Cyber Fundamentals AI Service Terms

Last updated: 1 October 2026

These Service Terms form part of the Terms and Conditions of app.cyberfundamentals.ai (the "Terms") and are incorporated into them by reference. Capitalised words not defined here have the meaning given in the Terms. These Service Terms explain what Cyber Fundamentals AI does, how its assessments and other outputs should be understood, and what each party is responsible for. If these Service Terms conflict with the Terms, these Service Terms prevail to the extent of the conflict, except where the Terms set out rights that cannot be limited under applicable law.

Cyber Fundamentals AI is provided to organisations, not to consumers. In these Service Terms:

  • "Customer" means the organisation that registers for, subscribes to or is invited to use the Service and on whose behalf the Terms are accepted. The Customer is the "User" for the purposes of the Terms.
  • "Authorised Users" means the individuals the Customer permits to access the Service on its behalf, such as its employees, contractors and advisers.
The Customer is responsible for the use of the Service by its Authorised Users, and for ensuring that they comply with the Terms and these Service Terms.

1. About Cyber Fundamentals AI

Cyber Fundamentals AI is a cybersecurity assessment, evidence management, monitoring, reporting and decision-support platform. It helps organisations understand where they stand, identify what to improve next and support their decisions with evidence.

Through the Service, Customers can carry out cybersecurity assessments, record and manage evidence, connect supported third-party systems, track risks and remediation actions, and generate scores, maturity levels, findings, recommendations, framework mappings, dashboards and reports (together, "Outputs").

The Service supports the Customer's own cybersecurity and risk-management activities. It does not take over responsibility for them, and it does not certify, accredit or guarantee the security or compliance of any organisation.

"Customer Data" means the data, documents, evidence, responses and other content that the Customer, its Authorised Users, or a system connected on its behalf, provides to this Application.

2. How assessments are produced

Assessments and Outputs are produced by applying the Service's assessment methodology and scoring rules to:

  • the information, answers and representations provided by the Customer and its Authorised Users;
  • the evidence uploaded to, or collected through integrations connected to, this Application;
  • the systems, controls and organisational units the Customer includes in the assessment scope;
  • any review carried out by an assessor, where the Customer's plan includes or the Customer requests assessor review; and
  • the conditions that exist at the time the information and evidence are captured.
An assessment reflects the scope, information and evidence available at the relevant time. Cybersecurity environments change continually: technologies, configurations, vulnerabilities, threats, controls, personnel and business circumstances all change, so an Output may become outdated after the date it was produced. Matters outside the assessment scope, or not reflected in the information and evidence provided, are not assessed.

3. Cybersecurity assessments, scores and reports

Assessments, scores, maturity levels, ratings, findings, recommendations, framework and compliance mappings, assurance information and reports are designed to support the Customer's cybersecurity risk management and decision-making.

Unless the Owner expressly states otherwise in writing for a specific Output, an assessment, score, maturity level or rating is not:

  • a guarantee or warranty that the Customer, or any system, is secure;
  • a prediction that a cybersecurity incident will or will not occur;
  • confirmation that all vulnerabilities, weaknesses or threats have been identified;
  • confirmation that implemented controls will operate effectively at all times;
  • an insurance underwriting assessment, or a statement of insurability;
  • legal advice or a determination of regulatory or statutory compliance; or
  • a formal certification, accreditation or attestation.
The same applies when the Service maps Customer Data, controls or evidence against an external cybersecurity, regulatory or compliance framework. A mapping shows how the Customer's information relates to that framework's requirements, to support readiness and gap analysis. It is not a determination by the framework owner, a certification body or a regulator.

Where an Output is described as "approved", "reviewed" or "signed off" by an assessor, it records that a reviewer applied professional judgement to the information and evidence available at the time. It does not change the nature of the Output as described in this section.

4. No guarantee of security

No technology, control, framework, methodology, assessment or service can eliminate cybersecurity risk. The Service helps Customers understand and reduce that risk. It cannot remove it.

Accordingly, and without limiting any obligation the Owner expressly accepts in the Terms, the Owner does not warrant or guarantee that:

  • the Customer will not suffer a cybersecurity incident, compromise, ransomware attack or data breach;
  • the Customer's systems are free of vulnerabilities;
  • implementing any recommendation, achieving any score or reaching any maturity level will prevent an attack or incident; or
  • completing an assessment means that an organisation is secure or compliant.
This section is about the Customer's own environment and security posture. It doesn't reduce the Owner's own obligations regarding the security of this Application and of Customer Data that the Owner processes, which are set out in the privacy policy and in any data processing agreement between the Owner and the Customer.

5. Customer responsibilities

The Customer retains responsibility for its cybersecurity and risk-management decisions. In particular, the Customer is responsible for:

  • providing information and evidence that is accurate, complete, current and representative of its environment, and updating it when circumstances change;
  • determining and confirming the scope of each assessment;
  • reviewing findings, recommendations and other Outputs, and deciding whether, how and when to act on them in light of its own circumstances and risk tolerance;
  • designing, operating and maintaining its own cybersecurity programme, including appropriate technical and organisational security measures, monitoring, backups and incident-response and recovery arrangements; and
  • obtaining specialist professional advice (for example, technical, legal, regulatory or insurance advice) where appropriate.
The Owner is not responsible for managing the Customer's overall cybersecurity programme, and does not act as the Customer's Chief Information Security Officer, unless this has been expressly agreed in a separate written professional services agreement.

Where a Customer makes the Service available to its own clients (for example, as a managed service provider), that Customer is responsible for its own advice to, and its relationship with, those clients.

6. AI-assisted functionality

Some features of the Service use artificial intelligence to help analyse cybersecurity information, interpret and pre-screen evidence, explain requirements, identify potential gaps, draft summaries and recommendations, assist remediation planning, and help produce reports and other Outputs.

AI-assisted Outputs are decision support. They are generated from the information available to the Service, and they can be incomplete, imprecise or not suited to the Customer's specific circumstances. AI-assisted Outputs should be reviewed by a suitably informed person before they are relied on for any material cybersecurity, regulatory, legal, financial or business decision.

Where the Service shows that an AI-assisted Output has been reviewed or approved by a person, section 3 still applies. The Customer must not represent an AI-assisted Output to third parties as an independent professional determination unless it has been reviewed and approved as such.

7. Platform outputs and professional services

The Service gives the Customer cybersecurity information, structured assessments, recommendations and decision support, which reflect the expertise built into the Service's methodology and content. Platform-generated Outputs are general to the information provided. They don't replace specialist professional judgement applied to the Customer's particular circumstances.

Individually scoped consulting, audit, virtual CISO or other professional services are provided only under a separate written agreement with the Owner (or the relevant provider). That agreement, not these Service Terms, governs the scope, standard of care and liability for those services.

8. Third-party frameworks, standards and trademarks

The Service may refer to, or map Customer Data against, third-party frameworks and standards such as CyberFundamentals (CyFun®), NIS2, ISO/IEC 27001, Cyber Essentials and NIST frameworks. These frameworks, their names and marks belong to their respective owners. Reference to them does not imply endorsement by, affiliation with, or approval from those owners, unless the Owner expressly says so.

Using the Service does not by itself amount to certification, accreditation, regulatory approval or confirmation of statutory compliance under any framework or law. Where a recognised certification or conformity process exists, it is carried out by the relevant authorised body under that process. The Service may help a Customer prepare for it.

9. Customer Data, Outputs and reports

Customer Data. The Customer keeps all rights in its Customer Data. The Owner claims no ownership of Customer Data just because it has been processed or analysed by the Service, and uses it only as permitted by the Terms.

Owner materials. The software, assessment methodologies, scoring mechanisms, question sets, workflows, templates, report layouts, designs and documentation of the Service remain the property of the Owner or its licensors. Any of them embedded in an Output may be used only as part of that Output.

Status of reports. Reports, dashboards, assessment results, scores, maturity ratings, findings, recommendations and compliance mappings, whether viewed in this Application or exported, reflect the scope, information and evidence that applied on the assessment or report date shown on them.

Business use of reports. Notwithstanding the clause "Rights regarding content on this Application" in the Terms, the Customer may use, copy and share Outputs relating to its own organisation (or, for a managed service provider, the client the Output relates to) for its legitimate business purposes. This includes sharing them with its directors, employees, auditors, insurers, customers, suppliers, investors, advisers and regulators. When sharing an Output, the Customer must not alter it in a way that misrepresents its content, date or scope, and must not remove the statements describing its status and limitations.

10. Changes and contact

The Owner may update these Service Terms in the same way, and subject to the same notice provisions, as the Terms. The Owner and its contact details are as stated in the Terms.