Terms of Service.
These terms cover the website. Every engagement is governed by its own signed agreement, scope and rules of engagement, which take precedence.
Last updated 1 October 2026
Using this site
You may read, share and link to anything on this site. The content is general information about security practice, not advice on your specific systems.
Authorisation to test
We only test systems we are authorised in writing to test. Before any testing starts, the system owner (or someone with authority to act for them) signs a scope and rules of engagement setting out:
- the systems, applications and addresses in scope, and anything explicitly excluded;
- testing windows, rate limits and any techniques that are not permitted;
- emergency contacts on both sides and how testing is paused;
- confirmation that any third-party hosting or platform terms permit the testing.
We will not test a system you do not own or control, or that a third party has not authorised, whatever the request.
Estimates
The estimator on this site gives an indicative range from a few answers. It is a starting point for a conversation, not an offer, and nothing is binding on either side until there is a signed written proposal.
Engagements
Each engagement is governed by a signed agreement covering scope, fees, timing, confidentiality, liability and data handling. Where that agreement and these terms differ, the agreement wins.
What testing can and cannot show
A penetration test or audit reflects the state of the systems in scope, during the testing window, using the time and access agreed. It reduces risk; it cannot prove the absence of every vulnerability, and new weaknesses appear as systems and threats change. Our reports say plainly what was and was not covered.
Compliance and certification
We prepare organisations for SOC 2 examinations, ISO/IEC 27001 certification and PCI DSS assessments. We do not issue SOC 2 reports, ISO certificates or PCI Reports on Compliance; those are issued by licensed CPA firms, accredited certification bodies and Qualified Security Assessors respectively.
Confidentiality
Findings, reports and anything learned about your systems are confidential. We never publish or present client findings in identifiable form. The engagements on this site are representative composites with details changed.
Vulnerabilities in third-party products
If we find a vulnerability in a third-party product while testing your systems, we tell you first and agree how to report it to the vendor through coordinated disclosure. We do not disclose publicly without your agreement.
Ownership
You own the reports delivered to you once they are paid for. We keep ownership of our methods, tools and templates.
Liability
The website is provided as is. Liability for engagements is set out in the signed agreement for each one.
Governing law
These terms are governed by the laws of the Province of Alberta and the federal laws of Canada that apply there.