Terms of Service
These Terms of Service ("Terms") govern the security review service provided by Validra ("Validra", "we"). Placing an order implies unconditional acceptance of these Terms.
1. Purpose
Validra provides a targeted, evidence-based security review of a web application or SaaS product (the "Security Review"), designed to identify, validate, and prioritize security issues within an agreed scope, at any stage of the application's life, not only before it goes into production.
2. Nature of the service: no guarantee of results
The services provided by Validra consist of a technical analysis performed at a given point in time, combining automated tooling and manual testing, based on the information, access, and materials provided by the client.
This analysis is a good-faith assessment, carried out using practices and knowledge reasonably available at the time of the engagement. It does not, under any circumstances, constitute:
• a guarantee of the absence of any vulnerability, flaw, or security defect, whether or not detected during the engagement;
• a guarantee against any cyberattack, intrusion, data breach, or other security incident, past, present, or future;
• a commitment of regulatory compliance (GDPR, PCI-DSS, ISO 27001, or any other standard), unless explicitly stated in the contracted scope;
• a certification, a legal compliance audit, or a forensic or judicial expert opinion.
The client acknowledges that information security is a constantly evolving field and that no analysis, however rigorous, can guarantee the total absence of risk. The client remains solely responsible for implementing the recommendations, for the ongoing security of their application after the engagement, and for any decision made based on the report provided.
3. Service description
Security Review: a targeted security assessment of the agreed scope, combining code review where available, identification of sensitive surfaces, targeted manual testing, and validation of results. Findings are classified by certainty (observation, weakness, or demonstrated vulnerability) and prioritized by risk. The engagement concludes with a written report, a restitution walkthrough, and remediation recommendations. A limited retest is included when specified in the agreed scope.
Validra identifies, documents, explains, and prioritizes security issues. Validra does not implement fixes: the client or their developer remains responsible for applying the recommended remediations.
The exact scope of the engagement is defined with the client before it begins and is described on the Pricing page at the time of order.
4. Process and access
The client provides Validra with the access necessary to perform the engagement (read-only repository access, staging or test environment URL, relevant technical information). Validra never requires write or administrator access to production systems. The client warrants that they hold the necessary rights to authorize this access.
5. Pricing and payment
The reference price for the Security Review is displayed on the website, in euros, at the time of order.
Payment is split into two parts, tied to the outcome of the review performed within the agreed scope:
• An initial payment of €395 is due before the engagement begins. It covers the analysis and testing work carried out by Validra.
• If the review identifies security issues relevant to the agreed scope, the remaining €395 balance is due upon delivery of the report.
• If the review does not identify any issue relevant to the agreed scope, the client is not billed the remaining balance, and the engagement is considered complete once the report is delivered.
This payment structure reflects the outcome of the specific review performed within its defined scope. It does not constitute a guarantee that the application is free of vulnerabilities, nor a certification of its security: a review can only report on what was tested, using the access, time, and information available during the engagement. See Section 2 for the full disclaimer on the nature of the service.
6. Timelines
The stated timeline (5 business days) is indicative and starts once all necessary access and information have been received. It may be extended in case of missing elements, a larger-than-expected scope, or specific technical constraints, without giving rise to any compensation.
7. Intellectual property and confidentiality
The report delivered to the client belongs to the client and may be used freely internally. Validra retains ownership of its methodology, tools, and know-how.
Validra commits to treating any information, source code, or data shared by the client during the engagement as strictly confidential, and will not disclose it to any third party. A non-disclosure agreement (NDA) can be signed before any engagement, at the request of either party.
8. Limitation of liability
To the extent permitted by applicable law, Validra's total liability for any engagement, for all claims combined, is capped at the amount actually paid to Validra for that engagement.
Validra shall under no circumstances be liable for indirect damages, including but not limited to: data loss, business interruption, loss of revenue, reputational harm, or the consequences of a cyberattack occurring before, during, or after the engagement.
This limitation does not apply in the event of willful misconduct or gross negligence by Validra.
9. Right of withdrawal
For business clients (B2B), statutory consumer withdrawal rights do not apply. Where applicable consumer law would otherwise grant a withdrawal period, the client expressly agrees, by requesting that the engagement begin, that the service is fully performed before the end of that period and that the right of withdrawal no longer applies once work has started.
10. Termination
Any cancellation request made before the engagement begins may be eligible for a refund under the terms communicated at booking. Once an engagement has started, amounts paid remain due to Validra in proportion to the work completed.
11. Governing law and disputes
These Terms are governed by French law. Any dispute regarding their interpretation or performance shall, failing an amicable resolution, fall under the exclusive jurisdiction of the competent French courts.
12. Contact
For any question regarding these Terms: teobrondel6@gmail.com. Operated by Téo Brondel, sole trader (auto-entrepreneur), SIRET 935 405 985 000 18, registered address: 17 rue Primo Levi, 28300 Lèves, France.