Terms
The rules for using this website, and the ones that apply if we end up working together. Written to be understood rather than to be unreadable.
Last updated September 19, 2026
The short version
- Nothing on this site is an offer you can accept. Prices are estimates, the list is a request, and there is no agreement until we have both signed one.
- We only test systems you own or are entitled to let us test, and we need that in writing first. No exceptions.
- Security work reduces risk. It does not make you unbreakable, and anyone who promises otherwise is selling you something.
- What we learn about you stays confidential, with no case studies and no name-dropping unless you say yes in writing.
Who these terms are between
They are between you and Layer8Secure, a security business operating on the Treasure Coast, Florida. "We" and "us" mean Layer8Secure; "you" means whoever is reading the site or engaging us.
The website is built and operated on our behalf by HatchTag. That matters for how your information is handled rather than for these terms — the privacy notice explains the split.
Using this website
Read it, use the shop, send us an email. In return, please do not attack it, scrape it wholesale, or try to break into the parts that are not yours. The irony would be considerable, and it would still be unauthorised access.
Found a flaw? We would rather hear it from you than from someone else. Report it to DigitalChocolate@layer8secure.com. A report made in good faith — no data taken, no service disrupted, no demand attached — will be met with thanks and a fix, not a lawyer.
The site is provided as it is. We keep it accurate and available, but we do not promise it will never be wrong or never be down.
The shop is not a checkout
This is the clause worth reading twice, because the page is designed to look like a shop and behaves like one right up until the end.
Adding something to your list does not buy it. The list lives in your own browser. Sending it opens your email programme with a message you can edit or discard, and even once it arrives it is a request for a quote, not an order. Nothing on this website is an offer capable of being accepted, and no contract exists between us until we have issued a written quote or statement of work and you have accepted it in writing.
We take no payment on this site. There is no card field, no payment processor and no stored payment method. We will never ask for card or bank details by email; if you receive a message that appears to be from us and does, treat it as a phishing attempt and call +1 (772) 978-6185.
Prices, quotes and what changes them
- Figures on the shop are indicative. They are honest estimates for a typical small business, not a price list, and a figure marked "from" is a starting point.
- We survey before we quote. What a job actually costs depends on the building, the network and what is already there. The quote that follows the survey is the real number.
- Hardware is passed through at cost where a manufacturer sets the price, and moves when they move it.
- Tax is not included in any figure shown on the site.
- A written quote holds for 30 days unless it says otherwise, and it prices the scope it describes. Work added later gets quoted later.
- Recurring services — monitoring, retainers, per-person training — are billed for the term in the quote and renew only if you agree to renew.
The agreement for the work itself
Any engagement is governed by the written quote, statement of work or services agreement we sign with you. That document sets the scope, the dates, the fees and the payment terms.
Where it and this page disagree, that document wins. These terms cover the website and fill the gaps; they are not a substitute for an engagement agreement and they do not override one you have signed.
Authorisation for testing
Penetration testing, phishing simulation and network assessment all involve doing, on purpose and with permission, things that are crimes without it. So the permission is not a formality.
- We test only within a scope agreed in writing, during an agreed window, and only after you have confirmed in writing that you own the systems in scope or are entitled to authorise testing of them.
- If a system is hosted, managed or owned by somebody else, that somebody else has to agree too. Cloud and hosting providers usually have their own rules for this, and we will not proceed on an assurance that "it will be fine".
- We will stop immediately if we find we are outside scope, if we find evidence of an existing compromise, or if continuing looks likely to cause real damage — and we will tell you why.
- Authorisation you are not entitled to give is not authorisation. If you confirm a scope you do not have the right to confirm, that is on you, and you agree to cover us for claims that follow from it.
Phishing simulations are run to train, not to catch people out. Results come back to you as aggregates, and we do not name individuals to their employer for clicking a test email.
What we need from you
- Accurate information about what you run and what matters. We can only assess what we are told about or can find.
- Access, credentials or physical entry where the agreed scope needs it, when it needs it.
- Current, tested backups before any testing begins. Testing is careful, not risk-free.
- A named person who can make decisions and answer the phone during an engagement.
- Payment to the terms in the quote.
What security work can and cannot do
A test tells you what a competent attacker could find in the time agreed, with the access agreed, on the day it was run. It is a snapshot. It is not a certificate, not a guarantee, and not a promise that nothing will ever go wrong.
We do not warrant that your systems are or will remain secure, that a test finds every weakness, or that following our recommendations prevents every incident. Anyone who does warrant that is describing something that does not exist. What we do commit to is competent work, carried out carefully, reported honestly — including when the honest answer is that you do not need what you asked us for.
Confidentiality
Both directions. What you tell us about your systems, your people and your weaknesses stays with the people doing the work, and it is used for the engagement and nothing else.
We will not name you as a client, publish a redacted report, or use your findings in marketing without your written agreement. If you have your own NDA, we will sign it.
The exception is the narrow one everybody has: if the law requires disclosure, or if we find something that presents an immediate danger to people, we may have to act. We will tell you first wherever we lawfully can.
Who owns what
- This website — its text, design and code — belongs to us or to HatchTag. Read it and link to it freely; do not republish it as your own.
- Reports and deliverables we produce for you are yours to use inside your organisation, and to show an auditor, insurer or customer who needs to see them.
- Our methods, tooling and templates stay ours. A report you commissioned does not transfer the machinery that produced it.
- Hardware carries its manufacturer's warranty, and we pass that through to you rather than replacing it with one of our own.
Liability
We do not limit liability for anything the law does not let us limit — including our own fraud, and death or personal injury caused by our negligence.
Beyond that, and to the extent the law allows: our total liability for any engagement is capped at the fees you paid us for it, and we are not liable for indirect or consequential loss, lost profit, lost data or business interruption. If something we did causes a problem, tell us early — there is usually a fix, and there is always a conversation.
Changes to these terms
We update this page when the business changes. The date at the top changes with it. A change applies to what happens after it is published — it does not rewrite an engagement already agreed under an earlier version, which stays governed by the terms in force when you signed.
Governing law
These terms are governed by the laws of the State of Florida, and the courts of Florida have jurisdiction. If one part of this page turns out to be unenforceable, the rest of it still stands.
Contact
Questions about any of this go to DigitalChocolate@layer8secure.com or +1 (772) 978-6185. You will get a person, not a form.
This page is written in plain English for people who have to live with it. It is not legal advice, and it has not been through a lawyer. If you are about to sign something substantial — or if you work under HIPAA, PCI or a regulator with opinions — have your own counsel read it first.