Terms & Conditions
Terms governing communications, authorized information security consulting engagements, confidentiality, deliverables, and limitations of liability.
Effective date: August 20261. Overview
IHeartInfoSec is an independent cybersecurity consulting practice operated as a sole proprietorship in Texas. These Terms & Conditions ("Terms") govern the relationship between IHeartInfoSec ("Consultant," "we," "us," or "our") and any individual or organization ("Client") that engages Consultant for information security consulting services, receives communications from Consultant, or accesses this website.
Specific engagement terms, scope, and pricing are governed by a separate written agreement between Consultant and Client. These Terms apply in addition to that agreement and prevail where they do not conflict with it.
2. Engagement authorization
No security testing, assessment, or active engagement activity begins without a signed authorization document and agreed rules of engagement. Verbal approvals are not sufficient.
The Client is responsible for ensuring that the authorization provided accurately reflects ownership of or authority over the systems, networks, and data in scope. Consultant will not perform testing against systems not covered by the authorization. Any request to expand scope must be documented in writing before work proceeds.
Consultant reserves the right to suspend or terminate an engagement if circumstances suggest that the authorization is invalid, the scope has been misrepresented, or continuing the work creates unreasonable risk to third parties.
SMS or electronic messages used in authorized social-engineering exercises are sent only within a documented client engagement and only to recipients covered by the client's written authorization. Enrollment in the voluntary transactional SMS program does not constitute authorization for simulated phishing, smishing, or social-engineering exercises.
3. Engagement conduct and data handling
Consultant will perform services in a professional manner consistent with the agreed scope and rules of engagement. Consultant will use reasonable care to minimize disruption to systems and services during testing, though some temporary impact may be unavoidable.
Information and data collected during an engagement will be limited to what is necessary to perform the contracted services. Sensitive data encountered incidentally during testing will not be exfiltrated, retained, or disclosed beyond what is required to document the finding. Engagement data will be handled, stored, and disposed of in accordance with our Privacy Policy and any additional requirements agreed to in writing.
4. Deliverables and intellectual property
Findings reports, executive summaries, and other written deliverables produced specifically for an engagement become the Client's property upon delivery, subject to payment of fees.
Consultant retains all rights to methodologies, tools, techniques, templates, and generalized knowledge developed or used in the course of performing services. Deliverables may not be redistributed, published, or used to authorize testing against systems outside the agreed scope without Consultant's prior written consent.
Consultant may reference the general nature of services performed (e.g., "penetration testing engagement") for business purposes, but will not identify the Client or disclose findings without the Client's written permission.
5. Confidentiality
Each party agrees to hold the other's confidential information in confidence and not to disclose it to third parties without prior written consent. Confidential information includes, but is not limited to, engagement findings, client systems and architecture, pricing, and proprietary methodologies.
Confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was independently known to the receiving party prior to disclosure; (c) is received lawfully from a third party without restriction; or (d) is required to be disclosed by law, court order, or regulatory authority, provided the disclosing party gives prompt notice where permitted.
Confidentiality obligations survive termination of an engagement for a period of three (3) years, except that obligations covering trade secrets or authentication credentials survive indefinitely.
6. SMS communications
IHeartInfoSec sends transactional SMS messages to clients and business contacts who voluntarily enroll via the Communication Preferences form. Opt-in consent is voluntary and is not required to obtain any IHeartInfoSec service.
Who sends: IHeartInfoSec.
Who receives: Clients and business contacts who affirmatively opt in.
Message categories: Consultation scheduling, meeting reminders, engagement coordination, project-status updates, requests for client action, and secure report or deliverable availability notifications.
- Message frequency varies based on engagement activity and client preference.
- Message and data rates may apply according to the recipient's mobile service plan.
- Reply STOP to opt out of future messages. A confirmation message may be sent after an opt-out is processed.
- Reply HELP for assistance or email support@iheartinfosec.com.
- SMS delivery depends on carrier availability and network conditions. Carriers are not liable for delayed or undelivered messages.
- Mobile telephone numbers and SMS consent information are not sold, rented, or shared with third parties or affiliates for marketing or promotional purposes.
7. Email communications
Email communications from Consultant are sent in connection with authorized consulting engagements, engagement administration, business inquiries, and direct client correspondence. Email is not used for unsolicited marketing.
- Simulated phishing or social-engineering email campaigns are sent only within a documented client engagement and only to recipients covered by the client's authorization.
- Recipients of simulated phishing messages may contact support@iheartinfosec.com to confirm the legitimacy of a message or request information about the applicable engagement.
- To opt out of future business correspondence, reply with "unsubscribe" or contact support@iheartinfosec.com directly.
- Email addresses are not sold or shared with third parties for marketing purposes.
- Email is not a secure channel for transmitting sensitive engagement findings. Consultant will use encrypted delivery where required by the engagement agreement.
8. Disclaimer of warranties
Services are provided on an "as-is" and "as-available" basis. Consultant makes no warranty, express or implied, that any engagement will identify all vulnerabilities, weaknesses, or risks present in the tested environment. Security testing is a point-in-time assessment and does not guarantee the future security of any system, network, or application.
Consultant does not warrant that testing will be free from any temporary disruption to services, latency, or unintended side effects, even when reasonable care is taken. No assessment can guarantee that a breach, data loss, or security incident will not occur.
9. Limitation of liability
To the maximum extent permitted by applicable law, Consultant's total liability arising out of or related to any engagement or these Terms, regardless of the form of action, will not exceed the total fees paid by Client for the specific engagement giving rise to the claim.
In no event will Consultant be liable for any indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of revenue, loss of data, business interruption, or cost of substitute services, even if advised of the possibility of such damages.
These limitations apply to the fullest extent permitted by law and reflect a reasonable allocation of risk between the parties.
10. Indemnification
Client agrees to indemnify, defend, and hold harmless Consultant from and against any claims, liabilities, damages, fines, penalties, and expenses (including reasonable legal fees) arising out of or related to: (a) testing or activities performed within the authorized scope at Client's direction; (b) Client's misrepresentation of authority over systems in scope; (c) Client's use of deliverables outside the permitted scope; or (d) Client's breach of these Terms or the applicable engagement agreement.
11. Acceptable use
Clients and communication recipients may not use Consultant's services, deliverables, or communication channels to: engage in unlawful activity; misrepresent authorization for any testing or assessment; access or test systems outside the agreed scope; redistribute engagement findings without authorization; or interfere with the delivery or integrity of authorized engagements.
Consultant may terminate services or restrict communications where a violation of these provisions is suspected.
12. Privacy
Personal and business information collected in connection with engagements and communications is handled in accordance with our Privacy Policy.
Mobile telephone numbers and SMS consent information will not be shared with third parties or affiliates for marketing or promotional purposes.
13. Governing law
These Terms are governed by the laws of the State of Texas, without regard to conflict-of-law principles. Any dispute not resolved by mutual agreement will be submitted to binding arbitration or a court of competent jurisdiction in Texas, as the parties may agree in writing.
14. Changes
Consultant may revise these Terms from time to time. The effective date indicates the most recent revision. Continued use of services or communications following a material update constitutes acceptance of the revised Terms.
15. Contact
IHeartInfoSecsupport@iheartinfosec.com