Terms of the Free Website Security Check

Standard terms on which the Operator checks the security of a website free of charge. If no vulnerabilities are found, the report on the check is free of charge as well. If vulnerabilities are found, the client learns their number and severity free of charge and may buy the report on them at a fixed price stated in advance. The check is offered to businesses.

1.Definitions

1.1

In these Terms the following terms have the following meaning:

  1. (a)“Operator” means Osaühing Ida Portal, registry code 10970449, registered office: Kivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia, which provides its services under the name Security Test Team;
  2. (b)“Client” means the legal person, or the natural person acting in the course of his or her business or profession, who has concluded the Contract with the Operator;
  3. (c)“Operator’s Website” means the website securitytest.team;
  4. (d)“Client Website” means the website named in the Authorisation, within the domain names listed in the Authorisation;
  5. (e)“Request” means the application for a Check, sent through the form on the Operator’s Website or by email;
  6. (f)“Authorisation” means the document which the Operator draws up for a Client Website on the basis of a Request, which refers to these Terms and names the Client, the Client Website, the period of the Check, the network addresses the Check is performed from and the contact persons of the parties, and by whose signature the Client permits the Check and accepts the offer of the Operator;
  7. (g)“Check” means the external examination of the security of the Client Website described in Section 5;
  8. (h)“Finding” means a vulnerability of the Client Website that a specialist of the Operator has confirmed;
  9. (i)“Severity” means the qualitative rating of a Finding under the Common Vulnerability Scoring System, version 4.0: low, medium, high or critical;
  10. (j)“Check Report” means the report on a Check that has identified no Findings;
  11. (k)“Notice” means the document which informs the Client of the Findings and of the Price;
  12. (l)“Findings Report” means the report which describes every Finding in the detail necessary to reproduce and to remedy it;
  13. (m)“Price” means the price of the Findings Report stated in the Notice;
  14. (n)“Retest” means the examination of whether the Findings described in the Findings Report have been remedied;
  15. (o)“Contract” means the contract for the Check concluded between the Operator and the Client on these Terms.

2.Nature and subject of these Terms

2.1

These Terms are the standard terms on which the Operator concludes the Contract. They become part of the Contract when the Client signs the Authorisation, which refers to them.

2.2

The description of the Check on the Operator’s Website, these Terms included, is an invitation to make offers. The offer of the Operator is the Authorisation it sends to a particular requester.

2.3

The Check is offered to businesses: to legal persons and to natural persons who act in the course of their business or profession. The Operator does not conclude the Contract with consumers. By sending the Request and by signing the Authorisation the Client confirms that it acts in the course of its business or profession.

2.4

Under the Contract the Operator performs the Check free of charge and provides the Client with the Check Report or with the Notice, and the Client has the right, but not the obligation, to buy the Findings Report at the Price.

2.5

The first Check of a Client Website is free of charge. A further Check of the same Client Website requires the consent of the Operator.

2.6

Services other than the Check, the Findings Report and the Retest are provided under a separate contract.

3.Conclusion of the Contract

3.1

The person who wishes to have a website checked sends a Request through the form on the Operator’s Website or by email to info@securitytest.team and names the website to be checked. Before the form is sent, the requester can review and correct every entry; the form names the entries that are missing or invalid.

3.2

The Operator examines the Request and replies within 1 business day. If the Request can be fulfilled, the Operator sends the Authorisation for signature.

3.3

The Authorisation is signed by a person entitled to represent the Client, either by hand or with a qualified electronic signature within the meaning of Regulation (EU) No 910/2014, such as the Estonian digital signature given with an identity card, Mobile-ID or Smart-ID, or a signature given with a European Digital Identity Wallet. The parties agree that a signature given in one of these ways satisfies the form they have agreed for the Contract.

3.4

The Contract is concluded at the moment the signed Authorisation reaches the Operator. The Operator confirms the conclusion by email and sends the Client a copy of the signed Authorisation and of these Terms in the version in force on that day. The Operator keeps the signed Authorisation for the period stated in the Privacy Policy.

3.5

The Contract is concluded in the language of the Operator’s Website that the Client has used for the Request, or in English. The Authorisation states the language.

3.6

Until the Contract is concluded, the Operator may decline a Request, in particular where:

  1. (a)the right of the requester to dispose of the website is not confirmed;
  2. (b)the requester does not act in the course of its business or profession;
  3. (c)the website is used for an activity prohibited by law;
  4. (d)the Check would require actions that these Terms exclude;
  5. (e)the conclusion of the Contract would breach the law or an international sanction;
  6. (f)the Operator has no capacity to perform the Check within a reasonable time.

4.Authority of the Client

4.1

By signing the Authorisation the Client represents and warrants that:

  1. (a)the Client is the owner of the Client Website or has been authorised by its owner to permit the Check;
  2. (b)the person who signs the Authorisation is entitled to represent the Client;
  3. (c)the rules on security testing of the hosting, cloud and software-as-a-service providers with which the Client Website is placed permit the Check, or those providers have consented to it;
  4. (d)the Check does not breach the rights of third parties or the obligations of the Client towards them.

4.2

Where the Client Website is placed with a hosting, cloud or other provider whose rules require that security testing be notified or consented to, the Client notifies the provider or obtains its consent before the Check starts.

4.3

The Operator may require the Client to confirm its control over the Client Website, in particular by placing a file or a domain name record specified by the Operator.

4.4

The Client compensates the Operator for the damage caused by the fact that a representation or warranty of this section proves untrue, including the claims of third parties.

5.The Check

5.1

The Check is performed from the internet, the way a visitor sees the Client Website: without user accounts and without access to the servers, the source code or the internal network of the Client.

5.2

The Check covers:

  1. (a)the configuration of HTTPS and TLS: protocol versions, certificates and redirects;
  2. (b)security headers and the attributes of cookies;
  3. (c)files and interfaces exposed to the internet: backup copies, configuration files, folders of version control systems, administration panels and debugging pages;
  4. (d)the content management system, its extensions, the frameworks and the server software with publicly known vulnerabilities;
  5. (e)public forms and parameters: injection and cross-site scripting, tested with harmless probes;
  6. (f)the pages of login, registration and password recovery: protection against guessing and against the enumeration of accounts;
  7. (g)information disclosed by error messages, source maps and metadata;
  8. (h)the domain name records that protect against forged email: SPF, DKIM and DMARC.

5.3

The Check is performed by the methods of the OWASP Web Security Testing Guide. Automated tools are used to map the Client Website; every Finding is confirmed by a specialist of the Operator.

5.4

The Check does not include and the Operator does not perform:

  1. (a)denial-of-service attacks and load testing;
  2. (b)social engineering against the staff, the clients or the contractors of the Client;
  3. (c)physical access to premises and equipment;
  4. (d)the deletion, alteration or encryption of the data of the Client Website;
  5. (e)access to personal data beyond the minimum necessary to confirm a Finding, and the copying of such data;
  6. (f)the examination of systems that are not named in the Authorisation, including the services of third parties that the Client Website uses;
  7. (g)examination with user accounts, examination of the internal functions of the Client Website and review of its source code.

5.5

The Operator performs the Check and provides the Client with the Check Report or with the Notice in 1 to 5 business days after the authorisation is signed. Within these limits the period depends on the workload of the Operator and on the complexity of the Client Website.

5.6

If the Client Website becomes unstable during the Check, the Operator suspends the Check and informs the contact person of the Client without delay.

5.7

The Client may stop the Check at any time by a notice to the Operator. The Operator stops the Check at once after it has received the notice.

5.8

If the Operator finds signs that a third party has already gained unauthorised access to the Client Website, the Operator informs the Client without delay and free of charge and provides the information the Client needs in order to respond.

6.Result of the Check

6.1

If the Check identifies no Findings, the Operator provides the Client with the Check Report free of charge. The Check Report describes what was checked, in which period, by which methods and with what result.

6.2

If the Check identifies Findings, the Operator provides the Client with the Notice free of charge. The Notice states:

  1. (a)the number of the Findings;
  2. (b)the Severity of every Finding and the vector from which it follows;
  3. (c)the class of every Finding and the part of the Client Website it concerns;
  4. (d)the evidence that every Finding exists, without the details that would make it possible to reproduce the Finding;
  5. (e)the Price;
  6. (f)the period for which the Price is valid.

6.3

The Severity is determined under the Common Vulnerability Scoring System, version 4.0, as published by the Forum of Incident Response and Security Teams (FIRST). The vector stated in the Notice allows the Client to verify the rating.

6.4

The receipt of the Notice does not oblige the Client to buy the Findings Report.

7.The Findings Report and the Price

7.1

The Operator determines the Price on the basis of the number of the Findings and the Severity of each of them. The Price is stated in the Notice as a fixed amount in euros and does not change after the Notice has been sent.

7.2

The Price is the price of the Findings Report alone, which is delivered in full at once. The Retest is a separate commitment of the Operator, given free of charge, and is not part of what the Price pays for.

7.3

The Price is valid for 30 days from the day the Notice is sent. During that period the Notice is a binding offer of the Operator to provide the Findings Report at the Price.

7.4

The Client accepts the offer of the Notice by a written confirmation, for which an email is sufficient, that names the Notice and the Price. The Operator then issues the invoice.

7.5

The invoice is paid by bank transfer to the account stated in it. The payment is made when the amount has been credited to the account of the Operator. The Price does not include value added tax; the tax is charged where the law requires it, and the invoice states where it is payable by the Client under the reverse charge. Each party bears the charges of its own bank.

7.6

The Operator delivers the Findings Report immediately after the payment has been received, through a secure channel agreed with the Client.

7.7

For every Finding the Findings Report contains:

  1. (a)a description of the Finding and the part of the Client Website it concerns;
  2. (b)the evidence and the steps to reproduce the Finding;
  3. (c)the vector and the score under the Common Vulnerability Scoring System, version 4.0, and the class under the Common Weakness Enumeration;
  4. (d)the consequences the exploitation of the Finding may have;
  5. (e)recommendations on how to remedy the Finding.

7.8

After the Client has remedied the Findings, the Operator performs the Retest of every Finding free of charge. The Client requests the Retest within 60 days of the report. The Operator communicates the result of the Retest in writing.

7.9

If the Client does not accept the offer of the Notice while the Price is valid, the offer lapses and the Client owes the Operator nothing. After that the Findings Report can be bought by agreement of the parties.

7.10

If the Operator does not deliver the Findings Report after the payment, the Client may withdraw from its purchase, and the Operator returns the amount paid without delay. This does not affect the other remedies the law gives the Client.

8.Obligations of the parties

8.1

The Operator:

  1. (a)performs the Check with the care and the skill of a professional and within the limits of these Terms and of the Authorisation;
  2. (b)uses the least intrusive action that confirms a Finding;
  3. (c)keeps the information it has obtained confidential in accordance with Section 10;
  4. (d)names a contact person who can be reached during the Check.

8.2

The Client:

  1. (a)provides accurate information about itself and about the Client Website;
  2. (b)names a contact person who can be reached during the Check;
  3. (c)makes sure before the Check starts that a current backup copy of the Client Website exists;
  4. (d)informs the Operator without delay of changes to the Client Website during the Check and of every circumstance that may affect the Check;
  5. (e)uses the Check Report, the Notice and the Findings Report in accordance with Section 9.

9.Rights to the results

9.1

The economic rights of the author in the Check Report, the Notice and the Findings Report belong to the Operator.

9.2

From the moment of delivery of the Check Report, and from the moment of payment for the Findings Report, the Client receives a non-exclusive licence, unlimited in time and territory, to use the document for its own needs: to remedy the Findings, for internal purposes and for disclosure to its auditors, insurers, supervisory authorities and the contractors who remedy the Findings, provided that they are bound by confidentiality.

9.3

The Client does not present the Check Report or the Findings Report as a guarantee or a certificate of the security of the Client Website and does not quote them in a way that misleads about the scope, the period or the result of the Check.

9.4

The methods, the tools and the know-how of the Operator remain with the Operator.

10.Confidentiality

10.1

The Operator keeps confidential the Findings and all other information about the Client and the Client Website that it has obtained in connection with the Contract. The obligation is not limited in time.

10.2

The Operator does not disclose the Findings to third parties, does not publish them and does not use them for any purpose other than the performance of the Contract. This applies equally where the Client does not buy the Findings Report.

10.3

The Operator does not name the Client as its client without the written consent of the Client.

10.4

The obligation of confidentiality does not apply to information that the Operator is obliged to disclose by law or by a binding decision of a court or an authority. The Operator discloses such information to the extent required and, where the law permits, informs the Client beforehand.

10.5

The Operator destroys the working data of the Check 30 days after the engagement is closed. The engagement is closed on the day the Check Report is delivered, on the day the Price ceases to be valid without the Client having accepted the offer of the Notice, or on the day the result of the Retest is communicated or the period for requesting the Retest expires.

10.6

The measures by which the Operator protects the information of the Client are set out in the Information Security Policy.

11.Personal data

11.1

Each party processes the personal data of the representatives and the contact persons of the other party as an independent controller, for the conclusion and the performance of the Contract. The Operator processes such data in accordance with its Privacy Policy.

11.2

The Check is not aimed at personal data. If the Operator nevertheless obtains access to personal data contained in the Client Website, it processes that data on behalf of the Client as a processor within the meaning of Article 28 of Regulation (EU) 2016/679, and the Client is the controller. This section then is the contract required by that Article.

11.3

The subject matter and the duration of the processing are the Check and the Retest; its nature and purpose is the confirmation of Findings; the personal data and the data subjects are those to which the Finding gives access, as a rule the users of the Client Website.

11.4

As a processor, the Operator:

  1. (a)processes personal data only on the documented instructions of the Client, which are contained in the Contract and in the Authorisation, and transfers personal data outside the European Economic Area only on such instructions and in accordance with Chapter V of Regulation (EU) 2016/679, unless it is required to do so by Union or Member State law to which the Operator is subject; in such a case the Operator informs the Client of that legal requirement before processing, unless that law prohibits it;
  2. (b)immediately informs the Client if, in its opinion, an instruction infringes Regulation (EU) 2016/679 or other data protection provisions of the Union or of a Member State;
  3. (c)ensures that the persons authorised to process personal data are bound by confidentiality;
  4. (d)takes the measures required by Article 32 of Regulation (EU) 2016/679;
  5. (e)engages as sub-processors the providers named in the Privacy Policy, at present Cloudflare, Inc. for hosting and for the storage of data in the European Union, under the general written authorisation the Client gives by concluding the Contract; informs the Client by email of an intended change of the sub-processors before it takes effect, so that the Client can object to it and, if the Operator maintains the change, terminate the Contract; and imposes on every sub-processor the same data protection obligations as this section imposes on the Operator;
  6. (f)assists the Client in answering the requests of data subjects and in meeting the obligations of Articles 32 to 36 of Regulation (EU) 2016/679;
  7. (g)notifies the Client without undue delay after it has become aware of a personal data breach;
  8. (h)does not copy personal data, masks it in the evidence so that the Notice contains none, does not send it by email or through messengers, and delivers the Findings Report only through the secure channel of Section 7;
  9. (i)when the engagement is closed, deletes the personal data or returns it to the Client, at the choice of the Client, and deletes the existing copies, unless Union or Member State law requires the storage of the personal data;
  10. (j)makes available to the Client the information necessary to demonstrate compliance with this section and allows for audits by the Client or by an auditor the Client has mandated.

12.Warranties and liability

12.1

The Check is limited in its period, its scope and its methods. The fact that the Check has identified no Findings does not mean that the Client Website has no vulnerabilities. The Check Report and the Findings Report are not a guarantee that the Client Website cannot be compromised.

12.2

The Operator is liable without limitation for damage it has caused intentionally or through gross negligence, and for death, bodily injury and damage to health.

12.3

In all other cases, the following applies:

  1. (a)since the Check is performed free of charge, the Operator is not liable for damage caused in the course of the Check through ordinary negligence, unless the damage results from an action that Section 5 excludes;
  2. (b)the total liability of the Operator in connection with the Findings Report and the Retest is limited to the Price paid by the Client;
  3. (c)the Operator is not liable for loss of profit and indirect damage, for damage caused by third parties who exploit a vulnerability of the Client Website, for a failure of the Client Website caused by its condition where the Operator has acted within the limits of Section 5, or for the consequences of the fact that the Client has not remedied a Finding or has remedied it otherwise than recommended.

12.4

A party is not liable for a breach caused by force majeure: a circumstance beyond its control which it could not reasonably have been expected to take into account, to avoid or to overcome.

13.Term and termination

13.1

The Contract enters into force at the moment it is concluded and remains in force until the parties have performed their obligations.

13.2

Until the Client has accepted the offer of the Notice, the Client may terminate the Contract at any time by a notice to the Operator, without stating reasons and without any payment.

13.3

The Operator may terminate the Contract by a notice to the Client where:

  1. (a)a representation or warranty of the Client proves untrue;
  2. (b)the Client requires actions that these Terms exclude;
  3. (c)the continuation of the Check would breach the law or the rights of third parties.

13.4

The provisions on the rights to the results, confidentiality, personal data, liability, governing law and jurisdiction remain in force after the Contract has ended.

14.Governing law and jurisdiction

14.1

The Contract is governed by the law of the Republic of Estonia.

14.2

The parties seek to resolve a dispute by negotiation. A claim is made in writing, and the party that has received it answers without undue delay.

14.3

A dispute that is not resolved by negotiation is resolved by the court of the Republic of Estonia in whose jurisdiction the registered office of the Operator is located.

15.Final provisions

15.1

The Operator may change these Terms. A change applies to Contracts concluded after it has taken effect; a Contract is governed by the version of these Terms that was in force on the day the Authorisation was signed.

15.2

The Contract consists of the Authorisation, these Terms and, where it has been sent, the Notice. If the Authorisation differs from these Terms, the Authorisation prevails.

15.3

Notices under the Contract are sent by email: to the Operator at the address stated in these Terms, to the Client at the address stated in the Request or in the Authorisation.

15.4

The Client does not transfer the Contract to a third party without the written consent of the Operator. This does not restrict the assignment of a claim for money.

15.5

If a provision of these Terms is invalid, the validity of the remaining provisions is not affected.

15.6

These Terms are drawn up in English and are published in translation. If a translation differs from the English text, the English text prevails.

16.Details of the Operator

16.1

The Operator:

DetailValue
NameOsaühing Ida Portal
Legal formPrivate limited company (osaühing)
RegisterCommercial Register of the Republic of Estonia
Registry code10970449
Registered officeKivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia
Emailinfo@securitytest.team
Telephone+372 5852 4760 (SMS only)

16.2

The bank details of the Operator are stated in the invoice.