SecBaseline

Terms of Service

Terms governing use of the SecBaseline security and compliance suite.

Effective date
August 22, 2026
Operated by
Cyber Security Tech Solutions
Important

SecBaseline is an explanatory, conversion, drafting, mapping, and remediation-planning aid. It is not a substitute for authoritative standards, qualified professional judgment, formal assessment, certification, accreditation, legal advice, or an authorization decision.

Covered SecBaseline services

This document applies to the SecBaseline suite and the following websites and subdomains, together with related pages, APIs, authentication flows, and features that link to this document:

  • secbaseline.com
  • stig.secbaseline.com
  • cis.secbaseline.com
  • oscal.secbaseline.com
  • ssp.secbaseline.com
  • crosswalk.secbaseline.com

It also applies to future SecBaseline tools hosted under secbaseline.com unless a different policy or agreement is presented for that tool.

01

Agreement to these Terms

These Terms of Service ("Terms") are a binding agreement between you and Cyber Security Tech Solutions, the operator of SecBaseline ("Company", "we", "us", or "our"). They govern your access to and use of SecBaseline, including the websites, applications, features, APIs, accounts, exports, documentation, and related services that link to these Terms.

By accessing or using SecBaseline, creating an account, submitting content, or clicking an acceptance control presented with these Terms, you agree to be bound by them. If you use SecBaseline on behalf of an organization, you represent that you have authority to bind that organization, and "you" includes that organization.

If you do not agree to these Terms, do not use SecBaseline.

02

Eligibility

You must be at least 18 years old and legally capable of entering into a binding agreement to use SecBaseline. If the law where you live sets a higher age of majority for contracting, you must meet that age.

03

What SecBaseline provides

SecBaseline provides tools intended to help users understand and work with cybersecurity baselines, hardening guidance, control mappings, scan findings, compliance artifacts, machine-readable OSCAL content, and System Security Plan materials.

  • STIG Explainer may parse or explain DISA STIG findings, map findings through CCI to NIST 800-53, prioritize findings, and provide remediation-planning information.
  • CIS Benchmark Explainer may explain CIS Benchmark recommendations, describe potential operational impact, organize findings, and support mapping or prioritization.
  • OSCAL Bridge may convert, validate, render, or explain OSCAL-related content and may use deterministic schema validation and AI-assisted interpretation.
  • SSP Studio may assist with FIPS 199 categorization, baseline selection, control implementation narratives, and export of System Security Plan or OSCAL-related content.
  • STIG to CIS Crosswalk may compare controls and classify relationships using published or derived mappings and deterministic control-set logic.
  • Additional SecBaseline tools and features may be added, changed, placed in preview, or discontinued over time.
04

Educational and professional-use disclaimer

SecBaseline is a decision-support and productivity tool. It does not replace official standards, benchmark publications, governing contracts, statutes, regulations, agency instructions, program-specific guidance, assessors, authorizing officials, legal counsel, or qualified cybersecurity professionals.

Without limitation, SecBaseline does not provide or constitute:

  • A security assessment, penetration test, certification, accreditation, attestation, audit opinion, or compliance determination.
  • A CMMC certification assessment, C3PAO assessment, FedRAMP authorization, Authority to Operate, Authority to Connect, or similar government or third-party authorization.
  • A guarantee that a system is secure, compliant, hardened, eligible for a contract, or protected against compromise.
  • Legal, regulatory, accounting, procurement, insurance, export-control, or contracting advice.
  • An authoritative replacement for current DISA STIGs, CIS Benchmarks, NIST publications or schemas, DoD guidance, or any program-specific system of record.
05

No affiliation or endorsement

SecBaseline and Cyber Security Tech Solutions are not affiliated with, sponsored by, endorsed by, or acting on behalf of the Defense Information Systems Agency, the United States Department of Defense, the National Institute of Standards and Technology, the Center for Internet Security, or any other standards body, government agency, assessor, or accrediting organization unless expressly stated in writing.

References to third-party names, standards, controls, marks, publications, schemas, or frameworks are for identification, interoperability, commentary, education, or mapping purposes.

06

Your responsibility for authoritative sources and validation

You are solely responsible for verifying SecBaseline output against the authoritative, current version of the applicable standard, benchmark, schema, contractual requirement, agency instruction, or other governing source before relying on it.

Standards, mappings, schemas, security guidance, and program requirements change. SecBaseline may not immediately reflect every revision, erratum, interpretation, profile, overlay, implementation note, or program-specific requirement.

07

Remediation and production-system risk

Security hardening changes can disrupt authentication, networking, services, workloads, applications, logging, compatibility, availability, or business operations. You are responsible for evaluating the effect of any suggested remediation in your environment.

Before applying a change to a production system, you should independently review the change, confirm it against the authoritative requirement, test it in a non-production environment where practical, maintain appropriate backups and recovery procedures, and follow your organization's change-management process.

You assume all risk arising from implementation of remediation steps, commands, scripts, configuration changes, policy changes, or other technical actions derived from SecBaseline output.

08

AI-assisted features

Some SecBaseline features use generative or other artificial intelligence to explain, summarize, organize, classify, or draft content. AI output can be inaccurate, incomplete, outdated, ambiguous, or unsuitable for your environment. A confident-sounding response is not evidence of correctness.

You must independently review AI-assisted output before using it for security changes, compliance evidence, an SSP, a POA&M, an assessment, an audit response, a contractual representation, a submission to a government system, or any decision that could materially affect security, operations, eligibility, legal obligations, or third-party rights.

09

OSCAL, SSP, mapping, and compliance-output limitations

  • Schema-valid does not mean program-valid. An OSCAL artifact can pass schema validation and still be incomplete, inconsistent, inaccurate, or unacceptable to an assessor, authorizing program, customer, or agency.
  • Machine-readable conversion does not establish the truth of the underlying facts. You are responsible for verifying source content and generated fields.
  • An SSP generated or drafted with SecBaseline is not an Authority to Operate and is not automatically acceptable to eMASS, Xacta, FedRAMP, a C3PAO, a prime contractor, an agency, or any other reviewing party.
  • Control mappings and crosswalks are aids. Shared mappings do not prove that two requirements are technically, legally, or operationally equivalent.
  • FIPS 199 categorization, baseline selection, scoring, prioritization, or similar calculations depend on the accuracy and completeness of the information you provide and may require program-specific judgment.
10

Accounts and account security

Some SecBaseline features may require an account. You are responsible for maintaining the confidentiality of your authentication credentials, restricting access to your account, and promptly notifying us if you suspect unauthorized access.

You may not share credentials in a manner that defeats account controls, impersonate another person or organization, or use another user's account without authorization.

We may suspend or restrict access when reasonably necessary to protect SecBaseline, users, data, or third parties, investigate suspected misuse, comply with law, or address a material breach of these Terms.

11

User content and ownership

As between you and Cyber Security Tech Solutions, you retain your ownership rights in content you submit to SecBaseline, subject to any rights held by third parties in that content.

You grant Cyber Security Tech Solutions a limited, non-exclusive, worldwide license to host, copy, transmit, transform, analyze, display, and otherwise process your content only as reasonably necessary to provide, secure, support, maintain, and improve the SecBaseline service, comply with law, and enforce these Terms.

This license ends when the content is deleted from active systems, except to the extent limited copies remain temporarily in backups, logs, legal records, or security records, or retention is otherwise required by law.

12

Your content responsibilities

You represent and warrant that:

  • You have all rights, permissions, licenses, and authority necessary to submit and process your content through SecBaseline.
  • Your use of SecBaseline and your content will not violate law, contractual restrictions, confidentiality obligations, export controls, privacy rights, intellectual-property rights, or other third-party rights.
  • You will not submit content that you are prohibited from transmitting to an Internet-based service.
  • You will not use SecBaseline as the sole repository or backup for information you cannot afford to lose.
13

Restricted and sensitive information

Unless a particular SecBaseline feature is expressly designated in writing by Cyber Security Tech Solutions as approved for a specific data type, you must not submit classified information, CUI, ITAR-controlled or other export-controlled technical data, protected health information, full payment-card data, Social Security numbers, live passwords, private keys, tokens, credentials, or other highly sensitive regulated information.

You are responsible for sanitizing logs, scan results, system descriptions, SSP material, screenshots, configuration data, and other content before submission.

14

CIS Benchmark and third-party licensing

CIS Benchmark content is subject to rights and licensing terms established by the Center for Internet Security. SecBaseline does not grant you a license to CIS Benchmark content. You must obtain and use CIS Benchmark content under terms that authorize your possession, submission, analysis, and use.

Other third-party standards, publications, tools, schemas, and content may also be subject to their own licenses or terms. You are responsible for complying with those terms.

15

Acceptable use

You may not use SecBaseline to:

  • Violate any law, regulation, court order, contractual restriction, or third-party right.
  • Gain unauthorized access to systems, accounts, networks, data, or services.
  • Develop, deploy, or facilitate malware, destructive code, credential theft, denial-of-service activity, or other malicious activity.
  • Probe, scan, test, or attack SecBaseline or its infrastructure except through a written security-testing authorization from Cyber Security Tech Solutions or a published vulnerability-disclosure program that expressly permits the activity.
  • Circumvent access controls, rate limits, security controls, feature restrictions, or technical limitations.
  • Interfere with the service or impose an unreasonable or disproportionately large load on SecBaseline.
  • Scrape, crawl, bulk-download, mirror, or systematically extract SecBaseline content or data in a way that exceeds normal human use or an authorized API.
  • Reverse engineer, decompile, or attempt to discover non-public source code, models, prompts, security mechanisms, or trade secrets except to the limited extent such restriction is prohibited by applicable law.
  • Misrepresent SecBaseline output as an official statement, government determination, third-party certification, or assessor conclusion.
  • Use SecBaseline output to create materially deceptive compliance evidence or to conceal a known security or compliance deficiency.
16

Intellectual property

SecBaseline, including its original software, site design, interfaces, branding, documentation, explanatory material, original mappings, compilations, and other original content, is owned by Cyber Security Tech Solutions or its licensors and is protected by applicable intellectual-property laws.

These Terms give you a limited, revocable, non-exclusive, non-transferable right to use SecBaseline for its intended purpose. No ownership right is transferred to you.

Third-party standards, marks, publications, and benchmark content remain the property of their respective owners.

17

Feedback

If you provide suggestions, ideas, bug reports, or other feedback about SecBaseline, you grant Cyber Security Tech Solutions a perpetual, irrevocable, worldwide, royalty-free right to use that feedback to improve, modify, market, and operate our products and services without obligation to compensate you. This section does not transfer ownership of your private user content.

18

Privacy

Our SecBaseline Privacy Policy explains how we collect, use, disclose, retain, and protect personal information. By using SecBaseline, you acknowledge the practices described in that Privacy Policy.

19

Free services, paid features, and changes

SecBaseline may offer free features, paid features, preview features, usage limits, or separate service tiers. We may add, modify, suspend, limit, or discontinue features when reasonably necessary for security, legal, operational, maintenance, product, or business reasons.

If a paid SecBaseline offering is introduced, applicable pricing, billing terms, taxes, renewal terms, and cancellation rights will be presented before purchase or in a separate order form. Unless a separate written agreement states otherwise, these Terms will continue to govern use of the service.

20

Third-party services and links

SecBaseline may link to, depend on, or interoperate with third-party services, standards repositories, authentication providers, hosting providers, AI providers, or other external resources. We do not control third-party services and are not responsible for their availability, security, content, accuracy, privacy practices, or terms.

21

Beta, preview, and experimental features

Features identified as beta, preview, experimental, in development, early access, or similar may be incomplete, unstable, changed without notice, or removed. You use those features at your own risk and should not rely on them for production-critical or compliance-critical workflows without independent validation.

22

Service availability and data loss

We work to keep SecBaseline available and secure, but we do not guarantee uninterrupted or error-free operation. Maintenance, security events, provider outages, Internet failures, software defects, abuse-prevention measures, and other events may interrupt access.

You are responsible for maintaining independent copies of important source data, compliance evidence, SSP content, mappings, exports, and other materials. Do not use SecBaseline as your sole system of record or sole backup unless a separate written agreement expressly provides otherwise.

23

Disclaimer of warranties

TO THE MAXIMUM EXTENT PERMITTED BY LAW, SECBASELINE AND ALL CONTENT, OUTPUT, FEATURES, DOCUMENTATION, MAPPINGS, CONVERSIONS, VALIDATIONS, EXPLANATIONS, REMEDIATION GUIDANCE, AND SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE".

CYBER SECURITY TECH SOLUTIONS DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, SECURITY, AVAILABILITY, COMPLIANCE, AND RESULTS.

WE DO NOT WARRANT THAT SECBASELINE WILL IDENTIFY EVERY SECURITY ISSUE, PRODUCE AN ACCEPTABLE COMPLIANCE ARTIFACT, PREVENT A BREACH, SATISFY AN ASSESSOR OR CUSTOMER, QUALIFY YOU FOR A CONTRACT, OR MEET EVERY PROGRAM-SPECIFIC REQUIREMENT.

24

Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, CYBER SECURITY TECH SOLUTIONS, ITS OWNER, AFFILIATES, LICENSORS, SERVICE PROVIDERS, CONTRACTORS, REPRESENTATIVES, AND AGENTS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, BUSINESS, CONTRACTS, OPPORTUNITY, GOODWILL, DATA, SYSTEM AVAILABILITY, SECURITY, COMPLIANCE STATUS, OR PROCUREMENT ELIGIBILITY, ARISING OUT OF OR RELATED TO SECBASELINE.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF CYBER SECURITY TECH SOLUTIONS AND THE OTHER RELEASED PARTIES FOR ALL CLAIMS ARISING OUT OF OR RELATED TO SECBASELINE OR THESE TERMS WILL NOT EXCEED THE GREATER OF: (A) THE AMOUNT YOU PAID DIRECTLY TO CYBER SECURITY TECH SOLUTIONS FOR THE SECBASELINE SERVICE GIVING RISE TO THE CLAIM DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY; OR (B) ONE HUNDRED U.S. DOLLARS (US $100).

THE LIMITATIONS IN THIS SECTION APPLY REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF A PARTY WAS ADVISED THAT DAMAGES WERE POSSIBLE. SOME JURISDICTIONS DO NOT ALLOW CERTAIN LIMITATIONS, SO SOME OF THESE LIMITATIONS MAY NOT APPLY TO YOU.

25

Indemnification

To the maximum extent permitted by law, you agree to defend, indemnify, and hold harmless Cyber Security Tech Solutions, its owner, affiliates, licensors, service providers, contractors, representatives, and agents from and against claims, demands, investigations, damages, losses, liabilities, judgments, settlements, penalties, costs, and reasonable attorneys' fees arising out of or related to:

  • Your use or misuse of SecBaseline.
  • Your content or your submission of content to SecBaseline.
  • Your implementation of remediation, configuration, hardening, mapping, or compliance actions based on SecBaseline output.
  • Your violation of these Terms, applicable law, contractual obligations, or third-party rights.
  • Your representation or submission of SecBaseline output to an assessor, auditor, customer, prime contractor, government agency, authorizing official, or other third party.

We may assume control of the defense of a matter subject to indemnification, and you agree to cooperate reasonably with that defense.

26

Suspension and termination

You may stop using SecBaseline at any time. If account functionality is available, you may request account deletion subject to our Privacy Policy and applicable law.

We may suspend, restrict, or terminate your access if we reasonably believe you violated these Terms, created a security or legal risk, misused the service, failed to pay an applicable charge, or if suspension is reasonably necessary to protect users, systems, data, or third parties.

Provisions that by their nature should survive termination will survive, including provisions concerning ownership, licenses needed for retained records, disclaimers, liability limits, indemnification, dispute resolution, and general legal terms.

27

Governing law

These Terms and any dispute arising out of or related to them or SecBaseline are governed by the laws of the State of Rhode Island, without regard to conflict-of-law rules, except to the extent applicable federal law controls.

28

Informal dispute resolution

Before filing a lawsuit or arbitration, you and Cyber Security Tech Solutions agree to make a good-faith effort to resolve the dispute informally for at least 30 days. To begin informal resolution, send a written notice describing the dispute and requested relief to info@cybersecuritytechsolutions.com. This requirement does not prevent either party from seeking urgent injunctive relief when necessary to prevent unauthorized access, misuse, infringement, disclosure of confidential information, or other imminent harm.

29

Binding arbitration and class-action waiver

PLEASE READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS.

Except for disputes that qualify for small-claims court and requests for temporary or preliminary injunctive relief concerning unauthorized access, misuse, intellectual property, or confidential information, any dispute arising out of or relating to these Terms or SecBaseline that is not resolved through the informal process above will be resolved by binding individual arbitration rather than in court.

The arbitration will be administered by the American Arbitration Association under its applicable Consumer Arbitration Rules or Commercial Arbitration Rules, as appropriate to the dispute and the parties. The Federal Arbitration Act governs the interpretation and enforcement of this arbitration provision.

ARBITRATION WILL TAKE PLACE ONLY ON AN INDIVIDUAL BASIS. TO THE MAXIMUM EXTENT PERMITTED BY LAW, YOU AND CYBER SECURITY TECH SOLUTIONS WAIVE ANY RIGHT TO A JURY TRIAL AND ANY RIGHT TO PARTICIPATE IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION OR ARBITRATION.

You may opt out of this arbitration provision by sending an email to info@cybersecuritytechsolutions.com within 30 days after you first accept these Terms. Your opt-out notice must state your name, the email address associated with your SecBaseline account if any, and that you are opting out of the SecBaseline arbitration provision. Opting out of arbitration does not opt you out of the rest of these Terms.

30

Venue for disputes not subject to arbitration

For any dispute that is not subject to arbitration, you and Cyber Security Tech Solutions consent to the exclusive jurisdiction and venue of the state and federal courts located in Rhode Island, except where applicable law does not permit that choice.

31

Export controls and sanctions

You may not use, export, re-export, transfer, or provide SecBaseline in violation of United States export-control or sanctions laws. You represent that you are not prohibited from receiving the service under applicable sanctions or export restrictions.

SecBaseline is not an export-control classification service. You are responsible for determining whether your systems, data, technical information, or use are subject to export restrictions.

32

Government users

Unless a separate written agreement with Cyber Security Tech Solutions expressly states otherwise, SecBaseline is offered under the same commercial terms to government and non-government users. Use of SecBaseline does not create a government contract, authorization, endorsement, security accreditation, or representation that the service meets a particular government hosting or handling requirement.

33

Changes to these Terms

We may update these Terms to reflect changes to SecBaseline, law, security practices, or business operations. The effective date at the top identifies the current version. If a change materially affects your rights, we will provide notice as required by applicable law. Your continued use after updated Terms become effective constitutes acceptance where permitted by law.

34

General terms

  • Entire agreement. These Terms and the SecBaseline Privacy Policy are the entire agreement between you and Cyber Security Tech Solutions concerning the public SecBaseline service unless a separate written agreement expressly controls.
  • Order of precedence. If you have a separate written agreement signed by Cyber Security Tech Solutions that expressly governs a SecBaseline service, that agreement controls to the extent of a direct conflict.
  • Severability. If any provision is held unenforceable, it will be enforced to the maximum lawful extent and the remaining provisions will remain in effect.
  • No waiver. Failure to enforce a provision is not a waiver of the right to enforce it later.
  • Assignment. You may not assign these Terms without our prior written consent. We may assign these Terms as part of a merger, acquisition, reorganization, sale of assets, or transfer of the SecBaseline business.
  • No third-party beneficiaries. These Terms do not create rights for third parties except as expressly stated.
  • Headings. Headings are for convenience and do not limit the meaning of the Terms.
  • Electronic communications. You agree that notices and communications relating to SecBaseline may be provided electronically where permitted by law.

Contact

Cyber Security Tech Solutions

Rhode Island, United States