Legal · Assessment Terms
CyberDNA Pty Ltd (ABN: 95 627 959 200)
Version 1.0 — Effective date: 20/07/2026
These Cloud Exposure Assessment Terms & Authorisation (“Assessment Terms”) form a legally binding agreement between CyberDNA Pty Ltd (ABN [95 627 959 200]) (“CyberDNA”, “we”, “us” or “our”) and the person or entity accepting them (“you”, “your” or the “Customer”), governing the free Cloud Exposure Assessment (the “Assessment”) that CyberDNA provides using its FIKS platform (“FIKS” or the “Platform”).
The Assessment is the first time FIKS connects to your cloud environment. Your authorisation is essential. By ticking the “I authorise the Assessment and agree to these terms” (or similar) box, or by connecting your cloud environment to FIKS, you confirm that you have read and agree to these Assessment Terms and that you are authorised to grant the access described below.
If you are accepting on behalf of an entity, you represent and warrant that you have authority to bind that entity. If you do not agree, or you are not authorised to grant access to the cloud environment, you must not proceed with the Assessment.
1.1 The Assessment is a one-time, complimentary (no-fee) security exposure assessment in which FIKS connects to your nominated cloud environment (the “Customer Environment”), reads configuration and related metadata, and produces a report of identified security exposures, misconfigurations and posture findings (the “Assessment Report”).
1.2 The Assessment is read-only. FIKS uses least-privilege, read-only access and does not make changes to, exploit, disrupt, or write to your Customer Environment. The Assessment is not a penetration test and does not involve active exploitation or intrusion.
1.3 The Assessment is a point-in-time review based only on the data accessible to FIKS at the time it is performed.
2.1 You represent, warrant and agree, on a continuing basis, that:
2.2 You expressly authorise CyberDNA and FIKS to access and read the Customer Environment, using the read-only, least-privilege credentials, roles or permissions that you provide or approve, solely for the purpose of performing the Assessment and producing the Assessment Report.
2.3 The warranties and authorisation in this clause 2 are essential terms. You must not grant, and you warrant that you will not grant, access to any environment that you are not authorised to have assessed.
3.1 You must: (a) provide accurate connection details and configure the read-only, least-privilege access in accordance with CyberDNA’s instructions; (b) ensure you have all rights and consents required under clause 2; and (c) maintain appropriate back-ups of your systems and data independently of the Assessment.
3.2 You acknowledge that the completeness and accuracy of the Assessment depend on the scope and accuracy of the access and data you provide, over which CyberDNA has no control.
3.3 You may revoke the access granted to FIKS at any time. Revoking access before the Assessment completes may prevent CyberDNA from completing the Assessment or producing the Assessment Report.
4.1 The Assessment Report is provided for your information only. It reflects the state of the Customer Environment at a point in time, based on the data available to FIKS.
4.2 To the maximum extent permitted by law, and subject to clause 7:
5.1 In performing the Assessment, CyberDNA collects configuration data, metadata and findings relating to your Customer Environment (“Assessment Data”). CyberDNA uses Assessment Data only to perform the Assessment, produce and discuss the Assessment Report, and improve and secure the Platform, and as otherwise permitted by these Assessment Terms.
5.2 Overseas hosting. You acknowledge and agree that Assessment Data may be stored and processed outside Australia. As at the effective date, FIKS is hosted in Germany (using the Hetzner cloud infrastructure); CyberDNA may also host or process data in Australia (Amazon Web Services, Sydney region) and/or other jurisdictions from time to time. By accepting these Assessment Terms, you consent to the storage, processing and disclosure of Assessment Data (including any Personal Information it contains) outside Australia, including in Germany and the European Union. To the extent of that consent, Australian Privacy Principle 8.1 does not apply to that overseas disclosure.
5.3 Each party will comply with the Privacy Laws (as defined in CyberDNA’s End User Licence Agreement and Privacy Policy) applicable to it. To the extent Assessment Data contains Personal Information, you warrant you have all consents and authority necessary for CyberDNA to handle it as described. CyberDNA’s handling of Personal Information is described in its Privacy Policy at https://www.cyberdna.com.au/privacy-policy/.
5.4 Security and retention. CyberDNA will apply reasonable security measures to Assessment Data. CyberDNA may retain Assessment Data for a reasonable period to deliver and discuss the Assessment Report and, thereafter, will delete or de-identify it except to the extent required to be retained by law, held in routine back-ups, or retained in aggregated and de-identified form. You acknowledge that no method of transmission or storage is completely secure.
6.1 Each party must keep confidential the other party’s non-public information disclosed in connection with the Assessment, and use it only for the purposes of the Assessment. CyberDNA will treat your Assessment Data and the content of the Assessment Report relating to your Customer Environment as confidential.
6.2 CyberDNA owns all Intellectual Property Rights in FIKS and in the format, methodology and templates of the Assessment Report. CyberDNA grants you a non-exclusive, non-transferable, royalty-free licence to use the Assessment Report for your own internal business purposes. As between the parties, you own the underlying data about your Customer Environment.
6.3 CyberDNA may collect and use data derived from the Assessment in aggregated and de-identified form (from which you and any individual are not reasonably identifiable) to operate, improve and benchmark the Platform.
7.1 Nothing in these Assessment Terms excludes, restricts or modifies any guarantee, right or remedy conferred by the Australian Consumer Law or any other law that cannot lawfully be excluded (“Non-Excludable Rights”).
7.2 To the extent CyberDNA is liable for failure to comply with a non-excludable guarantee that can be limited, CyberDNA’s liability is limited, at its election, to resupplying the services or paying the cost of having them resupplied.
8.1 Nothing in this clause limits liability for death or personal injury caused by negligence, for fraud, for a breach by you of your authorisation warranties in clause 2 or your indemnity in clause 9, or for any liability that cannot be excluded or limited by law (including Non-Excludable Rights).
8.2 You acknowledge that the Assessment is provided free of charge. To the maximum extent permitted by law, and subject to clauses 7 and 8.1:
8.3 CyberDNA is not liable for any loss or damage to the extent caused by your breach of these Assessment Terms, your acts or omissions, your Customer Environment, credentials or configuration, third-party products or infrastructure, or your reliance on (or failure to act on) the Assessment Report.
9.1 You indemnify CyberDNA and its officers, employees, contractors and related bodies corporate against all liabilities, losses, damages, costs and expenses (including reasonable legal costs on a full indemnity basis) arising out of or in connection with: (a) any breach of your authorisation warranties in clause 2 (including any claim that CyberDNA or FIKS accessed an environment without proper authorisation); (b) any breach of clause 5 (data and privacy); or (c) any wilful, unlawful or negligent act or omission by you.
9.2 This indemnity is a continuing obligation and survives completion or termination of the Assessment.
10.1 These Assessment Terms commence when you accept them or connect your Customer Environment, and continue until the Assessment is completed and the Assessment Report delivered, unless terminated earlier.
10.2 Either party may terminate the Assessment at any time on notice. On completion or termination, you should revoke the access granted to FIKS, and CyberDNA will cease accessing the Customer Environment and will handle Assessment Data in accordance with clause 5.4.
10.3 Clauses 4, 5, 6, 7, 8, 9, 10.3 and 11 survive completion or termination.
11.1 These Assessment Terms are governed by the laws of the State of Victoria, Australia, and each party submits to the non-exclusive jurisdiction of the courts of Victoria.
11.2 CyberDNA may amend these Assessment Terms from time to time by posting an updated version; the version you accept applies to your Assessment.
11.3 These Assessment Terms are the entire agreement between the parties in relation to the Assessment. If you subsequently subscribe to, or use, the FIKS platform beyond the Assessment, the FIKS End User Licence Agreement applies to that use.
11.4 If any provision is invalid or unenforceable, it is to be read down or severed to the minimum extent necessary without affecting the remaining provisions.
By ticking “I authorise the Cloud Exposure Assessment and agree to these terms”, or by connecting your cloud environment to FIKS, you agree to be bound by these Assessment Terms and confirm you are authorised to grant the access described above.