LAGAN CYBER
Control register — TRM series

Terms of Supply

What WESTPORT CYBER LIMITED, trading as Lagan Cyber, undertakes and what a subscribing organisation undertakes, entered the way the rest of this site enters things: one numbered term per entry, each with its operation, its evidence and the party who carries it.

Register TRM · Version 2.0 · In force 15 August 2026 · Supplier: WESTPORT CYBER LIMITED · Company No. NI741244 · Governing law: Northern Ireland · hello@lagancyber.co.uk

How to read an entry

Each entry carries the same four fields as the privacy register. Control states the term. Implementation describes how it bites in practice. Evidence kept names what either side could produce if the term were ever tested. Owner names the party who carries the obligation, which is also shown in the tag beside the heading.

Supply here is business to business. A subscribing organisation is called the customer; the people it authorises to sign in are its users, and its relationship with them is its own. Where the platform touches personal data, the privacy register governs, and PRV-12 sets out the processing terms that sit beneath these ones.

Nothing in this register cuts down a right that legislation grants and forbids excluding. Where the two conflict, legislation wins and the rest of the entry survives.

TRM-01 Parties and the documents that bind them Both parties

Three documents govern a subscription, and they are ranked so that a conflict between them has an answer.

TRM-01
Both parties

Control

The agreement consists of this register, the processing terms executed under PRV-12, and the order confirming scope and fees; where they disagree, the order prevails over the processing terms, which prevail over this register.

Implementation

The supplier is WESTPORT CYBER LIMITED, incorporated in Northern Ireland under company number NI741244 and trading as Lagan Cyber. The customer is the organisation named on the order, contracting through someone with authority to commit it. Nobody outside those two acquires a right to enforce any part of the agreement.

Evidence kept

The signed order, the executed processing terms, and the dated version of this register in force when the order was placed.

Owner

Both parties.

TRM-02 What this website is, contractually Lagan Cyber

Reading these pages creates no contract. It is worth saying once, precisely, rather than assuming it.

TRM-02
Lagan Cyber

Control

The public site is descriptive material about the product and does not constitute an offer that anyone can accept into a contract.

Implementation

Coverage figures, control counts and domain descriptions published here are compiled by hand, carry the date they were compiled, and move when the library moves. A subscription begins when an order is agreed in writing, not when a page is read or an email is sent. Specimen records shown on the evidence page are illustrative constructions rather than extracts from any real tenant.

Evidence kept

Dated page versions; the order file, which is the only document that starts a subscription.

Owner

Lagan Cyber.

TRM-03 Who may subscribe Customer

The product is bought by organisations for their own security posture, which shapes who can hold an account.

TRM-03
Customer

Control

Subscription is open to an organisation acting in the course of a business, contracting through a person authorised to bind it, and using the platform for that organisation’s own compliance work.

Implementation

Individual users must be at least 18 and must be acting for the customer. Consumer legislation confers rights that cannot be contracted away, and nothing here attempts it; the terms are simply written for a business buyer, because that is who the product is for. A reseller, managed service provider or adviser may subscribe on behalf of a client only where that arrangement is recorded on the order, since it changes who instructs whom.

Evidence kept

The order and the authority recorded on it; the account register showing organisation and role per user.

Owner

Customer.

TRM-04 Changes to checks and control mapping Both parties

A control library moves when the frameworks under it move. How that reaches the customer is worth writing down before it happens.

TRM-04
Both parties

Control

Checks, control mappings and the evidence schema can change. A change that alters a result, retires a check or widens what a connector reads is notified to the customer before it takes effect, with the reason for it.

Implementation

Each subscription records the control domains, connectors and framework mappings in scope on the day it starts, so both sides can see what was agreed rather than argue about it later. Where a framework publisher revises a control, the library is restated against the published text and the restatement is dated. Feedback a customer gives about a check can be used to improve the platform without payment or attribution, though nothing identifying the customer is published without written agreement.

Evidence kept

The subscription record listing domains, connectors and mappings at commencement; dated change notices issued afterwards.

Owner

Both parties.

TRM-05 Accounts and credentials Customer

The customer controls who holds an account, which means the customer controls most of the risk attached to one.

TRM-05
Customer

Control

Accounts are personal to a named individual, are not shared, and are removed by the customer when a person no longer needs them.

Implementation

An administrator at the customer adds, changes and removes users, and is responsible for keeping that list current when somebody moves role or leaves. Credentials are not to be shared between people, published, or embedded in scripts. A suspected compromise is reported to hello@lagancyber.co.uk as soon as it is suspected rather than once it is confirmed, and the account can be frozen on request while it is investigated.

Evidence kept

The user list and its change history; sign-in logs; the dated report of any suspected compromise and what followed it.

Owner

Customer.

TRM-06 Licence granted to the customer Lagan Cyber

What the customer gets is a right to use the platform for a period, not a copy of it.

TRM-06
Lagan Cyber

Control

The customer receives a revocable licence, personal to it and not transferable, to use the platform for its own compliance work while the subscription runs.

Implementation

The licence covers the customer’s own staff and the advisers, auditors and assessors it invites to view its evidence. It does not extend to reselling access, running the platform as a service for other organisations, or benchmarking it for publication. Reverse engineering, scraping the interface, or extracting the control library to build a competing mapping falls outside the licence, and outside what the subscription pays for.

Evidence kept

The order recording seats and scope; access logs distinguishing customer staff from invited reviewers.

Owner

Lagan Cyber.

TRM-07 Authority to connect a tenant Customer

Connecting an identity provider to anything is a consequential act. The term exists so nobody does it casually.

TRM-07
Customer

Control

The person who connects a cloud tenant warrants that they are authorised to grant that access on behalf of the organisation that owns it.

Implementation

Consent is granted through the provider’s own authorisation flow, so the grant is visible in the customer’s directory and revocable there at any moment without asking this company first. Revoking it stops future reads immediately; records already written stay under the retention clocks in PRV-15 until the customer instructs otherwise. Where the tenant belongs to a client rather than to the subscriber, the subscriber confirms it holds that client’s written authority before connecting it.

Evidence kept

The consent grant recorded in the customer’s own directory; the connection record; the customer’s authority file where a client tenant is involved.

Owner

Customer.

TRM-08 The read-only boundary Lagan Cyber

This is the term a security team will look for first, so it is stated as an obligation rather than as a feature.

TRM-08
Lagan Cyber

Control

Scopes requested against a connected tenant are read-only, and the platform undertakes not to write, remediate or otherwise change a customer’s environment.

Implementation

A finding is reported, never fixed from here; remediation stays with the customer’s own team or its IT provider. Nothing in the product can alter a policy, disable an account, quarantine a message or reset a credential. Any future capability that would need a write permission would require a fresh consent granted by the customer, after notice, and would not be enabled by a change to these terms alone.

Evidence kept

The published scope list; the consent record in the customer’s directory, which shows exactly what was granted; the tenant’s own audit log.

Owner

Lagan Cyber.

TRM-09 Ownership of customer material Customer

Evidence about a customer’s controls belongs to that customer. Nothing about the arrangement changes that.

TRM-09
Customer

Control

Configuration readings, evidence records, policy documents, questionnaire responses and training results belong to the customer, and this company claims no ownership of them.

Implementation

Material is held to run the service the customer asked for and for nothing else. It is not mined for a benchmark, pooled into a shared dataset, sold, or used to train a model offered to anyone else. Aggregate statistics about how the platform itself performs may be produced, provided nothing in them can be traced to a customer, a tenant or a person.

Evidence kept

The processing terms; tenant identifiers on stored records; access logs showing internal reads.

Owner

Customer.

TRM-10 What an evidence record proves Both parties

The product’s output is a claim about a configuration at a moment. Overstating what that claim carries would be the easiest mistake to make here.

TRM-10
Both parties

Control

An evidence record states what was checked, against which reference, in which system, at what time, by what method and with what result — and it states nothing beyond that.

Implementation

A result recorded against a reference in ISO/IEC 27001:2022 Annex A, a Cyber Essentials technical control, an NCSC CAF outcome or a NIS2 measure describes a configuration at the moment of collection. It is not certification, accreditation or an audit opinion; those are issued by accredited bodies against their own process, and the framework names remain the property of their respective publishers, used here to describe what a record maps to. A green result is preparation for an assessment, not the outcome of one.

Evidence kept

The record itself, append-only and content-hashed so that an assessor can see it has not been altered after collection.

Owner

Both parties.

TRM-11 Acceptable use Customer

A short list, because a long one tends to be read as exhaustive.

TRM-11
Customer

Control

The platform is used lawfully, against tenants the customer is entitled to examine, and without attempting to reach another customer’s data.

Implementation

  • Connecting a tenant without the authority described at TRM-07 is prohibited.
  • Probing, load-testing or attacking the platform is prohibited, save for testing agreed in writing beforehand.
  • Uploading material that is unlawful, or that infringes somebody’s rights, is prohibited.
  • Presenting an evidence record as a certificate, or altering one before showing it to an assessor, is prohibited.
  • Automated interfaces are used within any documented rate limits, and not to bulk-extract the control library.

Evidence kept

Platform audit logs; the dated notice sent where use is questioned, and the customer’s reply.

Owner

Customer.

TRM-12 Availability and support Lagan Cyber

What is promised about uptime is what can be honoured, stated at that level rather than dressed up.

TRM-12
Lagan Cyber

Control

Reasonable skill and care go into keeping the platform reachable, without a promise that it runs without interruption or defect.

Implementation

Scheduled maintenance is notified in advance where it will interrupt service, and falls outside UK working hours where that is practical. Urgent security work can happen without notice, and is explained afterwards. Support runs by email during UK working hours; a formal service level with credits attached is agreed on an order rather than by amendment of this entry. Security reports are triaged the same working day under PRV-18.

Evidence kept

Maintenance notices; the support mailbox; incident records for outages nobody scheduled.

Owner

Lagan Cyber.

TRM-13 Fees, invoicing and overdue sums Both parties

Prices belong on an order, where they can be specific, rather than on a page that would date immediately.

TRM-13
Both parties

Control

Fees, billing period and payment terms are those stated on the order, and a price change never applies inside a period already paid for.

Implementation

Invoices are issued in pounds sterling, payable within 30 days unless the order says otherwise, and VAT is added where it applies. A change to recurring fees takes effect at the next renewal and is notified at least 30 days beforehand, which leaves room to decline it by not renewing. Sums still unpaid after the due date carry statutory interest for late commercial payment, and access can be suspended under TRM-18 after written warning where an invoice stays overdue.

Evidence kept

Invoices and payment records, held six years after the accounting period closes; dated price-change notices.

Owner

Both parties.

TRM-14 Intellectual property Both parties

Two estates, kept separate: the platform and its control library on one side, the customer’s material on the other.

TRM-14
Both parties

Control

Rights in the platform, its interface, its checks and its control library stay with this company; rights in customer material stay with the customer, as TRM-09 records.

Implementation

The mapping between a check and a published framework reference is original work, and it is licensed for use inside the subscription rather than assigned. Framework and scheme names cited in it belong to the bodies that publish them and are used descriptively to say what a control maps to. Where a customer sends a suggestion and it is adopted, the resulting feature belongs to this company, which is why TRM-04 says so plainly at the point feedback is given.

Evidence kept

The control library and its version history; the order recording what was licensed.

Owner

Both parties.

TRM-15 Confidentiality Both parties

A compliance tool sees a customer at its least flattering. The duty runs in both directions and outlives the subscription.

TRM-15
Both parties

Control

Information received from the other party that is marked confidential, or obviously confidential from its nature, is used only to perform the agreement and disclosed only to people who need it.

Implementation

Security findings about a customer’s environment fall inside this duty automatically, without needing a label. Staff and contractors on either side are bound before they get access. The duty does not reach information that was already known without restriction, that becomes public without a breach, or that is independently developed; nor does it prevent a disclosure that law or a regulator compels, where the other party is told first unless telling them is itself unlawful. The duty continues for five years after the subscription ends, and indefinitely for anything that is also personal data.

Evidence kept

Confidentiality undertakings held on file for staff and contractors; the record of any compelled disclosure and the notice given.

Owner

Both parties.

TRM-16 Warranties, and their edges Lagan Cyber

The warranties given are narrow and real. Stating the edge of one is part of giving it.

TRM-16
Lagan Cyber

Control

The platform is supplied with reasonable skill and care, performs materially as the documentation in force describes, and is operated under the security controls recorded at PRV-17.

Implementation

A check reports what an interface returned at the time it ran. A configuration can change a minute later, an interface can report something incomplete, and a control can be satisfied by a compensating measure the platform cannot observe. So the output is a well-evidenced view rather than a guarantee about a customer’s security, and it is not advice — legal, regulatory or otherwise. Judgements about whether an organisation meets an obligation stay with that organisation and its assessors.

Evidence kept

Documentation versions; the method and timestamp on each evidence record.

Owner

Lagan Cyber.

TRM-17 Allocation of liability Both parties

The limits below are the commercial bargain behind the price, and they are set out in the order the law requires them to be read.

TRM-17
Both parties

Control

Liability that law forbids limiting is untouched; beyond that, each party’s exposure is capped and certain categories of loss are excluded on both sides.

Implementation

Nothing excludes liability for death or personal injury resulting from negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited. Subject to that, neither party answers for lost profit, lost revenue, lost anticipated savings, wasted management time, loss of goodwill, or loss arising indirectly, in each case whether or not the loss was foreseeable. Also subject to that, total liability for all claims connected with the agreement is capped at the fees paid or payable in the twelve months preceding the event that gave rise to the claim. A claim must be notified within twelve months of the party becoming aware of the circumstances behind it.

Evidence kept

The order, which fixes the fees the cap is measured against; correspondence notifying a claim.

Owner

Both parties.

The exclusion of indirect loss does not touch a customer’s liability to pay fees for the service it has received, and it does not touch either party’s obligations under the processing terms, where data protection law fixes the position independently of what a contract says.

TRM-18 Suspension and ending the agreement Both parties

Both exits are described, including the abrupt one, so neither arrives as a surprise.

TRM-18
Both parties

Control

Either party may end the agreement at the end of a billing period on 30 days’ notice, or immediately for a material breach the other has failed to cure within 30 days of being told about it in writing.

Implementation

Access can be suspended without ending the agreement where an invoice is overdue after written warning, where use appears to breach TRM-11, or where continuing to run poses an immediate security risk to the platform or another customer. Suspension is notified with the reason and lifted once the cause is resolved. Either party may also end things immediately if the other enters an insolvency process. Fees already paid for a period that has begun are not refunded on a termination for the customer’s breach.

Evidence kept

Dated notices of suspension, breach and termination, with the reason recorded in each.

Owner

Both parties.

TRM-19 Exit and what leaves with the customer Lagan Cyber

An evidence platform that is hard to leave is worth less than one that is easy to leave, because the evidence has to survive the supplier.

TRM-19
Lagan Cyber

Control

On termination the customer can take its evidence with it in a readable form, and what stays behind is deleted or returned as the processing terms require.

Implementation

Export is available throughout the subscription and for 30 days after it ends, covering evidence records with their references, methods, timestamps and hashes, in a structured format that opens without this platform. After that window the material is deleted under PRV-15 and PRV-16, except for the accounting and audit-log residue those entries name. Connected tenant access ends at termination, and the customer can revoke the consent in its own directory at any point without waiting.

Evidence kept

The export record; the deletion job record; confirmation issued to the customer when both are complete.

Owner

Lagan Cyber.

TRM-20 Law, notices and change control Both parties

Where a dispute is heard, how a message counts as given, and how this register changes.

TRM-20
Both parties

Control

The agreement is governed by the law of Northern Ireland, with the courts of Northern Ireland having exclusive jurisdiction over disputes arising from or connected with it.

Implementation

A notice takes effect when it reaches the account address on record for the customer; for this company the address is hello@lagancyber.co.uk, with post to the registered office standing against company number NI741244 at Companies House. Before litigating, each side agrees to put the complaint in writing and give the other 14 days to answer it, which resolves most things without help. This is version 2.0, in force 15 August 2026, replacing version 1.0 of 5 August 2026; a change adverse to an existing customer applies from the next renewal and is notified at least 30 days ahead. Neither party may transfer the agreement without the other’s written consent, save to a successor of the whole business.

Evidence kept

Dated notices; superseded versions of this register, issued on request.

Owner

Both parties.

← Back to Lagan Cyber