
TERMS OF ENGAGEMENT
PRAECEPTA CYBERSECURITY LLC — TERMS OF ENGAGEMENT
Version 1.0 · August 2026
1. About us
PRAECEPTA CYBERSECURITY LLC, a company registered in Dubai, UAE. Registered address Sail Star Business Center, Bay Square, Business Bay, Dubai, UAE.
2. Website terms
2.1 Content is general information
Content published on praecepta.co — including articles, research, framework mappings, reference architectures and other resources — is provided for general information.
It constitutes security architecture guidance. It is not legal, regulatory, tax, insurance, actuarial or financial advice, and it is not a substitute for professional advice on your specific circumstances. Engage qualified legal counsel for binding interpretation of any regulatory obligation.
2.2 No engagement is created
Accessing this site, downloading a resource or subscribing to our communications does not create a professional relationship between us. A professional relationship arises only under a signed engagement agreement.
2.3 Framework and regulatory content
Our published material references cybersecurity and data protection frameworks and regulations. These are revised by their issuing bodies without notice. Figures and structural descriptions are accurate as at the version date shown on each document.
You must verify the current issue of any framework or regulation against its issuing body before relying on our material for an assessment, a regulatory submission, or any decision. Framework applicability is jurisdiction-specific and entity-specific.
2.4 Use of our published resources
Our ungated resources may be downloaded, used internally, and shared unaltered with attribution. They may not be resold, rebranded, presented as your own work, or incorporated into a commercial product or service offering without our written permission.
Where you wish to use our material in a client-facing proposal or bid library, you may — with attribution. Please tell us; we generally welcome it.
2.5 Intellectual property
All content on praecepta.co, and all methodologies, frameworks, assessment instruments, templates, reference architectures and crosswalks we publish, remain the intellectual property of PRAECEPTA CYBERSECURITY LLC.
Third-party framework and standard names are the property of their respective owners. Our references to them do not imply endorsement by, or affiliation with, those bodies.
2.6 Third-party links
We may link to third-party sites. We do not control them and are not responsible for their content or practices.
3. Engagement principles
The following apply to our professional engagements. They are subject in all respects to the signed MSA and SOW, which prevail.
3.1 Scope and deliverables
Every engagement is defined in a Statement of Work specifying deliverables, acceptance criteria, assumptions, exclusions and change control. Work outside the agreed scope requires written change control.
3.2 Advisory nature of our work
Our deliverable is advice, analysis and design. Decisions on whether and how to implement, and the consequences of those decisions, are yours.
We do not guarantee that following our advice will prevent a security incident, achieve regulatory compliance, or satisfy any third party including a regulator, auditor or insurer. No such guarantee is possible in this field, and any consultancy offering one should be treated with caution.
3.3 What we do not do
We do not provide penetration testing, managed detection and response, security operations, or implementation engineering. Where an engagement identifies a need for these, we will say so and refer.
We do not provide legal advice. Where an engagement raises questions of legal interpretation — including whether a regulation applies to you, or whether a data transfer is lawful — we will identify the question and recommend you obtain counsel's opinion.
3.4 Reliance on client information
Our advice relies on information provided by you and on what is observable within the agreed scope. We do not independently verify client-provided information unless verification is an express deliverable.
Where information is withheld, inaccurate or incomplete, our conclusions may be affected. Where our access is restricted, we will state the limitation in the deliverable.
3.5 Declared interests and product recommendations
PRAECEPTA holds declared technology partnerships. Our full Declaration of Interests is published at praecepta.co/declaration-of-interests and is provided in writing before any engagement in which a product recommendation may arise.
Our advisory fees carry no product economics. They are unaffected by what you subsequently procure, including if you procure nothing.
Where you require a competitive selection conducted by an advisor with no commercial interest in any candidate, we will tell you that PRAECEPTA does not meet that requirement, refer you to alternatives, and where you wish, deliver the surrounding architecture work with the selection excluded.
3.6 Intellectual property in engagements
PRAECEPTA Background IP — our methodologies, frameworks, assessment instruments, templates, reference architectures, crosswalks and know-how, including any developed or improved during an engagement — remains ours. You receive a non-exclusive, non-transferable licence to use the deliverable for your internal business purposes.
Client Foreground IP — the specific deliverable produced for you, and your own information within it — is yours on payment in full.
You do not acquire the right to reuse our instruments, templates or methodologies on other engagements, or to provide them to third parties, without our written permission.
​
3.7 Confidentiality
We treat client information as confidential and disclose it only to those who need it to deliver the engagement, under equivalent obligations.
Our confidentiality obligations to clients override any other commercial interest, including participation in expert networks, vendor relationships, published research and marketing. We do not discuss identifiable client environments, security postures or incidents in any external forum.
We may refer to an engagement in anonymised terms — for example, "a UAE financial institution" — unless you tell us not to. We do not name clients or use client logos without documented written consent.
3.8 Data protection in engagements
Where we process personal data on your behalf we act as processor and you as controller. A Data Processing Addendum forms part of the engagement agreement.
We ask clients to minimise personal data provided to us. Where evidence can be provided in redacted or anonymised form, we prefer it.
3.9 Fees, invoicing and payment
Fees are as set out in the Commercial Schedule. Unless stated otherwise, fees exclude VAT, travel and disbursements.
Invoices are payable within 30 days. We reserve the right to charge interest on overdue amounts and to suspend work where invoices remain unpaid.
Cross-border engagements. Where withholding tax applies to payments to PRAECEPTA, the engagement agreement will address gross-up and treaty relief.
3.10 Liability
Intended position:
​
-
Total liability capped at the fees paid under the relevant SOW, or a fixed sum, whichever counsel advises is enforceable
-
Exclusion of indirect, consequential, special and punitive loss, loss of profit, loss of business, loss of data and loss of goodwill
-
No exclusion of liability that cannot lawfully be excluded, including for death, personal injury or fraud
-
Liability apportioned where loss arises from client decisions, client-provided information, or third-party implementation
Uncapped liability is not commercially viable for a specialist practice of our size and we do not accept it. Where a client requires a higher cap, we will discuss it — it is a pricing and insurance question, not a matter of principle.
3.11 Professional indemnity insurance
We maintain professional indemnity, general liability and cyber liability cover. Certificates are available on request.
3.12 Subcontracting and associates
We may engage associates or subcontractors on specific engagements. We remain responsible for the work. Associates are bound by equivalent confidentiality and data protection obligations. Where a client's agreement requires prior approval of subcontractors, we will obtain it.
3.13 Channel engagements
Where we deliver as a subcontractor to a consultancy, systems integrator, MSSP or distributor, our Channel Charter applies in addition to these terms. It covers named-account protection, mutual non-solicitation, deal registration precedence, and white-label delivery discipline. It is provided at the outset of any channel relationship.
3.14 Termination
Either party may terminate an engagement at least 30 days written notice. On termination, fees for work performed and committed disbursements remain payable. Provisions on confidentiality, IP and liability survive.
3.15 Governing law and jurisdiction
All matters relating to the Website and these Terms & Conditions, and any dispute or claim arising therefrom or related thereto in each case, including non-contractual disputes or claims, shall be governed by and construed in accordance with the internal laws of the United Arab Emirates without giving effect to any choice or conflict of law provision or rule whether of the United Arab Emirates or any other jurisdiction.
In any legal suit, action, or proceeding arising out of, or related to, these Terms & Conditions or the Website, you agree to submit to the exclusive jurisdiction of, the state and federal courts sitting in, United Arab Emirates, and waive any jurisdictional, revenue, or inconvenient forum objections to such courts although we retain the right to bring any suit, action, or proceeding against you for breach of these Terms & Conditions in your country of residence or any other relevant country. You waive any and all objections to the exercise of jurisdiction over you by such courts and to venue in such courts.
4. Changes to these terms
We may update these terms. The version and date appear above. Changes do not affect signed engagement agreements.
5. Contact
PRAECEPTA CYBERSECURITY LLC · Sail Star Business Center, Bay Square, Business Bay, Dubai, UAE
ops@praecepta.ae · praecepta.co
