Terms of Use
1. Nature and Scope of Assessment
This assessment is strictly limited to the passive observation and review of publicly accessible information associated with the target website. No unauthorized access, exploitation, or intrusion of any kind was performed or attempted.
The activities conducted under this assessment are limited to the following:
- Review of publicly visible HTTP/HTTPS response headers
- Inspection of SSL/TLS certificate configuration and validity
- Review of publicly accessible files such as robots.txt, sitemap.xml, and security.txt
- Passive DNS enumeration and WHOIS record review
- Analysis of publicly available technology stack indicators (e.g., server banners, meta tags)
- Review of cookie attributes and security flags as visible from a standard browser session
- Assessment of Content Security Policy (CSP), HSTS, and other security headers
The following activities were explicitly OUT OF SCOPE and were NOT performed:
- Active vulnerability scanning or exploitation
- Brute-force, fuzzing, or denial-of-service testing
- Access to any restricted, authenticated, or internal areas of the website
- Interception or capture of user traffic or credentials
- Any action requiring credentials, bypass of access controls, or elevated privileges
2. Legal Declaration & Compliance Notice
2.1 No Unauthorized Access
All information reviewed during this assessment was obtained exclusively from publicly accessible sources. No systems, accounts, or data were accessed without authorization. This assessment does not constitute unauthorized access under any applicable law, including but not limited to:
- Computer Fraud and Abuse Act (CFAA) — United States
- Computer Misuse Act 1990 — United Kingdom
- EU Directive on Attacks Against Information Systems (2013/40/EU)
- Applicable national cybersecurity and data protection legislation
2.2 No Data Collection or Retention
No personal data, user credentials, or confidential organizational information was collected, stored, or retained during this assessment. Any incidentally observed data was not recorded and is not referenced in this report.
2.3 Terms of Service Compliance
The assessor confirms that this assessment was conducted in a manner consistent with the target website's publicly published Terms of Service, where applicable. Automated scanning tools, if used, were operated within rate limits and in a manner designed to avoid service disruption.
2.4 Responsible Disclosure
Any security vulnerabilities identified during this assessment will be handled in accordance with responsible disclosure principles. Findings will not be published, shared, or disclosed to any third party without the prior written consent of the target organization, or until a reasonable remediation period has elapsed in accordance with coordinated vulnerability disclosure (CVD) guidelines.
3. Limitation of Liability
This assessment represents the findings and opinions of the assessor based on information available at the time of review. The assessor makes no representations or warranties, express or implied, regarding:
- The completeness or exhaustiveness of the assessment findings
- The absence of vulnerabilities not identified during this review
- The accuracy of third-party data sources referenced herein
- The continued validity of findings after the assessment date
The assessor shall not be held liable for any damages, losses, or legal consequences arising from the use, reliance upon, or implementation of recommendations contained within this report. The organization is solely responsible for its own security decisions and remediation actions.
4. Confidentiality & Distribution
This document and its contents are strictly confidential. It is intended solely for the use of the named recipient(s) and authorized personnel within the target organization. Unauthorized copying, distribution, or disclosure of this document — in whole or in part — is strictly prohibited without the prior written consent of the assessor.
If you have received this document in error, please notify the assessor immediately and destroy all copies in your possession.
5. Authorization & Consent
By commissioning or accepting this assessment, the recipient organization acknowledges and confirms that:
- They are the owner, operator, or authorized representative of the assessed website
- They have the legal authority to authorize this assessment
- They have read and understood the scope and limitations described herein
- They accept the findings are provided in good faith for informational and remediation purposes only