Skip to content
The //Zyber// Security

Legal

Master Service Agreement (Template)

This MSA governs all engagements between the Client and TheZyberSecurity. Each engagement is scoped by a separate Statement of Work (SoW) that incorporates this MSA.

Last updated · 2026-07-21Reviewed by counsel: pending (owner to confirm)

1. Services

The Zyber Security will provide the Services described in each SoW using commercially reasonable skill and care. Services are outcomes-oriented but time-limited by SoW.

2. Fees & payment

Fees, milestones, and payment schedule are stated in each SoW. Invoices are payable within 30 days (net-30). Overdue invoices accrue interest at the lower of 1.5% per month or the statutory maximum.

3. Deliverables & acceptance

Deliverables are described in each SoW. Client has 10 business days from delivery to raise acceptance objections in writing; absent timely objection, deliverables are deemed accepted.

4. Rules of engagement

For any offensive-security services (penetration testing, red-teaming, vulnerability assessment), the parties will execute Rules of Engagement (ROE) before testing begins. The ROE will define scope, testing windows, blackout dates, allowed and prohibited techniques, evidence-handling procedures, and emergency-stop contacts.

5. Confidentiality

Each party will hold the other's Confidential Information in confidence, use it only for the purposes of the Services, and protect it with at least the standard of care it uses for its own similar information (but not less than reasonable care). Confidentiality obligations survive termination for 5 years, and indefinitely for trade secrets.

6. Intellectual property

  • Client Materials remain the property of Client.
  • Provider Tools (methodologies, scripts, templates, know-how developed independently or before the engagement) remain the property of The Zyber Security.
  • Deliverables: on payment in full, Client receives a worldwide, perpetual, non-exclusive license to use Deliverables for internal business purposes.

7. Data protection

Where the Services involve processing of Personal Data on Client's behalf, the parties will additionally execute our Data Processing Addendum.

8. Warranties

Each party warrants that (a) it has authority to enter into this MSA; (b) it will comply with applicable laws in performance; (c) Provider will perform Services with reasonable skill and care by suitably qualified personnel.

9. Limitation of liability

Except for (a) breach of confidentiality; (b) IP indemnity; (c) gross negligence, willful misconduct, or fraud; and (d) statutory rights that cannot be limited — each party's aggregate liability is capped at the fees paid or payable under the applicable SoW in the 12 months preceding the claim.

10. Indemnity

Each party will defend and indemnify the other against third-party claims arising from breach of confidentiality, misappropriation of IP, or breach of applicable law by the indemnifying party.

11. Term & termination

This MSA continues until terminated. Either party may terminate for uncured material breach after 30 days written notice, or immediately for insolvency. Termination of the MSA does not automatically terminate active SoWs unless expressly stated.

12. Governing law

Governing law: [to be finalized with counsel]. Exclusive jurisdiction: courts of that jurisdiction, subject to applicable arbitration clauses.

13. Miscellaneous

Assignment: neither party may assign this MSA without the other's prior written consent, except to an affiliate or in connection with a bona fide corporate transaction. Notices: in writing to the addresses in each SoW. Entire agreement: this MSA plus each SoW is the entire agreement.

14. Contact

Contracts and legal: contact@thezybersecurity.com.


This MSA is a template ready to be reviewed and finalized by counsel before signature.