Terms of Service
Last updated: 9 July 2026
These terms govern your use of the SentryScan managed security scanning service. By placing an order, creating an account, or using the service, you agree to them. Please read them โ in particular section 4 (Authorisation to scan) and section 7 (Nature and limitations of scanning), which matter for a service of this kind.
1. Who we are
The service is provided by Sentryscan Limited ("SentryScan", "we", "us"), a company registered in England and Wales (company number 17321496) with its registered office at International House, 51 Borough High Street, London SE1 1NB. You can contact us at info@sentryscan.services.
The service is designed for business customers. By ordering, you confirm you are acting in the course of a business, or with the consent of the business whose systems are in scope.
2. The service
SentryScan is a managed vulnerability scanning service. Depending on your plan, we scan the systems you authorise for exposed services, web-application issues, misconfigurations, TLS/certificate problems, and known vulnerabilities, and deliver a plain-English report by email or through your private dashboard. Higher tiers include expert review of results.
What the service is not. SentryScan is an automated vulnerability assessment with optional human review. It is not a manual penetration test, a red-team engagement, a security audit, or a formal certification of any kind. Grades and compliance-style summaries in our reports are indicative aids, not certifications, and do not by themselves demonstrate compliance with any standard or regulation.
3. Orders and accounts
- An order is an offer to buy the service; it is accepted when we confirm it (for paid self-serve plans, when payment succeeds via Stripe Checkout).
- You must give accurate information โ in particular the scope of systems to scan โ and keep your account details up to date.
- You are responsible for keeping your password confidential and for activity under your account.
- We may decline or cancel an order at our discretion, including where we cannot reasonably verify authorisation to scan the requested scope (any payment already taken for work not performed will be refunded).
4. Authorisation to scan
We only scan systems you own or are explicitly authorised to test. Unauthorised scanning of computer systems may be a criminal offence, including under the Computer Misuse Act 1990 in the United Kingdom and the Crimes Act 2011 in Gibraltar.
- You warrant that, for every system you place in scope, you either own it or hold the explicit authority of its owner to have it security-tested โ including active vulnerability testing that interacts with the system โ for the duration of the engagement.
- The person who confirms the authorisation at order time warrants that they have authority to give that consent on behalf of the company named on the order.
- Your order-time authorisation covers recurring scans of the agreed scope for as long as your plan or subscription remains active. Any change to scope requires a fresh authorisation โ a new order, or written confirmation to us, which we record before the new scope is scanned.
- Where a system in scope is hosted or managed by a third party (for example shared hosting, cloud, or managed service providers), you are responsible for obtaining any consent that provider requires before it is scanned.
- You must be able to evidence that authority on request, and must tell us immediately if it changes (for example, if a system in scope is sold, migrated to a third party, or moved to shared infrastructure whose provider does not permit testing).
- You will indemnify us against losses, claims and costs arising from scanning a system that you placed in scope without proper authority, or from any breach of the warranties in this section.
- We record the authorisation confirmation you give at order time (including its wording, the scope, and technical metadata) as evidence of the engagement's lawful basis.
- We may suspend or terminate scanning immediately, without refund, if we reasonably believe scope is not properly authorised.
5. Fees and payment
- Prices are in pounds sterling (GBP), as shown at the time of order. We are not currently VAT registered, so no VAT is added to our prices; if we become VAT registered, VAT will be added at the prevailing rate from that point and we will tell you before it affects a renewal.
- Payment is taken by card via Stripe. We never see or store your full card details.
- Subscription plans bill in advance on a recurring basis (monthly or annual, as selected) until cancelled.
- If a renewal payment fails we will retry and notify you; we may suspend the service until payment succeeds.
- The free first scan is a genuine free tier: no card is required and it creates no obligation to buy.
6. Cancellation and refunds
- Subscriptions are rolling and can be cancelled at any time; cancellation takes effect at the end of the period already paid for, and no further payments are taken. Except where these terms say otherwise, amounts already paid for the current period are not refunded, and the service continues to the end of that period.
- One-off scans can be cancelled for a full refund at any time before scanning has begun. Once scanning has begun, the fee is non-refundable.
- If we materially fail to deliver the service you paid for and cannot remedy it within a reasonable time, you are entitled to a refund of the affected fees.
7. Nature and limitations of scanning
- A scan is a point-in-time assessment. Findings, grades and summaries reflect what our tooling and review could observe at the time of the scan, from the vantage point scanned.
- No scan finds every vulnerability. We do not warrant that scanned systems are free of vulnerabilities, that all vulnerabilities present will be detected, or that reported findings contain no false positives. A clean report is not a guarantee that a system is secure.
- We use widely adopted tooling with conservative, non-destructive settings. Nevertheless, any security scanning places load on the systems tested and carries an inherent residual risk of disruption. You are responsible for ensuring systems in scope are backed up and for telling us about fragile systems or preferred scanning windows in advance.
- Reports may reference third-party severity data (such as CVE, KEV and EPSS information) which we do not control and which changes over time.
- Remediation is your responsibility. Our reports explain findings and suggest fixes, but we do not modify your systems.
8. Reports, confidentiality and intellectual property
- Reports are prepared for you and your organisation's internal use (including sharing with your own advisers, insurers, auditors or customers under confidentiality). You may not resell reports or the service, or present our output as your own security testing service, without our written agreement.
- We treat your reports, scope and findings as confidential and restrict access to them, as described in our Privacy Policy.
- We retain all rights in our tooling, templates, branding and know-how. You retain all rights in your systems and data.
9. Your obligations
- Provide and maintain an accurate scope, and notify relevant stakeholders (for example your hosting provider, where their terms require it) that authorised scanning will occur.
- Use the service and its output lawfully, and not to attack, exploit or gain unauthorised access to any system.
- Keep contact details current so we can reach you about findings โ some findings are time-sensitive.
10. Liability
- Nothing in these terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be excluded by law.
- Subject to that, we are not liable for indirect or consequential loss, loss of profits, revenue, anticipated savings, goodwill, or loss or corruption of data.
- Subject to the above, our total aggregate liability arising out of or in connection with the service in any 12-month period is limited to the fees you paid us in the 12 months preceding the event giving rise to the claim (or ยฃ100, if greater).
- You remain solely responsible for the security of your systems and for acting (or not acting) on the contents of our reports.
11. Suspension and termination
- We may suspend or terminate the service immediately if you materially breach these terms โ in particular section 4 โ or if payment for it fails and is not remedied.
- You may stop using the service and cancel at any time (see section 6).
- On termination, sections that by their nature should survive (including sections 4, 7, 8 and 10) continue to apply.
12. Changes
We may update the service and these terms from time to time. If a change to these terms materially affects a subscription you hold, we will notify you by email before it takes effect, and you may cancel before the next renewal if you do not accept it. The version published on this page applies to new orders.
13. General
These terms (together with your order and our Privacy Policy) are the entire agreement between us for the service. If any part of them is found unenforceable, the rest remains in effect. A failure to enforce a right is not a waiver of it. You may not assign your rights under these terms without our consent. These terms do not give rights to any third party.
14. Governing law
These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from them.
15. Contact
Questions about these terms: info@sentryscan.services.