LEGAL / TERMS

Terms & Conditions

Effective September 22, 2026

Website information is general and does not create an advisory relationship. Paid work begins only under a confirmed written scope or agreement.

Agreement

These Terms & Conditions govern use of the Cobalt Risk Advisory LLC website. Advisory services are also governed by the applicable proposal, statement of work, master services agreement, or other written engagement terms. If engagement-specific terms conflict with these website terms, the signed engagement terms control for that work.

Advisory scope

Cobalt provides technical cybersecurity and compliance advisory within the agreed scope. Unless expressly stated in a signed agreement, Cobalt does not provide independent audits or certifications, legal advice, insurance brokerage or underwriting, custodial services, penetration testing, managed security monitoring, or emergency incident response.

References to SOC 2, ISO 27001, GDPR, CCPA, HIPAA, Vanta, Drata, AWS, Azure, Google Cloud, or other frameworks and platforms describe potential client environments and advisory subject matter. They do not imply endorsement, partnership, certification, legal conclusions, or authority to issue an audit opinion.

Client responsibilities and authorization

Clients are responsible for accurate information, authorized access, appropriate backups, qualified internal decision makers, timely review, and implementation choices. You must not provide access or materials you are not authorized to share. Credentials and authentication secrets should never be sent through the public website.

Third-party systems

Recommendations may involve products or services controlled by third parties. Cobalt does not control their availability, security, pricing, licensing, data handling, terms, or decisions. Clients remain responsible for evaluating and contracting with third-party providers.

Fees, expenses, and scheduling

Fees, payment timing, deliverables, assumptions, and approved expenses are stated in the applicable written scope. Changes may require a written change order. Cancellation and refund treatment is described in the Engagement Cancellation Policy and any signed agreement.

Confidentiality and intellectual property

Confidentiality obligations and ownership of engagement deliverables are governed by the applicable written agreement. Website content and Cobalt’s pre-existing methods, templates, branding, and know-how remain the property of Cobalt or its licensors. Client data remains the client’s property.

No guaranteed outcome

Cybersecurity and compliance outcomes depend on implementation, changing threats, operations, third parties, applicable law, and independent reviewer decisions. Cobalt does not guarantee certification, audit results, regulatory compliance, uninterrupted systems, elimination of vulnerabilities, or prevention of incidents.

Disclaimer and limitation of liability

To the extent permitted by law, the website is provided “as available” without warranties of accuracy, completeness, merchantability, fitness for a particular purpose, or noninfringement. Cobalt will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages arising from website use. Liability for paid services is governed by the signed engagement agreement.

Governing law and contact

These website terms are governed by the laws of the Commonwealth of Kentucky, without regard to conflict-of-law principles. Questions may be sent to direct@cobaltriskadvisory.com or mailed to Cobalt Risk Advisory LLC, 1616 Auburn Dr, Lexington, KY 40505.