Service Agreement
Comprehensive commercial terms for SentinelCore software, compliance, security, consulting, managed oversight, implementation and support services.
Effective date: The date displayed on the applicable quotation, invoice, checkout confirmation, order record, statement of work or written acceptance.
This Service Agreement governs SentinelCore products and services supplied through this website, by invoice, by quotation, by payment link, by written proposal, by statement of work or by accepted procurement request. By purchasing, accessing, installing, using or receiving SentinelCore software, reports, consulting, implementation, managed oversight, compliance or support services, the client accepts these terms unless a separately signed written agreement expressly replaces them.
1. Definitions
In this agreement, “SentinelCore”, “we”, “us” and “our” refer to the supplier of the relevant SentinelCore product or service. “Client”, “you” and “your” refer to the person, business, organisation or authorised representative purchasing or using the product or service. “Services” includes consulting, assessment, implementation, installation, support, managed oversight, compliance review, risk assessment, software configuration, reporting, training and related work. “Software” includes SentinelCore platforms, dashboards, modules, downloadable packages, scripts, source packages, configuration files, templates and digital deliverables. “Deliverables” includes reports, dashboards, documents, policies, checklists, plans, training materials, recommendations, software access, implementation records and other outputs.
2. Engagement scope
Each SentinelCore product or service is delivered according to the applicable product description, limitations, invoice, written proposal, website description, service notes, checkout record, accepted quotation or confirmed statement of work. Any work outside that scope requires written approval and may be quoted separately.
Scope must be interpreted practically and commercially. Unless expressly included in writing, a purchase does not include unlimited consulting, unlimited custom development, unlimited revisions, legal certification, formal regulatory audit certification, emergency incident response, onsite attendance, third-party licensing, hosting, domain registration, infrastructure costs, after-hours work, custom integrations, migration of legacy data, code rewrites, procurement support, staff training beyond the stated allocation, or remediation of unrelated client-side infrastructure defects.
3. Professional advisory nature
Compliance analysis, risk assessment, security reviews, continuity plans, governance recommendations, U.S. Privacy & HIPAA support, HealthGuard outputs, DisasterShield plans, SentinelIntercept recommendations and BreachSimulator findings are professional advisory outputs. They are intended to support decision-making, improve governance, reduce risk and help the client understand practical remediation steps.
They do not constitute legal advice, insurance advice, tax advice, formal audit certification, regulatory certification, forensic certification, statutory sign-off or a guarantee that the client is fully compliant, fully secure, breach-proof, incident-proof or immune from business interruption.
Where legal interpretation, regulatory representation, litigation advice, formal audit certification or statutory sign-off is required, the client should obtain advice from an appropriately qualified attorney, auditor, regulator, insurer or specialist professional.
4. United States compliance context
SentinelCore products and services are designed with reference to United States operational, commercial, privacy and governance expectations, including U.S. Privacy & HIPAA, applicable U.S. privacy and records laws, the Consumer Protection Act, the Electronic Communications and Transactions Act, ordinary contractual principles and sector-specific operational requirements where relevant.
Compliance obligations are organisation-specific. The client remains responsible for determining which laws, regulations, codes, contracts, procurement rules, sector standards, internal policies and insurance obligations apply to its business. SentinelCore may assist with identifying obvious governance and security considerations, but the client remains accountable for legal compliance, executive approval, implementation, staff conduct, record keeping, regulator engagement and ongoing monitoring.
5. No guarantee of compliance
SentinelCore software, reports, assessments, recommendations, governance frameworks, policy templates, implementation guidance and training materials are designed to assist organisations in improving their compliance posture. No software solution, report, assessment, policy set, recommendation or implementation activity can guarantee complete compliance with U.S. Privacy & HIPAA, applicable U.S. privacy and records laws, the Consumer Protection Act, the Electronic Communications and Transactions Act, employment legislation, health legislation, sector-specific regulations, payment gateway rules, contractual obligations or future legislative requirements.
Responsibility for compliance remains with the client organisation. The client must ensure that recommendations are reviewed, approved, implemented, monitored and updated in line with its own legal, operational and regulatory obligations.
6. No guarantee of security
The client acknowledges that no security solution, monitoring platform, governance process, assessment methodology, simulation, technical control, report, checklist or managed service can guarantee the prevention of all security incidents, breaches, ransomware attacks, insider threats, data leaks, operational failures, fraud, misconfiguration, denial-of-service attacks, cloud failures, third-party compromise or cybersecurity events.
SentinelCore provides commercially reasonable services, guidance and technology intended to reduce risk rather than eliminate risk entirely. Security depends on many factors outside SentinelCore’s control, including client behaviour, credential handling, patching, infrastructure quality, hosting providers, user training, device condition, third-party software, internal policies, physical security and management discipline.
7. Client cooperation
The client must provide accurate information, authorised access, relevant documentation, working credentials, available stakeholders, suitable hosting, timely feedback, required approvals, truthful instructions and a safe working context. Delays caused by missing access, unavailable personnel, inaccurate information, unsupported infrastructure, third-party outages, procurement delays, internal disagreement, incomplete documentation or slow approvals may extend delivery dates.
Where client cooperation is required and not provided within a reasonable time, SentinelCore may pause delivery, revise the timeline, charge for wasted time, reschedule work, issue a revised quote, limit the deliverable based on available information or close the engagement as far as reasonably completed.
8. Authority and lawful use
SentinelCore only performs assessments, simulations, integrations, monitoring, reviews and software work on systems where the client has lawful authority to request such work. The client warrants that it owns, controls or has written permission to test, review, access, configure, monitor or assess the relevant systems, data, networks, applications, domains, devices, locations and infrastructure.
Breach simulation, risk assessment, vulnerability review, network review, interception-style analysis and exposure analysis are defensive, controlled and non-destructive. SentinelCore will not assist with unauthorised access, credential theft, illegal exploitation, harmful intrusion, malware deployment, data theft, unlawful surveillance, evasion, persistence, destructive actions or any activity that SentinelCore reasonably considers unsafe, unlawful or unethical.
9. Security boundaries and prohibited instructions
The client may not instruct SentinelCore to access systems without permission, bypass authentication unlawfully, obtain credentials improperly, exploit third-party systems, compromise accounts, exfiltrate data, disable controls without approval, conceal activity, attack unrelated systems, or perform any action that would reasonably be considered unauthorised or harmful.
If the client provides such an instruction, SentinelCore may refuse the instruction, suspend the engagement, terminate the engagement and retain fees for work already performed. Refusal to perform unlawful or unsafe work does not create refund eligibility.
10. Software setup and hosting
Unless expressly stated in writing, hosting, domain registration, DNS management, email hosting, third-party licences, paid APIs, SSL certificates, cloud fees, server remediation, backup storage, SMS fees, payment gateway fees, premium plugins, paid libraries and infrastructure charges are excluded.
Setup support assumes that the client supplies appropriate hosting, authorised access and a technically suitable environment. Complex migrations, custom development, non-standard server remediation, malware cleanup, hosting control panel repair, email deliverability repair, legacy application refactoring, data cleaning, third-party API troubleshooting and custom infrastructure architecture may be quoted separately.
11. Managed services
Managed oversight services such as SentinelCore Overwatch are limited to the included device count, site count, system count, reporting cadence, monitoring scope, support channel, response window and service description purchased by the client. Extra devices, urgent onsite response, major remediation, after-hours emergency work, project implementation, vendor management beyond the included scope, hardware replacement, licensing, procurement and large-scale incident response may be billed separately.
Managed services are not a substitute for internal governance, executive accountability, staff training, endpoint security, backups, insurance, legal advice or client-side operational discipline. They are intended to provide oversight, reporting, visibility, coordination and support within the agreed scope.
12. Deliverables and acceptance
Deliverables may include reports, dashboards, software packages, configuration records, checklists, policies, findings, training notes, implementation plans, recommendations, risk registers, continuity plans, access credentials or deployment records. Deliverables are considered accepted unless the client reports a material issue in writing within five (5) business days of delivery.
A material issue is a substantial defect that prevents the deliverable from being used for its stated purpose. Minor formatting preferences, subjective tone preferences, internal disagreement with findings, later changes in business requirements, client delay, or requests for additional scope do not automatically constitute material defects.
13. Revisions and corrections
Where a deliverable contains a reasonable error, omission or technical issue within the agreed scope, SentinelCore will be given a reasonable opportunity to correct it. Revisions are limited to correcting or clarifying the agreed deliverable and do not include additional analysis, new scope, new products, new sites, new systems, new legal review, new design direction, new integrations or new business requirements unless agreed in writing.
14. Payment and scheduling
Services are scheduled after payment confirmation, accepted purchase order, written procurement approval or written credit approval. SentinelCore may pause work for overdue amounts, failed payments, disputed charges, missing information, unsafe access conditions, material scope disputes, suspected fraud, chargebacks, payment gateway holds or incomplete verification.
Payment does not create an obligation for SentinelCore to perform unlawful work, unsafe work, out-of-scope work or work that cannot reasonably be performed in the client’s environment.
15. Payment gateways and verification
SentinelCore may utilise third-party payment gateways, acquiring banks, card processors, wallet providers, EFT processors, subscription processors and financial service providers. The client acknowledges that payment processing, card handling, banking security controls, anti-fraud measures, refund procedures, chargeback procedures, payment verification requirements and settlement timing are governed by the applicable payment gateway, banking institution and regulatory framework.
SentinelCore reserves the right to suspend fulfilment pending fraud verification, payment confirmation, identity verification, proof of authority, procurement confirmation or payment gateway clearance where reasonably necessary. SentinelCore may refuse or cancel an order where the transaction appears fraudulent, unauthorised, high-risk, sanctioned, abusive or inconsistent with payment gateway requirements.
16. Chargebacks and payment disputes
The client agrees to first engage SentinelCore’s support and dispute resolution process before initiating a chargeback, payment dispute or payment reversal. Where a chargeback is initiated after software delivery, service delivery, report issuance, consulting delivery, setup work, managed service commencement or implementation completion, SentinelCore reserves the right to provide supporting evidence to the relevant payment processor, acquiring bank, card issuer or financial institution.
Such evidence may include invoices, proposals, product descriptions, correspondence, support records, access records, delivery logs, work notes, report copies, screenshots, meeting confirmations, acceptance records and proof of digital delivery.
17. Refunds and cancellations
Refunds and cancellations are governed by the SentinelCore Refund Policy, the applicable invoice, the applicable product description and any written statement of work. Approved refunds will be processed within fourteen (14) calendar days from written approval by SentinelCore, subject to payment gateway, bank, card issuer and third-party processing times outside SentinelCore’s control.
Monthly services require thirty (30) calendar days written cancellation notice unless otherwise agreed in writing. Annual services are provided at discounted rates based on commitment periods and may not be cancelled for a pro-rata refund once delivery has commenced, except where required by applicable law or expressly agreed by SentinelCore in writing.
18. Intellectual property
All SentinelCore software, frameworks, methodologies, assessment models, reports, templates, source code, branding, design elements, workflows, checklists, training materials, documentation structures, scripts, product logic, UI concepts and associated intellectual property remain the property of SentinelCore unless otherwise agreed in writing.
The client receives a non-exclusive, non-transferable licence to use purchased products and deliverables for its internal business purposes. The client may not resell, redistribute, sublicense, publish, copy for third parties, white-label, reverse engineer, clone, commercially exploit or create derivative products from SentinelCore materials unless expressly permitted in writing.
19. Licence restrictions
Software licences apply only to the client, site, business unit, device count, user count, domain, environment or deployment described in the applicable product description, invoice or written agreement. Additional deployments, users, devices, locations, subsidiaries, customer environments or white-label use may require additional licensing.
SentinelCore may suspend or revoke access where software is used outside the licensed scope, copied unlawfully, shared with unauthorised parties, used to compete with SentinelCore, used for unlawful purposes, or used in a way that creates security, reputational or legal risk.
20. Confidentiality
SentinelCore will treat client operational, security, business and technical information as confidential and will use it only for delivery, support, administration, billing, legal compliance, security record keeping and lawful business purposes. The client must avoid sending unnecessary sensitive information unless required for the agreed scope.
The client is responsible for ensuring that information supplied to SentinelCore may lawfully be shared for the purpose of the engagement. Where personal information is supplied, the client must ensure that the processing is lawful, proportionate, relevant and necessary.
21. U.S. Privacy & HIPAA and personal information
SentinelCore will process personal information in accordance with its Privacy Policy and applicable U.S. Privacy & HIPAA principles. Depending on the engagement, SentinelCore may act as a responsible party or operator. Where SentinelCore processes personal information on behalf of the client, the client remains responsible for defining the lawful purpose, ensuring the information is necessary, obtaining required authorisations, limiting unnecessary data sharing and maintaining appropriate internal controls.
SentinelCore may implement reasonable technical and organisational measures appropriate to the nature of the engagement. However, the client remains responsible for its own staff practices, internal access control, data retention, notices, consent management, data subject requests, regulator engagement, third-party processors and ongoing compliance monitoring.
22. Client data and backups
The client is responsible for maintaining its own backups unless backup services are expressly included in writing. SentinelCore is not responsible for loss of client data caused by pre-existing hosting issues, unsupported infrastructure, third-party platform failures, client actions, unauthorised changes, malware already present in the environment, expired hosting, expired domains, DNS failure, hardware failure or failure to maintain backups.
23. Third-party services
SentinelCore may integrate with, rely on or recommend third-party services such as hosting providers, payment gateways, email providers, monitoring tools, APIs, DNS providers, security tools, analytics tools and communication platforms. SentinelCore is not responsible for the performance, pricing, availability, security, policy changes, outages, data handling or contractual terms of third-party services unless expressly agreed in writing.
24. Timelines and delivery dates
Delivery dates, activation windows, turnaround times and implementation estimates are provided in good faith and depend on payment clearance, client cooperation, access availability, hosting suitability, third-party availability, internal review, scope stability and technical conditions. A stated timeline is not a guarantee where delay is caused by circumstances outside SentinelCore’s reasonable control.
Where the product description mentions a delivery period such as three, five, seven, ten or fourteen business days, that period generally begins once payment is confirmed and all required access, information and approvals have been received.
25. Support and fair use
Support, consulting and managed services are subject to fair use. Fair use means reasonable support within the purchased scope, normal business communication, appropriate technical questions and cooperation by the client. It does not include unlimited training, repeated rework caused by client changes, abusive conduct, after-hours emergencies, unrelated IT support, general business consulting, legal drafting, procurement administration, repeated onboarding of new staff or major implementation work unless included in writing.
Abusive conduct, unlawful instructions, unsafe access practices, non-payment, repeated out-of-scope demands, harassment, threats or misuse of support channels may result in suspension or termination.
26. Limitation of liability
To the maximum extent permitted by law, SentinelCore is not liable for indirect loss, consequential loss, lost profits, lost revenue, business interruption, reputational damage, loss caused by third-party systems, pre-existing vulnerabilities, client misconfiguration, unauthorised changes, unsupported infrastructure, poor credential practices, failure to implement recommendations, expired licences, hosting failures, cloud failures, payment gateway issues, staff negligence or unlawful third-party actions.
Where liability cannot lawfully be excluded, SentinelCore’s total liability is limited to the fees paid by the client for the specific affected engagement giving rise to the claim, to the extent permitted by law.
27. Indemnity
The client indemnifies SentinelCore against claims, losses, penalties, demands, damages, costs and expenses arising from unauthorised instructions, unlawful access requests, inaccurate information, misuse of software, client breach of law, client breach of this agreement, third-party claims arising from client data, failure to obtain permissions, failure to implement recommendations or use of SentinelCore deliverables outside the agreed scope.
28. Force majeure
SentinelCore shall not be liable for delays or failures caused by events beyond its reasonable control, including but not limited to power failures, load shedding, internet outages, telecommunications failures, civil unrest, government action, natural disasters, pandemics, cyber attacks against third-party infrastructure, hosting provider failures, cloud service interruptions, payment gateway outages, banking interruptions, supplier failures, fire, flood, strike action, transport disruption or events that materially prevent ordinary delivery.
29. Suspension and termination
SentinelCore may suspend or terminate services where the client fails to pay, initiates unjustified chargebacks, provides unlawful instructions, refuses required cooperation, misuses software, breaches licence restrictions, behaves abusively, creates unsafe access conditions, supplies false information or materially breaches this agreement.
Termination does not affect amounts already due, rights accrued before termination, confidentiality obligations, intellectual property rights, limitation of liability, indemnities or payment obligations for work already performed.
30. Communications and notices
Operational communications may be sent by email, support channel, invoice notes, website notices or other agreed communication methods. The client must ensure that its contact details are accurate and monitored. A notice sent to the client’s supplied email address will be treated as delivered unless SentinelCore receives a bounce-back or clear delivery failure.
31. Records and evidence of delivery
SentinelCore may maintain records of orders, invoices, access provisioning, correspondence, support requests, delivery notes, report delivery, implementation steps, payment status and acceptance for operational, legal, accounting, payment gateway and dispute resolution purposes. These records may be used to evidence delivery, scope, timing, client instructions and work performed.
32. Non-solicitation
Unless otherwise agreed in writing, the client may not directly solicit SentinelCore personnel, contractors or specialist partners involved in the engagement for competing private work during the engagement and for six (6) months after completion. This does not prevent ordinary public recruitment where the person responds independently to a general advertisement.
33. Marketing references
SentinelCore will not publish sensitive client security details without permission. Unless the client objects in writing, SentinelCore may refer generally to the type of work performed for internal capability tracking and anonymised case study development. Named logo usage, public case studies or detailed public references require client approval.
34. Governing law and jurisdiction
This agreement shall be governed by the laws of the United States. Any dispute arising from this agreement shall be subject to the jurisdiction of the courts of the United States, unless the parties agree in writing to mediation, arbitration or another dispute resolution process.
35. Dispute resolution
Before formal proceedings are started, the parties should make a reasonable good-faith attempt to resolve disputes through written communication, management escalation and practical remediation. The client should provide enough detail for SentinelCore to understand the complaint, including the product or service purchased, invoice number, issue experienced, desired remedy and supporting evidence.
36. Severability
If any provision of this agreement is found to be invalid, unlawful or unenforceable, that provision will be interpreted, limited or severed to the minimum extent necessary. The remaining provisions will continue to apply.
37. Changes to terms
SentinelCore may update these terms from time to time to reflect changes in services, legislation, payment gateway requirements, operational requirements or commercial practice. The version linked on the invoice, active at the time of purchase or otherwise incorporated into the accepted order applies unless a signed written agreement states otherwise.
38. Entire agreement
This Service Agreement, together with the applicable invoice, quotation, product description, statement of work, Refund Policy, Privacy Policy and any written special terms accepted by SentinelCore, constitutes the commercial agreement for the relevant purchase. No informal message, sales discussion, website summary or verbal statement overrides these terms unless confirmed in writing by SentinelCore.
39. Contact
Questions about this agreement may be sent to hello@sentinelcorehq.com. Clients should include their company name, invoice number and a clear description of the relevant issue or request.
This agreement was modified on the 22nd of June 2026.