By accessing or using the Hub — whether through the interactive tool or by receiving, opening, or reviewing a generated PDF report — the Authorized User acknowledges that they have read, understood, and agree to be bound by these terms in their entirety. If the Authorized User does not agree to these terms, they must immediately cease use of the Hub and destroy or delete any copies of reports in their possession.
01About the Platform
SureShield, Inc. ("SureShield") provides the Hub (collectively, the "Platform") to you, the user of the Platform ("Authorized User", "you" or "your"), for your commercial use, and subject to the following Terms. By using the Platform, you enter into and agree to these Terms, and if you are using the Platform on behalf of a legal entity (such as a business or your employer), you represent and warrant that you have sufficient authority to bind such legal entity to these Terms. In that case, "Authorized User", "you" and "your" will also refer to that legal entity. For the purpose of the following Terms, references to "we", "us" and "our" include SureShield, Inc. and its affiliates, subsidiaries, agents, representatives, successors and assigns.
The Platform is a proprietary cyber-risk intelligence service developed and operated by SureShield, Inc., and distributed under the BORDERHAWK brand. The Platform ingests, processes, and presents externally observable cybersecurity signals relating to telecommunications carriers and other entities operating within the United States telecommunications sector. Outputs take the form of (a) an interactive, browser-based report hub that enables users to query, filter, and explore scored data in real time, and (b) downloadable or distributable PDF reports containing pre-generated risk scores, signal inventories, financial impact estimates, and remediation guidance for individual carrier domains.
02Nature and Sources of Data
All data presented in the Platform is derived exclusively from publicly observable, passively collected sources. No system owned, operated, or controlled by any assessed entity was accessed, probed, exploited, or otherwise interacted with in an active or intrusive manner.
Sources include, but are not limited to:
- Publicly disclosed Common Vulnerabilities and Exposures (CVE) records from the National Vulnerability Database (NVD) and the CISA Known Exploited Vulnerabilities (KEV) Catalog;
- Passively observed open-port and service-banner data obtained through internet-wide scanning infrastructure that does not initiate or complete connections beyond what is necessary for service enumeration of public-facing hosts;
- Domain Name System (DNS) records, including SPF, DKIM, and DMARC configurations, publicly resolvable at the time of data collection;
- HTTP and HTTPS response headers and web-layer indicators observable from the public internet;
- Exploit Prediction Scoring System (EPSS) probability scores published by FIRST.org; and
- Publicly available corporate registry data, including entity names, FCC registration information, and financial-size indicators derived from public filings or licensed third-party data aggregators.
SureShield does not conduct penetration testing, red-team exercises, social engineering campaigns, phishing simulations, physical security assessments, or any form of active intrusion testing in connection with the Platform. Nothing in the Platform constitutes or implies active security testing of any kind.
03Platform Outputs Are Not a Security Audit
The Platform is not a substitute for a formal cybersecurity assessment.
Risk scores, band classifications (Minimal, Low, Medium, High, Critical), pillar scores, subdomain inventories, and remediation guidance presented in the Platform are external risk indicators derived from passive data sources. They reflect a subset of the externally observable attack surface and do not represent:
- An assessment of internal network architecture, access controls, endpoint security, personnel security practices, physical security, or governance frameworks;
- A penetration test or ethical-hacking engagement;
- A vulnerability assessment conducted by a qualified security professional with privileged or authorized access to the assessed systems;
- An audit, examination, or certification under any recognized security framework, including but not limited to SOC 2, ISO/IEC 27001, NIST SP 800-53, NIST CSF, FedRAMP, PCI-DSS, HIPAA, or any other regulatory standard; or
- A legal, regulatory, or compliance opinion of any kind.
Authorized Users are strongly encouraged to engage qualified cybersecurity professionals licensed in the relevant jurisdictions to conduct formal evaluations before making material security or procurement decisions. The existence of a score or band in the Platform does not imply that SureShield has conducted, recommends, or endorses any specific remediation action in respect of any specific entity.
04Point-in-Time Limitation
All scores, signals, vulnerability records, port observations, and related data reflect the state of publicly observable infrastructure at the time the underlying data was collected. Cybersecurity posture is dynamic. Scores may change — and may change materially — as a result of remediation actions taken by an assessed entity, changes to the underlying data sources (including CVE status changes, KEV additions or removals, or EPSS score updates), changes in infrastructure configuration, or the passage of time between data collection and any given user's review of the Platform.
SureShield makes no representation, and accepts no obligation, to update scores or signals in real time or within any particular time window following the occurrence of an event that would otherwise affect a score. PDF Reports, once generated, represent a static snapshot as of the date printed on the Report and are not automatically updated after generation.
05Financial Impact Estimates
Where the Platform presents an estimated breach impact figure (expressed in U.S. dollars), annualized breach likelihood percentage, or similar financial or probabilistic metric, such figures are directional indicators only. They are not actuarial opinions, insurance underwriting figures, certified risk quantification outputs, or financial advice of any kind.
The estimated breach impact is computed by applying a risk-scaled multiplier to an industry-average baseline cost per breach derived from published industry research. The actual financial impact of any data breach or cybersecurity incident depends on a wide range of factors that are not observable from external data, including but not limited to the nature and volume of data held by the assessed entity, the entity's incident response capabilities, applicable state and federal notification obligations, regulatory jurisdiction, insurance coverage, litigation exposure, and reputational damage.
The Platform's financial estimates should not be relied upon as a substitute for actuarial analysis, cyber-insurance underwriting, or advice from a qualified financial professional. Modelled breach likelihood percentages are statistical outputs of the Platform's scoring model and do not constitute a prediction, guarantee, or warranty that a breach will or will not occur within any stated period.
06Disclaimer of Warranties
To the maximum extent permitted by applicable law, the Platform, including all scores, reports, data, signals, estimates, and other outputs, is provided "as is" and "as available," without warranty of any kind, express or implied. SureShield and its affiliates, officers, employees, agents, licensors, and service providers (collectively, "SureShield Parties") expressly disclaim all warranties, including:
- Any implied warranty of merchantability, fitness for a particular purpose, or non-infringement;
- Any warranty that the Platform will be accurate, complete, current, reliable, error-free, uninterrupted, or free of viruses or other harmful components;
- Any warranty that defects will be corrected; and
- Any warranty that the Platform or any output will meet the Authorized User's requirements or expectations.
Some jurisdictions do not permit the exclusion of implied warranties. To the extent such exclusions are prohibited by applicable law, the scope and duration of any applicable implied warranty shall be the minimum required by that law.
07Limitation of Liability
To the maximum extent permitted by applicable law, in no event shall the SureShield Parties be liable for any indirect, incidental, special, consequential, punitive, or exemplary damages, or damages for loss of profits, revenue, data, business, goodwill, or anticipated savings, arising out of or in connection with the Platform or its outputs, whether based on contract, tort (including negligence), strict liability, or any other legal theory, even if the SureShield Parties have been advised of the possibility of such damages.
The SureShield Parties' aggregate liability to any Authorized User for all claims arising out of or relating to the Platform shall not exceed the greater of: (a) the amounts paid by that Authorized User's organisation to SureShield under the applicable services agreement in the twelve (12) months preceding the event giving rise to the claim; or (b) one hundred U.S. dollars (USD $100.00).
The limitations in this Section shall apply notwithstanding the failure of any limited remedy of its essential purpose, and shall not apply to liability that cannot be excluded or limited by applicable law (including liability for death or personal injury caused by negligence, or fraud or fraudulent misrepresentation).
08Indemnification
To the full extent permitted under applicable law, each Authorized User agrees to indemnify, defend, and hold harmless SureShield Inc and BorderHawk LLC from and against any claims, liabilities, damages, judgments, awards, losses, costs, expenses, or fees (including reasonable attorneys' fees) arising out of or relating to:
- any violation of these Terms;
- any use of the Sites or its outputs beyond the scope of authorization granted by SureShield;
- any decision made, action taken, or omission made in reliance on the Site's outputs without obtaining independent professional verification where such verification would be prudent; or
- the Authorized User's unauthorized redistribution or disclosure of Sites outputs.
09Confidentiality and Authorized Use
The Platform, including all Reports and scored data generated by it, is provided for the exclusive internal use of authorized personnel within the Authorized User's organization. Access to, and use of, the Platform and any Reports is subject to the following restrictions:
- The Platform and all Reports are confidential and constitute proprietary information of SureShield, Inc.
- Authorized Users may not redistribute, resell, sublicense, publish, transmit, broadcast, or otherwise make available any portion of the Platform or any Report to any third party without prior written consent from SureShield.
- Authorized Users may not use the Platform or any Report to disparage, defame, or make unsupported public statements about any assessed entity.
- Authorized Users may not use the Platform or any Report in any legal or regulatory proceeding without first notifying SureShield and obtaining its written consent, which shall not be unreasonably withheld.
- Authorized Users may not reverse-engineer, decompile, disassemble, or otherwise attempt to derive the source code, scoring algorithms, weighting methodology, or proprietary data models underlying the Platform.
- Any use of Report outputs in sales, marketing, or client-facing materials must be approved in writing by SureShield prior to publication.
Obligations of confidentiality survive termination or expiry of any applicable agreement and any cessation of access to the Platform.
10Third-Party Data and Intellectual Property
The Platform incorporates data from third-party sources, including but not limited to CISA KEV, NVD, EPSS (FIRST.org), and commercial data aggregators. SureShield does not warrant the accuracy, completeness, or timeliness of third-party data and is not responsible for errors or omissions originating in third-party sources. All third-party trademarks, service marks, and trade names referenced in the Platform are the property of their respective owners. Their inclusion does not imply endorsement of or affiliation with SureShield.
All scoring methodologies, proprietary algorithms, weighting models, and Report templates are the intellectual property of SureShield, Inc. and are protected by applicable trade secret, copyright, and other intellectual property laws.
11No Legal, Regulatory, or Compliance Advice
Nothing in the Platform constitutes legal advice, regulatory guidance, or a compliance opinion. Cybersecurity risk scores are not indicators of compliance or non-compliance with any federal, state, local, or international law or regulation, including the Federal Communications Commission (FCC) rules, state public utility commission requirements, NIST guidelines, or sector-specific cybersecurity regulations. Authorized Users should consult qualified legal counsel for advice on regulatory obligations applicable to their specific circumstances.
12Accuracy of Entity Identification and Domain Attribution
Domain names and associated infrastructure included in the Platform are attributed to entities on the basis of public registration data and FCC licensing records. In certain cases domain attribution may be imprecise, particularly where a domain is operated by a third-party managed service provider, hosted on shared infrastructure, or registered to an entity whose legal relationship with the assessed carrier is ambiguous. SureShield disclaims any warranty of accuracy with respect to entity-to-domain attribution and accepts no liability for misattribution of domains, subdomains, or associated signals.
13Governing Law and Dispute Resolution
These terms and any disputes arising from or relating to them or the Platform shall be governed by and construed in accordance with the laws of the State of Georgia, United States of America, without regard to its conflict-of-law provisions. Any dispute not resolved by good-faith negotiation shall be submitted to binding arbitration in Atlanta, GA under the rules of the American Arbitration Association (AAA), except that either party may seek injunctive or other equitable relief in a court of competent jurisdiction to prevent irreparable harm.
14Amendments, Severability & Waiver
SureShield reserves the right to amend these terms at any time. The current version will be presented to Authorized Users prior to accessing the Platform via the interactive acknowledgement gate. Continued use of the Platform following any amendment constitutes acceptance of the amended terms.
If any provision of these terms is held to be invalid, illegal, or unenforceable under applicable law, the remaining provisions shall continue in full force and effect. Any failure by SureShield to enforce any provision shall not constitute a waiver of SureShield's right to enforce that or any other provision in the future.
15User Acknowledgement
By accessing or using the Hub — whether through the interactive tool or by receiving, opening, or reviewing a generated PDF report — the Authorized User acknowledges that they have read, understood, and agree to be bound by these terms in their entirety. If the Authorized User does not agree to these terms, they must immediately cease use of the Hub and destroy or delete any copies of Reports in their possession.
Questions on these notices?
Contact the SureShield team for clarification on scope, licensing, or any of the items above.