Skip to content
weftsecurity
Services ⌄
Application security servicesSpecialist help from code review to runtime protection.Explore all services →
⌘Code & supply chainSAST, dependencies, secrets and code audits◇Delivery infrastructureCI/CD, SCM, cloud, containers and IaC◎Application testingWeb, API and mobile penetration testing◉Runtime protectionContainer and workload prevention and detection↗Ways to engageOne-time, ongoing or partner delivery↔How we workFit security into your delivery environment
Who we help ⌄
For teams responsible for software securitySoftware businessesB2B, fintech, healthtech and legaltechConnected productsIoT, OT and embedded softwareService partnersAgencies, MSPs, vCISOs and consultants
How we workTrustFAQ
Email usDiscuss your application

Legal

Terms of Service

Effective September 21, 2026

WEFT Security

Application-security services for authorized defensive work.

jawad@weftsecurity.com

These Terms govern use of the WEFT Security website and any application-security assessment, testing, review, remediation, advisory, or related professional service we provide. A signed proposal, statement of work, or order may add to or replace these Terms for a specific engagement.

1. Authority and authorized scope

You must be able to enter into a contract and, when acting for an organization, have authority to bind it. You may ask us to access or test only systems, code, applications, accounts, environments, and data you own or are explicitly authorized to assess. The written scope, timing, techniques, exclusions, access, contacts, and emergency procedure for an engagement must be agreed before work begins.

2. Our services

Services may include web, API, or mobile penetration testing; code and supply-chain review; SAST and remediation; CI/CD, SCM, signing, cloud, container, secret, or IaC review; runtime assessment and protection support; retesting; and related advisory work. The exact deliverables, schedule, dependencies, and acceptance terms are stated in the applicable proposal or order.

3. Your responsibilities

You will provide accurate scope and architecture information, necessary approvals, suitable test accounts and access, backups where relevant, a technical contact, and timely notice of changes that could affect safety or results. You remain responsible for operating your systems, reviewing recommendations, approving production changes, and deciding how to treat residual risk.

4. Safe and lawful use

Neither party may use the services to attack an unauthorized third party, introduce malware, evade access controls, conduct unlawful surveillance, disrupt systems outside the agreed test, violate privacy, or infringe intellectual-property rights. We may pause work when authorization is unclear or continued testing could create material harm.

5. Fees and payment

Fees, currency, taxes, expenses, payment dates, milestones, and cancellation terms are stated in the applicable proposal, order, or invoice. Unless that document states otherwise, work outside the agreed scope requires written approval and may require a revised fee or schedule.

6. Changes, cancellation, and rescheduling

Either party may request a scope or schedule change. Its effect on fees, timing, and deliverables must be agreed in writing. Cancellation, rescheduling, deposits, completed work, and non-recoverable costs are handled under the applicable proposal or order and any mandatory law.

7. Confidential information and data

Each party will use reasonable measures to protect the other party’s non-public information and use it only for the relationship. You retain ownership of your code, systems, data, and materials. You grant us the limited right to access and process them only as needed to deliver, secure, document, and administer the authorized engagement. Personal-data handling is described in our Privacy Policy.

8. Access and third-party tools

We will use agreed access methods and limit credentials and privileges to the task. Security tools, hosting providers, collaboration services, or customer-directed integrations may be subject to their own terms. We will not intentionally send sensitive customer material to a third party outside the agreed delivery method.

9. Deliverables and intellectual property

After payment of applicable fees, you may use engagement-specific reports and deliverables for your internal business, remediation, assurance, and authorized client purposes. WEFT retains rights in its pre-existing methods, templates, tools, software, know-how, and general improvements. Third-party and open-source materials remain subject to their own licenses.

10. Findings and limitations

Security work is time-bound and scope-bound. Results can include false positives, false negatives, incomplete coverage, environmental uncertainty, or risks introduced after testing. A report, retest, or control does not guarantee that a system has no vulnerabilities, will remain secure, meets every compliance duty, or will resist every attack. Certification, legal advice, and independent audit opinions are not provided unless explicitly stated by a qualified party.

11. Warranties and liability

We will perform agreed services with reasonable care and skill. Except where law or a signed order requires otherwise, other warranties are disclaimed. To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages. WEFT’s aggregate liability arising from an engagement will not exceed the fees paid for that engagement during the twelve months before the event giving rise to the claim. Limits do not apply where prohibited by law.

12. Termination

Either party may terminate for a material breach that is not cured within a reasonable written cure period, or immediately where continued work would be unlawful or create a material security risk. Payment, confidentiality, ownership, disclaimers, liability limits, and other provisions that should survive will continue after termination.

13. Changes and contact

We may update these website Terms and will post the revised effective date. A signed engagement document in force is not changed by a later website update unless the parties agree. Questions may be sent to jawad@weftsecurity.com.

weftsecurity

Application security handled across code, delivery infrastructure, exposed applications, and runtime.

Discuss your applicationBook a call
ServicesCode & supply chainDelivery infrastructureWeb, API & mobile testingRuntime protection
EngagementsOne-time assessmentOngoing AppSecPartner deliveryHow we work
CompanyWho we helpTrustFAQContact
LegalTerms of servicePrivacy policyLegal questions
© 2026 WEFT Security. Authorized defensive security use only.
EmailLinkedInBack to top ↑