Penetration Testing Terms of Service
NightShift, operated by Skripted LLC
By checking the box and placing an order, you agree to these terms. Please read them before ordering a penetration test. If you do not agree, do not place an order.
1. What we do
We perform automated black-box penetration testing against the systems and assets you specify, and deliver a written report of our findings. We identify vulnerabilities; we do not fix them. Implementing any remediation is your responsibility.
2. Rules of engagement
We test only the targets and methods you authorize. We do not perform denial-of-service testing unless you explicitly authorize it, and we do not extract data beyond what is needed to demonstrate a vulnerability. We do not perform social engineering, physical access, or insider-threat testing. We will halt testing immediately if you ask us to.
3. Authorization to test, and your ownership of the target
You must define the exact scope of the test (domains, IP addresses, and applications) before testing begins. By submitting that scope, you represent and warrant that you either own the target systems or have explicit written authorization from the owner to have them tested.
You authorize us to perform security testing against that defined scope, during the time window we agree on. This authorization is limited to the scope you provide. You are solely responsible for any consequences of authorizing testing against systems you do not have the right to test, and you will indemnify us against any claim arising from such authorization.
4. Risks you accept
Penetration testing carries inherent risk. Although we take reasonable care to minimize impact, testing can in rare cases cause service disruption, performance degradation, or data issues. You are responsible for maintaining current backups before testing starts. We are not liable for downtime, data loss, or other consequences resulting from testing performed within the authorized scope.
5. Excluded systems
You will not include in scope, and we will not test, any system where the use or failure of that system could lead to death, personal injury, or environmental damage. This includes life-support systems, emergency services, nuclear facilities, autonomous vehicles, and air traffic control systems.
6. Your data and our report
Findings may include sensitive information about your systems. We treat your data as confidential and use it only to deliver your report. The report is provided for your internal use.
Our service is not designed to store sensitive personal data (for example, health records, payment card data, or government identification numbers). You should not deliberately provide such data to us. We may retain anonymized, non-identifying technical data derived from the engagement to maintain and improve our service.
Our testing uses third-party AI services to analyze results. Target response data (such as URLs, headers, and response bodies) may be processed by these providers under their own terms. We do not intentionally send credentials or secrets discovered during testing to these providers. By placing an order, you consent to this processing.
7. No guarantee of security
The service is provided on an "as is" and "as available" basis. We warrant only that the testing will be performed in a professional and workmanlike manner. We make no other warranties, express or implied, including any implied warranty of merchantability or fitness for a particular purpose. We do not warrant that the testing will identify every vulnerability, or that your systems are or will be secure. A clean or partial report reflects findings at a single point in time and is not a warranty of security.
8. Payment, refunds, and cancellation
Fees are as listed at the time of purchase. Report packages must be used within 12 months of purchase; unused reports expire at the end of that period.
Before testing starts. You may cancel a report before testing of that report begins and receive a full refund for it.
Once testing starts. Once we have begun testing a specific report, the fee for that report is non-refundable, because our costs and effort are committed at that point.
Unused reports in a package. For multi-report packages, you may request a refund for any unused reports within 30 days of purchase. After 30 days, unused reports remain usable until the 12-month expiry but are no longer refundable.
Rescheduling. A scheduled test may be rescheduled by mutual agreement between you and us.
9. Limitation of liability
To the maximum extent permitted by law, our total aggregate liability arising out of or related to an engagement will not exceed the amount you paid for that engagement. We will not be liable for any lost profits, loss of data, or any indirect, incidental, special, punitive, or consequential damages, regardless of whether we were advised of the possibility of such damages.
10. Acceptable use
You will not use our findings or report for any unlawful purpose, or to test, access, or interfere with any system outside the authorized scope.
11. Changes to these terms
We may update these terms from time to time. The version in effect at the time of your purchase applies to your engagement.
12. Governing law and dispute resolution
These terms are governed by the laws of the State of New York, USA, without regard to its conflict-of-laws rules.
Any dispute arising out of or relating to these terms or an engagement will be resolved by binding arbitration seated in New York, New York, rather than in court. Judgment on the arbitration award may be entered in any court of competent jurisdiction.
To the extent permitted by law, disputes will be resolved only on an individual basis, and you waive any right to bring or participate in a class, collective, or representative action.