Cybersecurity Services Scope and Limitations Policy
This Policy defines the authorised scope, safe-working rules, professional responsibilities, operational limitations and fair allocation of risk applicable to cybersecurity, OSINT, vulnerability assessment, incident response and related advisory services supplied by Quantum Intelligence Hub LTD (“QIH”).
Purpose and scope
This Policy applies where it is incorporated into an order, proposal, statement of work or agreement for services including:
- cybersecurity consultancy and risk assessment;
- authorised vulnerability scanning, security review and penetration testing;
- website, hosting, WordPress, WooCommerce, server and cloud security review;
- lawful OSINT and public-exposure analysis;
- incident triage, containment support, recovery guidance and forensic assistance;
- security awareness, threat intelligence and business-continuity advice; and
- AI-supported security analysis under appropriate human oversight.
If an executed statement of work conflicts with this Policy, the specifically negotiated statement of work prevails for that engagement.
Nature and standard of the services
QIH services may be advisory, investigative, technical, educational or response-oriented, depending on the agreed scope. QIH will perform contracted services with reasonable care and skill, using methods proportionate to the authorised environment and information available at the time.
A report records findings observed within the agreed scope and assessment window. It is not a permanent certification that a system is free of vulnerability or future attack.
Written authorisation before testing
- Target domains, IP addresses, applications, accounts and environments must be identified.
- Permitted methods, testing window, contacts and stop conditions must be documented.
- The Client warrants that it has authority to permit testing of every in-scope asset.
- Where a cloud or SaaS provider requires separate permission, the Client must obtain it before testing.
- Out-of-scope assets will not be tested. Accidentally encountered data will not be explored and will be reported securely.
Safe rules of engagement
- Testing will follow the agreed method and professional standard appropriate to the service.
- Techniques presenting material availability or data-integrity risk require express approval.
- QIH and the Client will identify emergency contacts and a stop-testing procedure.
- Critical findings may be communicated securely before delivery of the final report.
- Where production systems are tested, backup and rollback arrangements should be assessed in advance.
- QIH may pause testing where continuing would create disproportionate harm or exceed authority.
Outcomes that are not guaranteed
Findings, severity and remediation
Findings are assigned severity according to evidence available at assessment. A severity rating is a professional risk assessment, not a guarantee of actual loss. Recommendations should be tested against dependencies and applied through appropriate change control.
- QIH will aim to make reports clear, traceable and consistent with scope.
- The Client remains responsible for deciding, implementing and validating remediation unless QIH has expressly accepted implementation responsibility.
- Retesting is included only where stated in the order or separately purchased.
- Reports must not be materially altered or presented out of context in a misleading manner.
OSINT and digital intelligence
OSINT work uses lawful, accessible sources and provides decision support rather than a law-enforcement or judicial determination.
- Source reliability, date and context will be considered where reasonably practicable.
- Unverified allegations will not be presented as established fact.
- QIH will not use unlawful access, identity theft, deception or unauthorised surveillance.
- Special-category or other high-risk personal data will be processed only where necessary, proportionate and supported by a valid legal basis.
- Clients must independently verify material findings before taking high-impact action.
Incident response and digital forensics
- Initial priorities may include containment, evidence preservation, reduction of business impact and appropriate escalation.
- Missing or altered logs, encryption, delayed notification and unavailable systems may materially limit an investigation.
- QIH is not a law firm or law-enforcement body and cannot guarantee admissibility of evidence or identification of an attacker.
- Forensic imaging, chain-of-custody work or expert evidence for proceedings must be expressly scoped.
- The Client should promptly consider notification of its legal adviser, cyber insurer, regulator or law-enforcement authority where appropriate.
Personal data breaches and notification
The parties will cooperate according to their legal roles where a personal data breach is suspected. The controller determines notification duties and risk. Under UK GDPR, a notifiable breach must be reported to the ICO without undue delay and, where feasible, within 72 hours after awareness; affected individuals must also be informed without undue delay where the breach is likely to result in a high risk.
Where QIH acts as processor, it will inform the controller without undue delay and within any shorter contractual period after becoming aware of a relevant breach. Official guidance: ICO Personal Data Breaches Guide.
Data, logs and confidentiality
- Only data reasonably necessary for the agreed purpose should be processed.
- The Client confirms that it is authorised to provide QIH with relevant logs and information.
- Test evidence, access material and reports will be protected by suitable access controls.
- Credentials will not ordinarily be reproduced in clear text in reports and should be shared through secure channels.
- Temporary credentials should be rotated or revoked after completion.
- Retention and secure deletion will be governed by contract, legal duties and legitimate incident requirements.
AI-supported security analysis
AI tools may support classification, summarisation or analysis. Material critical findings remain subject to appropriate human review. Client confidential information will not be uploaded to public AI services without prior assessment of contractual, privacy and security safeguards. AI output does not by itself constitute technical, forensic or legal certainty.
Client responsibilities
- Provide accurate scope, an up-to-date asset list, authority and required access.
- Maintain suitable backups, disaster recovery and business-continuity arrangements.
- Disclose known risks, sensitive dependencies and material changes.
- Maintain passwords, MFA, permissions, endpoint controls and staff security practices.
- Assess and track findings within timeframes proportionate to risk.
- Follow lawful breach, employment, privacy and sector-specific obligations.
- Not use QIH knowledge, reports or tooling for unauthorised attacks, extortion, defamation or other unlawful conduct.
Third-party systems and providers
Cloud, hosting, CDN, payment, email, security, WordPress, API or AI providers may be involved. QIH will carry out reasonable security and suitability assessment for providers it selects and manages. An independent provider failure may be outside QIH’s control; however, QIH’s own negligence in provider selection, configuration, instruction or incident response is not excluded merely because a third party was involved.
Suspension, refusal and emergency measures
QIH may refuse, pause or terminate work involving an unauthorised target, unlawful purpose, false authority, unsafe testing condition, material payment breach, sanctions concern or serious security risk. Except where urgent action is required, QIH will reasonably explain the reason and, where appropriate, allow an opportunity to remedy it.
Where QIH is expressly authorised to manage the affected infrastructure, proportionate emergency action may include blocking malicious traffic, isolating compromised components, disabling a compromised account or temporarily taking a service offline. QIH will document material action and seek to minimise disruption. Rights arising from QIH’s own breach or negligence remain unaffected.
Fair allocation of liability
- QIH does not exclude its obligation to provide contracted services with reasonable care and skill.
- QIH is not responsible for the Client’s unauthorised instruction, concealed information, failure to implement controls or independent system administration.
- Any aggregate liability cap must be expressly stated in the principal agreement and be reasonable and proportionate to the service.
- Nothing excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot lawfully be excluded. Contractual treatment of deliberate misconduct, confidentiality, data protection and intellectual-property infringement is governed by the principal agreement and mandatory law.
- Mandatory consumer rights remain protected. Official guidance: GOV.UK – Writing a Fair Contract for Customers.
Contact, updates and governing law
Security incidents: security@qihhub.com · Privacy: privacy@qihhub.com · Support: support@qihhub.com · Legal: legal@qihhub.com.
This Policy may be updated to reflect changes in threats, services, technical standards or law. Material changes will be communicated reasonably and will not retrospectively remove accrued rights. This Policy is governed by the law of England and Wales. The mandatory consumer protections and rights of redress available in a consumer’s country of residence remain unaffected.
