Legal
Service Disclaimer
Last updated 31 August 2026 · NextLayerSec LLC, Bismarck, North Dakota
The short version. Security work reduces risk. It cannot eliminate it. Anyone who tells you otherwise is selling something, and what they are selling is not security.
Risk reduction, not risk elimination
Every service described on this site is intended to reduce the likelihood and the impact of a security incident. None of them prevents one. A business that completes an assessment, implements every recommendation, and maintains the controls afterwards can still be breached.
NextLayerSec does not warrant, guarantee, or represent that any service will prevent unauthorized access, data loss, business interruption, fraud, or any other security event.
Assessments describe a point in time
An assessment reflects the environment as it was observed, using the access and information made available during the engagement. Environments change. A finding that was accurate on the day of review may not be accurate a month later, and a control that was in place may be changed, disabled, or bypassed afterwards.
An assessment is not a penetration test, a red team exercise, a vulnerability scan, a forensic investigation, or an audit, unless the signed statement of work says otherwise in those words.
Scope limits
Work is limited to what is agreed in writing. In particular:
- Systems, tenants, and accounts named in the statement of work, and no others
- What the licensing you hold actually makes available. Some controls require a licence tier you may not have
- The access you authorize. We cannot review what we cannot see
- Changes you approve. Nothing is implemented in your environment without your sign-off
Findings outside the agreed scope may be mentioned if noticed, but absence of a finding is never evidence that no issue exists in an area that was not examined.
Not compliance certification
NextLayerSec is not a certification body, an accredited auditor, or a qualified assessor for any regulatory framework. Work may be informed by frameworks such as NIST CSF, NIST SP 800-53, or CIS Controls, and deliverables may reference them, but that is not the same as certifying compliance and must not be represented as such to a regulator, an insurer, or a customer.
Nothing on this site or in any deliverable is legal advice, insurance advice, or a formal opinion on your regulatory obligations. Those questions belong to your attorney, your carrier, and your auditor.
Third-party products
Engagements may involve products from Microsoft, Huntress, and other vendors. Those products are governed by their own terms and their own service levels. NextLayerSec does not control their availability, pricing, feature set, or performance, and is not responsible for a vendor's outage, defect, or change in terms.
Your responsibilities
Security outcomes depend on work that only you can do. That includes applying updates, maintaining backups and testing that they restore, keeping licensing current, removing access when staff leave, approving recommended changes, and not disabling controls after they are put in place.
Recommendations that are declined, deferred, or reversed are outside our control and outside our responsibility.
Information on this website
Content here is general information about services, written for a business audience. It is not tailored advice for your environment and should not be relied on as such. Technical details, product capabilities, and threat conditions change, and pages are not always updated the moment they do.
Incidents in progress
If you believe you are dealing with an active security incident, do not wait on a web form. Contact your incident response provider, your cyber insurance carrier, and where appropriate law enforcement. NextLayerSec does not provide emergency incident response and this site is not monitored around the clock.
Agreements control
Where anything on this page conflicts with a signed statement of work, master services agreement, or other written agreement between us, the signed agreement controls.
Questions about this page? Use the contact form.