Close Enterprise Deals. Pass Audits. Prove Security to Anyone Who Asks.

RateYourCyber is an AI-powered GRC automation platform spanning 25+ frameworks (ISO 27001, SOC 2, GDPR, DORA, NIS2, NIST CSF 2.0, CIS Controls v8.1, IEC 62443, ISO 22301, ISO 42001, the NCSC CAF, HIPAA, CMMC, Financial Crime Compliance (FCC), and more) so your team can demonstrate compliance to investors, enterprise clients, and regulators. No dedicated compliance hire needed to get full value from day one.

Industry Comparison Analysis Dashboard

Trusted by organisations across seven geographies

United Kingdom · European Union · Switzerland · Mexico · Africa · Saudi Arabia · Pakistan

Get in touch to be connected with our representatives in your region.

Why Traditional Solutions Fall Short

Traditional Assessments Cost More, Deliver Less

Pay thousands for comprehensive assessments that identify problems but provide no guidance on fixing them. Implementation plans cost extra. Annual retainers drain budgets.

Enterprise GRC Tools Are Too Complex

Enterprise GRC tools are built for security professionals, not business leaders. They're complex, expensive, and require dedicated staff to operate. Implementation takes months and costs escalate quickly.

Annual Audits Become Outdated Fast

Annual audits provide outdated snapshots. Security posture changes continuously. Regulators and partners now expect ongoing monitoring and compliance documentation.

Comprehensive assessments across every risk surface

Professional Security Assessments

Six comprehensive assessments: Cybersecurity Maturity, Business Continuity, HR Security, Data Privacy, Physical Security, and DPIA. Each delivers 1000-point scoring, board-ready reports, and industry benchmarking.

Strategic Implementation Roadmaps

3-year implementation plans with week-by-week actionable tasks, time estimates, and budget considerations. No consulting fees required.

Threat Monitoring

Unified security intelligence: domain impersonation detection, supplier security assessment, vulnerability scanning, dark web credential monitoring, and attack surface discovery. Continuous grading across SSL, email authentication, and security headers.

Third-Party Risk Management

Flexible vendor assessment questionnaires with automated scoring and risk tracking. Demonstrate systematic supply chain security management.

Compliance Documentation

Auto-generated security policies tailored to your size and industry. Risk register populated directly from your assessment gaps. Full compliance mapping and implementation across ISO 27001, NIST CSF, SOC 2, GDPR, DORA, and NIS2. ESG cybersecurity disclosure reports aligned with GRI 418, SASB TC-SI-230a, and EDCI 2026.

Advanced Analytics & Benchmarking

Waterfall charts, maturity tracking, and industry comparisons. Demonstrate continuous improvement to investors, boards, and regulators.

Progress Tracking & Measurement

Watch your maturity score improve as you complete implementation tasks. Track domain-level progress and compare against industry peers.

Board-Ready Reporting

Professional PDF reports suitable for board presentations, investor due diligence, and regulatory submissions. Executive summaries with strategic recommendations.

Tailored Security Policies

Highly customized policies based on your assessment results, organization profile, industry, size, infrastructure, and governance requirements.

Financial Crime Compliance (FCC)

AML programme governance for regulated financial firms. Business-wide risk assessment aligned to FATF 40 Recommendations, regulatory obligations register across FCA, SAMA, FinCEN and CNBV, Board risk appetite management with conflict detection, tabletop exercises, and Board and regulator reporting in PDF, DOCX, and XLSX.

Feature preview image

Feature Details

Key Benefits:

    One platform for every compliance obligation you carry

    ISO 27001, SOC 2, GDPR, DORA, NIS2, the NCSC CAF, HIPAA, CMMC 2.0, NCA ECC, SACS-002, SAMA CSF, LFPDPPP, ISO 42001 for AI governance, ESG reporting, Financial Crime Compliance (FCC) with AML programme management, NIST CSF 2.0, CIS Controls v8.1, IEC 62443 for industrial and operational technology, ISO 22301 for business continuity, plus management and governance frameworks including ISO 9001, COBIT and ITIL, all mapped to a single risk register and policy library. Evidence is collected once and counts everywhere it applies: an approved policy, a completed audit, a training record or a supplier assessment satisfies the clauses that ask for it across every framework at the same time, with no re-uploading and no duplicate work. Where a document is attached to a specific requirement it carries across to the matching requirement in other frameworks, and the platform names the authority that says the two correspond. So you pass audits faster, close enterprise deals sooner, and prove security to anyone who asks. As new frameworks are added, existing work carries forward.

    Risk in financial terms, not traffic lights

    FAIR-based risk quantification with Monte Carlo simulation translates every security gap into a monetary exposure range, calibrated against industry-recognised breach cost data. The figures your CFO and board need to make decisions, not red, amber, and green tiles.

    See RateYourCyber In Action

    Watch this comprehensive demonstration of our complete platform: professional assessments, strategic roadmaps, continuous monitoring, compliance documentation, and board-ready reporting.

    How It Works

    • Complete Strategic Assessment

      Answer strategic questions about your security practices across 8 critical domains. Our intelligent platform guides you through the process with plain-English explanations. Complete in 30-45 minutes.

    • Receive Professional Analysis

      Get immediate access to board-ready reports with maturity scoring, industry benchmarking, compliance gap analysis, and 3-year implementation roadmaps. All professionally formatted and ready for stakeholder presentation.

    • Implement Strategic Improvements

      Follow week-by-week action plans with specific tasks, time estimates, and priorities. Track progress, monitor continuous vulnerability scanning, and watch your maturity score improve as you implement controls.

    • Maintain Continuous Compliance

      Ongoing monitoring updates your risk posture automatically. Generate current reports for audits, investor requests, or board meetings at any time. Demonstrate continuous improvement and systematic security management.

    Simple, Transparent Pricing

    Free Cybersecurity Assessment
    Free
    5-minute quick check
    • 3 critical security domains
    • Instant maturity scoring
    • Industry benchmarking
    • Basic recommendations
    • No credit card required
    • Results in 5 minutes
    Start Free Assessment
    One-Time Assessment
    $799
    • Complete 1000-point assessment
    • Board-ready professional report
    • 3-year implementation roadmap
    • Industry benchmarking analysis
    • Advanced visualizations
    • Compliance documentation
    • No ongoing commitment
    Get Assessment
    Enterprise
    Custom
    For multi-entity organisations
    • Everything in Annual Subscription
    • Multi-entity management
    • Cross-subsidiary comparison
    • Dark web credential monitoring
    • Domain impersonation detection
    • M365 + Google Workspace integration
    • Custom integrations (EDR, SIEM)
    • Group-level executive reporting
    • Dedicated account manager
    • API access + SSO
    Get in Touch

    Customer Stories

    See what our customers say about RateYourCyber on Gartner Peer Insights

    ★★★★★

    "Blown away by the detailed reporting"

    "Incredibly simple to use and a staggering amount of value returned. What would normally be weeks of consultancy and unfathomable documentation was replaced within minutes with an easy to navigate report."

    What they liked: The level of detail, the accessibility of the reporting, the ease of use, the absence of agents or widgets
    ★★★★★

    "Comprehensive Security Coverage and Professional Reporting"

    "It's simple to use, covers a wide range of areas of concern to our business and the reports generated look sleek and professional."

    Key highlights: The scope of security areas it covers

    Get Your Cyber Sorted

    Questions about our platform or need custom solutions for your organization? We're here to help.

    Ready to Get Started?

    Join organizations worldwide who trust RateYourCyber for professional security assessments, strategic implementation, continuous monitoring, and compliance documentation ready for audits, investors, and regulators.

    Start Your Journey Today
    Effective: 11 August 2026

    This Privacy Policy explains how personal data is collected, used, stored and protected when you visit the RateYourCyber website, create or use an account, use the RateYourCyber platform or otherwise interact with us.

    RateYourCyber is the name of the platform and services. The legal entity currently responsible for the processing described in this Privacy Policy is ALFASOTERIA LIMITED, company number 15903182, a company incorporated in England and Wales.

    If you have questions about this Privacy Policy or how we process personal data, please use our contact form.

    1. Who We Are

    The RateYourCyber platform is currently operated and supplied by ALFASOTERIA LIMITED, company number 15903182, incorporated in England and Wales. For the personal data described in this Privacy Policy, ALFASOTERIA LIMITED is the data controller where we determine the purposes and means of processing that data.

    In some circumstances, particularly where a Business Customer uses the Platform to submit or otherwise process personal data relating to individuals within its organisation or otherwise under its control, the Business Customer may be the controller and we may process that personal data on its behalf as a processor. Where we act as a processor, the relevant processing will be governed by our agreement with the relevant Business Customer, including any applicable Data Processing Agreement.

    2. Personal Data We Collect

    The personal data we collect depends on how you interact with the Platform and the services you use.

    Account and contact information. This may include your name, email address, organisation or company name, job title or role where provided, account and user identifiers, and information you provide when contacting us. We use this information to create and manage accounts, provide the Platform, communicate with you and provide support.

    Assessment and Platform data. Depending on how you use the Platform, this may include assessment responses, scores, reports, recommendations, implementation roadmaps, information about your organisation's security practices, information about systems, domains or other assets, information obtained through integrations, scan results, and other information you choose to submit. Where a Business Customer submits personal data relating to its employees, customers, suppliers or other individuals, the Business Customer remains responsible for ensuring that it has an appropriate lawful basis for that processing and that the relevant processing arrangements are in place.

    Security, technical and usage information. We may collect information necessary to operate and secure the Platform, including IP address, login and authentication information, device and browser information, timestamps, access and activity logs, security events, error and diagnostic information, and information relating to use of Platform features.

    Free security scan information. If you use a public security scanning tool provided by RateYourCyber, we may record the domain or other asset scanned, the date and time of the scan, the requesting IP address, and technical information reasonably necessary to operate and protect the scanning service. We use this information principally for security, abuse prevention, service operation and audit purposes.

    Payment and transaction information. When you purchase a service, payment information is processed by our payment provider. We do not ordinarily store full payment card details ourselves. We may retain transaction information such as purchaser name, billing information, transaction reference, amount paid, currency, product or plan purchased, and payment status.

    Communications. If you contact us through our contact form, we may collect the information contained in your message, including your name, email address and any other information you choose to provide.

    Special category data. We do not intentionally request special category personal data as part of the Platform. However, information submitted by a customer may contain special category personal data or other sensitive information. If you are a Business Customer, you should not submit special category personal data to the Platform unless the relevant service requires it and you have an appropriate lawful basis and processing arrangement for doing so.

    3. How We Use Personal Data

    Providing the Platform: to create and administer accounts, authenticate users, provide assessments and other services, generate reports and recommendations, provide monitoring and scanning functionality, provide Posture Certificates and Trust Centre functionality, provide customer support, and administer purchases and subscriptions.

    Security and abuse prevention: to protect the Platform and our systems, detect and prevent unauthorised access, investigate security incidents, prevent abuse of scanning and other public tools, maintain audit and security records, and enforce our Terms of Service.

    Service improvement: to understand how the Platform is used, identify technical problems, improve performance and reliability, develop new functionality, and produce aggregated or de-identified insights.

    Communications: to send account and authentication messages, purchase confirmations, service notifications, security notifications, subscription and renewal information, responses to enquiries, and other communications necessary to administer the services. We will not use your personal data for direct marketing where consent is required unless you have provided the relevant consent or another lawful basis permits the communication.

    Legal and regulatory purposes: to comply with legal and regulatory obligations, respond to lawful requests from public authorities, establish, exercise or defend legal claims, and maintain appropriate business and financial records.

    4. Legal Bases for Processing

    Contract. We process personal data where necessary to enter into or perform a contract with you, including creating and managing your account, providing purchased services, processing transactions, providing customer support, and administering subscriptions.

    Legitimate interests. We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and interests. These interests may include securing the Platform, preventing fraud and abuse, maintaining and improving the service, investigating security incidents, maintaining appropriate business records, defending legal claims, and managing our business. Where we rely on legitimate interests, we consider the impact of the processing on individuals and the applicable safeguards.

    Legal obligation. We may process personal data where necessary to comply with a legal or regulatory obligation.

    Consent. Where required by law, we process personal data on the basis of your consent. Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

    5. Who We Share Personal Data With

    We do not sell or rent personal data. We may share personal data with the following categories of recipients where necessary for the purposes described in this Policy.

    • Technology and hosting providers, for cloud hosting, infrastructure, databases, authentication, security, monitoring, backups and other technical services required to operate the Platform.
    • Payment providers, who process payments and subscriptions in accordance with their own privacy notices and our contractual arrangements with them.
    • Email and communications providers, to send transactional, account and service communications.
    • Formspree, Inc., which currently processes information submitted through our contact form on our behalf.
    • Analytics and measurement providers, including Google Analytics, to understand how the website and Platform are used and to improve their performance. The use of cookies and similar technologies is described in section 10.
    • Professional advisers and authorities, including lawyers, accountants, auditors, insurers, professional advisers, law enforcement agencies, regulators, courts and other public authorities, where reasonably necessary for the purposes described in this Policy or where required or permitted by law.

    If we sell, transfer, restructure or reorganise all or part of the RateYourCyber business, personal data may be transferred to the relevant purchaser, successor entity or group company where permitted by law. Where required, we will provide appropriate notice and ensure that applicable data protection requirements continue to apply.

    6. International Transfers

    Some of our service providers may process personal data outside the United Kingdom or the European Economic Area. Where a transfer is subject to UK or EU international-transfer requirements, we use a legally recognised transfer mechanism appropriate to the relevant transfer. Depending on the circumstances, this may include an applicable adequacy decision or adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses where applicable, or another lawful transfer mechanism recognised under applicable data protection law. Where required, we also implement supplementary measures and other safeguards appropriate to the transfer. For information about a particular international transfer, please use our contact form.

    7. Data Retention

    We retain personal data only for as long as reasonably necessary for the purposes for which it is processed, including to provide the services, comply with legal obligations, resolve disputes and enforce agreements. Our current retention approach is broadly as follows:

    • Account information: while the account remains active and for an appropriate period afterwards.
    • Assessment data and reports: for as long as necessary to provide historical reporting, maturity tracking, contractual and legal purposes.
    • Transaction and billing records: for the period required by applicable legal, accounting and tax requirements.
    • Security and usage logs: typically up to 12 months, unless a longer period is reasonably necessary for security, investigation or legal purposes.
    • Public scan records: typically up to 12 months for abuse prevention and service security.
    • Support and contact records: for as long as reasonably necessary to resolve the matter and maintain appropriate business records.

    Where a Business Customer is the controller and we process personal data on its behalf, retention will also be governed by the applicable contract and Data Processing Agreement. When personal data is no longer required, we will securely delete it or anonymise it where appropriate.

    8. Data Security

    We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration or disclosure. Depending on the service and the nature of the information, these measures may include encryption in transit, encryption at rest, access controls, authentication controls, least-privilege access, logging and monitoring, security testing, backup and recovery measures, and secure hosting arrangements. No internet transmission or information system can be guaranteed to be completely secure.

    9. Your Data Protection Rights

    Subject to applicable law and any relevant exemptions, you may have the following rights: access to a copy of personal data we hold about you; rectification of inaccurate or incomplete personal data; erasure in certain circumstances; restriction of processing in certain circumstances; objection to processing based on legitimate interests, and an absolute right to object to direct marketing; data portability, where applicable, in a structured, commonly used and machine-readable format; and withdrawal of consent at any time where processing is based on consent.

    Where applicable, you may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects. We do not generally intend for the Platform's automated scoring or reporting outputs to constitute decisions about individuals producing such effects. The Platform primarily assesses organisational security maturity.

    To exercise a right, please use our contact form. We may need to verify your identity before responding to a request. We will normally respond within one month. Where permitted by law, this period may be extended by up to two further months where a request is complex or we have received a large number of requests. If we need to extend the period, we will tell you.

    10. Cookies and Similar Technologies

    Strictly necessary technologies. We may use strictly necessary cookies or similar technologies for authentication, maintaining a secure session, preventing fraud and abuse, and providing functionality you have specifically requested. Where a cookie or similar technology is strictly necessary for a service you have requested, applicable law may permit it to be used without consent.

    Analytics. We may use Google Analytics for website measurement. Our configuration is intended to minimise the use of information stored on your device and to respect applicable consent choices. Depending on the configuration and your consent status, Google may receive limited measurement signals, including cookieless signals, to provide website measurement. Where applicable law requires consent for analytics cookies or similar technologies, we will obtain that consent before using them.

    reCAPTCHA and security technologies. Some pages may use Google reCAPTCHA or similar security technologies to prevent automated abuse. These technologies may involve information being collected by the relevant provider and may use cookies or similar technologies. Where consent is legally required, we will obtain it before deploying the relevant technology.

    Cookie controls. Where consent is required, you will be given an appropriate mechanism to accept or reject non-essential cookies and similar technologies. You can also control cookies through your browser settings.

    11. Data Relating to Children

    The Platform is intended for use by businesses and organisations and is not directed to children. We do not knowingly collect personal data from children for the purpose of providing the Platform. If you believe that a child has provided personal data to us, please contact us through our contact form so that we can assess the situation and take appropriate action.

    12. Third-Party Websites and Services

    The Platform or website may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy information provided by third-party websites and services before providing them with personal data.

    13. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes to our services, changes in how we process personal data, changes in law or regulatory requirements, changes to our service providers, or improvements to our privacy practices. We will publish the updated version on the website and update the effective date. Where a change is material and applicable law requires notification, we will provide appropriate notice.

    14. Complaints

    If you have concerns about how we process your personal data, please contact us first through our contact form so that we can investigate and try to resolve the matter. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection supervisory authority. You can find information about making a complaint on the ICO's website. If you are in the European Economic Area and EU GDPR applies to the relevant processing, you may also complain to the supervisory authority in the relevant EEA country.

    15. Contact Us

    For privacy questions, data protection requests or concerns, please use our contact form. The data controller is ALFASOTERIA LIMITED, company number 15903182, incorporated in England and Wales, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

    16. Current Supplier

    As at the effective date of this Privacy Policy, the RateYourCyber platform is operated and supplied by ALFASOTERIA LIMITED, company number 15903182. The identity of the controller or supplier may change as the RateYourCyber business develops. Where responsibility for processing changes, we will update this Privacy Policy and provide any notices required by applicable law.

    Version 11 August 2026. Updated and Effective: 11 August 2026

    These Terms of Service govern your access to and use of the RateYourCyber platform and any services you purchase through it. Please read these Terms carefully before using the Platform or making a purchase.

    1. About RateYourCyber and these Terms

    1.1 The Platform. RateYourCyber is the name of the platform and services described in these Terms. The legal entity currently supplying the services is ALFASOTERIA LIMITED, a company incorporated in England and Wales under company number 15903182 ("we", "us" or "our"). RateYourCyber is a platform and service name and does not itself constitute a separate legal entity or contracting party.

    1.2 Your contract with us. When you purchase a service through the Platform, your contract is with the supplier identified in the purchase process and your purchase confirmation. As at the Effective Date of these Terms, that supplier is ALFASOTERIA LIMITED. The supplier identified at the point of purchase will be responsible for supplying the relevant service and receiving payment for it.

    1.3 Future changes to the supplier. We may reorganise the ownership, operation or structure of the RateYourCyber business, including transferring the Platform, relevant intellectual property, customer contracts or other assets to a group company, successor entity or purchaser of the relevant business. Where applicable law requires your consent, notice or a new agreement for such a transfer, we will obtain or provide it as required. Nothing in this clause reduces any statutory right you have.

    1.4 Consumers and Business Customers. Some provisions of these Terms apply differently depending on whether you purchase as a Consumer or as a Business Customer. A Consumer means an individual acting for purposes wholly or mainly outside that individual's trade, business, craft or profession. A Business Customer means a person or organisation purchasing or using the Platform in the course of a trade, business, craft or profession. If you purchase on behalf of an organisation, you confirm that you have authority to bind that organisation to these Terms. If you are a Consumer, nothing in these Terms limits or excludes any right or remedy that cannot lawfully be limited or excluded.

    2. The Platform and our services

    2.1 What we provide. RateYourCyber provides a self-assessment cybersecurity maturity platform that enables organisations to evaluate aspects of their security posture, generate reports, receive implementation roadmaps and track progress over time. Depending on the plan purchased, the Platform may include:

    • self-assessment cybersecurity maturity questionnaires across multiple domains;
    • automated scoring and reporting tools;
    • industry comparison and benchmarking based on organisational size and sector;
    • strategic implementation roadmap generation with prioritised recommendations;
    • continuous vulnerability monitoring and alerting;
    • domain and attack-surface scanning;
    • third-party and supply-chain risk assessment tools;
    • compliance documentation and policy-generation tools;
    • business continuity and disaster recovery planning tools;
    • a Posture Certificate;
    • a Trust Centre page;
    • financial crime compliance programme tools for regulated firms; and
    • other functionality identified on the applicable plan page at the time of purchase.

    2.2 Plan-specific functionality. Not every feature is available on every plan. The functionality, assessment types, scan allowances, usage limits and other features included in your purchase are those stated on the applicable plan page, purchase screen, scope disclaimer or order confirmation at the time of purchase. The applicable plan page forms part of the contract between you and us in relation to the features included in your purchase.

    2.3 Self-assessment and automated assessment. The Platform provides self-assessment and automated assessment tools. Our assessments and outputs are based, in whole or in part, on information supplied by you and, where applicable, automated scans, integrations and other data collected by the Platform. You remain responsible for reviewing the outputs and deciding what action, if any, to take.

    2.4 What we do not provide. Unless expressly agreed otherwise in writing, we do not provide: cybersecurity consultancy; professional cybersecurity advice; penetration testing; independent security audits; legal or regulatory advice; certification against ISO 27001 or any other standard or framework; or cybersecurity implementation services.

    2.5 No certification or compliance determination. Use of the Platform, completion of an assessment or receipt of any report or certificate does not by itself make your organisation compliant with any law, regulation, standard or framework, including GDPR, DORA, ISO 27001 or any other requirement.

    3. Account and access

    3.1 Account information. You must provide accurate and complete information when creating an account and must keep that information up to date.

    3.2 Account security. You are responsible for keeping your account credentials confidential and for activity carried out through your account. You must notify us promptly if you become aware of unauthorised access to your account or another security incident affecting your account.

    3.3 Authorised users. Where your plan permits multiple users, you are responsible for ensuring that those users comply with these Terms. You must not knowingly allow unauthorised persons to access your account or paid Platform functionality.

    4. Your information and assessment inputs

    4.1 Accuracy. You are responsible for the accuracy, completeness and currency of information you provide to the Platform. You acknowledge that scores, reports, recommendations and other outputs may be affected by inaccurate, incomplete or outdated information.

    4.2 Responsibility for decisions. You are responsible for business, technical, compliance or other decisions made using Platform outputs. The Platform is intended to support governance and decision-making. It does not replace appropriate professional judgement or advice.

    5. Domain and asset scanning

    5.1 Your authority. Where you nominate a domain, IP address, website, system or other asset for scanning, you represent and warrant that: (1) you own or control the relevant asset, or have the necessary authority from its owner or controller to nominate it for scanning; (2) you have obtained all permissions necessary for the scanning activities to be performed; (3) the scanning will not breach any contract, law, regulation or obligation owed to a third party; and (4) the authority described above will remain in place for the duration of the relevant scanning activity.

    5.2 Suspension of scanning. If we reasonably believe that an asset may have been nominated without the necessary authority, or that continued scanning may expose us, you or another person to material legal, regulatory, security or operational risk, we may suspend or stop scanning that asset. Where reasonably practicable, we will notify you of the reason for the suspension. We will not be liable for delay or interruption caused by a suspension made reasonably and in good faith under this clause.

    5.3 Scanning indemnity. If you breach clause 5.1 and that breach results in a third-party claim against us, you will indemnify us against the reasonable external legal costs and other reasonable losses directly arising from that claim, to the extent caused by your breach. This indemnity does not apply to the extent that the claim was caused by our own breach of these Terms, negligence or wilful misconduct.

    6. Acceptable use

    You must not: use the Platform for an unlawful purpose; attempt to gain unauthorised access to our systems or another person's systems or accounts; interfere with or disrupt the Platform or its infrastructure; introduce malicious code or harmful content; misrepresent your identity or affiliation; share account credentials with unauthorised persons; nominate an asset for scanning without the necessary authority; use the Platform to conduct unlawful surveillance or other unlawful activity; reproduce, extract or reverse engineer our assessment methodology, scoring models or other proprietary functionality except to the extent permitted by law; resell, sublicense or redistribute the Platform without our written permission; or use the Platform in a manner that could reasonably be expected to compromise its security, integrity or availability. We may suspend access where reasonably necessary to prevent or respond to a security incident, unlawful activity or material breach of this clause.

    7. Purchases, prices and payment

    7.1 Prices. The price payable for a service is the price displayed at the point of purchase or otherwise agreed in writing. Unless stated otherwise, prices are in pounds sterling. Any applicable taxes or mandatory charges will be displayed before you complete your purchase where required.

    7.2 Payment. You must pay the applicable fees using the payment method made available at checkout or otherwise agreed with us. The supplier identified at checkout or in your order confirmation is responsible for supplying the service and receiving payment. As at the Effective Date, the supplier is ALFASOTERIA LIMITED.

    7.3 Failed payment. If a payment is unsuccessful, we may notify you and require payment by another method. For Business Customers, we may suspend paid functionality where an amount remains unpaid after reasonable notice.

    8. SME Plan

    8.1 Term and pricing. The SME Plan provides Platform access for one organisation and may be purchased: (a) as an annual subscription at the annual price displayed at the point of purchase, currently £3,000 per year, providing a committed twelve-month term; or (b) as a monthly subscription at the monthly price displayed at the point of purchase, currently £300 per month, which continues from month to month until cancelled. The annual and monthly subscriptions are separate offerings. The monthly subscription may be cancelled with effect from the end of the current monthly billing period. The annual subscription is a commitment for the full twelve-month term and cancellation takes effect at the end of that term, subject to any statutory rights that apply.

    8.2 Included functionality. The SME Plan includes the assessment types, scan allowance and other functionality stated on the applicable plan page at the time of purchase. Depending on the plan, this may include continuous monitoring, risk-register functionality, policy generation, compliance mapping and reporting.

    8.3 Renewal. For Business Customers, an annual SME Plan renews automatically for a further twelve-month period unless cancelled before the renewal date. A monthly SME Plan continues on a monthly basis unless cancelled before the next monthly billing date. We will provide reasonable advance notice of an upcoming renewal and the price applicable to the renewal where required by applicable law.

    8.4 Cancellation. A Business Customer may cancel an SME Plan through its account or by contacting us. Cancellation of a monthly SME Plan takes effect at the end of the current monthly billing period. Cancellation of an annual SME Plan takes effect at the end of the current annual term. Unless otherwise agreed or required by law, cancellation does not entitle a Business Customer to a refund of fees already paid for the current billing period or annual term. If you are a Consumer, your statutory cancellation and termination rights apply and take precedence over this clause.

    9. Posture Pack

    9.1 One-off purchase. The Posture Pack is a one-off purchase. It is not a subscription and does not renew automatically. The current price is £495 including twelve months of validity.

    9.2 Included services. The Posture Pack includes the assessments, scans, Posture Certificate and Trust Centre functionality described on the applicable Posture Pack scope disclaimer and purchase page.

    9.3 Validity. The Posture Pack is valid for twelve months from purchase. Before expiry, we may invite you to purchase re-certification at the price applicable at that time. The current stated re-certification price is £295.

    9.4 Completion. You are responsible for providing the information and completing the steps necessary for the assessments and scans to be carried out. The Posture Certificate may be issued once the required assessments and scans have been completed.

    10. Consumer cancellation rights

    This clause applies only where you are a Consumer and the statutory cancellation provisions apply to your purchase.

    10.1 Statutory cancellation period. You may have a statutory right to cancel your contract within 14 days of entering into it without giving a reason. The right is subject to statutory exceptions and qualifications.

    10.2 Request for immediate performance. If you want us to begin providing the service before the end of the 14-day cancellation period, you must expressly request that we do so. We will obtain that request through the purchase process where applicable.

    10.3 Cancellation after performance has begun. If you expressly request that we begin providing the service during the cancellation period and subsequently cancel before the service has been fully performed, you may be required to pay an amount proportionate to the service supplied up to the time you notify us of your cancellation, where permitted by law. We will not charge you for any amount that applicable law does not permit us to charge.

    10.4 Fully performed services. Where a service has been fully performed during the cancellation period following your express request for immediate performance and the required acknowledgement, your statutory cancellation right may cease in accordance with applicable law.

    10.5 How to cancel. You may exercise a statutory cancellation right through the cancellation facility on the Platform, using the contact form provided on the Platform, or by post to our registered office. You may use the model cancellation form provided with your purchase confirmation, but you do not have to use that form provided you make a clear statement that you wish to cancel.

    10.6 Refunds following cancellation. Where you validly exercise a statutory cancellation right, we will provide any refund required by applicable law within the applicable statutory period. Where permitted by law, we may deduct an amount properly due for services supplied before cancellation following your express request for early performance.

    10.7 Other statutory rights. Nothing in these Terms affects any statutory right or remedy that applies to you as a Consumer.

    11. Intellectual Property

    11.1 Our intellectual property. We own or have the necessary rights to use the Platform and its content, including: software; functionality; assessment methodologies; scoring algorithms; report structures and templates; designs; documentation; databases; trademarks; know-how; and other intellectual property. Patent Pending. Except as expressly permitted by these Terms, no rights in our intellectual property are transferred to you.

    11.2 Your information. You retain ownership of information and materials that you submit to the Platform. You grant us the rights reasonably necessary to host, process, analyse and use that information to provide, maintain, secure and improve the services, subject to our data protection obligations.

    11.3 Customer use of reports. Subject to these Terms, you may download, reproduce and share reports generated for your organisation for internal governance and legitimate business purposes. You must not present a report as an independent audit, certification or professional assurance report unless it expressly states that it is one.

    12. Posture Certificate

    12.1 Nature of the Certificate. The Posture Certificate records your self-assessment results and, where applicable, automated scan results as at the date stated on the Certificate. It is a point-in-time statement of information provided by you and scan results obtained by the Platform. It is not: an audit; a penetration test; an independent assurance report; professional cybersecurity advice; or a certification against ISO 27001 or any other standard or framework.

    12.2 Certificate wording. The Certificate will contain wording explaining its nature and limitations. The following wording is part of the Certificate:

    "This Posture Certificate is a point-in-time statement of information provided by the customer and the results of automated checks performed by RateYourCyber. It is not an audit, penetration test, assurance report or certification and should not be relied upon as evidence of compliance with any law, regulation, standard or framework."

    "No representation or warranty is given to any recipient or other third party by RateYourCyber in relation to this Certificate, and RateYourCyber assumes no duty of care to any recipient arising from its publication or use."

    The disclaimers printed on the Certificate form part of the Certificate and must not be removed, obscured or altered.

    12.3 No compliance determination. The Certificate does not state or imply that your organisation complies with any law, regulation, standard or framework.

    12.4 Sharing. You may share your current Posture Certificate and Trust Centre page with third parties for legitimate business purposes, including procurement, governance, insurance, investment and commercial due diligence.

    12.5 Restrictions on representations. You must not: alter the Certificate; remove, obscure or alter material qualifications or disclaimers; state or imply that RateYourCyber has independently certified your organisation; state or imply that RateYourCyber has confirmed your legal or regulatory compliance; describe the Certificate as an audit, penetration test or independent assurance report; or present an expired or revoked Certificate as current.

    12.6 Third-party reliance. The Certificate is supplied to you and may be shared by you with third parties. To the maximum extent permitted by law, we do not assume responsibility to a third party solely because you have shared a Certificate or made a Trust Centre available to that third party. The disclaimers printed on the Certificate are intended to make clear to recipients the nature and limitations of the Certificate.

    12.7 Revocation. We may suspend, withdraw or revoke a Certificate where we reasonably believe that: material information on which it was based was false, misleading or materially inaccurate; the required scanning authority did not exist; the Certificate has expired; or the Certificate has been presented in a materially misleading manner. Where reasonably practicable, we will notify you before revoking a Certificate.

    13. Service availability and changes

    13.1 Availability. We will use reasonable care and skill in providing the Platform. We do not guarantee that the Platform will always be available or uninterrupted. The Platform may be unavailable temporarily for maintenance, security measures, upgrades, technical failures or circumstances beyond our reasonable control.

    13.2 Changes to the Platform. We may modify or update the Platform from time to time to: improve security; improve performance; introduce new functionality; comply with applicable law; address technical issues; or reflect changes in technology or our business.

    13.3 Paid functionality. We will not deliberately remove the core functionality of a paid plan during its paid term without reasonable justification. If a change materially and adversely affects the core functionality of a paid service, we will provide reasonable notice where practicable.

    13.4 Business Customer remedy. Where a material change substantially reduces the core functionality of a paid service during its paid term, a Business Customer may contact us to discuss an appropriate remedy. Where appropriate, this may include termination and a pro-rata refund of prepaid fees for the materially affected period. Nothing in this clause limits any statutory rights of a Consumer.

    14. Suspension and Termination

    14.1 Suspension. We may suspend your access where reasonably necessary because: you have materially breached these Terms; an amount remains unpaid after reasonable notice; your use creates a material security risk; we reasonably suspect unlawful or unauthorised activity; or suspension is required by law or a competent authority. Where practicable, we will give you notice before suspension and a reasonable opportunity to remedy the relevant breach. Immediate suspension may be appropriate where delay would create a material security, legal or operational risk.

    14.2 Termination by us. We may terminate the agreement if: you materially breach these Terms and, where the breach is capable of remedy, fail to remedy it within a reasonable period after being notified; continued provision of the service would be unlawful; or continued provision would expose us to material legal or regulatory risk.

    14.3 Termination by Business Customers. A Business Customer may terminate its subscription in accordance with the cancellation provisions applicable to its plan.

    14.4 Effect of termination. On termination: your right to use paid Platform functionality ends; you must stop using our intellectual property except where these Terms expressly permit continued use; accrued payment obligations remain payable; and provisions intended by their nature to survive termination continue to apply. Where applicable, we will retain or delete data in accordance with our Privacy Policy and any applicable Data Processing Agreement.

    15. Disclaimers

    15.1 Automated assessments. Automated assessments have inherent limitations. Results may be affected by: information supplied by you; configuration changes; technical limitations; scanning limitations; third-party systems; information becoming outdated; limitations of integrations; and other circumstances outside our reasonable control.

    15.2 No guarantee of security. Use of the Platform does not guarantee that your organisation, systems, domains or data will be secure or free from vulnerabilities. We do not guarantee that every vulnerability, weakness, threat or risk will be identified.

    15.3 Professional judgement. The Platform is intended to support governance and decision-making. You remain responsible for deciding what actions to take based on Platform outputs and for obtaining professional advice where appropriate.

    15.4 Consumer rights. Nothing in this clause limits or excludes any statutory right or remedy that cannot lawfully be limited or excluded.

    16. Liability

    16.1 Liability that cannot be excluded. Nothing in these Terms excludes or limits liability to the extent that such liability cannot lawfully be excluded or limited, including liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any other liability that applicable law does not permit to be excluded or limited.

    16.2 Consumer liability. If you are a Consumer, nothing in these Terms limits or excludes your statutory rights or our liability where doing so would be unlawful. In particular, nothing in these Terms excludes or limits liability arising from statutory obligations applicable to the supply of services to Consumers where that exclusion or limitation is prohibited by law.

    16.3 Business Customer indirect losses. This clause applies only to Business Customers. Subject to clause 16.1, we will not be liable for: indirect or consequential loss; loss of profit; loss of revenue; loss of business opportunity; loss of anticipated savings; loss of goodwill; or loss arising from decisions made by you or a third party based on Platform outputs, in each case whether arising in contract, tort, negligence, breach of statutory duty or otherwise.

    16.4 General liability cap. Subject to clauses 16.1, 16.2 and 16.5, our total aggregate liability to a Business Customer arising out of or in connection with the Platform or these Terms will not exceed: (a) for an annual subscription, the fees paid or payable by that Business Customer to us during the 12 months preceding the event giving rise to the claim; and (b) for a one-off purchase, the amount paid by that Business Customer for the relevant service.

    16.5 Specific liabilities. The general liability cap in clause 16.4 does not apply to: your payment obligations; your liability under clause 5.3 for unauthorised scanning; your liability for infringement of our intellectual property rights; your liability for fraudulent or deliberately misleading use of the Platform or a Posture Certificate; or any liability which applicable law does not permit to be capped.

    16.6 Free or demonstration access. Where we provide free or demonstration access, our liability to a Business Customer arising solely from that free or demonstration access is limited to £100, subject to clause 16.1 and any liability that cannot lawfully be limited. Nothing in this clause limits a Consumer's statutory rights.

    16.7 Reliance on Platform outputs. You acknowledge that cybersecurity assessment involves judgement and that Platform outputs are not guarantees of security or compliance. You are responsible for decisions made by you or your organisation based on those outputs, subject to any liability which we cannot lawfully exclude or limit.

    17. Business Customer indemnity

    This clause applies only to Business Customers.

    17.1 Indemnity. You will indemnify us against reasonable external legal costs and other reasonable losses arising from a third-party claim to the extent caused by: your material breach of these Terms; your unlawful use of the Platform; your infringement of a third party's intellectual property rights through materials you submit to the Platform; your unauthorised nomination of an asset for scanning; or your materially misleading representation of a Posture Certificate. You will not be required to indemnify us to the extent that the relevant claim was caused by our own breach of these Terms, negligence or wilful misconduct.

    17.2 Conduct of claims. We will, where reasonably practicable, notify you of a claim for which we seek an indemnity and allow you reasonable involvement in the defence or settlement of that claim. We will not settle a claim in a manner that admits liability on your behalf or imposes a material non-monetary obligation on you without your consent, such consent not to be unreasonably withheld or delayed.

    18. Data Protection

    18.1 Personal data. We will process personal data in accordance with our Privacy Policy and, where applicable, a separate Data Processing Agreement.

    18.2 Business Customers. Where we process personal data on behalf of a Business Customer as a processor, the parties will comply with applicable data protection requirements and any applicable Data Processing Agreement.

    18.3 Security. We will maintain appropriate technical and organisational measures appropriate to the nature of the services and the risks associated with the processing we undertake.

    19. Confidentiality

    Each party must keep confidential information received from the other party confidential and must not disclose it except: to its employees, contractors, professional advisers or service providers who need to know it and are subject to appropriate confidentiality obligations; where disclosure is required by law or a competent authority; or with the other party's consent. This obligation does not apply to information that: is publicly available other than through breach of confidentiality; was already lawfully known; is independently developed; or is lawfully received from a third party without a duty of confidentiality.

    20. Aggregated and de-identified information

    We may use aggregated and de-identified information derived from use of the Platform for purposes including: improving the Platform; developing benchmarking; analysing trends; research and product development; and producing statistical or industry-level insights. We will not use information in a way that identifies you or another identifiable individual unless we have an appropriate lawful basis to do so and have informed you as required by applicable law.

    21. Support and complaints

    If you have a question, complaint or support request, please contact us using the contact form provided on the Platform. We aim to respond to enquiries within two business days, although this is a target rather than a guaranteed response time. Nothing in this clause limits any statutory rights or remedies available to Consumers.

    22. Changes to these Terms

    22.1 Updates. We may update these Terms from time to time to reflect: changes in law; changes to the Platform; changes to our business; security requirements; or changes in industry practice.

    22.2 Existing paid contracts. For Business Customers, an update will not retrospectively alter rights or obligations that have already accrued. Where an update materially and adversely affects a paid service, we will provide reasonable notice where practicable.

    22.3 Consumers. Where you are a Consumer, we will only make changes in accordance with applicable consumer law.

    23. Electronic communications and notices

    You agree that we may communicate with you electronically, including by email and through your account. We may send you: purchase confirmations; renewal notices; service notices; security notifications; changes to these Terms; cancellation confirmations; and other communications relating to your account or services. Where applicable law requires information to be provided on a durable medium, we will provide it in a form that satisfies the relevant requirement.

    24. Records of acceptance

    When you accept these Terms or complete a purchase, we may record: the date and time of acceptance; the version of these Terms accepted; the effective date of that version; the supplier identified at checkout; the plan or product purchased; the price and payment information; the wording and confirmations presented at checkout; any express consent or request relating to immediate performance; the purchase or transaction reference; and relevant technical information associated with the transaction. These records may be retained as evidence of the agreement and the circumstances in which it was entered into, subject to applicable data protection and retention requirements.

    25. Events outside our control

    We will not be responsible for delay or failure to perform caused by circumstances beyond our reasonable control, including: internet or telecommunications failures; third-party infrastructure failures; cyberattacks or security incidents not caused by our breach of these Terms; failures of third-party data sources or integrations; acts of government or regulatory authorities; natural disasters; war, terrorism or civil disorder; or widespread technical or infrastructure failures. This clause does not affect any statutory rights that cannot lawfully be excluded.

    26. General

    26.1 No waiver. A failure or delay by either party to exercise a right does not constitute a waiver of that right.

    26.2 Severability. If any provision of these Terms is found to be invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions will continue in force.

    26.3 Assignment. You may not transfer or assign your rights or obligations under these Terms without our prior written consent, except where required by law. We may transfer or assign these Terms, or the contract between us, to a group company, successor entity or purchaser of all or substantially all of the relevant RateYourCyber business, provided that: the transfer does not reduce any statutory rights you have; and where applicable law requires your consent, notice or a new agreement, we will obtain or provide it.

    26.4 Entire agreement. These Terms, together with the applicable plan description, purchase confirmation, Privacy Policy and any applicable Data Processing Agreement, constitute the entire agreement between you and us in relation to the Platform and supersede prior discussions and understandings concerning that subject matter. Nothing in this clause limits liability for fraud or fraudulent misrepresentation.

    26.5 Third-party rights. Except where these Terms expressly provide otherwise, a person who is not a party to these Terms has no right to enforce any term of them under the Contracts (Rights of Third Parties) Act 1999.

    26.6 No partnership or agency. Nothing in these Terms creates a partnership, agency, employment or joint venture relationship between you and us.

    27. Governing law and jurisdiction

    These Terms and any contract between you and the supplier are governed by the laws of England and Wales. If you are a Business Customer, the courts of England and Wales will have exclusive jurisdiction over disputes arising out of or in connection with these Terms or the services. If you are a Consumer, you will benefit from any mandatory jurisdictional rights available to you under applicable law.

    28. Supplier details

    The RateYourCyber Platform is currently supplied by ALFASOTERIA LIMITED, company number 15903182, incorporated in England and Wales, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. The supplier applicable to your purchase will be identified at the point of purchase and in your purchase confirmation. For questions, complaints or other enquiries, please use the contact form provided on the Platform.

    Schedule 1: Consumer Model Cancellation Form

    Complete and return this form only if you wish to cancel your contract.

    To: ALFASOTERIA LIMITED, company number 15903182, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. This form may be submitted through the cancellation facility on the RateYourCyber website, or posted to the address above.

    I/We hereby give notice that I/We cancel my/our contract for the supply of the following service:

    • Service / Plan:
    • Order / Purchase reference:
    • Date contract entered into:
    • Name of consumer(s):
    • Address of consumer(s):
    • Email address used for purchase:
    • Signature of consumer(s), where this form is notified on paper:
    • Date: