Effective date: September 3, 2026 · Last updated: September 2026
This page consolidates the corporate information and the policies that govern your relationship with CyberNest Secure LLC — as a visitor to this website and as a client of our services. Where an individually negotiated engagement agreement, proposal, or statement of work conflicts with anything on this page, that signed agreement controls.
CyberNest Secure is a cybersecurity consulting and advisory firm serving healthcare, government and municipal, financial, and other regulated organizations in Puerto Rico and beyond. We provide risk assessments, virtual CISO (vCISO) leadership, penetration testing, incident response planning, cloud and infrastructure security, security awareness training, and AI security services.
Nothing on this website constitutes an offer to contract, and no engagement begins until a written agreement is executed by both parties.
↑ Back to topThese terms apply to clients who engage CyberNest Secure LLC for professional services. They supplement, and do not replace, the signed proposal, statement of work, or master services agreement governing a specific engagement. For terms governing use of this website itself, see our Terms & Conditions.
Each engagement is defined by a written proposal or statement of work identifying the services, deliverables, schedule, assumptions, and fees. Work outside that defined scope requires a written change order. Verbal requests do not modify scope.
Security testing is performed only against systems the client is entitled to authorize. Before any testing begins, the client represents and warrants that it owns the in-scope systems or holds documented authority to permit testing of them, and that such testing does not violate any agreement with a third party, including hosting, cloud, or software providers. The client is responsible for obtaining any consent required from affiliates, landlords, service providers, or data owners. CyberNest Secure may suspend or decline work where authorization cannot be evidenced.
The client is also responsible for providing timely access, accurate environment information, a designated point of contact, and current backups of any system within scope.
Security testing carries inherent risk, including service degradation or interruption, particularly against fragile or legacy systems. We take reasonable care to minimize disruption and will agree testing windows and escalation procedures in advance. The client accepts that some risk cannot be eliminated and is responsible for maintaining backups and continuity arrangements.
Assessments, tests, and reports describe conditions observed during a defined period, using the information and access made available to us. They are not exhaustive and do not certify, warrant, or guarantee compliance with any law, regulation, or framework — including HIPAA, NIST, PCI DSS, ISO, or IRS Publication 1075 — nor that systems are free from vulnerabilities or will not be compromised. Final compliance determinations remain with the client and its legal counsel or regulators.
Fees, payment schedules, and expense handling are set out in the applicable proposal or statement of work. Unless otherwise agreed in writing, invoices are payable within thirty (30) days of the invoice date. Applicable taxes are the responsibility of the client. We may suspend work on materially overdue accounts after written notice.
Each party will protect the other's confidential information using at least the same care it applies to its own, and will use it only to perform or receive the services. Findings, reports, network detail, and credentials disclosed during an engagement are treated as client confidential information. These obligations survive termination. Nothing prevents disclosure required by law, provided the disclosing party gives notice where legally permitted.
On full payment, the client receives a non-exclusive, non-transferable right to use the deliverables prepared for it for its own internal business purposes. CyberNest Secure retains ownership of its pre-existing materials, methodologies, tooling, templates, and general knowledge and experience, including anything developed independently of the engagement. Reports may not be republished, resold, or provided to third parties as an independent certification without our prior written consent, except to the client's auditors, insurers, regulators, and legal advisors on a confidential basis.
We may engage qualified subcontractors or specialist personnel to perform parts of an engagement. We remain responsible for their work and bind them to confidentiality and data protection obligations no less protective than those in these terms.
Services are performed in a professional and workmanlike manner consistent with generally accepted industry practice. Except as expressly stated, all services and deliverables are provided without warranties of any kind, whether express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data, even if advised of the possibility. Except for breach of confidentiality, a party's gross negligence or willful misconduct, or the client's payment obligations, each party's total aggregate liability arising out of an engagement is limited to the fees paid for that engagement in the twelve (12) months preceding the event giving rise to the claim. The specific limitation applicable to an engagement is set out in its signed agreement and controls over this summary.
Either party may terminate an engagement on thirty (30) days' written notice, or immediately for material breach that remains uncured fifteen (15) days after written notice. On termination, the client pays for services performed and expenses incurred through the effective date. We may suspend testing immediately if we reasonably believe it is unauthorized, unlawful, or causing unintended harm.
These terms are governed by the laws of the Commonwealth of Puerto Rico, without regard to conflict-of-law principles. The parties submit to the exclusive jurisdiction of the courts located in San Juan, Puerto Rico, unless the signed engagement agreement provides otherwise.
↑ Back to topThis policy applies to everyone who uses this website, our client portals and shared workspaces, and any tooling, report, or deliverable we provide. It exists because the material we produce — vulnerability detail, attack paths, proof-of-concept content — is useful to a defender and equally useful to an attacker.
You may not:
Reports we issue frequently contain exploitable detail. Clients are expected to distribute them on a need-to-know basis, store them with access controls appropriate to their sensitivity, and not post them to public repositories, ticketing systems, or file shares open to the whole organization.
If you believe you have found a security vulnerability in this website or our infrastructure, please report it to info@cybernestsec.com with enough detail to reproduce it. Please do not access, modify, or exfiltrate data belonging to others, and give us a reasonable opportunity to remediate before any public disclosure. We will not pursue action against good-faith research that respects those limits.
We may investigate suspected violations and may suspend access, suspend or terminate an engagement, and report unlawful activity to the appropriate authorities. Suspension for a violation does not relieve the client of payment obligations for services already performed.
↑ Back to topThis policy explains what happens to personal information in connection with this website and our general business communications. Client data we encounter while delivering services is governed separately by Section 5.
We do not operate analytics, advertising pixels, or cross-site tracking on this website. We do not sell or rent personal information, and we do not use it for behavioral advertising.
When you submit the contact form, your name, email, company, area of interest, and message are sent to us and delivered to our business mailbox through Microsoft 365. Nothing is emailed to you or to anyone else. The form is protected by Cloudflare Turnstile, which checks that you are not a bot and processes your IP address for that purpose under its own terms. We use what you send to answer your inquiry and retain it in our business mailbox in the normal course. We send cybersecurity advisories and updates only if you tick the separate opt-in box, and you can withdraw that consent at any time.
Our Security Posture Check asks eight questions and emails you the resulting report. To receive it we ask for your name, company, position, business email and work phone, and which compliance or security frameworks apply to your organization. All are required, and we accept business email addresses only. When you submit, those details and your answers are sent to us and the report is emailed to you through Microsoft 365. We retain your details as a business contact record so that a consultant can follow up once. We send cybersecurity advisories and updates only if you tick the separate opt-in box on the form, and you can withdraw that consent at any time. We do not sell, rent, or pass them to any third-party marketing or lead-generation service. You may ask us to delete your information at any time by writing to info@cybernestsec.com. We will honor the request unless we have a legal, contractual, or legitimate business requirement to retain it. The form is protected by Cloudflare Turnstile, which checks that you are not a bot and processes your IP address for that purpose under its own terms. Your answers are self-reported: the assessment is indicative only and does not certify, grant, or evidence compliance with any framework.
This site stores nothing in your browser's local storage and sets no advertising or tracking cookies of our own. The language you read in is chosen by the page address: Spanish pages live under /es/.
We use the information you send to respond to your inquiry, provide and administer services, issue invoices, and meet legal and professional obligations. We share it only with service providers acting on our behalf under confidentiality obligations, with professional advisors, or where required by law or legal process. We do not sell personal information.
We keep business correspondence and engagement records for as long as needed for the purpose collected and for the periods required by applicable tax, professional, and legal requirements, then dispose of them securely.
You may ask us what personal information we hold about you, ask us to correct it, ask us to delete it where we have no continuing legal or contractual need to retain it, and ask us to stop sending you communications. Write to info@cybernestsec.com and we will respond within a reasonable period. We may need to verify your identity before acting.
This is a business-to-business website and is not directed to children. We do not knowingly collect personal information from children.
Our operations are based in Puerto Rico, and information you send is processed in the United States. If you contact us from another jurisdiction, you understand that its data protection rules may differ. If you believe rights under a non-US regime apply to your information, write to us and we will work with you in good faith.
We may update this policy as our practices or the services on this site change. The effective date at the top of this page reflects the current version.
↑ Back to topDelivering security work means we are routinely exposed to our clients' most sensitive material: protected health information, personally identifiable information, credentials, configuration detail, and evidence of live weaknesses. This policy sets out how we handle it.
When we handle personal data on behalf of a client, the client determines the purpose of the processing and we act on its documented instructions. Where a client is a HIPAA covered entity or business associate and our work involves protected health information, we will execute a Business Associate Agreement before that information is accessed, and the terms of that agreement govern.
Our working preference is not to hold client personal data at all. Where an objective can be met with synthetic, masked, or de-identified data, we use that instead. Where real data must be accessed, we take the smallest sample that supports the finding, and we record the existence of sensitive data in our reports rather than reproducing it — for example, citing a record count and field type instead of the records themselves.
Client data and deliverables are encrypted in transit and at rest. Reports and evidence are exchanged through access-controlled channels, not as unprotected email attachments. Credentials obtained during an engagement are stored in a secrets manager, used only for the authorized scope, and surrendered or rotated at the client's direction when the engagement ends.
Working data collected during an engagement — captures, extracts, evidence files, and credentials — is retained only as long as needed to complete the work and support the report, and is then securely destroyed. Final deliverables and engagement records are retained for the period stated in the engagement agreement or required by law. A client may request earlier return or destruction of its data at any time, and we will confirm completion in writing.
Personnel and subcontractors are bound by written confidentiality obligations, are briefed on the handling requirements of each engagement, and receive security and privacy training appropriate to their role.
Where we use third-party providers that may process client personal data, we select providers offering appropriate safeguards and bind them contractually to protections no less protective than those we owe the client. We will identify relevant subprocessors on request.
If we become aware of a security incident affecting client personal data in our custody, we will notify the affected client without undue delay, provide the information reasonably available to support the client's own assessment and notification obligations, and cooperate in investigation and remediation. Notification obligations to individuals and regulators generally rest with the client as the data owner. Where applicable, we support clients in meeting Puerto Rico Act 111-2005, as amended and other breach notification requirements that apply to them.
Questions about this policy, requests for a Business Associate Agreement, security questionnaires, and data return or destruction requests should be sent to info@cybernestsec.com.
This page describes our general policies and is provided for information. It is not legal advice, and it does not create rights beyond those in a signed agreement. Where a client's executed engagement agreement, Business Associate Agreement, or data processing terms differ from this page, those documents control.
Contact us for a Business Associate Agreement, a completed security questionnaire, or clarification on any term before an engagement begins.