TOTAL CYBER SOLUTIONS, LLC

GENERAL TERMS AND CONDITIONS

Effective Date: August 23, 2026
Last Updated: August 23, 2026

These General Terms and Conditions (“Terms” or “GT&C”) establish the general contractual terms under which Total Cyber Solutions, LLC (“TCS”) provides information technology, cybersecurity, managed services, professional services, cloud services, consulting, compliance, software, hardware, licensing, and related products and services to its customers.

In these Terms, “TCS,” “we,” “our,” or “us” means Total Cyber Solutions, LLC, and “Client,” “Customer,” “you,” or “your” means the individual, company, organization, governmental entity, or other legal entity purchasing or receiving Services from TCS.

These Terms are intended to operate together with applicable proposals, quotations, Statements of Work, Managed Services Agreements, Service Level Agreements, service orders, Rules of Engagement, and other written agreements between TCS and Client.


1. ACCEPTANCE AND CONTRACT DOCUMENTS

Client accepts these Terms by:

  • signing an agreement that incorporates these Terms;
  • signing or accepting a Statement of Work (“SOW”);
  • accepting a TCS proposal or quotation incorporating these Terms;
  • electronically accepting these Terms;
  • issuing a purchase order that TCS accepts for Services subject to these Terms; or
  • otherwise expressly authorizing TCS to perform Services subject to these Terms.

The contractual relationship between TCS and Client may consist of several documents, including:

  1. a Master Services Agreement (“MSA”) or Managed Services Agreement;
  2. these General Terms and Conditions;
  3. one or more Statements of Work;
  4. proposals or quotations;
  5. Service Level Agreements (“SLAs”);
  6. Rules of Engagement (“ROE”);
  7. service orders;
  8. Business Associate Agreements (“BAAs”);
  9. Data Processing Agreements (“DPAs”);
  10. security or acceptable-use requirements; and
  11. other documents expressly incorporated into the parties’ agreement.

Collectively, these documents are referred to as the “Agreement.”

If a provision of a separately executed MSA, SOW, SLA, ROE, BAA, DPA, or other agreement expressly conflicts with these Terms, the more specific executed agreement shall control with respect to that subject matter.


2. DEFINITIONS

For purposes of these Terms:

2.1 “Client Data”

Means information, files, records, databases, credentials, configurations, documents, communications, logs, personal information, Controlled Unclassified Information (“CUI”), Federal Contract Information (“FCI”), and other data owned, controlled, or supplied by Client.

2.2 “Confidential Information”

Means non-public business, technical, financial, security, operational, personal, proprietary, or other sensitive information disclosed by either party.

2.3 “Deliverables”

Means reports, documentation, configurations, assessments, plans, software, scripts, or other materials specifically identified as deliverables in an applicable SOW.

2.4 “Services”

Means services provided by TCS under an Agreement, SOW, proposal, service order, or other authorization.

2.5 “Third-Party Services”

Means hardware, software, cloud services, telecommunications, applications, licenses, subscriptions, platforms, and other products or services provided by parties other than TCS.


3. TCS COMMITMENT

TCS will perform its Services in a commercially reasonable and professional manner using personnel with skills reasonably appropriate to the Services being performed.

TCS will perform as an independent contractor.

Nothing in the Agreement creates an employer-employee relationship, partnership, franchise, fiduciary relationship, joint venture, or agency relationship between TCS and Client.

Neither party may bind the other except where expressly authorized in writing.


4. SERVICES

Depending upon the applicable Agreement, TCS may provide Services including:

Managed IT Services

  • Help Desk and Service Desk
  • Tier 1, Tier 2, and Tier 3 support
  • workstation management
  • endpoint management
  • server administration
  • network administration
  • firewall administration
  • patch management
  • software deployment
  • Microsoft 365 administration
  • identity and access management
  • infrastructure monitoring
  • backup administration
  • disaster recovery support
  • cloud administration
  • asset management
  • vendor management
  • onsite IT support

Managed Cybersecurity Services

  • Security Operations Center services
  • security monitoring
  • SIEM administration
  • endpoint detection and response
  • managed detection and response
  • vulnerability management
  • security engineering
  • threat detection
  • threat hunting
  • security assessments
  • incident response
  • digital forensic support
  • penetration testing
  • adversarial simulation
  • security awareness services

Governance, Risk, and Compliance

TCS may provide consulting related to frameworks or requirements including:

  • CMMC;
  • NIST SP 800-171;
  • NIST SP 800-53;
  • NIST Cybersecurity Framework;
  • DFARS cybersecurity requirements;
  • FAR cybersecurity requirements;
  • HIPAA;
  • PCI DSS;
  • CJIS;
  • FedRAMP-related environments;
  • security policies;
  • risk assessments;
  • System Security Plans;
  • Plans of Action and Milestones;
  • security control assessments; and
  • governance and risk-management programs.

Cloud Services

Services may include:

  • Microsoft 365;
  • Microsoft Azure;
  • Amazon Web Services;
  • cloud migration;
  • cloud administration;
  • identity services;
  • cloud security;
  • backup;
  • disaster recovery; and
  • cloud architecture.

Professional Services

TCS may also provide:

  • consulting;
  • project management;
  • system implementation;
  • infrastructure deployment;
  • network engineering;
  • cybersecurity engineering;
  • software development;
  • assessments;
  • migrations;
  • remediation projects; and
  • other professional services.

The applicable SOW, proposal, or service agreement defines the Services purchased by Client.


5. STATEMENTS OF WORK

Specific Services may be documented through one or more SOWs.

An SOW may establish:

  • scope;
  • deliverables;
  • responsibilities;
  • assumptions;
  • exclusions;
  • milestones;
  • pricing;
  • service levels;
  • schedules;
  • project dependencies;
  • Client responsibilities; and
  • acceptance criteria.

Services outside the agreed scope may require a new SOW, Change Order, or additional authorization.


6. CHANGE CONTROL

Either party may request changes to the scope of Services.

Changes that materially affect:

  • scope;
  • cost;
  • staffing;
  • security;
  • technical requirements;
  • schedule; or
  • deliverables

may require a written Change Order or revised SOW.

TCS is not obligated to perform materially out-of-scope work until the parties agree upon applicable terms.


7. CLIENT RESPONSIBILITIES

Client agrees to reasonably cooperate with TCS.

Client is responsible for:

  1. providing accurate and complete information;
  2. providing timely access to facilities and systems;
  3. maintaining legitimate licenses for software used by Client;
  4. identifying regulated or sensitive information;
  5. notifying TCS of significant technology changes;
  6. maintaining appropriate physical security;
  7. identifying authorized users;
  8. promptly disabling accounts belonging to terminated personnel;
  9. promptly reporting suspected security incidents;
  10. reviewing TCS recommendations;
  11. maintaining insurance appropriate to Client’s business;
  12. complying with applicable laws and contractual requirements; and
  13. providing timely decisions and approvals.

TCS shall not be responsible for delays or failures caused by Client’s failure to provide reasonably necessary information, access, authorization, cooperation, or resources.


8. AUTHORIZED POINTS OF CONTACT

Client shall identify individuals authorized to communicate with TCS regarding Services (“Authorized Contacts”).

TCS may reasonably rely upon instructions from an Authorized Contact regarding:

  • service requests;
  • user accounts;
  • equipment;
  • software;
  • configuration changes;
  • purchasing;
  • projects;
  • access rights;
  • system administration; and
  • routine technology matters.

Client shall promptly notify TCS when an Authorized Contact’s authority changes or terminates.

TCS may require additional verification before implementing unusually sensitive requests.


9. PRIVILEGED ACCESS

Client authorizes TCS to obtain administrative or privileged access to Client systems to the extent reasonably necessary to perform contracted Services.

This may include access to:

  • servers;
  • endpoints;
  • firewalls;
  • switches;
  • routers;
  • Microsoft 365;
  • Azure;
  • AWS;
  • security platforms;
  • applications;
  • backup systems;
  • identity systems;
  • databases; and
  • other infrastructure.

TCS will use such access for legitimate purposes associated with providing Services.


10. CYBERSECURITY RISK ACKNOWLEDGMENT

Client acknowledges that no cybersecurity program, technology, product, service, or provider can guarantee absolute security.

Cyber threats continually evolve and may include:

  • ransomware;
  • malware;
  • phishing;
  • business email compromise;
  • credential theft;
  • zero-day vulnerabilities;
  • insider threats;
  • social engineering;
  • supply-chain compromises;
  • denial-of-service attacks;
  • cloud account compromise;
  • malicious artificial intelligence-enabled attacks; and
  • previously unknown vulnerabilities.

TCS does not guarantee that Client will never experience a security incident.

Cybersecurity Services are intended to reduce, detect, respond to, and manage cybersecurity risk—not eliminate all risk.


11. CLIENT SECURITY OBLIGATIONS

Client agrees to reasonably support security controls recommended or required for Services.

Depending upon Client’s environment, these may include:

  • multi-factor authentication;
  • endpoint detection and response;
  • supported operating systems;
  • patching;
  • encryption;
  • backups;
  • email security;
  • vulnerability remediation;
  • security awareness training;
  • least privilege;
  • conditional access;
  • logging;
  • network segmentation; and
  • appropriate firewall controls.

If Client refuses, disables, delays, circumvents, or materially modifies a security measure recommended by TCS, TCS shall not be responsible for damages to the extent reasonably attributable to that decision.

TCS may document such decisions as an Accepted Risk, Security Exception, or similar record.


12. UNSUPPORTED AND END-OF-LIFE SYSTEMS

Client acknowledges that obsolete or unsupported hardware and software may create significant cybersecurity and operational risk.

TCS may recommend replacement or remediation of:

  • unsupported operating systems;
  • end-of-life servers;
  • unsupported network devices;
  • obsolete applications;
  • unpatched systems; or
  • equipment no longer supported by its manufacturer.

If Client elects to continue operating such systems, Client accepts the additional risks associated with those systems.

TCS may exclude unsupported systems from service guarantees or security representations.


13. BACKUPS AND DISASTER RECOVERY

Backup and disaster recovery Services are provided only where expressly included in Client’s Agreement.

Client acknowledges that no backup technology can guarantee successful recovery under every circumstance.

Backup failures may result from:

  • hardware failure;
  • ransomware;
  • corruption;
  • software defects;
  • configuration errors;
  • third-party outages;
  • network failures;
  • storage failures;
  • Client actions; or
  • other circumstances.

Unless specifically guaranteed in an SLA, TCS does not warrant that every file, system, database, application, or historical version will be recoverable.

Client is responsible for maintaining business-continuity requirements appropriate to its organization.


14. CYBERSECURITY INCIDENTS

A cybersecurity incident may require work beyond ordinary managed Services.

Unless incident response is expressly included within Client’s Agreement, services relating to:

  • ransomware response;
  • forensic investigation;
  • malware eradication;
  • emergency restoration;
  • compromised-account investigation;
  • breach analysis;
  • regulatory response;
  • evidence preservation; and
  • recovery operations

may constitute separately billable professional or emergency Services.

TCS may recommend involvement of:

  • cyber insurance carriers;
  • breach counsel;
  • law enforcement;
  • forensic specialists;
  • regulatory counsel; or
  • other third parties.

15. PENETRATION TESTING AND OFFENSIVE SECURITY

Penetration testing, vulnerability exploitation, red-team testing, adversarial simulation, wireless testing, social engineering, or similar activities require written authorization.

Client represents and warrants that it:

  1. owns the systems being tested; or
  2. has sufficient authority from the system owner to authorize TCS to perform the testing.

Testing shall be governed by a SOW, Rules of Engagement, or similar written authorization.

Client acknowledges that legitimate security testing may cause:

  • service interruptions;
  • account lockouts;
  • system instability;
  • application failures;
  • performance degradation; or
  • other unintended operational effects.

Client is responsible for maintaining appropriate backups before testing begins.


16. COMPLIANCE AND CMMC SERVICES

TCS may assist Client with cybersecurity compliance, including CMMC, NIST, DFARS, FAR, HIPAA, or other requirements.

Unless expressly stated otherwise, TCS provides consulting, implementation, assessment-readiness, and remediation assistance.

TCS does not guarantee:

  • certification;
  • a particular assessment result;
  • a particular SPRS score;
  • successful CMMC certification;
  • regulatory approval;
  • contract award;
  • audit success;
  • continuous compliance; or
  • avoidance of regulatory enforcement.

Compliance depends upon technical, physical, administrative, personnel, contractual, and operational controls, many of which remain under Client’s control.

Client remains responsible for representations and attestations submitted to government agencies, regulators, customers, assessors, or other third parties unless otherwise expressly agreed.


17. THIRD-PARTY PRODUCTS AND SERVICES

TCS may procure, recommend, configure, resell, administer, or support Third-Party Services.

Examples include:

  • Microsoft;
  • Amazon Web Services;
  • cloud platforms;
  • cybersecurity software;
  • backup platforms;
  • telecommunications providers;
  • domain registrars;
  • hardware manufacturers;
  • Internet service providers; and
  • software vendors.

Third-Party Services are subject to their providers’ respective:

  • licenses;
  • service terms;
  • acceptable-use policies;
  • privacy policies;
  • warranties; and
  • service-level commitments.

TCS does not control third-party providers.

Except to the extent directly caused by TCS’s breach of its obligations, TCS is not responsible for third-party:

  • outages;
  • vulnerabilities;
  • licensing changes;
  • price increases;
  • product discontinuations;
  • data-center failures;
  • service modifications; or
  • security incidents.

18. HARDWARE AND SOFTWARE

Unless expressly included in an Agreement, hardware, software, licenses, subscriptions, and cloud consumption are separate from managed-service fees.

Third-party products are generally subject to the manufacturer’s or publisher’s warranty.

TCS does not extend or replace manufacturer warranties unless expressly stated.

Labor associated with warranty diagnosis, replacement, reinstallation, or configuration may be separately billable.


19. SUBCONTRACTORS

TCS may use qualified employees, contractors, subcontractors, consultants, cloud providers, and technology partners to perform portions of the Services.

Use of subcontractors does not relieve TCS of obligations expressly assumed under the applicable Agreement.

Where subcontractors require access to Client Confidential Information, TCS will require appropriate confidentiality or data-protection obligations consistent with the nature of the Services.


20. FEES AND CHARGES

Client agrees to pay the fees identified in the applicable:

  • Agreement;
  • SOW;
  • proposal;
  • quotation;
  • service order; or
  • invoice.

Fees may include:

  • recurring service charges;
  • project fees;
  • hourly labor;
  • emergency labor;
  • after-hours labor;
  • licensing;
  • hardware;
  • software;
  • cloud consumption;
  • travel;
  • shipping;
  • taxes; and
  • third-party expenses.

Unless expressly included in a fixed-fee arrangement, additional work requested by Client may be billed at TCS’s then-current professional-services rates.


21. INVOICING

Unless otherwise stated in the applicable Agreement:

  • recurring managed Services may be invoiced in advance;
  • project Services may be invoiced by milestone, periodically, or upon completion;
  • hardware and software may require advance payment;
  • licenses and subscriptions may be invoiced in advance; and
  • usage-based services may be billed in arrears.

Client agrees to pay invoices according to the payment terms stated on the applicable invoice or Agreement.


22. INVOICE DISPUTES

Client must notify TCS in writing of a good-faith invoice dispute within thirty (30) days of the invoice date.

The notice must reasonably identify:

  • the invoice;
  • disputed amount; and
  • basis for the dispute.

Client shall timely pay all undisputed amounts.

The parties will attempt in good faith to resolve disputed amounts.


23. LATE PAYMENTS

Unless prohibited by law or otherwise specified in an Agreement, overdue amounts may accrue interest at the lesser of:

1.5% per month (18% annually)

or

the maximum rate permitted by law.

Client may also be responsible for reasonable costs associated with collecting undisputed delinquent amounts, including attorneys’ fees where permitted by law.


24. SUSPENSION OF SERVICES

TCS may suspend some or all Services where:

  • undisputed invoices become materially delinquent;
  • Client materially breaches the Agreement;
  • Client’s environment creates an unreasonable threat to TCS infrastructure;
  • Services are being used unlawfully;
  • Client compromises TCS security;
  • a Third-Party Service required to deliver the Services is suspended; or
  • immediate action is reasonably necessary to protect systems, data, TCS, Client, or other customers.

Where reasonably practical, TCS will provide advance notice.

Emergency security conditions may require immediate action.


25. TAXES

Client is responsible for applicable sales, use, telecommunications, excise, or similar taxes imposed upon Services or products, excluding taxes based upon TCS’s net income.

Where required, TCS will collect and remit applicable taxes.


26. CLIENT DATA

As between TCS and Client, Client retains ownership of Client Data.

Client grants TCS a limited right to:

  • access;
  • process;
  • transmit;
  • copy;
  • store;
  • analyze; and
  • otherwise use

Client Data as reasonably necessary to perform Services.

TCS may process technical telemetry, security logs, device information, network information, configuration information, and similar operational data as necessary to provide and secure the Services.


27. DATA ACCURACY

Client is responsible for the accuracy and completeness of information supplied to TCS.

TCS shall not be responsible for errors, delays, or failures caused by inaccurate, incomplete, corrupted, or outdated information supplied by Client or Client’s vendors.

TCS will use commercially reasonable efforts to correct errors directly attributable to TCS when discovered.


28. CONFIDENTIALITY

Each party may receive Confidential Information belonging to the other.

The receiving party shall:

  1. protect Confidential Information using commercially reasonable safeguards;
  2. use it only for purposes associated with the Agreement; and
  3. disclose it only to personnel or service providers with a legitimate need to know.

Confidential Information does not include information that:

  • becomes public without violation of the Agreement;
  • was lawfully known before disclosure;
  • is lawfully received from another source without restriction; or
  • is independently developed without reliance upon the other party’s Confidential Information.

A party may disclose Confidential Information where legally required, subject to applicable law and reasonable notice where permitted.


29. PRIVACY AND REGULATED INFORMATION

Where Services involve personal information, Protected Health Information, CUI, FCI, payment information, or other regulated information, additional contractual requirements may apply.

These may include:

  • Business Associate Agreements;
  • Data Processing Agreements;
  • CUI handling requirements;
  • data residency requirements;
  • security addenda; or
  • government contract requirements.

Such agreements control where they impose requirements more specific than these Terms.


30. INTELLECTUAL PROPERTY

Each party retains ownership of intellectual property owned or independently developed by that party.

TCS retains ownership of its pre-existing and independently developed:

  • methodologies;
  • tools;
  • scripts;
  • software;
  • templates;
  • automation;
  • assessment procedures;
  • documentation frameworks;
  • training materials;
  • configurations;
  • processes;
  • techniques;
  • know-how; and
  • other intellectual property.

Unless an applicable SOW expressly provides otherwise, upon full payment Client receives a non-exclusive license to use Deliverables specifically created for Client for Client’s internal business purposes.

Client retains ownership of Client Data and Client-owned materials.


31. WARRANTIES

TCS warrants that Services will be performed in a commercially reasonable and professional manner.

TCS further represents that it has the right to provide Services and TCS-created materials supplied under the Agreement.

Client represents that it has sufficient rights and authority to:

  • enter into the Agreement;
  • authorize TCS to access Client systems;
  • provide Client Data to TCS; and
  • authorize security testing requested from TCS.

32. DISCLAIMER OF WARRANTIES

EXCEPT FOR WARRANTIES EXPRESSLY PROVIDED IN AN APPLICABLE AGREEMENT AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.”

TCS DISCLAIMS IMPLIED WARRANTIES INCLUDING:

  • MERCHANTABILITY;
  • FITNESS FOR A PARTICULAR PURPOSE;
  • NON-INFRINGEMENT; AND
  • UNINTERRUPTED OR ERROR-FREE OPERATION.

TCS DOES NOT WARRANT THAT ANY SECURITY PRODUCT OR SERVICE WILL PREVENT OR DETECT EVERY CYBERSECURITY THREAT.


33. LIMITATION OF LIABILITY

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR:

  • INDIRECT DAMAGES;
  • CONSEQUENTIAL DAMAGES;
  • EXEMPLARY DAMAGES;
  • SPECIAL DAMAGES;
  • PUNITIVE DAMAGES;
  • LOSS OF PROFITS;
  • LOSS OF REVENUE;
  • LOSS OF BUSINESS OPPORTUNITY; OR
  • LOSS OF GOODWILL

ARISING FROM OR RELATED TO THE AGREEMENT.

Unless otherwise stated in a signed Agreement, TCS’s aggregate liability arising from the applicable Services shall not exceed the lesser of Client’s proven direct damages or the total fees paid to TCS for the affected Services during the twelve (12) months immediately preceding the event giving rise to the claim.

This limitation applies regardless of whether the claim arises in contract, tort, negligence, strict liability, or another theory.

Nothing herein limits liability that cannot legally be limited.


34. EXCLUSIONS FROM TCS RESPONSIBILITY

To the extent permitted by law, TCS shall not be responsible for loss caused by:

  • Client personnel;
  • unauthorized Client users;
  • Client contractors;
  • third-party providers;
  • unsupported technology;
  • Client’s failure to follow security recommendations;
  • Client’s failure to maintain required licenses;
  • Client’s unauthorized configuration changes;
  • Client’s failure to maintain appropriate backups;
  • malicious third parties;
  • zero-day vulnerabilities;
  • events outside TCS’s reasonable control; or
  • Client’s breach of the Agreement.

35. INDEMNIFICATION

To the fullest extent permitted by law, Client shall defend, indemnify, and hold harmless TCS and its officers, directors, employees, agents, and contractors against third-party claims arising from:

  • Client’s unlawful use of Services;
  • Client’s breach of the Agreement;
  • Client Data that violates third-party rights;
  • unauthorized penetration testing requested by Client;
  • Client’s violation of applicable law; or
  • Client’s gross negligence or willful misconduct.

TCS shall provide reasonable notice of an indemnified claim and reasonable cooperation with its defense.

Any additional mutual indemnification obligations may be established in the applicable Agreement.


36. INSURANCE

Each party is responsible for maintaining insurance reasonably appropriate to its business.

TCS strongly recommends that Client maintain appropriate:

  • cyber liability insurance;
  • data breach coverage;
  • business interruption coverage; and
  • general liability insurance.

Client acknowledges that managed cybersecurity Services are not a substitute for cyber insurance.


37. FORCE MAJEURE

Neither party shall be liable for failure or delay caused by circumstances beyond its reasonable control, including:

  • natural disasters;
  • severe weather;
  • war;
  • terrorism;
  • civil disturbance;
  • epidemics;
  • pandemics;
  • utility failures;
  • telecommunications outages;
  • widespread Internet failures;
  • government action;
  • cloud-provider outages;
  • labor disruptions;
  • supply-chain disruptions; or
  • large-scale cyberattacks.

This provision does not excuse payment for Services already properly rendered.


38. MUTUAL NON-SOLICITATION

During the Agreement and for twelve (12) months following termination, neither party shall knowingly directly solicit for employment personnel of the other party who were materially involved in the Services, except through general employment advertisements not specifically directed toward those individuals.

The parties may separately agree to recruitment or placement terms.

This provision applies only to the extent enforceable under applicable law.


39. TERM AND RENEWAL

The term applicable to Services shall be established in the applicable Agreement or SOW.

Recurring Services may automatically renew where expressly provided in the Agreement.

Notice requirements for non-renewal shall be governed by the applicable Agreement.


40. TERMINATION FOR BREACH

Unless otherwise provided in the applicable Agreement, either party may terminate for a material breach if the breaching party fails to cure the breach within thirty (30) days following written notice.

Immediate termination or suspension may occur where reasonably necessary because of:

  • unlawful conduct;
  • intentional security compromise;
  • insolvency;
  • fraud;
  • material misuse of Services; or
  • circumstances making continued performance unlawful or unreasonably dangerous.

41. EFFECT OF TERMINATION

Termination does not eliminate:

  • amounts already owed;
  • obligations arising before termination;
  • confidentiality obligations;
  • intellectual-property protections;
  • indemnification obligations;
  • limitation-of-liability provisions; or
  • other provisions intended to survive termination.

42. TRANSITION AND OFFBOARDING

Upon termination, TCS will reasonably cooperate with Client or Client’s replacement service provider.

Transition Services may include:

  • credential transfer;
  • documentation transfer;
  • configuration information;
  • Client Data export;
  • vendor information;
  • license transition;
  • removal of TCS agents; and
  • reasonable knowledge transfer.

Unless included in Client’s Agreement, transition work may be billed at TCS’s then-current professional-services rates.

TCS is not required to transfer:

  • proprietary TCS tools;
  • internal automation;
  • confidential information belonging to other customers;
  • third-party intellectual property TCS cannot legally transfer; or
  • TCS security information unrelated to Client.

43. RETURN OR DESTRUCTION OF DATA

Following termination and completion of transition obligations, TCS may delete Client Data remaining in TCS-controlled systems in accordance with TCS’s retention procedures and applicable legal requirements.

Client is responsible for ensuring that required copies of Client Data are obtained during transition.

TCS may retain information where required for:

  • legal compliance;
  • accounting;
  • security;
  • dispute resolution;
  • insurance; or
  • legitimate recordkeeping purposes.

44. DISPUTE RESOLUTION

The parties agree to first attempt to resolve disputes through good-faith business negotiations.

Appropriate representatives from each party shall attempt to resolve the matter before formal proceedings are initiated.

The parties may mutually agree to mediation before arbitration.


45. BINDING ARBITRATION

Unless prohibited by law or superseded by a separately executed Agreement, disputes not resolved through negotiation shall be resolved through binding arbitration administered by the American Arbitration Association (“AAA”) under its applicable Commercial Arbitration Rules.

Unless otherwise agreed, arbitration shall:

  • involve one arbitrator;
  • occur in the Commonwealth of Virginia; and
  • be conducted in English.

Judgment upon the arbitration award may be entered by a court having jurisdiction.

Either party may seek temporary or preliminary injunctive relief from a court when reasonably necessary to protect:

  • Confidential Information;
  • intellectual property;
  • systems;
  • credentials;
  • Client Data; or
  • other rights where monetary damages would be inadequate.

THE PARTIES ACKNOWLEDGE THAT BINDING ARBITRATION GENERALLY WAIVES THE RIGHT TO HAVE A DISPUTE DECIDED BY A JUDGE OR JURY.


46. GOVERNING LAW

Unless otherwise specified in a separately executed Agreement, the Agreement shall be governed by the laws of the Commonwealth of Virginia, without regard to conflict-of-law principles.


47. GOVERNMENT CUSTOMERS

Where Client is a federal, state, or local governmental entity, provisions conflicting with mandatory procurement laws, sovereign immunity, appropriations requirements, mandatory dispute procedures, or other applicable government requirements shall apply only to the extent legally permissible.

Applicable:

  • government contracts;
  • purchase orders;
  • FAR clauses;
  • DFARS clauses;
  • agency supplements; and
  • mandatory flow-down provisions

shall control where legally required.


48. PUBLICITY

Neither party may use the other party’s trademarks, logos, or trade names in advertising or promotional materials in a manner suggesting endorsement without authorization.

TCS may identify Client as a customer only where permitted by the applicable Agreement or with Client’s consent.


49. WEBSITE AND ONLINE SERVICES

Use of TCS websites and publicly accessible online resources is permitted for lawful business and informational purposes.

Users may not:

  • obtain or attempt unauthorized access;
  • circumvent authentication;
  • probe or scan TCS systems without authorization;
  • introduce malicious software;
  • interfere with website operation;
  • harvest credentials;
  • impersonate another person;
  • misuse website forms;
  • scrape protected content contrary to applicable law;
  • interfere with another user’s access; or
  • use TCS systems for unlawful purposes.

TCS may restrict website or portal access where reasonably necessary to protect TCS, its customers, users, or systems.


50. USER ACCOUNTS AND CREDENTIALS

Users receiving credentials for a TCS portal or online service must protect those credentials.

Users shall:

  • use appropriate passwords;
  • use MFA where required;
  • not knowingly share credentials with unauthorized persons; and
  • notify TCS promptly of suspected credential compromise.

Client is responsible for activity performed through Client-controlled accounts except to the extent resulting from TCS’s breach of its obligations.


51. WEBSITE CONTENT

TCS attempts to provide accurate and useful website information but does not guarantee that website content is always:

  • complete;
  • current;
  • error-free;
  • applicable to every organization; or
  • suitable for a specific regulatory situation.

Website materials are provided primarily for informational purposes.


52. NO LEGAL, ACCOUNTING, OR INSURANCE ADVICE

TCS provides information technology, cybersecurity, and related consulting Services.

Unless expressly stated otherwise, TCS does not provide:

  • legal advice;
  • accounting advice;
  • tax advice;
  • investment advice; or
  • insurance advice.

Clients should obtain advice from qualified professionals where appropriate.


53. THIRD-PARTY WEBSITES

TCS websites may contain links to third-party resources.

Providing a link does not necessarily constitute endorsement.

TCS is not responsible for the:

  • content;
  • security;
  • availability;
  • privacy practices; or
  • accuracy

of third-party websites.


54. TCS WEBSITE INTELLECTUAL PROPERTY

Unless otherwise stated, original content appearing on TCS websites, including:

  • text;
  • graphics;
  • designs;
  • documents;
  • photographs;
  • video;
  • software;
  • logos;
  • trademarks;
  • service marks; and
  • branding

is owned by or licensed to Total Cyber Solutions, LLC.

The names and marks Total Cyber Solutions, Total Cyber Academy, and associated branding may not be used in a manner suggesting sponsorship, affiliation, authorization, or endorsement without written permission.


55. ELECTRONIC COMMUNICATIONS AND SIGNATURES

Client agrees that business may be conducted electronically where legally permitted.

Electronic communications may include:

  • email;
  • electronic signatures;
  • ticketing systems;
  • customer portals;
  • proposals;
  • invoices;
  • service notifications; and
  • electronic acceptance.

Electronic signatures and acceptance shall have the same effect as physical signatures to the extent permitted by law.


56. NOTICES

Formal notices required by an Agreement shall be delivered using the method specified in that Agreement.

Where no method is specified, notice may be provided through:

  • email;
  • recognized overnight delivery;
  • certified mail; or
  • another method providing reasonable evidence of delivery.

57. ASSIGNMENT

Neither party may assign an Agreement without the other party’s written consent, except that either party may assign it in connection with:

  • merger;
  • acquisition;
  • corporate reorganization;
  • sale of substantially all assets; or
  • transfer to a successor or affiliate

provided the successor assumes applicable obligations.


58. SEVERABILITY

If any provision of these Terms is determined to be invalid or unenforceable, it shall be enforced to the maximum extent permitted by law.

The remaining provisions shall remain in effect.


59. WAIVER

Failure to enforce any provision does not waive that provision.

A waiver concerning one event does not constitute a waiver concerning subsequent events.


60. NO THIRD-PARTY BENEFICIARIES

Unless expressly stated otherwise, the Agreement is intended solely for TCS and Client.

No other person or organization acquires contractual rights solely because of the Agreement.


61. ENTIRE AGREEMENT

The applicable:

  • MSA;
  • these Terms;
  • SOWs;
  • SLAs;
  • proposals;
  • service orders;
  • ROEs;
  • security addenda;
  • BAAs;
  • DPAs; and
  • incorporated documents

constitute the agreement between the parties concerning the applicable Services and supersede prior representations concerning the same subject matter.


62. AMENDMENTS

TCS may periodically update these online General Terms and Conditions.

The current version will identify its effective or last-updated date.

Changes apply prospectively.

Changes will not retroactively alter the terms of a separately executed agreement unless:

  • that agreement expressly permits incorporation of updated online terms;
  • the parties mutually agree; or
  • applicable law requires the change.

Material contractual changes affecting existing Services will be handled according to the applicable Agreement.


63. SURVIVAL

Provisions that by their nature are intended to continue after termination shall survive, including provisions relating to:

  • payment;
  • confidentiality;
  • intellectual property;
  • Client Data;
  • indemnification;
  • limitation of liability;
  • dispute resolution; and
  • accrued rights.

64. AUTHORITY TO ACCEPT

The individual accepting these Terms on behalf of Client represents that he or she has authority to bind Client.

Client acknowledges that it has had the opportunity to review these Terms before accepting Services.


65. CONTACT INFORMATION

Questions concerning these General Terms and Conditions may be directed to:

Total Cyber Solutions, LLC

Website: totalcyber.com
Email: contact@totalcyber.com
Telephone: 888-300-9118

Attn: Contracts / Legal


ACCEPTANCE

By executing an Agreement incorporating these General Terms and Conditions, Client acknowledges that:

  1. Client has reviewed these Terms;
  2. Client understands these Terms;
  3. Client agrees to be bound by them;
  4. the individual accepting them is authorized to act for Client; and
  5. these Terms form part of the contractual relationship between Client and Total Cyber Solutions, LLC.

© 2026 Total Cyber Solutions, LLC. All Rights Reserved.

 

Learn How We Can Secure Your Business