CyberGrape logo - Cyber Security and SMB1001 certification platform for small business
    CyberGrape - GRC platform for SMB1001 security certification
    Insights

    Terms and Conditions

    CyberGrape GRC Platform (cybergrape.io & smb1001.ai)

    Version 2.1

    Effective Date: 1 July 2026

    Last Reviewed: 25 June 2026

    CyberGrape Pty Ltd, ABN 83 696 722 988 (Australia)

    CyberGrape Ltd, NZBN 9429048818155 (New Zealand)

    Trading as CyberGrape

    Registered address: Level 1, 470 St Pauls Terrace, Fortitude Valley, QLD 4006, Australia

    This document has been prepared by CyberGrape for internal use and client engagements. It does not constitute legal advice. CyberGrape recommends that all parties, and in particular CyberGrape's insurance broker, review the Insurance and Limitation of Liability clauses before this document is published or relied upon.

    1. Acceptance of Terms

    1.1 These Terms and Conditions ("Terms") govern access to and use of the CyberGrape GRC Platform available at app.cybergrape.io and the marketing website at cybergrape.io (together, the "Platform"), provided by CyberGrape Pty Ltd (ABN 83 696 722 988) and/or CyberGrape Ltd (NZBN 9429048818155), trading together as "CyberGrape", "we", "us" or "our".

    1.2 By creating an Account, clicking "I Agree", or otherwise accessing or using the Platform, you agree to be bound by these Terms. If you are entering into these Terms on behalf of an organisation, you represent that you have authority to bind that organisation, and references to "Customer", "you" or "your" are to that organisation.

    1.3 Electronic acceptance of these Terms is valid and enforceable under the Electronic Transactions Act 1999 (Cth) and the Electronic Transactions Act 2002 (NZ).

    1.4 Continued use of the Platform following any amendment to these Terms in accordance with clause 16 constitutes acceptance of the amended Terms.

    2. Definitions

    • "Account" means a registered user account on the Platform.
    • "Authorised User" means an individual authorised by the Customer to access the Platform under the Customer's Subscription.
    • "Content" means any data, information, evidence, files, reports or other material submitted to, generated by, or processed within the Platform.
    • "Customer" or "Tenant" means the organisation that has subscribed to the Platform, including where accessed via an MSP (managed service provider) console.
    • "Data Breach Event" or "Cyber Event" means an event involving unauthorised access to, disclosure of, or loss of Content, including where the Content is held by CyberGrape or a Subprocessor on the Customer's behalf.
    • "Fees" means the subscription and other fees payable by the Customer for access to the Platform, as set out in an Order Form, invoice, or the Platform pricing page.
    • "Services" means the Platform and any associated consulting, implementation, or support services provided by CyberGrape.
    • "Subprocessor" means a third-party service provider engaged by CyberGrape to process Content on CyberGrape's behalf, as described in CyberGrape's Privacy Policy.
    • "Subscription" means the Customer's paid or trial access arrangement to the Platform.

    3. Access and Use

    3.1 Subject to these Terms and payment of applicable Fees, CyberGrape grants the Customer and its Authorised Users a non-exclusive, non-transferable, revocable licence to access and use the Platform for the Customer's internal business purposes during the Subscription term.

    3.2 The Customer must not, and must ensure Authorised Users do not: reverse engineer, decompile or disassemble the Platform; scrape, crawl or use automated means to extract data from the Platform other than via a documented API; sublicense, resell, or make the Platform available to any third party outside the scope of the Subscription; or use the Platform to build a competing product.

    3.3 The Customer is responsible for maintaining the confidentiality of Account credentials and for all activity under its Account, and must notify CyberGrape promptly at [email protected] of any suspected unauthorised access.

    4. Subscriptions and Payment

    4.1 Subscription tiers, features, and pricing are as set out in the applicable Order Form or the Platform pricing page. Fees are payable in advance for the applicable billing cycle (monthly or annual) unless otherwise agreed in writing.

    4.2 Subscriptions renew automatically for successive terms equal to the initial term, unless either party gives written notice of non-renewal at least 30 days before the renewal date.

    4.3 Payments are processed via CyberGrape's payment processor (Stripe) and invoiced via CyberGrape's accounting platform (Xero). Overdue amounts accrue interest at 5% per annum from the due date until paid, and CyberGrape may suspend access under clause 15 for non-payment.

    4.4 Except as required by the Australian Consumer Law, the Consumer Guarantees Act 1993 (NZ), or as otherwise stated in an Order Form, Fees already paid are non-refundable.

    5. Consumer Guarantees

    5.1 Nothing in these Terms excludes, restricts or modifies any condition, warranty, guarantee, right or remedy conferred on the Customer by the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)), the Consumer Guarantees Act 1993 (NZ), the Fair Trading Act 1986 (NZ), or any other applicable law that cannot lawfully be excluded, restricted or modified ("Non-Excludable Rights").

    5.2 The Platform is supplied for business purposes. To the extent the Customer is acquiring the Services for the purposes of a business, and to the extent permitted by section 64A of the Australian Consumer Law and section 43 of the Consumer Guarantees Act 1993 (NZ), all conditions, warranties and guarantees other than the Non-Excludable Rights are excluded, and CyberGrape's liability for breach of a Non-Excludable Right that cannot be excluded but can be limited is limited, at CyberGrape's election, to resupply of the Services or the cost of resupply.

    6. Intellectual Property

    6.1 The Platform, including all software, design, documentation, trademarks and underlying technology, is owned by or licensed to CyberGrape. Nothing in these Terms transfers any intellectual property rights to the Customer.

    6.2 The Customer retains ownership of Content it submits to the Platform. The Customer grants CyberGrape a non-exclusive, worldwide licence to host, store, process, and display Content solely to provide the Services and as otherwise permitted under CyberGrape's Privacy Policy.

    6.3 No licence is granted to use CyberGrape's trademarks, branding, or intellectual property outside the Platform without CyberGrape's prior written consent.

    7. Privacy and Data

    7.1 Personal information is collected and handled in accordance with CyberGrape's Privacy Policy (available at cybergrape.io/privacy), which forms part of these Terms by reference.

    7.2 Where Content submitted to the Platform includes personal information about the Customer's own personnel, contractors, customers or site visitors, CyberGrape acts as a service provider / data processor on the Customer's behalf for that Content, and the Customer remains responsible, as the controller / business, for having a lawful basis to provide that personal information to CyberGrape and for its own compliance obligations to those individuals.

    7.3 CyberGrape processes Content in accordance with the Privacy Act 1988 (Cth) and Australian Privacy Principles, the Privacy Act 2020 (NZ) and Information Privacy Principles, and, where applicable, the CCPA/CPRA, as further described in the Privacy Policy, including in relation to overseas disclosure to Subprocessors.

    8. Prohibited Conduct

    • Use the Platform for any unlawful purpose, or in breach of any applicable law or regulation;
    • Introduce malware, viruses, or other harmful code into the Platform;
    • Attempt to gain unauthorised access to the Platform, other Tenants' data, or CyberGrape's systems;
    • Interfere with or disrupt the integrity or performance of the Platform or its infrastructure;
    • Impersonate any person or entity, or misrepresent your affiliation with any person or entity;
    • Use the Platform in breach of any applicable export control or sanctions law.

    9. Third-Party Services and Integrations

    9.1 The Platform may integrate with third-party services selected by the Customer (for example, Microsoft 365, Black Kite, CrowdStrike, uSecure, and similar tools). Such integrations are subject to the third party's own terms, and CyberGrape is not responsible for the availability, accuracy, or performance of third-party services.

    9.2 CyberGrape relies on infrastructure and AI service providers, including Microsoft, Amazon Web Services, Cloudflare, OpenAI and/or Anthropic, to deliver the Platform. CyberGrape remains responsible for its own obligations under these Terms notwithstanding its use of such Subprocessors.

    10. Security and Data Breach Notification

    10.1 CyberGrape maintains administrative, technical and physical safeguards designed to protect Content, including encryption in transit and at rest, per-tenant encryption keys, access controls, multi-factor authentication, and audit logging, consistent with CyberGrape's alignment to ISO 27001:2022 and SMB1001:2026 control frameworks.

    10.2 If CyberGrape becomes aware of a Data Breach Event affecting a Customer's Content, CyberGrape will notify the affected Customer without undue delay and provide such information as is reasonably available to assist the Customer in meeting its own notification obligations under applicable law.

    10.3 The Customer must notify CyberGrape promptly at [email protected] of any suspected Data Breach Event or Cyber Event involving the Platform of which it becomes aware.

    11. Insurance

    11.1 CyberGrape maintains, and will use reasonable endeavours to keep current for the duration of each active Subscription, insurance including cyber liability and privacy protection insurance, and professional indemnity and public liability insurance, placed with reputable Lloyd's-backed underwriters, at levels of cover CyberGrape considers appropriate having regard to the nature and scale of the Services.

    11.2 Evidence of currency of CyberGrape's insurance (a Certificate of Insurance) is available to Customers on reasonable written request for the purpose of vendor due diligence or security assessment, subject to any confidentiality restrictions imposed by CyberGrape's insurer.

    11.3 The existence of insurance cover does not increase, and is not to be construed as increasing, CyberGrape's liability under these Terms beyond the caps set out in clause 12.

    12. Limitation of Liability

    12.1 Nothing in these Terms excludes, restricts or modifies any Non-Excludable Right (as defined in clause 5.1). This clause 12 applies to the maximum extent permitted by law and subject always to clause 12.1.

    12.2 To the maximum extent permitted by law, CyberGrape excludes all liability (whether in contract, tort including negligence, under statute or otherwise) for any indirect, consequential, special or punitive loss or damage, including loss of profits, loss of revenue, loss of anticipated savings, loss of goodwill or reputation, or business interruption, arising out of or in connection with these Terms or the Platform, even if CyberGrape has been advised of the possibility of such loss.

    12.3 Subject to clauses 12.1 and 12.5, CyberGrape's total aggregate liability arising out of or in connection with these Terms or the Platform, however arising and whether from a single event or a series of related events, must not exceed the greater of:

    • the total Fees paid by the Customer to CyberGrape in the 12 months immediately preceding the event giving rise to the claim; or
    • NZD $2,000,000 (or its equivalent in the currency in which the Customer is invoiced),

    this figure reflecting the level of cyber liability and privacy protection insurance cover CyberGrape maintains and reviews from time to time. This cap applies in aggregate to all claims arising from the same or related acts, errors or omissions.

    12.4 Claims properly characterised as arising from professional negligence in the provision of consulting or advisory Services, as distinct from Platform-related claims, are separately capped at NZD $2,000,000 for any one claim, consistent with the professional indemnity insurance CyberGrape maintains.

    12.5 Consistent with the exclusions available under CyberGrape's insurance arrangements, and to the maximum extent permitted by law, CyberGrape excludes liability for any loss arising directly or indirectly from:

    • war, or a cyber operation carried out as part of, or in immediate preparation for, war, or a cyber operation that causes a state to become an impacted state;
    • an act of terrorism, other than an act of cyber terrorism (being the premeditated use of disruptive activity by a non-state actor against a computer system), which remains within the scope of the cap in clause 12.3; and
    • the death of, or personal injury or illness to, any person, except that this exclusion does not apply to mental anguish or mental injury suffered as a direct result of a Data Breach Event or Cyber Event for which CyberGrape is legally liable.

    12.6 Each provision of this clause 12 is a separate and severable term. If any part is held unenforceable by a court of competent jurisdiction, the remainder continues in full force and effect.

    13. Notification of Claims and Time Bar

    13.1 The Customer must notify CyberGrape in writing at [email protected] of any actual or potential claim, or any circumstance that may give rise to a claim, as soon as reasonably practicable and in any event within 30 days of becoming aware of it. Prompt notification is required because CyberGrape's insurance is underwritten on a claims-made basis, and delayed notification may prejudice the availability of cover referred to in clause 11.

    13.2 Subject to any Non-Excludable Right, any claim against CyberGrape arising out of or in connection with these Terms must be commenced within 12 months of the date the Customer first became aware, or ought reasonably to have become aware, of the facts giving rise to the claim, after which the claim is barred.

    14. Indemnification

    14.1 The Customer indemnifies CyberGrape against any claims, losses, liabilities and reasonable costs (including legal costs) arising from: the Customer's breach of these Terms; the Customer's or an Authorised User's misuse of the Platform; or Content submitted by the Customer infringing the rights of, or otherwise causing loss to, a third party, except to the extent caused by CyberGrape's breach of these Terms or negligence.

    15. Suspension and Termination

    15.1 CyberGrape may suspend or terminate the Customer's access to the Platform for: non-payment of Fees more than 14 days overdue; material breach of these Terms not remedied within 14 days of written notice; misuse of the Platform; or the Customer's insolvency.

    15.2 The Customer may terminate its Subscription on 30 days' written notice, subject to any minimum term in an Order Form.

    15.3 On termination, the Customer may export its Content for a period of 30 days, after which CyberGrape will delete Content in accordance with its data retention practices described in the Privacy Policy.

    16. Changes to Terms

    16.1 CyberGrape may amend these Terms from time to time. Material changes will be notified by email to the Customer's registered administrator or via a prominent notice within the Platform at least 30 days before taking effect. Continued use of the Platform after the effective date of an amendment constitutes acceptance of the amended Terms.

    17. Dispute Resolution

    17.1 Before commencing formal proceedings (other than an application for urgent injunctive relief), the parties must attempt in good faith to resolve any dispute arising out of or in connection with these Terms through senior representative negotiation for a period of at least 20 business days.

    17.2 If the dispute is not resolved through negotiation, either party may refer the dispute to mediation before a mutually agreed mediator, prior to commencing litigation.

    18. Governing Law and Jurisdiction

    18.1 These Terms are governed by the laws of Queensland, Australia, and the parties submit to the non-exclusive jurisdiction of the courts of Queensland, except that where the Customer is based in New Zealand, New Zealand law applies to the Customer's use of the Platform and the parties submit to the non-exclusive jurisdiction of the courts of New Zealand.

    19. Entire Agreement, Severability and Waiver

    19.1 These Terms, together with any Order Form and the Privacy Policy, constitute the entire agreement between the parties regarding the Platform and supersede all prior discussions, representations or agreements on that subject.

    19.2 If any provision of these Terms is held invalid or unenforceable, that provision is severed and the remaining provisions continue in full force and effect.

    19.3 A failure or delay by either party to exercise any right under these Terms does not operate as a waiver of that right.

    20. Notices

    20.1 Notices to CyberGrape must be sent to [email protected] or to the registered address on the cover page of these Terms. Notices to the Customer will be sent to the email address or postal address associated with the Customer's Account.

    This document has been prepared by CyberGrape for internal use and client engagements. It does not constitute legal advice. CyberGrape recommends that all parties, and in particular CyberGrape's insurance broker, review the Insurance and Limitation of Liability clauses before this document is published or relied upon.

    © CyberGrape 2026