Skip to main content

Version: 2026-08-17 • Effective Date: August 17, 2026

1. Agreement and Parties

These Terms of Service ("Terms") are a legally binding agreement between you and Bitscaled LLC ("Bitscaled," "we," "us," or "our"), a Florida limited liability company operating from Tampa, Florida. They apply when you visit https://bitscaled.tech, create an account, use Client Workspace, Intranet, or Admin portals, submit a form, run a VaultTools check, or receive managed IT, cybersecurity, cloud, backup, or related professional services.

If you use the services on behalf of a company, you represent that you have authority to bind that company, and "you" includes that company.

A signed Master Service Agreement (MSA), Statement of Work (SOW), Business Associate Agreement (BAA), Non-Disclosure Agreement (NDA), or Data Processing Agreement (DPA) controls over these website Terms where they conflict. These Terms fill gaps for website, portal, and tool use and for work that is not covered by a signed contract.

2. Definitions

  • "Services" means our websites, portals, APIs, VaultTools public security tools, VaultSandbox spoof testing when offered, and contracted managed IT and professional services.
  • "Managed Services" means ongoing IT support, monitoring, security operations, Microsoft 365 administration, backup, or similar work described in an MSA or SOW.
  • "Workspace" means the client portal at /workspace used by organization members.
  • "VaultTools" means the public assessment tools hosted at vaulttools.bitscaled.tech and linked from /tools, including DNS/SSL, footprint, Microsoft 365 snapshot, breach check, ransomware scorecard, and BIMI. Email spoof / SMTP testing, when offered, is VaultSandbox (spooftest.bitscaled.tech), not the VaultTools API.
  • "Client Data" means data in your systems or tenants that we access to deliver Managed Services.
  • "Website Data" means information we collect as a controller from visitors, leads, and accounts.

3. Eligibility and Accounts

The Services are intended for business users. You must be at least 18 years old. You must provide accurate registration information and keep credentials confidential. You are responsible for activity under your account, including invited organization members.

Workspace roles labeled Organization Admin or Organization Member do not change the internal role identifiers used for access control. Organization admins may invite colleagues from Workspace team settings. Do not share passwords or MFA devices.

We may require acknowledgment of current Terms, Privacy Policy, and Acceptable Use Policy before portal access. Material version changes can require re-acknowledgment. Clicking acknowledge, checking an acceptance box, or completing Google Workspace eSign constitutes your electronic signature under the U.S. ESIGN Act and Florida UETA. We may retain the version, timestamp, IP address, and user agent of that acknowledgment.

4. Website, Articles, and Public Content

Public pages, articles, case studies, pricing pages, and tools are informational. They are not a proposal, SLA, or certification. Service descriptions may change. Quoted response times (including typical first response) are targets, not guarantees, unless an MSA or SOW states otherwise.

You may not scrape, harvest, or systematically copy the site except as allowed by robots.txt, a written license, or applicable law. See our DMCA Policy for copyright complaints about user or published content.

5. Managed IT and Professional Services

Managed Services are delivered only as described in the applicable MSA, SOW, order, or written statement of scope. We may use remote monitoring and management (RMM), privileged access, scripting, and vendor consoles as reasonably needed to perform the work.

  • On-site work is available in Florida, with Tampa Bay as the primary coverage area. Remote support may be provided nationwide where commercially reasonable.
  • Standard support hours are Monday to Friday, 8:00 AM to 6:00 PM EST, unless your plan states otherwise.
  • Emergency contact: emergency@bitscaled.tech and +1 (813) 419-0419. After-hours response depends on your contracted plan.
  • We do not promise 24/7 coverage, named SLAs, or specific uptime unless written in your contract.
  • These website Terms do not create insurance obligations. Any cyber, errors-and-omissions, or similar coverage Bitscaled maintains is described only in a signed MSA or upon written request.
  • Recommendations, architecture advice, and vCIO guidance are professional opinions, not legal, insurance, or audit opinions.
  • Bitscaled may use employees and vetted contractors under confidentiality and need-to-know access. Client Data they handle remains subject to the DPA.

6. Your Responsibilities

You agree to:

  • Provide timely access, accurate information, and a designated technical contact.
  • Maintain licenses for software you own; we do not transfer vendor licenses unless contracted.
  • Keep current backups of critical data unless backup is expressly in scope and accepted.
  • Apply our reasonable security recommendations or accept residual risk in writing.
  • Obtain all consents needed for us to access mailboxes, tenants, endpoints, and personal data.
  • Not use the Services for unlawful surveillance, unlicensed pentesting of third parties, or processing of special-category data unless a BAA or similar agreement is in place.
  • Comply with the Acceptable Use Policy.

7. Remote Access, Credentials, and Change Control

You authorize Bitscaled personnel and approved subprocessors to access your environment using credentials, agents, VPNs, or vendor portals you provide or that we deploy under contract. You must revoke access promptly when staff leave. We may refuse unsafe access methods (for example, shared local admin passwords without MFA).

Emergency changes may be made to contain an active incident. We will notify your designated contact as soon as practicable. You remain responsible for business decisions, including whether to pay a ransom, restore from backup, or notify regulators and individuals. Incident-response retainers, ransomware negotiation, and regulator notification on your behalf exist only if an SOW or MSA includes that work.

8. Backups and Disaster Recovery

Backup, immutability, offsite copies, and restore testing exist only to the extent purchased and configured. Website Terms do not create a backup obligation. Even when backup is in scope, restores depend on retention settings, network conditions, encryption keys you control, and the integrity of source data. You should keep an independent copy of irreplaceable records where legally required.

9. VaultTools and Authorized Security Testing

Public tools are offered to help you understand email authentication, DNS/TLS, external exposure, Microsoft 365 posture (guided or optional OAuth), breach listings, ransomware readiness, and BIMI. You may submit only domains, IPs, tenants, and email addresses you are authorized to assess. Unauthorized scanning, spoofing, or credential testing of third-party systems is prohibited and may be reported.

Tool output is a point-in-time technical snapshot, not a pentest, audit, or guarantee that a system is secure. Long footprint scans may run asynchronously. When VaultSandbox is offered, authorized spoof testing is available at spooftest.bitscaled.tech and via the website /tools/email-spoof flow. VaultTools `/api/email-spoof` on the tools gateway returns HTTP 410; spoof testing is not part of the VaultTools API surface.

10. AI Features, Hosted MCP, and Automation

Workspace and Intranet may include AI assistants, article automation, CRM enrichment, and hosted Model Context Protocol (MCP) endpoints. CRM MCP is /api/mcp. Workspace MCP is /api/workspace/mcp and uses company-scoped tokens. Do not send secrets, PHI, or card data into prompts unless the feature is contracted and appropriate safeguards exist.

AI output can be wrong, incomplete, or outdated. You must review it before relying on it for production changes, legal conclusions, or customer communications. We may log prompts and tool calls as described in the Privacy Policy.

11. Fees, Invoices, and PayPal

Fees for Managed Services are set in your MSA, SOW, or invoice. Public pricing pages are estimates. Workspace billing may collect payment through PayPal. PayPal processes card or wallet data under its terms; Bitscaled does not store full payment-card numbers on the website. Late payment may result in suspension after notice. Taxes are extra unless stated.

You authorize us to send invoices and payment reminders to the billing contacts you provide. Chargebacks initiated in bad faith after services were delivered are a material breach.

12. Privacy and Acceptable Use

The Privacy Policy, Cookies Policy, Acceptable Use Policy, and Data Processing Agreement are incorporated by reference. For Client Data we process on your instructions, the DPA (and a signed BAA where HIPAA applies) governs. Website Data is handled as described in the Privacy Policy.

13. Confidentiality

Each party will protect the other's non-public business, technical, and customer information using at least reasonable care, and will use it only to perform under these Terms or a signed contract. Exceptions: information that is public, independently developed, rightfully received from a third party, or required to be disclosed by law (with notice where legally permitted). A signed NDA controls if one exists.

14. Intellectual Property

Bitscaled LLC and its licensors own the websites, software, trademarks, documentation, and pre-existing tools. You retain ownership of Client Data and your pre-existing IP. Unless an SOW assigns deliverables, we grant you a non-exclusive license to use deliverables for your internal business during the service term. We may use anonymized, aggregated operational insights to improve services.

15. Third-Party Products

Microsoft, Google, Vercel, PayPal, SendGrid, and other vendors have their own terms. We are not responsible for third-party outages, license changes, or data handling except as required by our DPA or your MSA. Your use of a vendor tenant remains your contract with that vendor.

16. Disclaimers

EXCEPT AS EXPRESSLY STATED IN A SIGNED CONTRACT, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." WE DISCLAIM ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT SYSTEMS WILL BE ERROR-FREE, UNINTERRUPTED, OR IMMUNE FROM SECURITY INCIDENTS. PUBLIC TOOL RESULTS ARE INFORMATIONAL.

Bitscaled does not claim SOC 2, ISO 27001, or PCI DSS certification on these pages. We describe the controls we actually operate; any formal assurance reports are provided only under a signed MSA or NDA when available. Healthcare, financial, legal, or defense clients must execute the additional agreements required for their sector (including a BAA before PHI is in scope).

17. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, Bitscaled LLC AND ITS PERSONNEL WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, DATA, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY.

EXCEPT FOR LIABILITY THAT CANNOT BE LIMITED (SUCH AS INTENTIONAL MISCONDUCT WHERE PROHIBITED FROM LIMITATION), OUR TOTAL LIABILITY ARISING OUT OF THESE TERMS OR THE WEBSITE AND TOOLS IS LIMITED TO THE GREATER OF (A) AMOUNTS YOU PAID TO BITSCALED FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE TWELVE (12) MONTHS BEFORE THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS (US $100) IF YOU HAVE PAID NOTHING. SIGNED MSAs MAY SET DIFFERENT CAPS FOR MANAGED SERVICES.

18. Indemnification

You will defend and indemnify Bitscaled against third-party claims arising from your unlawful use of the Services, unauthorized testing, Client Data you instruct us to process, or your infringement of third-party rights, except to the extent caused by our willful misconduct.

19. Suspension and Termination

We may suspend access immediately for AUP violations, non-payment, legal risk, or security incidents. Either party may terminate website-only use at any time by stopping use. Managed Services terminate as stated in the MSA/SOW.

When a Managed Services engagement ends, unless the MSA/SOW states otherwise:

  • We will return or delete Client Data we hold as required by the DPA, subject to backup cycles and legal holds.
  • We will remove Bitscaled-deployed RMM agents and revoke Bitscaled-held credentials we no longer need.
  • You remain responsible for your vendor licenses, tenant admin roles, and any access you granted to third parties.
  • You should rotate secrets that Bitscaled personnel used in your environment.

20. Changes

We may update these Terms by posting a new version at https://bitscaled.tech/legal/terms and updating the effective date. Material changes to portal terms may require re-acknowledgment. Continued use of the public website after the effective date constitutes acceptance of the updated Terms for website use.

21. Export Controls and Sanctions

You may not use the Services if you are on a U.S. sanctions list or in an embargoed jurisdiction, or to export encryption or technical data in violation of U.S. law.

22. Force Majeure

Neither party is liable for delay caused by events beyond reasonable control, including hurricanes and other severe weather affecting Florida operations, internet or cloud provider failures, labor disputes, war, terrorism, or government action. Managed Services continuity remains subject to your contracted disaster-recovery scope.

23. Governing Law and Disputes

These Terms are governed by the laws of the State of Florida, excluding conflict-of-law rules. Exclusive venue for disputes that are not subject to a different MSA clause is the state or federal courts in Hillsborough County, Florida. The parties first will attempt good-faith resolution for thirty (30) days. Either party may seek injunctive relief for misuse of IP, confidential information, or security abuse. Jury trial waiver applies to the extent permitted by law. Class, collective, and representative actions are waived to the extent permitted by law.

24. Notices

Legal notices to Bitscaled must be sent to legal@bitscaled.tech and, if you have a mailing requirement, to Bitscaled LLC, Tampa, FL, United States. We may notify you via the site, the portal, or the email on your account. We do not publish a street address on this page; request a mailing address from legal if you need one for formal service of process.

25. Miscellaneous

  • These Terms, plus incorporated policies and any signed contracts, are the entire agreement for the Services they cover.
  • If a provision is unenforceable, the remainder stays in effect.
  • Failure to enforce a provision is not a waiver.
  • You may not assign these Terms without our consent, except to a successor in a merger or sale of substantially all assets with notice.
  • Headings are for convenience only.
  • There are no third-party beneficiaries except Bitscaled personnel entitled to the liability limitations.

26. Contact

Questions: legal@bitscaled.tech or +1 (813) 419-0419. Support: support@bitscaled.tech.

Explore our other legal documents

Related policies that explain how we operate, protect your data, and provide our services transparently.

Essential

Privacy Policy

How we handle website, account, newsletter, VaultTools, and managed-service data.

Read Privacy Policy
Essential

Terms of Service

The rules for using our website, client portal, public tools, and managed services.

Read Terms of Service
Essential

Acceptable Use Policy

What you may and may not do on our website, Client Workspace, public tools, and managed environments.

Read Acceptable Use Policy

Cookies Policy

Named cookies, localStorage consent, and how to change analytics preferences.

Read Cookies Policy
Essential

Data Processing Agreement

Processor terms for Client Data in managed services and hosted Workspace content.

Read Data Processing Agreement

Subprocessors

Vendors that may process Website Data or Client Data, including optional tools.

Read Subprocessors

DMCA Policy

Copyright notices, counter-notices, and designated agent contact.

Read DMCA Policy

Vulnerability Disclosure

How to report security issues in Bitscaled-operated systems in good faith.

Read Vulnerability Disclosure

Security & Compliance

These documents explain how we handle privacy, terms, cookies, data processing, and acceptable use without implying certifications outside the written policies.

Privacy practices documented
Service terms published
Data processing terms available
Cookie preferences supported

Questions About Our Legal Policies?

If you have questions about any of our legal documents or need clarification on our policies, our legal team is here to help.