Terms of Service

Last Updated: July 2026

Welcome to OVATE Security. By engaging our services or using our website, you agree to these Terms of Service. As a UK-based cybersecurity firm built by offensive security practitioners, we hold both ourselves and our clients to the highest standards of operational integrity, confidentiality, and legal compliance.

1. Scope of Services

OVATE Security provides continuous, adversary-focused cybersecurity services. We monitor, test, and defend continuously, not once a year. Our core engagements include, but are not limited to:

  • Digital Risk Protection: Safeguarding your digital footprint against external threats, data leaks, and brand impersonation.
  • Managed Detection & Response (MDR): Continuous monitoring, threat hunting, and rapid response across your entire attack surface.
  • Penetration Testing & Red Team: Adversary emulation that exposes weaknesses before your adversaries do.

2. Authorization and Rules of Engagement

Prior to any Penetration Testing, Red Team engagement, or active scanning, a formal Rules of Engagement (RoE) document must be signed by an authorized representative of your organization. You explicitly grant OVATE Security authorization to assess the agreed-upon digital assets. We are not liable for disruptions caused by vulnerabilities inherent in your existing systems.

3. Confidentiality and Non-Disclosure

We operate under strict confidentiality. Any vulnerabilities discovered, proprietary data accessed, or security architectures analyzed during our engagements will be treated with the utmost secrecy. Both parties agree to adhere to the specifics of the mutually signed Non-Disclosure Agreement (NDA) which supersedes these general terms where applicable.

4. Data Protection and UK GDPR

As a UK-based entity, OVATE Security strictly adheres to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Any personal or sensitive data incidentally accessed during our engagements is handled with the highest level of security, never stored longer than necessary, and never transferred outside of approved jurisdictions without explicit consent.

5. Intellectual Property and Deliverables

Upon full payment, the client retains ownership of all final reports and deliverables provided by OVATE Security. However, OVATE Security retains all intellectual property rights to the methodologies, proprietary tools, scripts, and techniques used to conduct the assessment.

6. Liability and Indemnification

While OVATE Security takes all reasonable precautions to prevent business disruption during our testing and monitoring phases, offensive security operations carry inherent risks. By agreeing to these terms, the client acknowledges these risks and agrees to hold OVATE Security harmless for any unintended downtime or data integrity issues arising directly from authorized security assessments.

7. Governing Law

These Terms of Service shall be governed by and construed in accordance with the laws of the United Kingdom, without regard to its conflict of law provisions. Any disputes arising under or in connection with these terms shall be subject to the exclusive jurisdiction of the courts of the United Kingdom.