Terms of Service

Effective Date: September 21, 2026

Business Name: LTH Cybersecurity
Legal Name: LTH CYBERSECURITY CORP.
Location: Yorkton, Saskatchewan, Canada

1. Overview

LTH CYBERSECURITY CORP., operating as LTH Cybersecurity ("LTH Cybersecurity", "LTH", "we", "us", or "our"), provides cybersecurity services including managed security services, penetration testing, security assessments, vulnerability assessments, incident response, security consulting, endpoint protection, security monitoring, hardening, and related professional services.

Services may be delivered directly by LTH Cybersecurity, through third-party security platforms or service providers, or through a combination of both. By purchasing, authorizing, or otherwise engaging LTH Cybersecurity to provide services, the client agrees to these Terms of Service together with any applicable proposal, quote, Statement of Work (SOW), Service Level Agreement (SLA), Rules of Engagement (ROE), or other written agreement.

2. Service Types

LTH Cybersecurity provides services under two general engagement models:

2.1 Managed and Recurring Services

Managed services are ongoing or recurring services provided for an agreed subscription or contract period. These may include managed detection and response (MDR), endpoint security, security monitoring, device management, managed security baselines, and other recurring security services.

Managed services may incorporate technology, monitoring, infrastructure, or security operations provided by third-party vendors. Any certifications held by a third-party provider apply to that provider and its applicable services and do not automatically constitute certification of LTH Cybersecurity itself.

2.2 Ad Hoc and Project-Based Services

LTH Cybersecurity also performs ad hoc, one-time, and project-based engagements. These may include penetration testing, vulnerability assessments, security audits, incident response, threat assessments, remediation, server or cloud hardening, consulting, and other professional services.

Ad hoc and project-based engagements are governed by the scope, price, timeline, payment terms, and other conditions specified in the applicable quote, proposal, SOW, ROE, or other written agreement. Unless specifically stated otherwise in that agreement, ad hoc and project-based services do not require a 12-month commitment and are not subject to the managed-services early termination charge described below.

LTH Cybersecurity may also provide cybersecurity, technical, or consulting services not specifically listed on our website or in these Terms on an ad hoc or custom basis. Such services will be subject to the scope, pricing, terms, and conditions agreed upon with the client in the applicable quote, proposal, Statement of Work (SOW), or other written agreement.

3. Contract Terms

3.1 Managed Services

3.2 Ad Hoc and Project-Based Services

4. Payments

5. Refunds and Cancellations

6. Client Responsibilities and Authorization

The client is responsible for providing accurate information, appropriate access, and any authorization reasonably required for LTH Cybersecurity to perform the agreed services.

For penetration testing, vulnerability testing, or other activities involving active security testing, the client represents that it owns the systems being tested or has sufficient authority to authorize the testing. Testing will be limited to the scope and conditions established in the applicable Rules of Engagement, SOW, or other written authorization.

LTH Cybersecurity is not responsible for delays or inability to complete work caused by unavailable systems, inaccurate scope information, revoked access, lack of authorization, or other circumstances outside our reasonable control.

7. Third-Party Services

Certain services may rely on third-party software, security platforms, hosting providers, monitoring services, or other vendors. Third-party services may be subject to their own terms, availability, technical limitations, and service conditions.

LTH Cybersecurity is not responsible for outages, product changes, discontinuation, or failures caused solely by third-party systems outside our reasonable control.

8. Security and Liability Disclaimer

Cybersecurity services reduce risk but cannot eliminate all security risk. No cybersecurity product, penetration test, assessment, monitoring service, or security control can guarantee that a system will be completely secure or that every vulnerability, attack, or compromise will be detected or prevented.

LTH Cybersecurity is not responsible for losses resulting from circumstances outside the agreed scope or our reasonable control, including:

To the maximum extent permitted by applicable law, LTH Cybersecurity, its officers, employees, contractors, agents, and service partners shall not be liable for indirect, incidental, special, consequential, or punitive damages, including loss of revenue, profits, data, business opportunity, or reputation.

To the maximum extent permitted by applicable law, LTH Cybersecurity's aggregate liability arising from an engagement shall not exceed the amount paid by the client to LTH Cybersecurity for the specific service giving rise to the claim.

9. Support Policy

10. Pricing and Scope Changes

Pricing is determined according to the service, scope, environment, organization size, complexity, risk, and other requirements of the engagement. Custom pricing may apply to complex or higher-risk environments.

Requests that materially expand the original scope of an engagement may require a revised quote, change order, additional milestone, or separate agreement before additional work is performed.

11. Indigenous Organization Discount

LTH Cybersecurity is committed to supporting Indigenous communities by offering a 7% discount on eligible services and packages to verified Indigenous organizations.

Eligibility requires majority Indigenous ownership or control, or recognition as an Indigenous government, band office, nonprofit organization, or similar Indigenous entity.

Verification documentation may be requested before the discount is applied. Documentation collected solely for eligibility verification will be handled securely and deleted when it is no longer required for that purpose.

Discount eligibility is subject to approval. LTH Cybersecurity may decline or revoke a discount where eligibility requirements are not satisfied. Discounts may not be combined with other promotions or contract-specific pricing unless agreed in writing.

12. Order of Precedence

Where an applicable SOW, SLA, ROE, proposal, quote, or other written agreement contains terms that conflict with these general Terms of Service, the terms of the more specific written agreement will govern with respect to that engagement.

13. Policy Updates

LTH Cybersecurity may update these Terms of Service from time to time. Updated terms will apply prospectively from their stated effective date. Changes will not retroactively alter the material commercial terms of an existing fixed-term agreement unless agreed to by the parties or otherwise permitted by that agreement or law.

```