Swift Vaultgate
// terms

Terms of Service

Swift Vaultgate · rev. 2019

By browsing or buying, you agree to a short set of rules. We own the content on this site unless we explicitly attribute it; please don't copy or redistribute it for commercial use without asking. Prices, lead times, and availability are subject to change without notice; an order confirms the price at the moment you confirmed it. We may decline to fulfil an order if we suspect fraud, if stock has run out, or for any other reasonable cause; you'll be refunded in full. If something goes wrong on our end — a damaged shipment, an item that isn't as described — tell us and we'll repair, replace, or refund within a reasonable time. Statutory consumer-protection rights in your country apply alongside these terms and are not reduced by them. Any dispute we can't resolve directly will be heard under the law of our country of incorporation.

Authorisation, scope and safe testing

Testing begins only after a signed rules-of-engagement document names the systems in scope, the testing window, and an emergency contact on both sides. Anything outside that document is out of bounds — if we find a path into an out-of-scope system, we stop and report rather than proceed. Denial-of-service techniques are excluded unless explicitly commissioned in writing.

You warrant that you own, or have written authority over, every system you place in scope. Findings are delivered within 72 hours of test completion as contracted.

Liability and governing law

Security testing reduces risk; it cannot guarantee the absence of vulnerabilities, and a clean report is a statement about what was tested, when, with the access given. Liability is capped at twice the engagement fee except where the law says otherwise. These terms are governed by Japanese law, exclusive venue the Nagoya District Court, Okazaki branch.

Retesting, disclosure and public references

One retest of remediated findings within 60 days of report delivery is included in every engagement; further retests are quoted separately. Findings belong to you — we make no public disclosure of anything discovered, and being named as a client reference is opt-in, never assumed. If we discover a vulnerability in a third-party product during your engagement, we coordinate disclosure with the vendor only after you have confirmed doing so creates no exposure for you.

Emergency out-of-hours support during an active incident is a separate service with its own rate card, agreed before the first hour is billed.

Certifications, tooling and what 'independent' means

Testers hold their certifications personally, and the firm does not resell any vendor's security product — which keeps findings free of the incentive to recommend whatever earns a margin. Where a report suggests tooling, alternatives are named. Licensed commercial tools used during testing are covered by the engagement fee; nothing is deployed into a client environment without being listed in the rules-of-engagement letter first.

Draft reports are reviewed by a second tester before delivery. That four-eyes step is part of the 72-hour clock, not an excuse for missing it.

Severability and survival

If any clause is unenforceable, the rest survive. Confidentiality, evidence-destruction and authorisation clauses survive engagement end — confidentiality for five years, the rest indefinitely. The governing version of these terms is the one published here.

Notices and points of contact

Formal notices go to the emergency contacts named in the rules-of-engagement letter, by encrypted email with delivery confirmation. During a live testing window both sides keep those contacts reachable; a testing window in which the client contact is unreachable may be paused for safety, with the paused hours returned to the engagement.

Subcontracting

Testing is delivered by our own staff. If a niche skill ever requires an external specialist, that person is named to you in advance, signs the same rules-of-engagement letter, and works under our supervision and our liability — silent subcontracting does not happen here. The same transparency applies to tooling authored by third parties: anything that phones home is either blocked at the perimeter or disclosed in the engagement letter before use.