Back

CertFirst Terms & Conditions

These Terms and Conditions (“Terms”) govern access to and use of the CertFirst website, training programs, certification services, examinations, vouchers, courseware, laboratories, digital platforms, publications, consulting services, memberships, and related products and services.

Please read these Terms carefully before using any website, product, training program, certification, or service covered by these Terms.

1. Company and Group Definitions

For purposes of these Terms:

“CertFirst” means CertFirst, a division of Saifirst Corporation, together with its authorized representatives.

“CertFirst Authorized partners” is used as a collective reference to CertFirst and the applicable brands, programs, publishers, certification providers, and affiliated entities operating under or in cooperation with CertFirst, including, where applicable:

  • CertCop
  • PostgreSQLCert
  • BioCertification
  • ExamIT
  • SecBay Press
  • Other CertFirst-owned, managed, licensed, or affiliated brands and programs

The use of the term “CertFirst Authorized partners” does not alter the separate ownership of any intellectual property belonging to an individual company, brand, publisher, vendor, licensor, or certification provider.

“Customer” means any person or organization that visits the website, creates an account, purchases a product or service, registers for training, participates in a certification program, receives an exam voucher, accesses digital content, or enters into a business relationship with CertFirst.

“Services” includes websites, training programs, certification programs, examinations, exam vouchers, laboratories, courseware, books, digital content, consulting, mentoring, coaching, memberships, partner services, reseller services, and other offerings made available by CertFirst.

2. Acceptance of These Terms

By visiting the CertFirst website or by registering for, purchasing, accessing, downloading, attending, or using any Service, you acknowledge that you have read, understood, and agreed to be legally bound by these Terms.

Acceptance may occur through:

  • Use of the website or Services;
  • Submission of a registration or order form;
  • Electronic acceptance of these Terms;
  • Payment of an invoice or training fee;
  • Access to course materials, laboratories, recordings, or digital platforms;
  • Attendance at a training program or examination; or
  • Execution of an order form, quotation, partner agreement, reseller agreement, licensing agreement, or other written agreement.

When accepting these Terms on behalf of a company, employer, government agency, educational institution, or other organization, you represent that you have authority to bind that organization.

If you do not agree with these Terms, you must not access or use the website or Services.

3. Additional Agreements and Order Documents

Certain Services may be governed by an additional written agreement, quotation, statement of work, registration form, order form, partner agreement, reseller agreement, certification agreement, vendor policy, or licensing agreement.

When a signed written agreement expressly conflicts with these Terms, the signed agreement will control only with respect to the specific subject addressed by that agreement.

Any purchase-order terms or customer-generated terms will not apply unless CertFirst expressly accepts them in a written document signed by an authorized CertFirst representative.

4. Eligibility, Registration, and Account Security

Customers must provide accurate, current, and complete information during registration, enrollment, purchasing, certification, or account creation.

Customers are responsible for:

  • Maintaining the confidentiality of usernames, passwords, examination credentials, and access codes;
  • Preventing unauthorized access to their accounts;
  • Promptly updating inaccurate or outdated information;
  • Maintaining appropriate backups and security for their devices and data; and
  • Immediately notifying CertFirst of suspected unauthorized access or account misuse.

An account, laboratory login, examination credential, course license, membership, or digital-content license may not be shared unless CertFirst provides written authorization.

The Customer is responsible for all activity conducted through its account unless the activity resulted directly from a security failure under CertFirst’s exclusive control.

5. Acceptable Website and Service Use

Customers may use the website and Services only for lawful, professional, educational, and authorized purposes.

Customers must not:

  • Transmit spam, unsolicited commercial communications, or malicious content;
  • Upload viruses, ransomware, spyware, destructive code, or harmful files;
  • Interfere with website, laboratory, examination, or platform operations;
  • Attempt to bypass security, licensing, payment, identity-verification, or access controls;
  • Obtain unauthorized access to accounts, databases, systems, or restricted content;
  • Collect personal information about another user without authorization;
  • Misrepresent identity, qualifications, affiliation, employment, partnership, or authorization;
  • Impersonate CertFirst, a CertFirst employee, instructor, certification provider, partner, or customer;
  • Manipulate headers, URLs, credentials, examination records, certificates, or identifying information;
  • Publish unlawful, defamatory, abusive, discriminatory, obscene, fraudulent, or infringing content;
  • Use the Services in violation of applicable laws, professional obligations, or contractual requirements; or
  • Engage in conduct that could damage the security, reputation, operations, customers, or business relationships of CertFirst Authorized partners.

CertFirst may investigate suspected misuse and may restrict or terminate access where reasonably necessary.

6. Customer-Submitted Content

Customers retain ownership of original content they submit to CertFirst, subject to the rights granted in this section.

By submitting reviews, testimonials, comments, assignments, files, feedback, photographs, recordings, suggestions, or other content, the Customer represents that:

  • The Customer owns the content or has permission to submit it;
  • The content does not infringe another party’s rights;
  • The content does not contain unlawfully disclosed confidential or personal information; and
  • The content complies with these Terms.

Unless otherwise stated in writing or covered by the Privacy Policy, content voluntarily submitted for publication, marketing, evaluation, support, or community participation may be used by CertFirst for the purpose for which it was submitted.

CertFirst may remove, restrict, preserve, or disclose submitted content when reasonably necessary to enforce these Terms, comply with law, protect rights or safety, investigate misconduct, or maintain website and platform integrity.

7. Confidential Information

Customers may receive nonpublic information concerning CertFirst Authorized partners, its customers, instructors, vendors, certification providers, suppliers, partners, products, pricing, examinations, technology, marketing, business operations, or future plans.

Such information must be protected as confidential when it is identified as confidential or when a reasonable person would understand that it is confidential.

The Customer must:

  • Use confidential information only for the authorized purpose;
  • Protect it using reasonable security measures;
  • Limit access to individuals who have a legitimate need to know;
  • Not disclose it to third parties without written authorization; and
  • Return, delete, or destroy it upon request or termination of the applicable relationship.

These obligations do not apply to information that the Customer can demonstrate:

  • Was lawfully known without a confidentiality obligation;
  • Became public without violation of these Terms;
  • Was lawfully obtained from an authorized third party;
  • Was independently developed without use of confidential information; or
  • Must be disclosed under a valid legal requirement.

Where legally permitted, the Customer must provide advance notice before making a legally required disclosure.

Unless a separate agreement states otherwise, confidentiality obligations continue for five years after disclosure. Trade secrets remain protected for as long as they qualify for protection under applicable law.

8. Intellectual Property Ownership

All training materials, courseware, presentations, instructor guides, examination content, question banks, videos, recordings, books, graphics, photographs, laboratory environments, software, source code, scripts, digital assets, certification designs, certificates, badges, trademarks, logos, websites, and related materials made available through CertFirst Authorized partners are protected by applicable copyright, trademark, patent, trade-secret, licensing, contractual, and other intellectual-property laws.

All rights remain with CertFirst Authorized partners or the applicable author, publisher, vendor, certification provider, licensor, or intellectual-property owner.

Purchasing or accessing a Service does not transfer ownership of the associated intellectual property.

Except where expressly authorized in writing, Customers receive only a limited, personal, nonexclusive, nontransferable, nonsublicensable, and revocable right to use the materials for the specific educational or business purpose for which access was granted.

9. Prohibited Use of Intellectual Property

Without prior written authorization from the applicable rights owner, Customers must not:

  • Copy, reproduce, republish, redistribute, sell, resell, sublicense, rent, lease, or commercially exploit protected materials;
  • Upload courseware, books, videos, examinations, laboratories, or instructor materials to file-sharing websites, cloud drives, social networks, repositories, learning platforms, or artificial-intelligence systems;
  • Record, photograph, screen-capture, livestream, transcribe, or reproduce training sessions, laboratories, examinations, or digital content;
  • Modify, translate, adapt, decompile, disassemble, reverse engineer, or create derivative works;
  • Remove copyright notices, trademark notices, watermarks, license information, digital-rights controls, or ownership statements;
  • Share account credentials, access links, laboratory credentials, examination questions, answer keys, instructor guides, or downloadable materials;
  • Use protected content to create competing training, examination, publishing, certification, or commercial products;
  • Use CertFirst Authorized partners materials to train, fine-tune, evaluate, populate, or improve an artificial-intelligence system without authorization;
  • Use automated tools, crawlers, bots, scraping systems, extraction software, or similar technologies to collect protected content; or
  • Claim ownership, authorship, sponsorship, authorization, accreditation, or affiliation that has not been granted in writing.

Notes personally created by an attendee may be used for that attendee’s individual study. Such notes may not reproduce substantial protected content or be published, sold, distributed, or used to provide competing training.

10. Trademarks, Branding, and Partner Representation

The names, brands, marks, certification titles, logos, badges, slogans, designs, domain names, and trade dress used by CertFirst Authorized partners are valuable proprietary assets.

No person or organization may, without current written authorization:

  • Display or use a CertFirst Authorized partners trademark or logo;
  • Describe itself as an authorized partner, reseller, distributor, instructor, examination center, certification body, affiliate, publisher, or training provider;
  • Issue certificates, badges, examination results, authorization letters, or partner credentials using CertFirst Authorized partners branding;
  • Register a company name, domain name, social-media account, advertisement, or listing containing a confusingly similar name;
  • Modify or combine CertFirst Authorized partners branding with another logo;
  • Suggest sponsorship, endorsement, accreditation, or affiliation that does not exist; or
  • Continue using partner branding after authorization expires, is suspended, or is terminated.

Authorized partners may use approved branding only within the territory, duration, format, and purpose stated in their written agreement and applicable brand guidelines.

All goodwill arising from authorized use of a CertFirst Authorized partners trademark benefits the applicable trademark owner.

11. Intellectual Property Violations and Enforcement

Unauthorized commercial use, copying, distribution, resale, infringement, misrepresentation, credential sharing, examination theft, false-partner representation, or misuse of CertFirst Authorized partners intellectual property constitutes a material violation of these Terms.

When CertFirst Authorized partners has credible evidence of a violation, it may, subject to applicable law:

  • Suspend or permanently terminate accounts, licenses, certifications, partnerships, examination privileges, and access rights;
  • Disable digital content, laboratory access, certificates, badges, or partner credentials;
  • Issue cease-and-desist or preservation notices;
  • Request removal of infringing website, marketplace, social-media, hosting, or search-engine content;
  • Seek temporary, preliminary, or permanent injunctive relief;
  • Seek recovery of actual damages, lost profits, unjust enrichment, investigation expenses, court costs, and attorneys’ fees where recoverable;
  • Seek statutory or enhanced damages where available;
  • Preserve evidence and cooperate with vendors, regulators, platforms, or law-enforcement agencies; and
  • Exercise any additional contractual, equitable, civil, administrative, or legal remedy available.

Suspected criminal conduct may be referred to the appropriate law-enforcement or regulatory authorities. Any decision regarding criminal investigation or prosecution belongs exclusively to the relevant governmental authority.

12. Liquidated Damages for Unauthorized Commercial Use

The commercial impact of intellectual-property theft, unauthorized certification activities, examination-content disclosure, false-partner representation, and large-scale content distribution may be difficult to calculate at the time the parties enter into an agreement.

Accordingly, where these Terms or a related partner, reseller, instructor, publisher, certification, licensing, distribution, or commercial agreement have been expressly accepted by the applicable parties, the parties agree that CertFirst Authorized partners may seek liquidated damages of not less than USD $100,000 for each separately proven act involving:

  • Unauthorized commercial reproduction, distribution, or resale of protected materials;
  • Deliberate copyright or trademark infringement;
  • Unauthorized disclosure or sale of examination content;
  • False representation as an authorized CertFirst partner, reseller, instructor, certification body, distributor, or affiliate; or
  • Commercial misuse of CertFirst Authorized partners intellectual property to obtain customers, revenue, contracts, or other financial benefit.

This amount is intended as a reasonable estimate of losses that may be difficult to measure and not as a punishment or penalty.

This provision applies only to the extent permitted and enforceable under applicable law. A court or tribunal may reduce, modify, or decline to enforce the amount where required by law.

Nothing in this section:

  • Guarantees an automatic award;
  • Replaces any legal requirement to prove the violation;
  • Limits the availability of injunctive or other nonmonetary relief;
  • Prevents recovery of greater actual, statutory, enhanced, or contractual damages when legally available; or
  • Permits double recovery for the same injury.

13. Training Registration and Confirmation

Training dates, instructors, delivery methods, and resources are not guaranteed until CertFirst provides written confirmation and receives the required payment.

Unless otherwise stated in an order form:

  • Training fees must be paid in full before the scheduled start date;
  • Dedicated instructors, laboratories, and course materials may not be reserved until payment is received;
  • Enrollment may be denied or cancelled for unpaid balances;
  • Course availability is subject to capacity, instructor availability, vendor requirements, and technical resources; and
  • Additional charges may apply for customization, onsite delivery, extended hours, additional participants, international delivery, special laboratories, or vendor materials.

A public course registration covers only the named attendee.

Corporate and private group-training fees are based on the participant limit stated in the quotation or order form. Additional participants require prior approval and may result in additional fees.

14. Training Prerequisites and Participant Responsibilities

Customers are responsible for reviewing and satisfying the prerequisites stated for each course, certification, examination, or laboratory.

Participants must have:

  • Appropriate computer literacy;
  • Required technical knowledge;
  • Compatible hardware and software;
  • Reliable internet connectivity for virtual delivery;
  • Required identification;
  • Necessary administrative permissions; and
  • Any vendor accounts or licenses identified before training.

Failure to meet prerequisites does not create refund, transfer, substitution, or rescheduling rights.

Participants must behave professionally and must not interfere with instructors, other participants, examinations, laboratories, or training operations.

CertFirst may remove a participant for abusive, unlawful, disruptive, discriminatory, threatening, dishonest, or unsafe conduct. Removal for participant misconduct does not entitle the Customer to a refund.

15. Payments, Taxes, and Charges

The Customer must pay all prices, taxes, processing fees, transaction fees, customization fees, vendor fees, travel charges, and other amounts identified during registration or in the applicable quotation, invoice, or order form.

Unless otherwise stated:

  • Prices are quoted in United States dollars;
  • Payment obligations are not contingent on attendance, examination success, reimbursement, employer approval, funding, or purchase-order processing;
  • The Customer is responsible for bank, foreign-exchange, wire-transfer, and payment-processing charges;
  • Discount codes cannot be exchanged for cash;
  • Discounts may not be combined unless expressly permitted;
  • Promotions may be modified or withdrawn before purchase; and
  • The Customer is responsible for any applicable tax-reporting obligations relating to incentives or promotional benefits.

CertFirst may correct pricing or description errors before confirming an order.

16. Cancellation, Refund, and Rescheduling Policy

Except where these Terms expressly provide otherwise, all payments are non-refundable.

All cancellation, substitution, transfer, and rescheduling requests must:

  • Be submitted in writing;
  • Identify the Customer and affected Service;
  • Be received within the applicable deadline; and
  • Be acknowledged in writing by CertFirst.

A request is not approved merely because it was submitted.

16.1 Public Instructor-Led Training

For public virtual or onsite training, the following cancellation charges apply:

Notice received 60 calendar days or more before the course:
CertFirst will retain 50% of the total training fee. The remaining eligible balance may be refunded after deducting non-refundable vendor, processing, administrative, and material costs.

Notice received between 29 and 59 calendar days before the course:
CertFirst will retain 75% of the total training fee. Any eligible balance may be refunded after applicable deductions.

Notice received 28 calendar days or fewer before the course:
The Customer is responsible for 100% of the training fee. No refund will be issued.

16.2 Corporate, Private, Customized, and Dedicated Training

Corporate, private, customized, onsite, and dedicated group training is non-refundable once confirmed because instructors, laboratories, courseware, vendors, and other resources are specifically allocated.

Cancellation, postponement, reduction in attendance, or failure of participants to attend does not reduce the amount payable.

Any exception must be approved in a written amendment signed by an authorized CertFirst representative.

16.3 No Refund After Delivery Begins

No refund, credit, transfer, or substitution will be available after any portion of a Service has been delivered or accessed, including:

  • Attendance at any training session;
  • Receipt or use of course materials;
  • Access to laboratories or learning platforms;
  • Delivery of login credentials;
  • Access to videos or recordings;
  • Downloading digital materials;
  • Activation of a license or membership; or
  • Commencement of an examination or certification process.

Late arrival, partial attendance, early withdrawal, scheduling conflicts, technical limitations under the Customer’s control, failure to attend, and failure to complete a course do not create refund rights.

16.4 Rescheduling

Rescheduling is subject to CertFirst approval, availability, instructor schedules, vendor requirements, and payment of applicable fees.

A rescheduling request:

  • Does not reset the original cancellation deadline;
  • Does not restore refund eligibility;
  • May require payment of price differences or administrative costs;
  • May be limited to one approved change; and
  • May be denied when submitted within 28 days of the scheduled start date.
16.5 Participant Substitutions

Before training begins and before materials or credentials are accessed, the Customer may request substitution of another qualified participant.

Substitutions require written approval and may be subject to identity-verification, licensing, vendor, examination, and administrative requirements.

17. Prepaid Training and Credits

Prepaid training packages, group-training credits, promotional credits, scholarship credits, and special offers:

  • Are non-refundable;
  • Have no cash value;
  • May not be resold or transferred without authorization;
  • Must be used within the stated validity period; and
  • Expire 12 months after purchase unless another period is stated in writing.

Expired credits will not be reinstated unless required by applicable law.

18. Digital Materials, Recordings, and Online Access

Digital content is licensed rather than sold.

Digital content is considered delivered when access credentials, download links, platform access, license keys, recordings, or files are issued or made available.

After digital content has been issued or accessed:

  • No refund, substitution, transfer, or exchange is available;
  • Access may be limited by time, device, user, territory, or license;
  • Credentials may not be shared;
  • Content may not be copied or redistributed; and
  • CertFirst may use access controls and technical measures to protect licensed materials.

Temporary interruptions caused by maintenance, internet conditions, third-party platforms, or events outside CertFirst’s reasonable control do not automatically create refund rights.

19. Certification Examinations and Exam Vouchers

Unless a vendor expressly provides otherwise in writing, certification exam vouchers are non-refundable after purchase and non-transferable after issuance.

This applies to vouchers issued by or through CertFirst for third-party or affiliated certification providers, including:

  • CompTIA;
  • EC-Council;
  • AWS;
  • CertCop;
  • PostgreSQLCert;
  • BioCertification; and
  • Other authorized certification vendors.

Voucher expiration dates are final.

Expired vouchers:

  • Have no remaining monetary value;
  • Cannot be extended, reinstated, exchanged, refunded, or credited;
  • Cannot be used after the vendor expiration date; and
  • Do not create a right to a replacement voucher.

Failure to schedule or attend an examination, examination failure, identification problems, violation of vendor rules, technical problems under the candidate’s control, or failure to use a voucher before expiration does not create refund or credit rights.

Certification is not guaranteed. Certification decisions remain subject to the requirements, examination results, conduct rules, and policies of the applicable certification provider.

20. Changes or Cancellation by CertFirst

CertFirst may cancel, postpone, reschedule, combine, relocate, or modify a course, examination session, delivery format, instructor assignment, laboratory, or Service when reasonably necessary.

When CertFirst cancels a paid Service and does not provide a reasonable replacement, CertFirst’s sole obligation will be, at its discretion and subject to applicable law, to provide:

  • A refund of the amount paid for the cancelled portion; or
  • A credit toward a future Service of equivalent value.

CertFirst is not responsible for airfare, lodging, visas, transportation, lost wages, lost productivity, internal business costs, or other expenses arising from a change or cancellation.

Customers should not make non-refundable travel arrangements until receiving final written confirmation.

21. Cybersecurity Training and Ethical Use

CertFirst cybersecurity education is intended exclusively for lawful, ethical, defensive, compliance, research, auditing, administrative, and authorized security-testing purposes.

Participants may use cybersecurity knowledge, tools, scripts, techniques, and laboratories only:

  • On systems they personally own; or
  • On systems for which they have explicit authorization from the lawful owner.

Participation in a CertFirst course does not provide permission to scan, access, test, monitor, intercept, exploit, disrupt, or modify any third-party system.

Participants must not use knowledge or tools obtained through the Services to:

  • Gain unauthorized access to a computer, network, application, cloud environment, account, database, or device;
  • Create, deploy, distribute, or support malware, ransomware, spyware, botnets, or destructive code;
  • Conduct phishing, credential theft, identity theft, fraud, extortion, cyberstalking, or unauthorized surveillance;
  • Perform denial-of-service attacks or disrupt services;
  • Steal, alter, encrypt, destroy, disclose, or exfiltrate data;
  • Evade lawful security, monitoring, or access controls;
  • Violate privacy, confidentiality, intellectual-property, employment, licensing, or contractual obligations; or
  • Violate local, state, federal, national, or international law.

Each participant is solely responsible for obtaining proper authorization and complying with applicable laws and professional standards.

22. Third-Party and Open-Source Technologies

Courses may demonstrate software, tools, platforms, operating systems, frameworks, utilities, artificial-intelligence systems, cloud services, forensic tools, vulnerability scanners, or security products created by third parties.

Unless expressly stated:

  • CertFirst does not own or control third-party products;
  • Third-party products are governed by their own licenses and terms;
  • References do not constitute endorsement or warranty;
  • Features and availability may change without notice; and
  • Customers are responsible for obtaining required licenses and complying with third-party requirements.

CertFirst is not responsible for third-party software defects, vulnerabilities, service interruptions, licensing changes, discontinued products, or actions taken by third-party providers.

23. External Links, Advertisements, and Promotions

The website may contain links to third-party websites, advertisers, payment processors, vendors, marketplaces, or resources.

CertFirst does not control and is not responsible for:

  • Third-party availability;
  • External content or privacy practices;
  • Third-party products or services;
  • Transactions between Customers and third parties; or
  • Damage arising from reliance on external resources.

Customers should review the applicable third party’s terms and privacy policies before completing a transaction.

24. Privacy and Electronic Communications

Personal information is collected, processed, stored, and protected in accordance with the CertFirst Privacy Policy and applicable law.

By registering for or purchasing Services, Customers consent to receiving operational communications relating to:

  • Orders and payments;
  • Training schedules;
  • Examination requirements;
  • Access credentials;
  • Security notifications;
  • Policy updates;
  • Customer support; and
  • Service administration.

CertFirst will use reasonable efforts to deliver electronic communications but cannot guarantee delivery because email providers, spam filters, incorrect addresses, security systems, and technical conditions may interfere with delivery.

Customers are responsible for maintaining a valid email address and reviewing relevant communications.

25. Disclaimer of Warranties

To the fullest extent permitted by law, the website and Services are provided on an “as is,” “as available,” and “with all faults” basis.

CertFirst Authorized partners does not guarantee that:

  • The website or Services will always be uninterrupted, secure, timely, or error-free;
  • All errors will be corrected;
  • Information will always be complete or current;
  • Every participant will pass an examination;
  • Training will result in certification, employment, promotion, salary increases, contracts, or business opportunities;
  • A Service will satisfy every Customer’s individual requirements; or
  • Third-party platforms or software will remain available.

Any legally implied warranty that cannot be excluded remains limited to the minimum extent required by applicable law.

26. Assumption of Risk

Customers acknowledge that technology and cybersecurity training may involve complex systems, powerful tools, simulated attacks, configuration changes, software installation, and laboratory activities.

Customers voluntarily assume responsibility for:

  • Following instructor and laboratory instructions;
  • Protecting production systems and data;
  • Using isolated or authorized environments;
  • Maintaining backups;
  • Verifying commands before execution;
  • Obtaining authorization; and
  • Evaluating whether a tool or technique is appropriate for a particular environment.

CertFirst is not responsible for damage caused by applying training exercises to unauthorized, unsupported, production, or inadequately protected systems.

27. Limitation of Liability

To the fullest extent permitted by law, CertFirst Authorized partners and its owners, officers, directors, employees, instructors, contractors, authors, publishers, licensors, vendors, partners, resellers, distributors, consultants, successors, and assigns will not be liable for indirect, incidental, special, punitive, exemplary, or consequential damages.

This exclusion includes loss of:

  • Profits;
  • Revenue;
  • Business opportunities;
  • Savings;
  • Data;
  • Goodwill;
  • Productivity;
  • Contracts;
  • Use of systems; or
  • Anticipated benefits.

Except for liability that cannot legally be limited, the total cumulative liability of CertFirst arising from a particular Service will not exceed the amount actually paid to CertFirst for the specific Service giving rise to the claim.

These limitations apply regardless of whether the claim arises under contract, negligence, tort, statute, misrepresentation, strict liability, or another legal theory.

28. Indemnification

The Customer agrees to defend, indemnify, and hold harmless CertFirst Authorized partners and its owners, officers, directors, employees, instructors, contractors, authors, publishers, licensors, certification providers, vendors, partners, resellers, distributors, successors, and assigns from claims, investigations, damages, liabilities, fines, penalties, judgments, costs, and reasonable attorneys’ fees arising from:

  • The Customer’s violation of these Terms;
  • Unlawful, unethical, negligent, fraudulent, or unauthorized conduct;
  • Misuse of cybersecurity knowledge or tools;
  • Infringement of intellectual-property or privacy rights;
  • Content submitted by the Customer;
  • False representations concerning partnership, certification, authorization, or affiliation;
  • Violation of examination or vendor rules;
  • Activity conducted through the Customer’s account; or
  • Violation of applicable law or a third-party agreement.

This obligation applies only to the extent permitted by law and does not require indemnification for losses caused solely by CertFirst’s willful misconduct.

29. Suspension and Termination

CertFirst may suspend, restrict, or terminate access to any website, account, course, laboratory, examination, certification, membership, partnership, license, digital content, or Service when it reasonably believes that:

  • These Terms have been violated;
  • Payment is overdue or disputed;
  • Credentials have been shared;
  • Intellectual property has been misused;
  • Examination security has been compromised;
  • A Customer has engaged in unlawful, abusive, deceptive, malicious, or unethical conduct;
  • Continued access creates a security, legal, operational, or reputational risk; or
  • Termination is required by a vendor, certification provider, regulator, court, or government authority.

Termination does not eliminate payment obligations or other provisions that by their nature should continue, including confidentiality, intellectual property, indemnification, limitation of liability, dispute provisions, and accrued rights.

30. Export Controls and Restricted Use

Customers must comply with applicable export-control, import-control, sanctions, and restricted-party laws.

Services, software, courseware, laboratories, or technical information must not be exported, re-exported, transferred, or provided where prohibited by law.

Customers must not use the Services to design, develop, support, or produce chemical, biological, nuclear, missile, or other prohibited weapons or unlawful activities.

CertFirst may refuse, cancel, suspend, or restrict a transaction when required to comply with applicable trade-control or sanctions requirements.

31. Corporate Client Non-Solicitation

Where expressly included in a signed corporate-training or service agreement, neither party may knowingly and directly solicit for employment personnel of the other party who were substantially involved in delivering the applicable Services during the engagement and for the period stated in that signed agreement.

This restriction does not apply to:

  • General public recruitment advertisements;
  • Unsolicited applications;
  • Individuals independently approaching the other party;
  • Recruitment conducted without targeted solicitation; or
  • Situations where enforcement would be prohibited by applicable law.
32. Notices and Changes to Services

CertFirst may provide notices through:

  • Email;
  • Customer accounts;
  • Website announcements;
  • Regular mail; or
  • The applicable learning or certification platform.

CertFirst may modify, suspend, replace, or discontinue part of a Service when reasonably necessary.

CertFirst may update these Terms by publishing a revised version and updating the “Last Updated” date.

Material changes will apply prospectively unless immediate application is required for legal, regulatory, security, or fraud-prevention reasons.

Continued use after the effective date of revised Terms constitutes acceptance of the revised Terms.

33. Governing Law and Dispute Resolution

These Terms are governed by the laws of the State of Illinois and applicable United States federal law, without regard to conflict-of-law principles.

Subject to applicable consumer-protection laws, contractual disputes arising from these Terms shall be brought in the state or federal courts located in DuPage County, Illinois, and the parties consent to the jurisdiction of those courts.

Notwithstanding the preceding paragraph, CertFirst Authorized partners or the applicable intellectual-property owner may seek:

  • Injunctive relief;
  • Evidence-preservation orders;
  • Emergency relief;
  • Enforcement of intellectual-property rights; or
  • Recognition or enforcement of a judgment

in any court having jurisdiction where the violation occurred, where the responsible party is located, or where relevant assets or evidence are located.

The United Nations Convention on Contracts for the International Sale of Goods does not apply.

34. Intellectual Property Complaints

A person who believes that material available through a CertFirst website infringes a copyright, trademark, or other intellectual-property right may submit a written complaint containing:

  • Identification of the protected work or right;
  • Identification and location of the allegedly infringing material;
  • The complainant’s name and contact information;
  • A statement explaining the basis of the complaint;
  • A statement confirming a good-faith belief that the disputed use is unauthorized; and
  • Supporting ownership or authorization documentation.

Complaints may be sent to:

Email: info@certfirst.com

Submitting a complaint does not guarantee removal, admission of liability, or commencement of legal proceedings.

35. Entire Agreement

These Terms, the Privacy Policy, applicable order documents, and any signed written agreement constitute the complete agreement concerning the applicable Services.

They replace prior communications or versions addressing the same subject.

No oral statement modifies these Terms unless confirmed in a written document signed by an authorized CertFirst representative.

36. Assignment

Customers may not assign or transfer their accounts, licenses, vouchers, certifications, partner rights, payment obligations, or rights under these Terms without prior written authorization.

CertFirst may assign its rights or obligations in connection with a merger, acquisition, restructuring, transfer of assets, service-provider arrangement, or corporate reorganization, subject to applicable law.

37. Waiver and Severability

Failure to enforce a provision does not waive the right to enforce it later.

If a provision is found invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable. If modification is not possible, the invalid portion will be severed, and the remaining provisions will continue in effect.

38. Survival

Provisions concerning payment obligations, confidentiality, intellectual property, restrictions on use, remedies, indemnification, limitations of liability, governing law, dispute resolution, and any other provisions intended by their nature to continue will survive expiration or termination.

39. Contact Information

Questions concerning these Terms may be directed to:

CertFirst
A Division of Saifirst Corporation
Website: www.certfirst.com
Legal inquiries: info@certfirst.com

40. Final Acceptance

By registering for, purchasing, accessing, attending, downloading, or participating in any CertFirst website, training program, certification, examination, laboratory, publication, membership, consulting engagement, or educational Service, you confirm that:

  • You have read and understood these Terms;
  • You agree to comply with these Terms;
  • You are responsible for your use of the Services;
  • You will use cybersecurity knowledge and tools only for lawful and authorized purposes; and
  • You agree to be legally bound by these Terms and any applicable written agreement.
Training Disclaimer 
CertFirst is an independent, vendor-neutral cybersecurity education and certification provider dedicated to advancing cybersecurity knowledge through ethical, legal, and responsible education. Our mission is to prepare cybersecurity professionals to defend and protect individuals, businesses, governments, and critical infrastructure from cyber threats.
The cybersecurity courses, laboratories, software, demonstrations, scripts, frameworks, utilities, tools, techniques, methodologies, exercises, and educational materials provided by CertFirst and its instructors, authors, certification partners, publishers, licensors, and training partners are intended solely for lawful educational, defensive, research, compliance, auditing, vulnerability assessment, penetration testing (with authorization), and cybersecurity awareness purposes.
Educational Purpose Only
All training offered by CertFirst is designed exclusively to teach cybersecurity professionals how to:
  • Protect their own digital assets.
  • Protect systems they own.
  • Protect systems owned by their employer or clients with proper written authorization.
  • Improve cybersecurity defenses.
  • Detect, prevent, investigate, respond to, and recover from cyber incidents.
  • Meet professional, regulatory, and compliance requirements.
The objective of CertFirst training is to strengthen cybersecurity—not to facilitate offensive or unlawful activities.
Ethical Use Requirement
By enrolling in, accessing, or participating in any instructor-led, virtual live, hybrid, self-paced, on-demand, laboratory, certification, webinar, workshop, coaching, mentoring, or educational program offered by CertFirst, you agree that you will use the knowledge, techniques, software, tools, laboratories, and instructional materials solely for ethical and lawful purposes.
You agree that you will never use the knowledge obtained through CertFirst training to:
  • Gain unauthorized access to any computer, network, cloud environment, application, database, account, or device.
  • Attack, disrupt, disable, damage, exploit, interfere with, or compromise any information system.
  • Develop, deploy, distribute, or facilitate malware, ransomware, spyware, viruses, botnets, or other malicious software.
  • Conduct phishing, credential theft, identity theft, fraud, cyberstalking, social engineering, denial-of-service attacks, or unauthorized surveillance.
  • Steal, modify, encrypt, destroy, or exfiltrate data.
  • Violate intellectual property rights, privacy rights, confidentiality obligations, or contractual agreements.
  • Engage in any activity that violates local, state, federal, or international laws.
Authorized Use Only
Many cybersecurity tools demonstrated during training are powerful professional tools that have legitimate defensive and administrative purposes.
You agree to use such tools only:
  • On systems that you personally own; or
  • On systems for which you have explicit written authorization from the owner.
Possessing cybersecurity knowledge does not authorize you to test, scan, monitor, exploit, attack, or access any third-party system.
Open Source and Third-Party Software
Many of the software applications, utilities, frameworks, scripts, operating systems, penetration testing tools, forensic utilities, vulnerability scanners, AI tools, cloud utilities, and other technologies demonstrated during CertFirst courses are open-source, commercially licensed, or publicly available software created and maintained by independent third parties.
These tools are widely available throughout the cybersecurity industry and can often be downloaded directly from their original developers or publishers.
CertFirst does not develop, own, publish, control, or maintain many of these third-party tools and merely demonstrates their legitimate professional use within an educational setting.
Individual Responsibility
Each participant is solely responsible for how they use any knowledge, software, techniques, or tools learned through CertFirst.
CertFirst cannot monitor, supervise, or control how students use information after training has concluded.
Accordingly, each participant accepts full legal and personal responsibility for all actions taken before, during, and after completion of any CertFirst course.
Assumption of Risk
You acknowledge that cybersecurity education includes learning techniques that, if misused, may cause damage or violate applicable laws.
You voluntarily assume all risks associated with your use of the knowledge, software, laboratories, tools, demonstrations, and instructional materials provided by CertFirst.
No Authorization
Nothing contained within any CertFirst course, certification, book, laboratory, webinar, presentation, publication, video, website, or educational material shall be interpreted as granting permission to perform unauthorized security testing or other activities against any person, organization, or system.
Written authorization from the lawful owner is always required.
Limitation of Liability
To the fullest extent permitted by applicable law, CertFirst, its owners, officers, directors, employees, instructors, contractors, authors, publishers, affiliates, licensors, certification partners, training partners, vendors, resellers, distributors, volunteers, consultants, successors, and assigns shall not be liable for any direct, indirect, incidental, consequential, exemplary, punitive, special, or other damages, claims, losses, liabilities, costs, expenses, penalties, judgments, or legal actions arising from or related to:
  • The use or misuse of any knowledge acquired through CertFirst training.
  • The use or misuse of any cybersecurity tools demonstrated during training.
  • Unauthorized activities performed by any participant.
  • Any criminal or civil conduct committed by a participant.
  • Actions taken by participants after completion of training.
  • Third-party software or open-source tools referenced during training.
Indemnification
By enrolling in any CertFirst course, you agree to defend, indemnify, and hold harmless CertFirst and its owners, officers, employees, instructors, contractors, affiliates, certification partners, publishers, licensors, vendors, distributors, and training partners from and against any claims, lawsuits, investigations, damages, liabilities, settlements, judgments, fines, penalties, costs, and reasonable attorneys’ fees arising from:
  • Your violation of this policy.
  • Your unlawful or unauthorized activities.
  • Your misuse of cybersecurity knowledge or tools.
  • Your negligence or intentional misconduct.
  • Your violation of any applicable law or regulation.
No Endorsement of Illegal Activity
CertFirst expressly condemns and prohibits hacking, cybercrime, unauthorized access, ransomware, malware deployment, identity theft, fraud, phishing, denial-of-service attacks, data theft, extortion, and every other form of unlawful or unethical cyber activity.
Instruction involving offensive security techniques is provided exclusively so that cybersecurity professionals can better understand, detect, prevent, investigate, and defend against real-world attacks.
Right to Refuse or Terminate Access
CertFirst reserves the right to suspend or permanently terminate any student’s access to courses, laboratories, certifications, examinations, learning platforms, memberships, or other services if CertFirst reasonably believes that the participant has violated this policy or engaged in unlawful, unethical, abusive, or malicious conduct.
Governing Responsibility
Each participant acknowledges that they alone are responsible for complying with all applicable laws, regulations, employer policies, contractual obligations, licensing requirements, and professional ethical standards.
Any civil, criminal, administrative, or regulatory liability resulting from misuse of the training rests solely with the individual responsible for those actions and not with CertFirst or its training partners.
Acceptance of Agreement
By registering for, purchasing, accessing, attending, or participating in any CertFirst training program, certification, laboratory, webinar, workshop, mentoring session, coaching engagement, online course, self-paced course, instructor-led class, examination, or educational service, you acknowledge that you have read, understood, and agreed to be legally bound by this Cybersecurity Training Disclaimer, Acceptable Use Policy, Assumption of Risk, and Limitation of Liability Agreement.