SPECTARI

Customer Authorization & Assessment Agreement

Spectari · Draft · Not in effect · Last updated 2026-07-30

This Agreement is between Spectari ("Provider", "we") and the individual or entity purchasing an assessment ("Customer", "you"). By purchasing or authorizing an assessment, you agree to these terms.

1. What we do

We perform a non-intrusive, external security assessment of the internet-facing hosts that resolve under a domain you designate (the "Target Domain") and deliver a written report. The assessment observes externally-visible configuration: it enumerates hosts under the Target Domain, resolves them, makes one ordinary HTTP request per host and opens one further brief connection per host to read that host's TLS certificate, and inspects the Target Domain's own published DNS records — including the records governing email authentication, certificate issuance and DNS delegation, a small number of names beneath the Target Domain that you may never have published, and any domain your own records point at, such as a mail provider named in your SPF record. Those are DNS lookups only: no host outside the Target Domain is contacted. It does not test for known vulnerabilities, and does not attempt exploitation of any kind.

2. Your authorization and warranty (essential)

You represent and warrant that, for each Target Domain, you own it or have express written authority to authorize security testing of it and all hosts resolving under it. You authorize us to conduct the assessment described above during the term. You confirm authorization by publishing the DNS TXT record we provide (spectari-verify=<token>) at the Target Domain; we re-verify this record before every assessment run. You must not designate a domain you do not control.

3. Scope and method

Assessments are external and non-intrusive by default. We do not perform denial-of-service, load/stress testing, brute-forcing, exploitation, social engineering, or data-exfiltration, and we perform no vulnerability testing at all. We only contact hosts that resolve under a verified Target Domain; any name a discovery source returns that does not resolve under it is discarded before any host is contacted. Hosts that resolve under your Target Domain but are operated on third-party platforms (e.g. SaaS, CDNs, marketplaces) are contacted, in the same non-intrusive way as any other in-scope host — they form part of the surface you asked us to assess. You warrant in Section 2 that you are entitled to authorize this for every host under the Target Domain.

4. No guarantee of security

An assessment reflects externally-observable conditions at a point in time. It is not exhaustive and is not a guarantee that your systems are secure or free of vulnerabilities. The report is provided "as is", without warranties of any kind, express or implied.

5. Acknowledged risk

Security assessment carries an inherent, non-zero risk of unexpected effects on a target system. While our method is designed to be safe, you acknowledge this residual risk and agree that we are not liable for incidental disruption arising from an assessment you authorized, except to the extent caused by our gross negligence or willful misconduct.

6. Limitation of liability

To the maximum extent permitted by law, our total liability arising out of or relating to this Agreement is limited to the fees you paid to us in the three (3) months preceding the event giving rise to the claim. We are not liable for indirect, incidental, special, consequential, or punitive damages, or lost profits or data.

7. Indemnification

You will indemnify and hold us harmless from any third-party claim, loss, or expense (including reasonable legal fees) arising from your designation of a Target Domain over which you lacked ownership or authority, or your breach of Section 2.

8. Data handling and confidentiality

We collect the Target Domain, your contact email, and the technical results of the assessment. We treat your report and results as confidential and do not sell them. We retain assessment data for 180 days, after which it is deleted — and we will delete it sooner at your request. A skeleton payment record without your email address or results is kept. See our Privacy Policy.

9. Subscriptions and cancellation

Monitoring subscriptions (Watch, Agency) are not currently offered and cannot be purchased. If introduced, they would renew monthly until cancelled, cancellation would take effect at the end of the current billing period, and fees already paid would be non-refundable except as required by law or under our stated refund policy.

10. Suspension

We may decline or halt any assessment, and cancel any order, if we reasonably believe authorization is invalid, a complaint has been raised, or continuing would be unlawful or unsafe.

11. Governing law

This Agreement is governed by the laws of South Carolina, United States, without regard to conflict-of-laws rules.