Legal
Terms of Service and Privacy Policy
Effective: April 5, 2026
Terms of Service
1. Acceptance of Terms
By accessing or using sigress.com, the Sigress Partner Portal, or any services provided by Sigress (“Company,” “we,” “us,” or “our”), you agree to be bound by these Terms of Service. If you do not agree to these terms, do not access or use our services. We reserve the right to modify these terms at any time. Continued use of the services following any changes constitutes acceptance of the revised terms.
2. Description of Services
Sigress provides white-label physical penetration testing, red team operations, close access cyber operations, and related security assessment services on a subcontractor basis to cybersecurity firms (“Partners”). The Partner Portal provides tools for engagement scoping, pricing, and deliverable management. All services are governed by the specific terms of each engagement as defined in the applicable statement of work or master services agreement between Sigress and the Partner.
3. Account Access
Access to the Partner Portal requires authentication through Microsoft Entra ID. You are responsible for maintaining the security of your credentials and for all activities that occur under your account. You agree to notify Sigress immediately of any unauthorized use of your account. Sigress reserves the right to suspend or terminate access at any time, with or without notice, for any reason.
4. Intellectual Property and Copyright
ALL INTELLECTUAL PROPERTY RIGHTS IN AND TO THE FOLLOWING REMAIN THE SOLE AND EXCLUSIVE PROPERTY OF SIGRESS:
- The Sigress website, Partner Portal, engagement builder, and all associated software, source code, and user interfaces
- All pricing models, algorithms, complexity scoring systems, and estimation methodologies
- All testing methodologies, tradecraft techniques, operational procedures, playbooks, and proprietary processes
- All deliverables, findings, reports, assessments, and engagement materials produced by Sigress operators
- All training materials, documentation, and knowledge base content
- The Sigress name, logo, trademarks, and all associated branding
Limited License to Partners. Partners are granted a limited, non-exclusive, non-transferable, revocable license to use deliverables and engagement materials solely for the purpose of the specific client engagement for which they were produced. This license does not constitute a transfer of ownership. White-label branding applied to deliverables is a license to present, not an assignment of intellectual property rights. The underlying work product, methodology, and content remain the exclusive property of Sigress.
No Derivative Works. Partners and users may not reproduce, modify, adapt, translate, create derivative works from, reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, algorithms, or underlying methodologies of any Sigress materials, tools, or deliverables without prior written consent from Sigress.
Non-Disclosure of Methodology. Partners shall not disclose, share, publish, or otherwise make available any Sigress methodologies, pricing structures, tool capabilities, operational procedures, or proprietary information to any third party, including but not limited to competitors, end clients (beyond the scope of authorized deliverables), or the general public. This obligation survives the termination of the partnership.
Enforcement and Remedies. Any unauthorized use, reproduction, distribution, or disclosure of Sigress intellectual property constitutes a material breach of these terms and may result in immediate termination of access and the partnership. Sigress reserves the right to seek injunctive relief, monetary damages, and recovery of attorney's fees and costs in any jurisdiction. The parties acknowledge that a breach of this section would cause irreparable harm for which monetary damages alone would be insufficient, and that Sigress shall be entitled to equitable relief, including injunction and specific performance, without the requirement of posting a bond.
Survival. The intellectual property and confidentiality obligations set forth in this section survive the expiration or termination of these Terms of Service, any statement of work, or any partnership agreement, indefinitely.
5. Acceptable Use
You agree not to:
- Use the services for any unlawful purpose or in violation of any applicable laws or regulations
- Attempt to gain unauthorized access to any systems, networks, or data beyond the scope of an authorized engagement
- Interfere with or disrupt the integrity or performance of the services or related systems
- Share, resell, or sublicense access to the Partner Portal or any Sigress tools without written authorization
- Use automated means to scrape, crawl, or extract data from the website or portal
- Misrepresent your identity, affiliation, or authorization level
6. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, SIGRESS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, OR ANY LOSS OF DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES RESULTING FROM YOUR ACCESS TO OR USE OF THE SERVICES. THE TOTAL LIABILITY OF SIGRESS FOR ANY CLAIMS ARISING UNDER THESE TERMS SHALL NOT EXCEED THE AMOUNT PAID BY YOU TO SIGRESS IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
7. Indemnification
You agree to indemnify, defend, and hold harmless Sigress, its officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, and expenses (including reasonable attorney's fees) arising out of or related to your use of the services, violation of these terms, or infringement of any intellectual property or other rights of any third party.
8. Disclaimer of Warranties
THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. SIGRESS DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE. PRICING ESTIMATES GENERATED BY THE PARTNER PORTAL ARE FOR REFERENCE PURPOSES ONLY AND DO NOT CONSTITUTE A BINDING QUOTE OR CONTRACT.
9. Termination
Sigress may terminate or suspend your access to the services at any time, with or without cause, with or without notice. Upon termination, your right to use the services ceases immediately. All provisions of these terms that by their nature should survive termination shall survive, including but not limited to intellectual property, confidentiality, limitation of liability, and indemnification.
10. Governing Law
These Terms of Service shall be governed by and construed in accordance with the laws of the Commonwealth of Virginia, without regard to its conflict of law provisions. Any disputes arising under these terms shall be resolved exclusively in the state or federal courts located in the Eastern District of Virginia.
Privacy Policy
1. Information We Collect
We collect information in the following ways:
Account Information. When you sign in to the Partner Portal via Microsoft Entra ID, we receive your name, email address, organization, and security group memberships as provided by your identity provider.
Usage Data. We collect information about how you interact with the website and Partner Portal, including pages visited, features used, and timestamps.
Contact Information. When you submit a contact form or send us an email, we collect the information you provide, including your name, email address, company, and message content.
2. How We Use Your Information
- Authenticating and authorizing access to the Partner Portal
- Providing, maintaining, and improving our services
- Communicating with you about your account, engagements, or inquiries
- Enforcing our terms of service and protecting against unauthorized use
- Complying with legal obligations
3. Information Sharing
We do not sell, rent, or trade your personal information. We may share information with third parties only in the following circumstances: with your consent; to comply with legal obligations, court orders, or law enforcement requests; to protect the rights, property, or safety of Sigress, our partners, or others; or with service providers who assist in operating our services, subject to confidentiality obligations.
4. Data Security
We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide services. We may also retain information as required by law, to resolve disputes, or to enforce our agreements. When information is no longer needed, we delete or anonymize it in accordance with our data retention policies.
6. Cookies and Tracking
The website uses essential cookies required for authentication and session management. We do not use third-party advertising cookies or cross-site tracking technologies.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at our contact page. We will respond to requests within 30 days.
8. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised effective date. Your continued use of the services after changes are posted constitutes acceptance of the updated policy.
10. Contact
For questions about these terms or our privacy practices, contact us at our contact page.