Kestrel Systems

AWS Security & Infrastructure Audits

Back

Terms of Service

Last updated September 13, 2026

Who these terms are between

These terms govern security audit and review services provided by Kestrel Systems (“we”) to you or the organization you represent (“you”). By engaging us, you agree to them. If you are agreeing on behalf of a company, you confirm you are authorized to bind that company.

Your authorization is required

You confirm that you own the systems, accounts, domains, and infrastructure you ask us to review, or that you hold written permission from their owner to authorize a security review of them. You are responsible for obtaining any consent required from your hosting provider, cloud provider, or any third party whose terms apply.

We rely on this authorization. If it turns out you did not have the right to grant it, you are responsible for the consequences, and you agree to indemnify us against any claim arising from our review of a system you were not authorized to give us access to.

What the service is

We perform a read-only review of the systems agreed in writing before work begins, and deliver a written report of findings ranked by severity with a description of impact. The scope of any engagement is what is stated in that written agreement and nothing beyond it.

We do not make changes to your systems, deploy fixes, or operate your infrastructure as part of an audit. Any remediation work is a separate engagement on separately agreed terms.

What the service is not

A security audit is a point-in-time review based on the access and information available to us at the time. It is not a guarantee that your systems are secure, that every vulnerability has been found, or that you comply with any law, regulation, standard, or framework.

We do not provide legal, regulatory, compliance certification, or insurance advice. A clean report is not a certification and should not be presented as one.

Your responsibilities

You are responsible for providing accurate information and timely access, for backing up your own systems and data, for deciding which findings to act on, and for implementing any fixes. Security outcomes after delivery of the report remain your responsibility.

Fees and payment

Fees are quoted as a flat rate and confirmed in writing before work starts. Fees are due as stated in that confirmation. If the scope you described materially differs from what we find once we have access, we will tell you and agree a revised fee with you before continuing, rather than adjusting it afterwards.

Confidentiality

We treat your systems, configuration, findings, and business information as confidential. We do not disclose them to third parties except where you direct us to, or where we are legally required to. We will not publish or use your name as a reference without your permission.

You agree to keep our reports and methodology confidential and not to redistribute them publicly.

Intellectual property

On payment in full, you own the report we deliver to you and may use it internally and share it with your own advisors. We retain ownership of our underlying methods, templates, and tooling.

Limitation of liability

To the fullest extent permitted by law, our total liability arising out of or relating to an engagement is limited to the fees you paid us for that engagement.

We are not liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, even if we were advised such damages were possible.

Nothing in these terms limits liability that cannot lawfully be limited, including liability for fraud or willful misconduct.

No warranty

Services are provided on an “as is” basis. To the extent permitted by law we disclaim all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement.

Ending an engagement

Either of us may end an engagement in writing at any time. If you end it after work has begun, fees for work already performed remain due. The confidentiality, liability, and indemnity sections survive the end of an engagement.

Governing law

These terms are governed by the laws of the State of Florida, without regard to its conflict of laws rules. Any dispute will be brought in the state or federal courts located in Hillsborough County, Florida, and we each consent to that jurisdiction.

Changes

We may update these terms. The version in effect for your engagement is the version published when that engagement was agreed.

Contact

Questions about these terms: ryan.cuff@icloud.com