TERMS AND CONDITIONS

HackByLaw.com

Effective Date: 8/17/2026
Last Updated: 8/17/2026

These Terms and Conditions (“Terms”) govern access to and use of the HackByLaw.com website and the cybersecurity, penetration testing, security assessment, consulting, monitoring, and related services offered by HA SOLUTION CONSULTING INC. d/b/a HackByLaw (“HackByLaw,” “Company,” “we,” “us,” or “our”).

By accessing this website, requesting services, submitting an inquiry, purchasing a service, or entering into a service engagement with HackByLaw, you (“Customer,” “you,” or “your”) agree to these Terms.

If you do not agree to these Terms, you must not use the website or purchase or use our services.


1. SERVICES

1.1. General

HackByLaw provides cybersecurity and information-security services, which may include:

  • penetration testing;

  • vulnerability assessments;

  • network security assessments;

  • web application security testing;

  • mobile-device and mobile-application security assessments;

  • configuration and security reviews;

  • wireless security assessments;

  • security monitoring;

  • cybersecurity consulting;

  • security awareness and recommendations;

  • incident-related advisory services;

  • cybersecurity assessments of authorized devices, systems, networks, applications, and infrastructure.

The specific services provided to a Customer will be determined by the applicable service description, statement of work, proposal, order, or separately executed agreement.

1.2. Scope of Services

The exact scope of a penetration test or security assessment may include:

  • target systems;

  • IP addresses;

  • domains;

  • applications;

  • devices;

  • networks;

  • testing locations;

  • testing methods;

  • testing dates and times;

  • permitted testing techniques;

  • exclusions;

  • reporting requirements; and

  • applicable limitations.

Where a separate written agreement, Statement of Work (“SOW”), or Rules of Engagement (“ROE”) exists, that document controls the specific scope of the engagement.

1.3. No Implied Services

HackByLaw is not required to perform services, testing techniques, or activities that are not expressly included in the agreed scope.


2. AUTHORIZATION AND LEGAL AUTHORITY

2.1. Customer Authorization

The Customer represents and warrants that it:

  1. owns the systems, devices, networks, applications, data, or infrastructure being tested; or

  2. has obtained all necessary legal authorization from the owner or authorized operator to permit HackByLaw to perform the agreed security testing.

2.2. Third-Party Systems

The Customer must not request HackByLaw to test a third-party system, account, network, device, application, or infrastructure without appropriate authorization.

HackByLaw may request written evidence of authorization before testing begins.

2.3. Prohibited Testing

HackByLaw may refuse or terminate any testing activity if it reasonably believes that the requested activity:

  • lacks appropriate authorization;

  • violates applicable law;

  • involves unauthorized access to third-party systems;

  • is intended to facilitate harassment, stalking, fraud, theft, or other unlawful activity;

  • presents an unreasonable risk to persons, systems, or third parties; or

  • materially exceeds the agreed scope.

2.4. Customer Responsibility

The Customer is responsible for obtaining all required permissions from:

  • hosting providers;

  • cloud providers;

  • Internet service providers;

  • application owners;

  • network owners;

  • employees or device users where required;

  • third-party service providers; and

  • any other party whose authorization may be required.


3. PENETRATION TESTING

3.1. Nature of Testing

Penetration testing is an authorized security assessment intended to identify vulnerabilities and demonstrate potential security weaknesses.

Depending on the engagement, testing may include:

  1. information gathering;

  2. vulnerability analysis;

  3. authentication testing;

  4. configuration analysis;

  5. network security analysis;

  6. application security testing;

  7. controlled exploitation;

  8. wireless security testing;

  9. simulated attacks;

  10. security validation; and

  11. reporting and recommendations.

Not every engagement will include every activity.

3.2. Potential Impact

Security testing can potentially cause:

  • temporary service interruption;

  • system instability;

  • application errors;

  • account lockouts;

  • network disruption;

  • increased system load;

  • loss or corruption of test data; or

  • other unintended effects.

HackByLaw will use commercially reasonable measures to minimize unnecessary disruption, but no penetration test can be guaranteed to be completely risk-free.

3.3. Backups

The Customer is responsible for maintaining appropriate backups and recovery mechanisms before testing begins.


4. BLACK BOX, GREY BOX AND WHITE BOX TESTING

Depending on the engagement, HackByLaw may perform:

Black Box Testing — limited information is provided to the tester before testing.

Grey Box Testing — selected information or credentials are provided.

White Box Testing — extensive technical information, credentials, architecture documentation, or source code may be provided.

The applicable engagement documentation will specify the testing methodology.


5. CUSTOMER RESPONSIBILITIES

The Customer agrees to:

  • provide accurate information;

  • provide necessary access and credentials;

  • identify authorized testing targets;

  • identify systems that must not be tested;

  • provide relevant technical documentation where applicable;

  • maintain backups;

  • identify emergency contacts;

  • cooperate with reasonable requests from HackByLaw;

  • notify HackByLaw of material changes to the testing environment;

  • promptly report any suspected adverse impact caused by testing.

Where information is required for the performance of services, the Customer should provide the requested information within the period specified in the applicable SOW or engagement agreement.


6. TESTING SCHEDULE

Testing will be performed during the dates and times agreed upon by the parties.

Where required by the engagement, testing may be conducted during:

  • normal business hours; or

  • an agreed maintenance/testing window.

Testing may be paused or terminated if HackByLaw reasonably determines that continuation creates an unacceptable risk to the Customer, third parties, or critical infrastructure.


7. REPORTS AND DELIVERABLES

7.1. Security Report

Following completion of the applicable testing phase, HackByLaw may provide a written security report containing, as applicable:

  • description of testing performed;

  • identified vulnerabilities;

  • severity ratings;

  • affected systems;

  • evidence of findings;

  • technical observations;

  • risk descriptions;

  • recommendations;

  • remediation guidance;

  • conclusions.

7.2. Customer-Specific Recommendations

Recommendations will be developed based on the findings identified during the applicable engagement and the information reasonably available to HackByLaw.

7.3. No Guarantee of Complete Security

A penetration test is an assessment performed within a defined scope and period.

A successful assessment does not guarantee that:

  • no vulnerabilities exist;

  • all vulnerabilities have been identified;

  • future vulnerabilities will not arise;

  • third parties cannot compromise the Customer’s systems; or

  • the Customer’s systems are completely secure.


8. ACCEPTANCE OF SERVICES

Unless otherwise provided in the applicable engagement agreement, the Customer will have [2–5] business days after delivery of the applicable report or deliverable to notify HackByLaw in writing of any material deficiency in the agreed services.

The notice should reasonably identify:

  • the alleged deficiency;

  • the applicable contractual requirement; and

  • the requested corrective action.

HackByLaw will have a reasonable opportunity to investigate and, where appropriate, correct a material deficiency in the services.


9. FEES AND PAYMENT

9.1. Fees

Fees will be stated in the applicable:

  • proposal;

  • invoice;

  • Statement of Work;

  • order;

  • service agreement; or

  • other written pricing document.

9.2. Payment

Unless otherwise agreed in writing, payment is due according to the payment terms stated on the applicable invoice or agreement.

9.3. Expenses

Any travel, special equipment, third-party services, or other reimbursable expenses must be approved or addressed in the applicable engagement documentation.

9.4. Taxes

Applicable taxes, if any, will be charged where legally required.

The Customer should not assume that a particular percentage of sales tax applies to cybersecurity services. California generally does not impose sales/use tax on services where the transaction is truly for services rather than a taxable sale of tangible personal property. (CDTFA)


10. CANCELLATION AND TERMINATION

Either party may terminate an engagement as provided in the applicable service agreement.

HackByLaw may suspend or terminate services if:

  • payment is materially overdue;

  • required authorization is withdrawn;

  • the Customer requests unlawful activity;

  • the Customer materially exceeds the agreed scope;

  • continued testing presents an unreasonable security or operational risk;

  • the Customer materially breaches the agreement.

Upon termination, the Customer remains responsible for payment for services properly performed up to the effective termination date, subject to the applicable agreement.


11. CONFIDENTIALITY

11.1. Confidential Information

Confidential Information includes information that is:

  • non-public;

  • proprietary;

  • technical;

  • operational;

  • security-related;

  • personally identifiable;

  • commercially sensitive; or

  • expressly identified as confidential.

11.2. Protection

Each party agrees to use reasonable measures to protect the other party’s Confidential Information against unauthorized access, use, disclosure, or dissemination.

11.3. Permitted Disclosure

Confidential Information may be disclosed where required by:

  • law;

  • valid legal process;

  • court order;

  • governmental authority; or

  • regulatory requirement.

Where legally permitted, the receiving party will provide reasonable notice before disclosure.

11.4. Duration

Confidentiality obligations will continue after completion or termination of the applicable engagement, subject to applicable law and the terms of any separate confidentiality agreement.


12. CUSTOMER DATA

HackByLaw may receive or access Customer data solely to the extent reasonably necessary to perform the agreed services.

HackByLaw will not intentionally use Customer data for unrelated purposes.

The Customer remains responsible for determining what information it provides to HackByLaw and for ensuring that it has the legal right to provide such information.


13. DATA RETENTION AND DELETION

Upon completion of an engagement, HackByLaw may delete or return Customer information in accordance with the applicable engagement agreement and its internal retention procedures.

However, HackByLaw may retain:

  • invoices;

  • contracts;

  • legal records;

  • audit records;

  • records required by law;

  • security logs;

  • limited records necessary to establish the performance of contractual obligations.

Where legally or operationally appropriate, retained information will remain subject to applicable confidentiality obligations.


14. INTELLECTUAL PROPERTY

14.1. HackByLaw Materials

Unless expressly transferred in writing, HackByLaw retains ownership of its:

  • methodologies;

  • tools;

  • scripts;

  • templates;

  • frameworks;

  • processes;

  • know-how;

  • software;

  • pre-existing intellectual property.

14.2. Customer Materials

The Customer retains ownership of its:

  • systems;

  • data;

  • documents;

  • trademarks;

  • software;

  • content; and

  • other pre-existing intellectual property.

14.3. Reports

Unless otherwise agreed, the Customer receives a right to use the final security report internally for its legitimate business, security, compliance, and remediation purposes.

HackByLaw does not automatically transfer ownership of its underlying methodologies, tools, or proprietary materials used to create the report.


15. THIRD-PARTY SERVICES

Some security assessments may involve third-party infrastructure, software, cloud services, hosting providers, or security tools.

HackByLaw is not responsible for failures, outages, restrictions, or changes imposed by third-party providers outside HackByLaw’s reasonable control.

The Customer remains responsible for obtaining authorization from third parties where required.


16. THIRD-PARTY SUBCONTRACTORS

HackByLaw may use qualified personnel or subcontractors where permitted by the applicable agreement.

HackByLaw will remain responsible for the performance of subcontracted services to the extent provided in the applicable agreement.

Where the engagement requires prior written approval for subcontractors, HackByLaw will obtain such approval before engaging them.


17. SECURITY INCIDENTS

If HackByLaw becomes aware of an incident involving Customer information in its possession or control that materially affects the confidentiality or security of that information, HackByLaw will take commercially reasonable steps consistent with applicable law and the applicable agreement.


18. LIMITATION OF LIABILITY

TO THE MAXIMUM EXTENT PERMITTED BY LAW, HACKBYLAW WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF BUSINESS OPPORTUNITY, OR LOSS OF DATA, ARISING FROM OR RELATED TO THE SERVICES.

Except to the extent prohibited by applicable law, HackByLaw’s aggregate liability arising out of an engagement will not exceed the amount actually paid by the Customer for the specific services giving rise to the claim during the [six/twelve] months preceding the event giving rise to the claim.

This limitation should be reviewed by a California attorney before publication, particularly because your penetration-testing activities can involve intentional interaction with customer systems.


19. NO WARRANTY

Except as expressly stated in a written agreement, services are provided based on the agreed scope and methodology.

HackByLaw does not warrant that a security assessment will identify every vulnerability, threat, attack path, misconfiguration, or security weakness.

No security assessment can guarantee that a Customer’s systems will not subsequently be compromised.


20. INDEMNIFICATION

To the extent permitted by applicable law, each party agrees to be responsible for claims, damages, liabilities, and reasonable costs arising from its own:

  • breach of these Terms;

  • violation of applicable law;

  • unauthorized conduct; or

  • gross negligence or willful misconduct.

The Customer specifically agrees to indemnify HackByLaw for claims arising from the Customer’s failure to obtain authorization to test systems belonging to third parties, except to the extent caused by HackByLaw’s own misconduct.


21. FORCE MAJEURE

Neither party will be responsible for delay or failure to perform caused by circumstances beyond its reasonable control, including:

  • natural disasters;

  • fire;

  • flood;

  • earthquake;

  • war;

  • terrorism;

  • governmental actions;

  • widespread Internet outages;

  • major telecommunications failures;

  • cloud-provider failures;

  • cyberattacks affecting critical infrastructure; or

  • other events that could not reasonably have been prevented.

The affected party will notify the other party as reasonably practicable.


22. DISPUTE RESOLUTION

The parties will first attempt in good faith to resolve disputes through direct communication.

If a dispute cannot be resolved informally, the dispute will be handled according to the dispute-resolution procedure stated in the applicable service agreement.

California law will govern the interpretation of these Terms, except where applicable law requires otherwise.

Any arbitration provision, venue selection, or class-action waiver should be stated carefully in the final contract and reviewed for enforceability under applicable California law.


23. WEBSITE USE

You may use HackByLaw.com only for lawful purposes.

You may not:

  • attempt to gain unauthorized access to the website;

  • interfere with website operation;

  • introduce malicious code;

  • conduct unauthorized security testing;

  • scrape or abuse the website;

  • impersonate HackByLaw;

  • use the website to facilitate unlawful activity.

HackByLaw reserves the right to restrict access where reasonably necessary to protect the website, users, or Company systems.


24. CHANGES TO SERVICES

HackByLaw may modify, suspend, or discontinue portions of the website or services.

Changes to an already-executed service engagement will be governed by the applicable agreement and will not automatically modify the agreed scope or price.


25. CHANGES TO THESE TERMS

HackByLaw may update these Terms from time to time.

The updated version will be posted on HackByLaw.com with a revised “Last Updated” date.

Changes will apply prospectively unless otherwise required by law or expressly agreed with the Customer.


26. SEVERABILITY

If any provision of these Terms is determined to be invalid or unenforceable, the remaining provisions will remain in effect to the extent permitted by law.


27. NO WAIVER

Failure to enforce any provision of these Terms does not constitute a waiver of the right to enforce that provision later.


28. ENTIRE AGREEMENT

For a specific cybersecurity engagement, these Terms, together with the applicable:

  • Statement of Work;

  • Proposal;

  • Rules of Engagement;

  • Service Agreement;

  • Appendices;

  • Data Processing Agreement, if applicable; and

  • other expressly incorporated documents

constitute the agreement governing the applicable services.

If there is a conflict between these Terms and a separately executed written service agreement, the separately executed agreement will control with respect to that engagement.


29. ELECTRONIC COMMUNICATIONS AND SIGNATURES

The parties may use electronic communications and electronic signatures where permitted by applicable law.

Electronic copies of agreements, reports, invoices, acceptance certificates, and other engagement documents may be treated as originals to the extent permitted by law.


30. CONTACT INFORMATION

HackByLaw / HA SOLUTION CONSULTING INC.

Website: HackByLaw.com

Email: [INSERT EMAIL]

Address: [INSERT BUSINESS ADDRESS]

Telephone: [INSERT PHONE]


unpaid amounts may accrue interest at the lesser of 1% per month or the maximum rate permitted by applicable law.