// Client terms

Client Terms

Last updated:

These client terms provide the practical baseline for paid security testing work. Signed agreements, statements of work, data processing agreements, or authorization letters control where they are more specific.

1. Engagement scope

Loki Intelligence tests only the company-controlled, internet-facing web application or API, supplied test roles or accounts, and safe actions expressly named and scheduled in a fully executed agreement. That agreement must include the applicable scope, exclusions, Rules of Engagement, test windows, stop contact, safety limits, and data terms. Cloud accounts and control planes, OT, third-party assets, destructive actions, denial-of-service, payment execution, unsafe production changes, persistence, malware, and social engineering are out of scope.

2. Customer authorization

The customer confirms that they own, operate, or are otherwise authorized to approve security testing for the scoped systems. One fully executed agreement may authorize every bounded assessment it expressly names and schedules, provided it records the named assets and exclusions, supplied test accounts, test window, stop contact, safe-test restrictions, rate limits, cost ceiling, and data handling and retention terms for each covered assessment. Anything outside that signed envelope needs a signed amendment or new agreement before testing.

3. Deliverables

For the current SKYEN baseline, each covered monthly assessment includes the agreement-defined scope and exclusions, surface inventory and methodology record, human-validated findings with reproducible evidence, an owner summary, engineering remediation guidance and acceptance criteria, one remediation session, one scoped retest, and a closure memo. The delivery target is approximately ten business days after the applicable agreement-defined scope, access, authorization and Rules of Engagement are complete; capacity and the actual schedule are confirmed in writing and this public target is not a fixed SLA.

4. Payments and timing

The current public standard offer starts at EUR 500 per month excluding VAT for one bounded web or API assessment per month; larger or more complex scopes are quoted. The written commercial schedule confirms the final price, billing date, VAT treatment, minimum term, renewal or non-renewal, cancellation, agency arrangement and any extra work. A one-off request can be discussed but is available only if quoted and accepted in writing. The website creates no automatic subscription or renewal. Work starts only for assessments expressly named and scheduled in a fully executed agreement after the applicable Rules of Engagement, stop contact, data terms, access and required settled-payment evidence are complete. No separate per-assessment signature, Work Order or human execution release is required; each execution is internally bound to a covered assessment.

5. Credentials and test accounts

Customers should provide test-owned accounts only when authenticated testing is required. Do not submit production secrets unless explicitly approved. Loki treats test-account credentials as sensitive operational data and avoids repeating them in notifications or customer-facing summaries.

6. Limits and safety

Security testing can reduce risk but cannot guarantee that a system is free from vulnerabilities. Loki may pause or stop testing if scope, authorization, safety, payment, or legal concerns are unclear.