Terms of Service
1. 1. About these terms
These terms cover the use of this website only. The site is published by U2 AI Studio Teknoloji A.S. under the U2 AI CyberTech brand and exists to explain what we work on, how we intend to work and how to reach us. By browsing the site or sending us a message through it, you accept the terms set out here. If you do not accept them, please do not use the site. Any engagement between us would be governed by its own written agreement, not by this text.
2. 2. Nature of the service and development stage
U2 AI CyberTech is at the development stage. The service described here is not being delivered yet. We have no client to name, no case study, no vulnerability count and no measured result, and nothing on this site should be read as one. Descriptions of scope, method, modules and frameworks describe our intent and our current practice rather than a commitment to a specific deliverable. The durations shown are designed lengths of work, not measured delivery times and not a promise of a completion date. No price is published, and nothing on this site is an offer, a quotation or a binding delivery term.
3. 3. Authorisation and scope
We do not test any system without a written authorisation from its owner. Articles 243 to 245 of the Turkish Penal Code make unauthorised access to an information system, and remaining in it, a criminal offence, and lawfulness rests on the informed written consent of the system owner. Consent cannot be implied and cannot be given verbally. The agreement must name the systems in scope, the IP ranges and the test dates, along with the rules of engagement. Any activity outside that scope invalidates the consent given and gives rise to liability under those articles as well as breach of contract, so we do not step outside it, and we expect the same discipline from the party instructing us. Where the systems belong to a third party, the authorisation must come from that owner.
4. 4. Data and confidentiality
Client data, prompts, documents, model weights, configurations and findings are treated as confidential and are used only for the engagement they were provided for. We do not use them for our own purposes and we do not use them to train, tune or evaluate anything of ours. Test data, copies, exported artefacts and working material are destroyed at the end of the work, and anything retained is limited to what the written agreement identifies and for the period it states. Handling, storage location, access control and destruction are agreed in writing before the work starts. Please do not send sensitive personal data or live credentials through this website.
5. 5. Framework references and no certification
References on this site to the OWASP Top 10 for LLM Applications, MITRE ATLAS, the NIST AI Risk Management Framework or any other body describe frameworks we work in alignment with. They are voluntary frameworks, and for MITRE ATLAS there is no certification scheme in existence. We hold no ISO 27001 certificate, no accreditation and no authorisation from any authority, and we issue none. Our work does not produce a certificate, a conformity assessment, an audit or an assurance opinion, and a security assessment is not an audit in the sense of Turkish law. Third party names appear for description only and imply no partnership, membership, approval or endorsement in either direction.
6. 6. No outcome guarantee and no professional advice
Security work cannot guarantee a result. Nothing on this site or in any engagement is a warranty that a system is unbreakable, that no incident will occur, that every weakness will be found or that any regulatory expectation is satisfied. Findings describe what was observed within the agreed scope, at the time of the work, with the access granted. Legal, regulatory and accounting matters mentioned here are set out in plain language for context only; this is not legal advice within the meaning of the Turkish Attorneys Act, not an audit or assurance service, and not accountancy or financial advice. Take your own professional advice before acting. Statutory notification duties, including data breach notification, remain with the data controller.
7. 7. Intellectual property
The U2 AI CyberTech name, the U2 AI Studio marks, the design of this site, its texts, illustrations, diagrams and other materials belong to U2 AI Studio Teknoloji A.S. or to their respective owners and may not be copied, republished or used commercially without written permission. In an engagement, the report and the findings written for a client belong to that client under the terms of the written agreement, while our methods, tooling, checklists and generic know how remain ours. Names, logos and standards referenced on the site belong to their owners.
8. 8. Liability
To the extent permitted by law we accept no liability for indirect or consequential loss arising from use of this site or from reliance on the general information published here, and the site may be changed, suspended or withdrawn at any time. Liability arising from an engagement is governed by its written agreement and by Turkish law. We do not seek to exclude liability that the law does not permit to be excluded: under Article 115 of the Turkish Code of Obligations, an agreement purporting to exclude liability in advance for gross fault is void, and we make no such attempt here. These terms are governed by Turkish law and disputes are subject to the competent courts of Turkey. For anything in this text, write to info@u2aicybertech.com.