1. Acceptance of Terms
By accessing, browsing, or using any ZT INFOSEC service — including the Complimentary Security Assessment Tool (free), the Risk Assessment SaaS Platform (subscription), Professional Security Consulting Services (engagement-based), or the ZT INFOSEC website (https://ztinfosec.com) — you agree to be bound by these Terms of Service (“Terms”). If you do not agree with any part of these Terms, do not use our services.
ZT INFOSEC reserves the right to modify these Terms at any time. Changes become effective immediately upon posting. Your continued use after modifications constitutes acceptance.
2. Definitions
- “Services” — all products and services offered by ZT INFOSEC, including assessments, the SaaS platform, consulting, and the website
- “You” / “Your” — the individual or organization using ZT INFOSEC services
- “Assessment” — security assessment reports and findings generated by our tools or staff
- “Confidential Information” — non-public information disclosed during service delivery
- “IP” / “Intellectual Property” — our methodologies, tools, reports, algorithms, and intellectual property
- “Personal Data” — information identifying you or your organization
- “AI Systems” — artificial intelligence models and tools used to generate assessments and recommendations, including local LLMs and cloud-based AI services
3. Services Overview
3.1 Complimentary Security Assessment Tool
What it is: a free, automated security reconnaissance service — a passive assessment using publicly available data only, with AI-assisted analysis generating a professional PDF report. It showcases ZT INFOSEC expertise.
What it is NOT: a penetration test (no exploitation), an active vulnerability scan, a compliance audit, a professional security assessment, a guarantee of security, real-time monitoring, or a comprehensive review — it assesses public data only.
Methodology: public DNS records (A, AAAA, MX, SPF, DKIM, DMARC); Certificate Transparency logs; HTTP headers and server banners; TCP port scanning (connect-only, no stealth scans); subdomain enumeration via public sources; WHOIS registration data; public IP geolocation and ASN information; and AI-assisted analysis of reconnaissance findings.
Deliverable: one PDF assessment report emailed to you, with professional findings, remediation recommendations, and risk ratings (Critical, High, Medium, Low, Informational).
3.2 Risk Assessment SaaS Platform
What it provides: comprehensive security risk assessments; compliance evaluation frameworks (PCI-DSS, ISO 27001, HIPAA, SOC 2, and others); continuous monitoring and reporting where applicable; custom reporting and executive dashboards; vulnerability tracking and remediation management; professional support based on subscription tier; and an AI-assisted analysis and recommendation engine.
Service availability: 99.5% uptime SLA (excluding maintenance), scheduled maintenance windows with notice, 24/7 email support for all tiers, and business-hours phone support for premium tiers.
Data processing: by using the SaaS Platform, you authorize us to collect and store security configurations and assessment data, analyze your security posture using automated tools, AI systems, and professional review, generate reports and recommendations based on your data, and use aggregated, anonymized data for service improvement.
3.3 Professional Consulting Services
Scope: custom security assessments and penetration testing, incident response and forensics, compliance consulting (PCI-DSS, HIPAA, SOC 2, ISO 27001, and others), and strategic security planning.
Engagement basis: a separate Statement of Work (SOW) for each engagement; terms in the SOW override general terms where conflicting; an NDA is typically required for sensitive assessments.
4. AI Disclosure and Transparency
4.1 How ZT INFOSEC uses AI
ZT INFOSEC uses artificial intelligence to enhance security assessments and generate professional recommendations. In the Complimentary Assessment Tool and SaaS Platform, AI systems analyze data and generate findings, with local LLMs providing primary processing and cloud services providing supplementary insights; all AI recommendations are validated by human review. In Professional Consulting, AI tools may support analysis during engagements, always subject to the Statement of Work and NDA, with AI usage disclosed to and approved by the client.
4.2 AI systems and models
Local infrastructure: Hermes local language models, self-hosted on ZT INFOSEC infrastructure in our Guatemala City data center. Data is encrypted with AES-256 at rest and TLS 1.2+ in transit, and is not shared with external AI services without explicit approval.
Cloud AI services (when used): limited supplementary analysis only, with data compartmentalized and minimized. Additional cloud AI usage requires a separate data processing agreement. Examples include enhanced NLP analysis, trend benchmarking, and specialized threat intelligence.
4.3 AI limitations and accuracy
You acknowledge that AI systems are not 100% accurate and may produce false positives or false negatives. All critical findings are human-reviewed before delivery. AI systems may contain training biases; recommendations are validated for accuracy, and human judgment overrides AI recommendations when necessary. Assessment reports identify which findings are AI-assisted, and consulting customers may request human-only review.
4.4 Data processing with AI
Your security data is encrypted and processed primarily locally; cloud AI usage is minimal and compartmentalized. You retain ownership of your assessment data. AI analysis does not train public models on your data, AI models do not permanently store your specific data, and only aggregated, anonymized insights may be retained for service improvement.
4.5 Your rights regarding AI
You have the right to request human review of AI-generated findings (for paid services), opt out of cloud AI so assessments use local LLMs only, know which findings are AI-assisted, and request additional human analysis (which may incur additional fees). Contact privacy@ztinfosec.com to exercise these rights.
5. Authorization and Authorized Use
5.1 You must be authorized
By using any ZT INFOSEC service, you confirm that:
- You own, control, or have explicit written authorization to assess the systems and domains you submit
- You are an authorized representative with legal authority to request assessments
- You are not submitting third-party, competitor, government, or critical-infrastructure domains without written authorization
- Your use complies with all applicable laws and regulations
For the Complimentary Assessment Tool, you should maintain written confirmation that you are authorized to assess submitted domains.
5.2 Explicitly prohibited uses
You agree NOT to:
- Submit unauthorized domains — assessing domains you don’t own without explicit written permission
- Circumvent rate limits using scripts, bots, or automation
- Abuse the service through rapid submissions, denial-of-service, or other attacks against our platform
- Scan critical infrastructure (government, military, healthcare, utilities, financial) without authorization — this violates the Computer Fraud and Abuse Act (CFAA)
- Use the service for any illegal purpose
- Provide false or fraudulent information
- Reverse-engineer or attempt to recreate our methodology
- Redistribute reports to unauthorized parties
- Remove ZT INFOSEC branding or attribution from reports
- Bypass security controls or extract data without authorization
Consequences of violation: your IP address may be blocked, your account may be suspended or terminated, submissions may be flagged for abuse reporting, you may be held liable for damages under the CFAA, GDPR, CCPA, or other laws, and we may report violations to law enforcement.
6. Limitations of Liability
6.1 Disclaimer of warranties
ALL SERVICES ARE PROVIDED “AS IS” WITHOUT ANY WARRANTIES. We make no warranties, express or implied, regarding the accuracy, completeness, or timeliness of findings; the absence of vulnerabilities not identified in our assessment; the suitability of recommendations for your specific environment; compliance with any standards, regulations, or frameworks; freedom from attack, breach, or compromise; uninterrupted or error-free operation; any specific security posture post-assessment; or the accuracy or completeness of AI-generated findings.
6.2 Time-limited validity
Assessment findings are valid only as of the assessment date. Security posture evolves continuously: new vulnerabilities emerge daily, configurations change frequently, and patches are released constantly. You should conduct periodic reassessments and engage professional services for critical security.
6.3 Limited scope
Our assessments cover only publicly available information (Assessment Tool), systems and data you authorize us to assess, and the specific scope defined in the engagement. They do not cover internal systems, databases, or custom applications outside scope; operational security such as employee training; third-party services or supply-chain risks; physical security or administrative controls; or any guarantee of security or compliance.
6.4 Maximum liability cap
ZT INFOSEC’s total liability to you, arising from or related to these Terms or use of our services, shall not exceed:
| Service | Maximum liability |
|---|---|
| Complimentary Assessment Tool | $0 (zero dollars) |
| Risk Assessment SaaS Platform | Fees paid in the 12 months preceding the claim, or $100, whichever is greater |
| Professional Consulting Services | Fees paid for the specific engagement, or $10,000, whichever is greater |
6.5 Excluded damages
ZT INFOSEC is not liable for: indirect or consequential damages (lost profits, revenue, or business opportunity; loss of data, files, or records; downtime; reputational harm); third-party claims (claims by assessed domain owners, law enforcement, competitors, or others, or claims arising from your misuse of the service); security-related damages (breaches occurring after the assessment date, vulnerabilities we did not identify, compliance failures where recommendations were not implemented, or delayed remediation); AI-related damages (damages from AI-generated false positives or negatives, business decisions based on AI recommendations, or reliance on AI analysis without human verification); and service-related damages (harm from your use or misuse of the service, reliance on assessment results, or third-party service failures).
6.6 Essential terms
You acknowledge that these liability limitations are essential to this agreement, that without them we would not provide services at these prices, that you assume all risk of using our services, and that these limitations apply even if we knew about possible damages.
7. Indemnification
7.1 You indemnify ZT INFOSEC
You agree to indemnify, defend, and hold harmless ZT INFOSEC, its officers, employees, agents, and contractors from any claims, damages, losses, liabilities, costs, and expenses (including attorneys’ fees) arising from or related to: your assessment of domains you don’t own or lack authorization to assess; your violation of the CFAA, GDPR, CCPA, or other laws; your misuse or malicious use of assessment findings; your submission of false or fraudulent information; any claim by assessed domain owners, law enforcement, or others; or your breach of these Terms or service-specific agreements.
7.2 Our limited indemnification
ZT INFOSEC will indemnify you for claims that our services infringe your intellectual property rights, provided you have complied with all Terms, used the service lawfully, and notified us promptly of the claim.
8. Intellectual Property Rights
8.1 Our ownership
ZT INFOSEC retains all rights to our website, platform, and services; our assessment methodology and processes; AI models, algorithms, and tools; report templates and formats; assessment methodologies and research; all custom developments and software; and our trademarks, logos, and brand elements.
8.2 Your limited license
We grant you a limited, non-exclusive, non-transferable license to access and use our services as described, read and review assessment reports, use findings internally to improve your security posture, and share findings with employees, contractors, and auditors under confidentiality.
8.3 Restrictions
You may not redistribute or resell assessment reports; remove ZT INFOSEC branding, logos, or copyright notices; create derivative works from our methodology; reverse-engineer or attempt to recreate our process; claim an assessment as your own work; or publish findings publicly without our consent.
8.4 Your data ownership
You retain ownership of your personal data, your business data (system configurations, custom data), and your assessment-specific information. You grant us the right to process your data to provide the service, use aggregated and anonymized data for improvement, and reference your company as a client if permitted.
9. Acceptable Use Policy
9.1 Service use requirements
You agree to use our services lawfully (in compliance with all applicable laws), ethically (following responsible security research principles), professionally (for legitimate business security evaluation), respectfully (respecting rate limits and service availability), and honestly (providing accurate information).
9.2 Security and safety
You agree not to transmit malware, viruses, or harmful code; conduct denial-of-service attacks; attempt unauthorized access to our systems; collect data about other users without consent; or harass, threaten, or defame individuals or organizations.
9.3 Service-specific restrictions
Complimentary Assessment Tool: maximum 10 assessments per email address per month; maximum 1 assessment per domain per 7-day period; maximum 100 assessments per IP address per day.
SaaS Platform: comply with your subscription terms; do not resell access to other organizations; do not use the platform to scan competitors without authorization.
Professional Services: comply with the Statement of Work and NDA; do not share findings with unauthorized parties; respect the confidentiality of ZT INFOSEC methodology.
10. Payment and Billing (Subscription Services)
10.1 Payment methods
ZT INFOSEC accepts payment via wire transfer, bank deposit, and Bitcoin. ZT INFOSEC does not accept credit cards or payment card data — see the Privacy Policy for payment information handling.
10.2 Payment terms
Subscription fees are billed in advance of each period. Monthly subscriptions renew automatically each month, and annual subscriptions renew automatically each year. You authorize us to process your selected payment method.
10.3 Pricing and changes
Current pricing is displayed at checkout. We may change pricing with 30 days’ notice; price changes take effect on your next renewal date, and you may cancel before renewal to avoid new pricing.
10.4 Billing issues
Failed payments may result in account suspension. We will attempt payment multiple times; contact us if you have payment problems.
10.5 Refund policy
No refunds for partial months on monthly subscriptions. No refunds on annual subscriptions (the annual discount applies). Cancellation refunds are available pro-rata within 30 days of subscription start. If the service is unavailable for more than 7 days, a pro-rata refund is available.
10.6 Taxes
You are responsible for all applicable taxes (sales tax, VAT, GST, or others). Provide a valid tax exemption certificate if applicable, and we will remove taxes from your invoice upon verification.
11. Termination and Cancellation
11.1 Termination by you
Complimentary Assessment: no formal termination required — simply stop using the tool. SaaS subscriptions: cancel anytime; access continues through the end of the current billing period, with no refunds for mid-month cancellation. Professional services: cancel per the Statement of Work terms; early termination fees may apply.
11.2 Termination by ZT INFOSEC
ZT INFOSEC may terminate or suspend your access immediately if you violate these Terms or the Acceptable Use Policy, violate applicable laws, fail to pay subscription fees, engage in fraudulent or harmful conduct, attempt unauthorized access to our systems, or use the service to harm others.
11.3 Effect of termination
Upon termination, your access to services ends, you lose the ability to submit assessments or access accounts, your personal data is deleted per the Privacy Policy, surviving terms (liability, indemnification, intellectual property) remain in effect, and outstanding fees remain due.
11.4 Data upon termination
Complimentary Assessment data is deleted per the Privacy Policy (90 days); SaaS Platform data is deleted 30 days after cancellation; Professional Services data is retained per the engagement agreement and legal requirements (typically 7 years).
12. Third-Party Services and Integrations
| Service | Purpose | Data shared |
|---|---|---|
| Private Email (privateemail.com) | Email delivery | Name, email, assessment reports |
| Google reCAPTCHA v3 | Bot prevention | IP address (scoring only) |
| Censys.io | Reconnaissance data | Domain names for queries |
| Cloud AI services (as needed) | Enhanced analysis | Minimal, compartmentalized data |
ZT INFOSEC is not responsible for the accuracy or security of third-party services, changes or discontinuation of third-party services, the privacy practices of third parties, failures, outages, or breaches of third parties, or any damages arising from third-party service use.
13. Service Maintenance and Availability
Availability: the Complimentary Assessment is provided on an “as available” basis with no SLA; the SaaS Platform carries a 99.5% uptime SLA calculated monthly; Professional Services availability is defined in the engagement SOW.
Maintenance: scheduled maintenance typically occurs Sunday 2:00–6:00 AM GMT with advance notice; emergency maintenance may occur without notice if necessary for security; updates may require temporary service interruption. We are not liable for downtime during maintenance.
Service changes: we reserve the right to update, modify, or enhance services; discontinue features; change pricing with notice; discontinue an entire service with 30 days’ notice for paid services; and modify the AI systems and models used, with notice for material changes.
14. Dispute Resolution
14.1 Informal resolution (required first)
Before pursuing legal action, the parties agree to attempt good-faith resolution: provide written notice of the dispute to privacy@ztinfosec.com and allow 30 days for negotiation. If unresolved, arbitration or litigation may follow.
14.2 Arbitration (optional)
For US-based disputes, the parties may agree to binding arbitration under American Arbitration Association (AAA) rules with a single arbitrator. The arbitrator’s decision is final and binding; each party bears its own costs unless the arbitrator awards otherwise.
14.3 Small claims court
Either party may pursue small claims court if the claim is within the court’s jurisdiction.
15. Governing Law and Jurisdiction
These Terms are governed by and construed in accordance with the laws of Guatemala, where ZT INFOSEC is headquartered; conflict-of-law principles are excluded. Any legal action must be brought exclusively in the courts of Guatemala City, Guatemala, or in a venue mutually agreed in writing. You waive any objection to venue or jurisdiction. In any legal proceeding, the prevailing party may recover reasonable attorneys’ fees and court costs.
16. Modifications to Terms and Services
We may modify these Terms at any time. We will update the “Last Updated” date, email you about material changes if we have your email address, and post changes on our website. Your continued use after changes constitutes acceptance. We also reserve the right to modify, enhance, or discontinue features, change pricing with notice, discontinue an entire service with 30 days’ notice for paid services, update system requirements, and update the AI systems and models used.
17. Severability and Entire Agreement
If any provision is found invalid or unenforceable, it will be modified to the minimum extent needed or, if modification is impossible, severed; all other Terms remain in full effect.
These Terms constitute the entire agreement between you and ZT INFOSEC regarding use of our services, superseding all prior agreements, understandings, and negotiations — except a separate Statement of Work for professional services, a Non-Disclosure Agreement where required, and the Privacy Policy (separate but complementary). No amendment is valid unless made in writing and signed by authorized representatives. Failure to enforce any right does not constitute a waiver; any waiver must be in writing and signed.
18. Important Service-Specific Disclaimers
18.1 Complimentary Assessment Tool
The free assessment is not a penetration test, an active vulnerability scan, a compliance audit, or a comprehensive review. It assesses only publicly available data, and results reflect data at assessment time only. AI-assisted findings may contain inaccuracies.
You understand that findings may contain false positives and may miss real vulnerabilities; the absence of a finding does not mean the absence of a vulnerability; this is a tool, not a professional assessment; and AI analysis is not 100% accurate. You must confirm you own or control the domain, are authorized to request the assessment, and are not assessing third-party domains without authorization.
18.2 Risk Assessment SaaS Platform
The platform is more comprehensive than the free tool but is still not a penetration test, still requires your authorization, and remains subject to all limitations herein. Findings are AI-assisted but human-reviewed. You are responsible for maintaining the confidentiality of your account, keeping your password secure, reporting unauthorized access immediately, implementing recommendations, conducting periodic reassessments, and not relying solely on AI recommendations without human validation.
18.3 Professional Consulting Services
The specific scope is defined in the Statement of Work; only activities in the SOW are included, and out-of-scope work requires an amendment. Recommendations are based on the information available; future exploits or techniques not yet known cannot be identified; time and scope constraints mean not everything can be tested; and implementation is your responsibility.
19. Computer Fraud and Abuse Act (CFAA) Compliance
ZT INFOSEC’s services do not involve unauthorized access to any systems, testing of credentials or login pages, exploitation of vulnerabilities, exfiltration of data from target systems, denial-of-service attacks, or any intrusive testing. All assessment activities use only publicly available information, comply with responsible security research principles, respect robots.txt and rate limits, and do not disrupt services or operations.
Users must be authorized: you confirm you own or control any domain you assess, you represent that you have authorization to assess it, you agree not to assess domains without authorization, and you assume all liability for unauthorized assessment.
20. AI and Automated Decision-Making
ZT INFOSEC uses AI systems to generate assessment findings and recommendations, prioritize and categorize security issues, suggest remediation steps, and identify patterns and trends. All critical findings receive human review before delivery.
ZT INFOSEC does not use AI to make automatic account suspension or termination decisions, automated legal determinations, or binding compliance certifications — AI findings are advisory only.
SaaS Platform and Consulting customers have the right to request human security professional review of AI findings, challenge or dispute AI-generated recommendations, and opt out of cloud AI services (using local LLMs only). Contact privacy@ztinfosec.com to exercise these rights.
21. Contact Information
Privacy and data protection matters: privacy@ztinfosec.com · ZT INFOSEC, Guatemala City, Guatemala · response within 30 days (GDPR requirement).
General service inquiries: info@ztinfosec.com · response within 5 business days.
22. Summary of Key Terms
| Your obligation | Our commitment |
|---|---|
| Confirm you’re authorized to assess submitted domains | We’ll process assessments securely |
| Use services lawfully and ethically | We’ll protect your personal data |
| Don’t circumvent rate limits or abuse the service | We’ll notify you of breaches within 72 hours |
| Don’t redistribute reports without permission | We won’t sell or share your data |
| Pay for subscriptions on time | We’ll provide the services as described |
| Implement recommendations promptly | We’ll maintain confidentiality |
| Conduct periodic reassessments | We won’t hold you liable beyond the caps |
| Understand AI limitations | We’ll use human review for critical findings |
23. Acceptance and Agreement
By using ZT INFOSEC services, you confirm that you have read these Terms in full, understand the limitations and disclaimers, accept all terms and conditions, confirm you are authorized to use the service, accept all liability limitations, release ZT INFOSEC from liability as described, understand and accept AI involvement in assessments, and acknowledge that AI findings may contain inaccuracies.
Version 1.0 · Last updated June 2026 · Next review June 2027 · See also our Privacy Policy.