⚠️ Template — not legal advice. Have a qualified lawyer review and adapt this before commercial use.

Audit Mandate & Terms of Service

Version 0.1 — draft

1. Authorization to test (the Mandate)

By verifying ownership of a domain and signing a mandate, you (the "Client") expressly authorize SecurScan to perform non-destructive security testing against the systems reachable at the domain(s) listed in the mandate scope, for the mandate's validity period. This authorization covers passive reconnaissance, active but read-only probing (GET requests only), authenticated testing with credentials you provide, and adversarial testing of AI/LLM endpoints you designate.

The tests are designed to avoid data modification or destruction. SecurScan will not knowingly issue state-changing requests (create, update, delete) and filters URLs that appear destructive. You acknowledge that any active security testing nonetheless carries inherent risk.

2. Client responsibilities

3. Scope & safety controls

Testing is confined to the mandate scope. Active and authenticated tests are GET-only, exclude URLs matching destructive keywords, and refuse to run against environments flagged as production. Requests resolving to private/internal address space are blocked.

4. Data handling & confidentiality

Findings and evidence are treated as confidential. You should ensure no real personal data is exposed to the scanner. If real personal data is encountered due to a misconfiguration on your side, you remain the data controller and are responsible for any resulting obligations.

5. Limitation of liability

Security testing is provided on a best-effort basis. To the maximum extent permitted by law, SecurScan is not liable for indirect or consequential damages, service disruption, or data loss arising from testing you authorized, particularly where you provided inaccurate scope or ran tests against production contrary to these terms.

6. No guarantee of completeness

A clean report does not guarantee the absence of vulnerabilities. Automated testing complements but does not replace a manual penetration test.

← Back to SecurScan