These Terms govern use of the WEFT Security website and any application-security assessment, testing, review, remediation, advisory, or related professional service we provide. A signed proposal, statement of work, or order may add to or replace these Terms for a specific engagement.
1. Authority and authorized scope
You must be able to enter into a contract and, when acting for an organization, have authority to bind it. You may ask us to access or test only systems, code, applications, accounts, environments, and data you own or are explicitly authorized to assess. The written scope, timing, techniques, exclusions, access, contacts, and emergency procedure for an engagement must be agreed before work begins.
2. Our services
Services may include web, API, or mobile penetration testing; code and supply-chain review; SAST and remediation; CI/CD, SCM, signing, cloud, container, secret, or IaC review; runtime assessment and protection support; retesting; and related advisory work. The exact deliverables, schedule, dependencies, and acceptance terms are stated in the applicable proposal or order.
3. Your responsibilities
You will provide accurate scope and architecture information, necessary approvals, suitable test accounts and access, backups where relevant, a technical contact, and timely notice of changes that could affect safety or results. You remain responsible for operating your systems, reviewing recommendations, approving production changes, and deciding how to treat residual risk.
4. Safe and lawful use
Neither party may use the services to attack an unauthorized third party, introduce malware, evade access controls, conduct unlawful surveillance, disrupt systems outside the agreed test, violate privacy, or infringe intellectual-property rights. We may pause work when authorization is unclear or continued testing could create material harm.
5. Fees and payment
Fees, currency, taxes, expenses, payment dates, milestones, and cancellation terms are stated in the applicable proposal, order, or invoice. Unless that document states otherwise, work outside the agreed scope requires written approval and may require a revised fee or schedule.
6. Changes, cancellation, and rescheduling
Either party may request a scope or schedule change. Its effect on fees, timing, and deliverables must be agreed in writing. Cancellation, rescheduling, deposits, completed work, and non-recoverable costs are handled under the applicable proposal or order and any mandatory law.
7. Confidential information and data
Each party will use reasonable measures to protect the other party’s non-public information and use it only for the relationship. You retain ownership of your code, systems, data, and materials. You grant us the limited right to access and process them only as needed to deliver, secure, document, and administer the authorized engagement. Personal-data handling is described in our Privacy Policy.
8. Access and third-party tools
We will use agreed access methods and limit credentials and privileges to the task. Security tools, hosting providers, collaboration services, or customer-directed integrations may be subject to their own terms. We will not intentionally send sensitive customer material to a third party outside the agreed delivery method.
9. Deliverables and intellectual property
After payment of applicable fees, you may use engagement-specific reports and deliverables for your internal business, remediation, assurance, and authorized client purposes. WEFT retains rights in its pre-existing methods, templates, tools, software, know-how, and general improvements. Third-party and open-source materials remain subject to their own licenses.
10. Findings and limitations
Security work is time-bound and scope-bound. Results can include false positives, false negatives, incomplete coverage, environmental uncertainty, or risks introduced after testing. A report, retest, or control does not guarantee that a system has no vulnerabilities, will remain secure, meets every compliance duty, or will resist every attack. Certification, legal advice, and independent audit opinions are not provided unless explicitly stated by a qualified party.
11. Warranties and liability
We will perform agreed services with reasonable care and skill. Except where law or a signed order requires otherwise, other warranties are disclaimed. To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages. WEFT’s aggregate liability arising from an engagement will not exceed the fees paid for that engagement during the twelve months before the event giving rise to the claim. Limits do not apply where prohibited by law.
12. Termination
Either party may terminate for a material breach that is not cured within a reasonable written cure period, or immediately where continued work would be unlawful or create a material security risk. Payment, confidentiality, ownership, disclaimers, liability limits, and other provisions that should survive will continue after termination.
13. Changes and contact
We may update these website Terms and will post the revised effective date. A signed engagement document in force is not changed by a later website update unless the parties agree. Questions may be sent to jawad@weftsecurity.com.