Terms
The rules the testing runs under. They are short on purpose — if a term here would surprise you, it should not be in the contract.
Authorisation
We test a domain only after someone with authority to permit it has signed the consent form in the client portal. That signature records a name, a job title, a timestamp and an IP address.
By signing, you confirm you own the domain or are authorised by its owner to permit testing of it. If that is not true, do not sign — we have no way of verifying it from the outside, and testing without authority is your liability, not ours.
Consent can be withdrawn at any time by telling us. Withdrawal stops future checks; it does not undo a check already carried out.
Scope
The check covers your public-facing web front end and the API endpoint that front end is configured to talk to. It does not cover your internal network, your staff devices, your email, or any third-party service you use.
All requests are reads, made at ordinary visitor volume, using credentials your own site publishes. We do not write, update or delete records, do not attempt to authenticate, and do not run anything designed to degrade availability.
Findings
Findings describe what your systems returned at the moment of the check. They are not a warranty that your systems are secure, and a clean result is not a certification.
Security changes as you ship. A check is a snapshot, which is why re-testing exists.
Acting on the remediation steps is yours to do. We will explain a fix and we will re-test it, but we do not make changes to your systems.
Confidentiality
What we find is yours. We do not publish it, disclose it to third parties, or identify you as a customer without your written agreement.
Research we publish under our own name is drawn from our own work and never from a client's findings.
Payment
Prices are agreed in writing before a report is produced, and you see the risk level of the result before you decide whether to buy the report.
One-off reports are payable in full. Ongoing monitoring is billed monthly for the agreed term and can be cancelled in line with what was agreed at the point of sale.
Liability
We take responsibility for carrying out the check competently and within the scope above.
We are not liable for a breach that occurs through a route the check does not cover, for changes you make after a check, or for losses arising from a fix you chose not to apply.
Governing law and the contracting entity are published here once the trading entity for Infinity Security is confirmed. These terms are reviewed before the site is put in front of paying customers.