Terms & Conditions
Anchor Cyber Terms & Conditions of Service
These Terms & Conditions of Services (“T’s & C’s”) govern all services provided by Anchor Cyber, Inc. (“Anchor Cyber”) to the client (“Client”) as described in one or more proposals, statements of work, or similar documents (each, a “Statement of Work” or “SOW”).
By accepting a SOW or any services from Anchor Cyber, Client agrees that it is bound by these T’s & C’s. These T’s and C’s and each executed Statement of Work constitute the complete and exclusive agreement between Anchor Cyber and Client (the “Agreement”) with respect to the services provided hereunder.
1. Scope of Services
Anchor Cyber will provide cybersecurity advisory, compliance, and related services as expressly described in each SOW.
Anchor Cyber reserves the right to reasonably adjust the methods, tools, and personnel used to perform services, provided the overall scope of the applicable SOW is not materially changed.
For the avoidance of doubt, the following are expressly excluded from all engagements unless separately agreed in writing:
(a) Legal Advice: Anchor Cyber does not provide legal advice. Nothing in any deliverable constitutes legal counsel. Client should engage qualified legal counsel for assessment of its compliance obligations.
(b) Penetration Testing: Unless expressly included in a SOW, Anchor Cyber does not perform penetration testing, active exploitation, red team operations, or any service involving unauthorized access to systems.
(c) Incident Response: Anchor Cyber’s services do not include incident response, digital forensics, breach notification, or crisis management unless specifically scoped in a separate SOW.
(d) Ongoing Monitoring: No engagement includes continuous monitoring, managed security services, or ongoing compliance management unless separately contracted.
(e) Guarantee of Award or Contract: Anchor Cyber makes no representation that completion of any service will result in Client receiving or retaining any government contract, award, or certification.
(f) CMMC Certification: Anchor Cyber is not a Certified Third-Party Assessment Organization (C3PAO) and does not perform CMMC certifications. Services offered under a SOW do not constitute a CMMC certification or a representation that Client meets any CMMC, NIST, or DFARS requirement. Services are readiness and advisory only.
2. Advisory Nature of Services (No Guarantee of Compliance)
Anchor Cyber provides advisory, assessment, and documentation services only.
Client acknowledges that:
Anchor Cyber does not guarantee compliance, certification, or audit outcomes
Compliance depends on Client’s proper implementation and ongoing operations
Regulatory frameworks (including CMMC, NIST, DFARS) may change
Anchor Cyber’s services are advisory in nature and do not constitute legal, accounting, or professional engineering advice.
Scores, assessments, and documentation prepared by Anchor Cyber reflect conditions observed at the time of the engagement and may not remain accurate thereafter.
No assessment, score, System Security Plan, or other deliverable prepared by Anchor Cyber constitute a certification or representation that Client meets any legal, regulatory, or contractual requirement.
3. Client Responsibilities
Client is responsible for:
Properly implementing and maintaining all security controls
Providing accurate and complete information
Ensuring prompt availability of personnel and resources as requested by Anchor Cyber to perform its services
Managing and updating its IT environment, vendors, and systems
Promptly notifying Anchor Cyber of any material changes to its IT environment, systems, or security posture during an engagement
Independently reviewing all deliverables and engaging qualified legal counsel or other qualified professionals to assess its compliance obligations
Anchor Cyber is not responsible for Client’s failure to implement recommendations. Client acknowledges that any inaccurate, incomplete, or misleading information provided to Anchor Cyber may render deliverables inaccurate, and Client releases Anchor Cyber from liability arising from such inaccuracies.
4. Change Orders and Out-of-Scope Work
Services not expressly included in a SOW are out of scope.
Anchor Cyber shall have no obligation to perform out-of-scope work absent a fully executed change order. Verbal authorizations or email approvals shall not constitute binding change orders unless confirmed in a change order signed by authorized representatives of both parties; provided, however, that out-of-scope services requested by Client and performed by Anchor Cyber will result in an adjustment of fees absent a formal written change order.
5. Regulatory and Technology Changes
Client acknowledges that cybersecurity requirements and technologies evolve.
Any additional work required due to regulatory updates, technology changes, or environmental changes shall be considered out of scope and will result in additional fees that may be billed separately.
Anchor Cyber makes no representation that any deliverable, score, plan, or recommendation will remain current, sufficient, or compliant following changes to applicable regulations, frameworks, or government guidance. Ongoing monitoring, updating, and re-assessment by Anchor Cyber shall require a separate engagement or change order to the Agreement.
6. Third-Party Systems and Vendors
Anchor Cyber is not responsible for:
Third-party platforms, tools, or service providers
Vendor failures or vulnerabilities
Security incidents arising from third-party systems
The accuracy, availability, or reliability of any third-party data, software, or cloud services used or accessed during an engagement
Any findings or deliverables that rely upon inaccurate output from third-party scanning or assessment tools
Client is solely responsible for evaluating its own third-party and supply chain risk and for independently assessing the security posture of its vendors and subcontractors.
7. Fees and Payment Terms
Client agrees to pay all fees in accordance with payment terms in the applicable Statement of Work (SOW).
Unless otherwise stated:
Payments are due as outlined in the SOW
Anchor Cyber may suspend services for non-payment
Client remains responsible for all incurred fees
All fees are non-refundable once work has commenced on the applicable phase or deliverable, except as expressly provided in the SOW
Disputed invoices must be raised in writing within ten (10) days of invoice date; amounts not subject to a good faith dispute remain due and payable
8. Nonpayment and Suspension of Services
If payment is not received when due:
Anchor Cyber reserves the right to suspend or delay services until payment is brought current
Anchor Cyber may withhold any or all deliverables, including but not limited to reports, documentation, System Security Plans (SSPs), scoring results, or other work product, until all outstanding invoices are paid in full
Any project timelines or delivery dates shall be automatically extended for the duration of such delay
Interest shall accrue on overdue balances at the rate of 1.5% per month (18% per annum), from the original due date until paid in full
Client shall reimburse Anchor Cyber for all reasonable costs of collection, including attorney’s fees and all costs and expenses, whether or not legal action is required to recover unpaid amounts.
Anchor Cyber shall not be liable for any impact, delays, or consequences resulting from suspension of services or withholding of deliverables due to nonpayment.
Client remains responsible for all fees incurred prior to suspension or termination.
9. Confidentiality
Each party agrees to protect confidential information of the other party and use it solely for purposes of the engagement.
“Confidential Information” means any non-public information disclosed by one party to the other, whether orally or in writing, whether or not designated as confidential, including without limitation business plans, pricing, methodologies, strategies, customer lists, security assessments, technical data, and Anchor Cyber’s deliverables.
Neither party shall disclose Confidential Information to any third party without prior written consent, except to employees or advisors bound by obligations no less protective than those in the Agreement.
Either party may disclose Confidential Information to the extent required by applicable law or court order, provided such party gives the other prompt written notice (to the extent legally permitted) and cooperates with the other party’s reasonable efforts to seek a protective order.
10. Intellectual Property
Anchor Cyber retains ownership of all pre-existing methodologies, templates, frameworks, tools, and know-how. Client retains ownership of Client-specific information and receives a perpetual internal-use license to all engagement-specific deliverables.
Client is granted a non-exclusive, non-transferable license to use deliverables for internal business purposes only.
Client may not resell, sublicense, publicly distribute, or use Anchor Cyber deliverables in any commercial offering without prior written consent.
Any feedback or suggestions provided by Client regarding Anchor Cyber’s methodologies, templates, frameworks, tools, and/or deliverables may be freely used by Anchor Cyber without obligation or attribution to Client.
11. Disclaimer of Warranties
Services are provided “as is” without warranties of any kind, including:
Fitness for a particular purpose
Continuous compliance or security
Accuracy or completeness
Non-infringement.
That results will meet any specific compliance threshold, government requirement, or audit standard.
That services will be uninterrupted or error-free.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, ANCHOR CYBER EXPRESSLY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE.
12. Limitation of Liability
To the maximum extent permitted by law:
Anchor Cyber’s total liability shall not exceed the total fees paid under the applicable SOW. In no event shall Anchor Cyber’s aggregate liability across all SOWs exceed the total fees paid in the twelve (12) months preceding the event giving rise to the claim.
Anchor Cyber shall not be liable for:
Indirect or consequential damages
Loss of profits, data, or business
Security breaches or cyber incidents
Regulatory fines, penalties, or sanctions imposed on Client by any government or certifying body
Loss of a contract, government award, or business opportunity arising from a failed audit or certification
Any claim based on Client’s failure to implement recommendations within a reasonable time
Client expressly acknowledges and agrees that:
(a) SPRS scores, SSPs, and CMMC readiness assessments are point-in-time assessments based solely on information provided by Client and conditions observed during the engagement;
(b) Any score or documentation submitted by Client to the government or any third party is submitted at Client’s sole discretion and risk;
(c) Anchor Cyber shall have no liability for government audits, investigations, contract terminations, or penalties arising from Client’s submission or use of any deliverable prepared under the Agreement;
(d) Client is solely responsible for the accuracy and completeness of any submission made to the Supplier Performance Risk System (SPRS) or any government or agency database.
THE LIMITATIONS IN THIS SECTION APPLY REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE, AND EVEN IF ANCHOR CYBER HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
13. Indemnification
To the maximum extent allowed by law, Client agrees to indemnify and hold harmless Anchor Cyber from claims arising from:
Client’s failure to implement recommendations
Client’s systems, operations, or decisions
Use or misuse of deliverables
Any claim by a third party arising from Client’s cybersecurity posture, data breach, or failure to meet regulatory requirements
Client’s representations to any third party (including government agencies, primes, or auditors) regarding its compliance status
Any inaccurate, incomplete, or misleading information provided by Client to Anchor Cyber
Anchor Cyber shall provide Client with prompt notice of Anchor Cyber’s knowledge of any indemnifiable claim and shall cooperate reasonably in the defense thereof at Client’s expense.
14. Term and Termination
The Agreement remains in effect as long as any SOW is active.
Either party may terminate:
Per terms defined in the SOW
For material breach (with reasonable cure period)
Anchor Cyber may terminate the Agreement or any SOW for its convenience upon thirty (30) days’ written notice.
Fees for work performed prior to termination remain due.
Upon termination, Anchor Cyber may retain copies of all deliverables for its records and for compliance with applicable record retention policies.
Sections 9 (Confidentiality), 10 (Intellectual Property), 11 (Disclaimer of Warranties), 12 (Limitation of Liability), 13 (Indemnification), 16 (Governing Law), and all provisions by their nature should survive, shall survive termination of the Agreement or an SOW.
15. Force Majeure
Neither party shall be liable for delays caused by events beyond reasonable control or any other Force Majeure event, which include, without limitation, acts of God, natural disasters, government actions, labor disputes, internet outages, cyberattacks against Anchor Cyber’s own infrastructure, or pandemics, or other event or conditions outside of the reasonable control of the party claiming relief due to a Force Majeure event. The affected party shall provide prompt notice and resume performance as soon as reasonably practicable.
A Force Majeure event or delay shall not relieve Client of any payment obligations accrued prior to such event or delay.
To the extent that regulatory frameworks (including CMMC, NIST, or DFARS) change during any such delay, any work required to bring Client's engagement into alignment with updated requirements shall constitute out-of-scope work, billable under a new or amended SOW at Anchor Cyber's then-current rates.
16. Governing Law
The Agreement is governed by the laws of the State of California.
Anchor Cyber and Client each irrevocably submit to the exclusive personal jurisdiction and venue of the state and federal courts located in San Diego County, California for any and all disputes, claims, or legal proceedings arising out of or relating to the Agreement, any SOW, or the services provided hereunder. Each party expressly waives any right to object to such jurisdiction or venue on any grounds, including inconvenient forum, and agrees not to commence any such action in any other jurisdiction.
In the event of a dispute arising out or related to the Agreement, an SOW, or the services provided by Anchor Cyber, the prevailing party shall be entitled to its reasonable attorneys’ fees and all expenses and costs, including, but not limited to, expert witness fees, incurred, as against the non-prevailing party in addition to any other relief to which the prevailing party is entitled.
17. Entire Agreement
The Agreement constitutes the entire agreement between the parties. The Agreement supersedes all prior and contemporaneous communications, negotiations, representations, warranties, and agreements, whether written or oral, relating to such subject matter. Each party acknowledges that it has not relied upon any representation, promise, or inducement not expressly set forth in the Agreement. Both parties agree and acknowledge that any additional or conflicting legal or commercial terms and/or conditions contained on or referenced in any purchase order, work order, or other order (each an “Order”), change order, quotation request, acknowledgement, or other document or form issued by or on behalf of Client, are void and of no force or effect. Anchor Cyber’s acknowledgment and/or acceptance of an Order shall not be deemed an acceptance of any such other terms and/or conditions or a waiver of the provisions hereof; instead, no modification or amendment of the Agreement shall be valid or binding unless made in writing and executed by duly authorized representatives of both parties, and no waiver of any provision shall constitute a waiver of any other provision or of the same provision on any other occasion. In the event of a conflict between these T’s and C’s and the SOW, the SOW shall govern only for that specific engagement.
18. Updates to Terms & Conditions
These Terms & Conditions may be updated from time to time. The version in effect at the time a SOW is executed will govern that engagement.
19. No Solicitation of Personnel
During the term of any active SOW and for one (1) year following its termination or expiration, Client agrees not to solicit or recruit directly or indirectly, any employee, contractor, or subcontractor of Anchor Cyber who was involved in providing services to Client, without prior written consent of Anchor Cyber.
20. Notices
Written notice may be served by email, and when used, delivery is complete upon transmission if before 5:00 p.m. on the business day transmitted or on the following business day if transmitted after 5:00 p.m., unless sender receives an automated message that the email has not been delivered.
For questions regarding these Terms & Conditions or the Agreement, please contact:
Anchor Cyber, Inc.
📧 mandy@anchorcyber.com