2. Description of Services
Nocera InfoSec® offers specialized information security services, including but not limited to:
- Controlled simulation of attacks on networks, web applications, APIs and infrastructure for vulnerability identification;
- Advanced simulation of real adversaries with the TTPs (tactics, techniques and procedures) of sophisticated threats (APT);
- Reverse engineering and behavioral analysis of malicious artifacts;
- Investigation and preservation of digital evidence in compliance with legal standards;
- Auditing and protection of corporate and executive profiles on digital platforms;
- Containment, eradication and recovery from security incidents;
- Collection and analysis of intelligence from open sources for defensive and investigative purposes;
- Continuous scanning of underground forums, marketplaces and hidden channels for data exposure;
- Hands-on cyber crisis response exercises for technical and executive teams.
The exact scope, methodology, deliverables and timelines of each service are defined in the Commercial Proposal and/or Statement of Work (SoW) signed by the Parties.
3. Scope and Authorization
3.1 Mandatory written authorization: all services that involve testing, access or interaction with the Client's systems, networks or digital assets require the Client's prior and express written authorization, specifying the authorized scope, target systems, time windows and the responsible person on the authorizing Party. No offensive technical service will start without this documentation.
The Client represents that it has the legal and contractual authority to authorize the activities on the systems, networks and data specified in the scope, and is responsible for obtaining the necessary authorizations from third parties (e.g. cloud providers, ISPs, vendors) whose systems may be impacted.
Nocera InfoSec® will act exclusively within the approved scope. Any scope expansion, including new systems, domains, IP ranges or techniques, requires a written contract amendment before execution.
Execution time windows will be agreed upon with at least 48 hours of advance notice, unless otherwise stated in the Proposal; in emergency Incident Response services, this period does not apply. The Rules of Engagement (RoE) will be documented in the Proposal and may include restrictions on certain attack vectors, time slots, critical production systems and the Client's customer data. Nocera InfoSec® will fully respect the agreed RoE.
4. Client Obligations
- Provide accurate information about the environment, infrastructure and systems in scope;
- Designate a technical point of contact available during service execution;
- Immediately notify Nocera InfoSec® of real incidents or alerts during the testing period;
- Not disclose, reproduce or redistribute reports, tools, exploits or deliverables without prior written authorization;
- Keep deliverables confidential, applying adequate access controls;
- Make payments within the agreed deadlines and conditions;
- Ensure the legality of the scope and the necessary authorizations;
- Apply recommended remediations within timeframes appropriate to the criticality level.
5. Nocera InfoSec® Obligations
- Perform with diligence and professional competence (OWASP, PTES, MITRE ATT&CK, NIST SP 800-115);
- Act exclusively within the authorized scope and the RoE;
- Maintain absolute confidentiality over all information, vulnerabilities and data accessed;
- Immediately notify critical vulnerabilities with imminent risk;
- Preserve the integrity of systems, avoiding unforeseen damage or unavailability;
- Deliver complete reports with evidence, risk, impact and remediation;
- Securely delete any data or accesses obtained after completion;
- Provide post-delivery support as defined in the Proposal.
6. Payment and Billing
Prices, payment conditions and billing method are defined in the Commercial Proposal. In the absence of a specific provision: payment within 30 days after invoice issuance; projects longer than 30 days may be billed in installments; emergency incident response may be charged by the hour, with immediate billing upon completion. For new clients or higher-value projects, an advance payment of 30% to 50% may be required before starting.
Late payment may incur a 2% penalty, 1% monthly interest, monetary correction by the IPCA index and suspension of services until the situation is regularized, with no liability for damages resulting from the suspension. Nocera InfoSec® may withhold delivery of the final report until full payment. Prices may be increased by applicable taxes, unless a valid exemption applies.
7. Intellectual Property
All tools, scripts, original exploits, methodologies, processes and know-how remain the exclusive property of Nocera InfoSec®. The Client acquires no rights over these assets.
Reports and deliverables produced for the Client are licensed for internal, non-exclusive and non-transferable use. Publication, sublicensing or distribution requires written authorization. All of the Client's data and systems remain the Client's property.
Zero-day vulnerabilities or original exploits discovered will be communicated to the Client and, after an agreed remediation period, may be responsibly disclosed to the affected vendor, without identifying the Client.
8. Confidentiality
All information exchanged between the Parties, including vulnerabilities, reports, system data and commercial information, is strictly confidential. Confidentiality obligations (a) take effect upon signing the NDA or the Proposal; (b) survive for 5 years; and (c) extend to employees and subcontractors.
Exceptions: information in the public domain without fault by the Party; demonstrable prior knowledge; legitimate receipt from a third party without restriction; or legal requirement or court order (with prior notice when possible).
9. Liability and Limitations
9.1 Limitation of liability: except in cases of willful misconduct or gross negligence, the total liability of Nocera InfoSec® is limited to the total amount paid for the specific service that gave rise to the damage.
Nocera InfoSec® is not liable for: indirect or consequential damages, lost profits, data loss or reputational damage; system degradation not previously disclosed as possible in the RoE; real incidents occurring during the testing period that were not caused by Nocera's activities; and damages arising from the Client's misuse or unauthorized disclosure of the reports.
Pentest and red team services are point-in-time assessments and do not guarantee the identification of all vulnerabilities, nor future protection. The Client will indemnify Nocera InfoSec® for claims arising from use outside the scope, lack of authority to authorize, or breach of these Terms.
10. Prohibited Uses
The Client is expressly prohibited from:
- Hiring the services for illegal purposes or against unauthorized third parties;
- Requesting activities outside the scope without a written amendment;
- Using reports, tools or knowledge acquired to carry out unauthorized attacks;
- Redistributing, selling or sublicensing the deliverables;
- Attempting to directly recruit Nocera professionals during the engagement and for 12 months after, without authorization.
Ethical use clause: Nocera InfoSec® may refuse or immediately terminate any engagement that indicates unethical or illegal use, without refund for services already delivered.
11. Termination
11.1 Termination for convenience: either Party may terminate upon 15 days of written notice. The Client pays for services already rendered, plus non-recoverable costs.
Nocera may terminate immediately in case of material breach, non-payment for more than 30 days, signs of illegal or unethical use, or refusal to provide essential information. Deliverables already produced are delivered upon payment; the Client's data is securely deleted; confidentiality remains in effect as per section 8.
12. Force Majeure
Neither Party shall be liable for failure or delay resulting from force majeure events (pandemics, natural disasters, war, large-scale cyber attacks, acts of government). The affected Party must notify within 48 hours. If the event persists for more than 30 days, either Party may terminate without penalties.
13. Legal Compliance
The services are provided in compliance with applicable Brazilian legislation, including Law No. 12,737/2012 (the Carolina Dieckmann Law), Law No. 12,965/2014 (Brazilian Civil Rights Framework for the Internet), Laws No. 9,609/1998 and No. 9,610/1998 (intellectual property and copyright) and the Brazilian Penal Code (art. 154-A and onwards). Every testing activity is carried out based on the express authorization of the systems' owner.
14. Dispute Resolution
The Parties will seek good faith resolution through direct negotiation within 30 days. If the conflict persists, mediation or arbitration may be used before any judicial litigation. These Terms are governed by Brazilian legislation, with the courts of the judicial district of São Paulo, SP, to settle disputes not resolved otherwise.
15. General Provisions
- Entire agreement: these Terms, the Proposal and the NDAs constitute the entire agreement between the Parties;
- Amendments: changes will be communicated 30 days in advance; continued use implies acceptance;
- Independence of clauses, no waiver and independent contracting;
- Subcontracting under NDA, with full Nocera liability toward the Client;
- Assignment: the Client may not assign rights or obligations without prior written consent.