limited right to process Customer Data as necessary to provide, secure and improve the Services and fulfil legal obligations.

CTB will not sell Customer Data.

20. Deliverable ownership

Upon payment of applicable fees, Customer may use customer-specific penetration-testing reports and deliverables for:

  • internal security purposes;
  • board reporting;
  • auditors;
  • insurers;
  • customers;
  • regulators;
  • prospective investors; and
  • legitimate compliance activities,

subject to confidentiality requirements.

CTB retains ownership of pre-existing methodologies, software, templates, tools and general know-how.

21. De-identified information

CTB may use aggregated or de-identified information that does not identify Customer or expose Customer Confidential Information for:

  • service improvement;
  • benchmarking;
  • analytics; and
  • security research.

22. Data protection

Each party will comply with applicable privacy and data-protection laws.

Where CTB processes personal data on behalf of Customer, the CTB Data Processing Agreement applies where incorporated into the engagement.

23. Security

CTB will maintain reasonable technical and organisational safeguards designed to protect Customer Data against unauthorised access, use, alteration or disclosure.

24. Security incidents

CTB will investigate confirmed security incidents materially affecting Customer Data and provide notifications required under applicable law or contractual commitments.

25. Warranties

CTB warrants that it will perform Services with reasonable care, skill and professionalism consistent with generally accepted cybersecurity industry practices.

CTB does not warrant that:

  • all vulnerabilities will be detected;
  • a system is or will become completely secure;
  • remediation will eliminate all risk;
  • exploitation will never occur; or
  • the Platform will always operate without interruption.

26. Customer warranties

Customer warrants that:

  • testing is authorised;
  • information supplied to CTB is materially accurate;
  • Customer will not use CTB deliverables unlawfully; and
  • Customer has authority to provide data supplied to CTB.

27. Indemnity for unauthorised testing

Customer will indemnify CTB against third-party claims arising directly from Customer's failure to obtain legally required permission for CTB to test a Target System, except to the extent caused by CTB testing beyond the agreed scope.

28. Limitation of liability

To the maximum extent permitted by law:

  • Neither party will be liable for indirect, consequential, special or punitive damages, or for loss of profits, goodwill or anticipated savings.
  • Each party's aggregate liability arising out of an engagement will not exceed the fees paid or payable to CTB under the applicable Order Form during the 12 months preceding the event giving rise to liability.

The limitation will not apply to liability that cannot legally be limited and may not apply to:

  • fraud;
  • wilful misconduct;
  • infringement of the other party's intellectual property;
  • breach of confidentiality; or
  • indemnity obligations,

to the extent expressly stated in an applicable Order Form or required by law.

29. Insurance

Each party will maintain insurance reasonably appropriate to its business and obligations.

Specific insurance requirements may be included in an Order Form.

30. Suspension

CTB may suspend Services where reasonably necessary because of:

  • security risk;
  • unlawful activity;
  • unauthorised testing instructions;
  • sanctions or legal requirements;
  • material contract breach; or
  • materially overdue payments.

31. Termination for cause

Either party may terminate an affected agreement for material breach if the breach is not remedied within 30 days after written notice, where capable of remedy.

Immediate termination may occur for serious unlawful activity, insolvency or a breach that cannot reasonably be cured.

32. Effect of termination

Upon termination:

  • outstanding fees become payable;
  • Customer access may cease;
  • each party will return or securely destroy Confidential Information where required; and
  • provisions intended to survive termination will remain effective.

33. Force majeure

Neither party is liable for delay caused by events beyond its reasonable control, excluding Customer's obligation to pay amounts already due.

34. Compliance

Each party will comply with laws applicable to its performance under the Agreement, including applicable:

  • anti-bribery laws;
  • sanctions requirements;
  • privacy laws; and
  • export-control laws.

35. Publicity

CTB will not publicly identify Customer as a customer or use Customer's logo for marketing without permission, unless expressly agreed.

36. Assignment

Neither party may assign the Agreement without consent, except in connection with a merger, restructuring or sale of substantially all relevant business assets, provided the assignee assumes the assigning party's obligations.

37. Notices

Formal legal notices must be provided to the contact details identified in the Order Form or another formally notified address.

38. Entire agreement

The Agreement constitutes the entire agreement concerning the relevant Services and supersedes prior discussions relating to those Services.

Customer purchase-order terms do not amend the Agreement unless CTB expressly accepts them in writing.

39. Governing law

The Agreement is governed by New Zealand law.

The parties submit to the jurisdiction of the courts of New Zealand.

40. Electronic acceptance

The Agreement may be executed electronically and in counterparts.

Use of the Platform or commencement of Services following an accepted Order Form may constitute acceptance where expressly stated in the applicable ordering process.

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.