·LEGAL
Terms & Conditions.
Version 01.01 · As of: 2026-03-01 · Applicable to all services of GermanAI Defense GmbH. Translation provided for reference only. The German version is legally binding.
A. General provisions
I. Scope
- These terms and conditions (T&C) apply to all offers, services, and contracts of GermanAI Defense GmbH (hereinafter “Provider”).
- The T&C apply in particular to the following services:
- Penetration testing
- Security Operations Center (SOC) services
- IT-security and ISMS consulting
- Data-protection consulting
- AI-based security analyses
- These terms apply exclusively to entrepreneurs within the meaning of § 310 (1) BGB.
- Conflicting or deviating terms of the customer are not accepted.
II. Contract content
- Offers are subject to confirmation and non-binding.
- A contract is concluded only through written confirmation.
- The scope of services is determined exclusively by:
- the offer
- the statement of work
- the order confirmation
III. Performance of services
- Services are provided according to the state of the art and on a “best effort” basis.
- Complete security of IT systems cannot be guaranteed.
- The Provider is entitled to use third parties (e.g., freelancers) to perform the services.
- AI is used in a supporting capacity. Results may be incomplete or incorrect.
IV. Customer cooperation obligations
- The customer provides all required information, systems, and access.
- The customer designates a contact person with decision-making authority.
- The customer is responsible for regular data backups.
- Delays due to missing cooperation are not the Provider’s responsibility.
V. Prices and remuneration
- All prices are net plus statutory VAT.
- Invoices are payable within 14 days.
- In case of default, the statutory provisions apply (§ 288 BGB).
- Services on a time-and-materials basis are billed monthly.
VI. Special provisions for security services
1. Penetration testing
- Tests may cause system impairments.
- The customer expressly agrees to this.
- Tests are performed exclusively within the agreed scope.
2. SOC services
- There is no guarantee that all attacks will be detected.
- Analysis is based on the available data and systems.
3. AI-based analyses
- AI may produce erroneous results.
- Decisions must not be made on an exclusively automated basis.
VII. Availability
- Continuous availability is not guaranteed.
- Maintenance and technical disruptions may occur.
VIII. Liability
- The Provider is liable without limitation in cases of intent and gross negligence, and for damages to life, body, or health.
- In cases of slight negligence, the Provider is only liable for breaches of essential contractual obligations (cardinal obligations).
- Liability is limited to typical and foreseeable damages.
- Maximum liability is, to the extent permitted by law, capped at the amount of the contractually agreed remuneration.
- Liability for
- lost profits,
- indirect damages,
- consequential damages
- There is no liability for whether
- security vulnerabilities are fully identified,
- attacks are prevented.
- The Provider is not liable for damages caused by inadequate customer data backups.
IX. Data protection
- Processing of personal data takes place in accordance with the GDPR.
- Where necessary, a data-processing agreement (DPA) will be concluded.
X. Confidentiality
- Both parties undertake to maintain confidentiality.
- This also applies after termination of the contract.
XI. Term and termination
- The contract term is set out in the respective contract.
- Unless otherwise agreed, the notice period is 30 days.
- The right to extraordinary termination remains unaffected.
XII. Final provisions
- German law applies.
- Place of jurisdiction is the Provider’s registered seat.
- Should individual provisions be invalid, the remainder of the contract remains effective.
Version 01.01 · public · Date: 2026-03-01
Annex 1. Penetration Testing Services
Annex to the T&C of GermanAI Defense GmbH
1. Subject
- This annex governs the performance of penetration tests by GermanAI Defense GmbH (hereinafter “Provider”).
- The specific scope of the tests is defined in the respective offer or statement of work.
2. Authorization
- The customer confirms that they
- are the owner of the systems to be tested, or
- are expressly authorized to perform the tests.
- The customer expressly grants the Provider permission to actively test the agreed systems.
- This permission includes in particular
- the targeted exploitation of security vulnerabilities,
- the simulation of attacks,
- conducting technical security analyses.
3. Scope of tests
- The Provider performs tests exclusively within the agreed scope.
- Systems outside the scope are not tested.
- Changes to the scope require written agreement.
4. Type of tests
- Penetration tests may involve active interventions in systems.
- Depending on the agreement, the following test types may be performed:
- Blackbox
- Greybox
- Whitebox
- The Provider is entitled to use both automated and manual testing procedures.
5. Risks and side effects
- The customer is aware that penetration tests may lead to the following effects:
- System outages
- Performance degradation
- Data loss or data alterations
- Service interruptions
- The customer expressly accepts these risks.
- The Provider takes measures to minimize risks but cannot fully exclude them.
6. Customer cooperation obligations
The customer commits in particular to:
- Ensuring backups before tests begin
- Providing points of contact
- Informing the Provider about critical systems
- Defining testing windows (e.g., outside business hours)
7. Liability disclaimer / limitation
- The Provider is not liable for damages resulting from agreed and authorized testing activities, unless they are based on intent or gross negligence.
- In particular, there is no liability for
- system outages,
- business interruptions,
- data losses,
- consequential damages.
- The customer acknowledges that the targeted exploitation of vulnerabilities is part of the test.
8. Test period
- The test is performed within the agreed period.
- The Provider is entitled to perform tests outside regular business hours, if so agreed.
9. Documentation and reporting
- After the test concludes, the customer receives a report with
- identified vulnerabilities,
- risk assessment,
- action recommendations.
- The report is intended exclusively for internal security purposes.
10. Confidentiality
- All information obtained during the test is treated confidentially.
- Disclosure to third parties only takes place with the customer’s consent or based on legal obligations.
11. Responsible Disclosure
- The Provider undertakes to report discovered vulnerabilities exclusively to the customer.
- Publication only occurs after prior written consent from the customer.
12. Final provisions
- This annex is part of the T&C of GermanAI Defense GmbH.
- In case of conflicts, the provisions of this annex take precedence over the general T&C.
Version 01.01 · public · Date: 2026-03-01