// Client terms

Client Terms

Last updated:

These client terms provide the practical baseline for paid security testing work. Signed agreements, statements of work, data processing agreements, or authorization letters control where they are more specific.

1. Engagement scope

Loki Intelligence tests only the domains, applications, APIs, accounts, cloud environments, and actions that are confirmed in the submitted scope or a signed statement of work. Out-of-scope systems, destructive actions, payment actions, production changes, and third-party assets are excluded unless explicitly approved in writing.

2. Customer authorization

The customer confirms that they own, operate, or are otherwise authorized to approve security testing for the scoped systems. The customer is responsible for listing exclusions, fragile workflows, safe testing windows, rate limits, and escalation contacts before testing begins.

3. Deliverables

Standard deliverables are an evidence-backed report, practical remediation guidance, severity and impact notes, and retest criteria where applicable. Extra workshops, custom evidence packs, legal questionnaires, or recurring testing commitments must be agreed separately.

4. Payments and timing

Work starts after the scope, authorization, commercial terms, and payment method are confirmed. Recurring work is available only when its cadence, deliverables, price, renewal, and cancellation terms are agreed in writing.

5. Credentials and test accounts

Customers should provide test-owned accounts only when authenticated testing is required. Do not submit production secrets unless explicitly approved. Loki treats test-account credentials as sensitive operational data and avoids repeating them in notifications or customer-facing summaries.

6. Limits and safety

Security testing can reduce risk but cannot guarantee that a system is free from vulnerabilities. Loki may pause or stop testing if scope, authorization, safety, payment, or legal concerns are unclear.