Terms of Service
Effective 5 August 2026
1. Parties
These terms govern the relationship between Preventionlabs (ABN to be listed upon registration) ("we", "us") and the client ("you") engaging our security research and audit services. Preventionlabs is located in Western Australia.
2. Services
We provide comprehensive security assessments of software systems. This includes vulnerability identification, root cause analysis, working Proofs of Concept for every finding, and recommended fixes. All testing is conducted locally against a production-equivalent copy of your system that you provide. No production systems are accessed at any point.
3. Engagement Process
- We deliver a free vulnerability finding in your public code. No charge. No obligation.
- If you engage us for a full assessment, you define the scope - what your business cares about most.
- Both parties sign a written engagement agreement before work begins.
- Payment of $10,000 AUD is made upfront via direct bank transfer before work commences.
- You provide a production-equivalent copy of your system with no real user data.
- We deliver a comprehensive security assessment with working PoCs for every finding.
- Your codebase is deleted from our systems on completion.
4. Payment
The engagement fee is $10,000 AUD per engagement, payable upfront by direct bank transfer (AUD) to a Commonwealth Bank account. Work begins when payment clears. No credit cards. No PayPal. No instalment plans.
GST will be added once Preventionlabs is registered for GST (required when cumulative revenue exceeds $75,000 in a 12-month period under A New Tax System (Goods and Services Tax) Act 1999).
5. Scope and Deliverables
The scope is defined by you - you tell us what your business cares about most. The assessment is scoped to that priority area and measured against modern attack standards including but not limited to:
- IDOR (Insecure Direct Object References)
- Authentication and authorisation bypass
- Injection (SQL, command, template)
- Business logic abuse and payment manipulation
- Data exposure (credentials, infrastructure, PII)
- Session management flaws
- Rate limiting and abuse
- XSS / CSRF
The deliverable is a comprehensive security assessment report with working Proofs of Concept for every finding and actionable remediation guidance.
6. No Guarantee of Findings
This service is a thorough security assessment, not a guarantee that vulnerabilities will be found. The engagement is for the assessment itself - the process, the expertise, and the report - regardless of the number of findings. This is consistent with the nature of professional services under the Australian Consumer Law.
7. Authorisation to Test
By engaging our services and providing a copy of your system, you expressly authorise Preventionlabs to perform security testing, vulnerability identification, and exploitation attempts against the provided copy. This authorisation is limited to the copy you provide and does not extend to any production system, third-party system, or any system not explicitly included in the engagement agreement.
8. Testing Protocol
- You provide a production-equivalent copy of your system - same codebase, same architecture, no real user data.
- All testing is conducted locally on our systems against the provided copy.
- No production systems, live databases, or real user data are accessed at any point.
- Every PoC runs against the locally hosted copy and is reproducible by you on your own copy.
- Your codebase is permanently deleted from our systems upon delivery of the final report.
9. Confidentiality
All findings, reports, and information about your systems are treated as strictly confidential. We will never publicly disclose any finding, vulnerability, or information about your systems without your written consent. This obligation survives termination of the engagement.
If you choose not to engage us after the free finding, we will never publicly disclose that finding. It stays between us.
10. Intellectual Property
All reports, findings, and Proofs of Concept delivered to you are yours. You own the deliverables. Your codebase is permanently deleted from our systems upon delivery of the final report. A copy of the delivered report is retained for 7 years for legal and tax compliance purposes, unless you request earlier deletion.
Our methodologies, tools, and processes remain our intellectual property.
11. Limitation of Liability
Subject to the consumer guarantees under the Competition and Consumer Act 2010 (Cth), Schedule 2 (Australian Consumer Law), our total liability to you for any claim arising out of or in connection with our services is limited to the amount you paid for the engagement.
As security assessment services are not of a kind ordinarily acquired for personal, domestic, or household use, our liability for a failure to comply with a consumer guarantee (other than a guarantee under sections 51, 52, or 53 of the ACL) is limited under section 64A of the ACL to, at our option:
- the supply of the services again; or
- the payment of the cost of having the services supplied again.
We are not liable for any indirect, incidental, special, or consequential damages, including lost profits, lost data, or business interruption, to the maximum extent permitted by law.
12. Scope of Service
All findings, Proofs of Concept, and recommended fixes are tested and verified against the production-equivalent copy of your system that you provide. That is the full extent of our assessment. We do not access, test against, or make any representation about your production systems.
Recommended fixes are examples of how a vulnerability could be mitigated, not instructions to be applied directly. They exist to educate you on the attack surface and illustrate a possible approach to remediation. You are responsible for determining whether any recommendation is compatible with your production systems, dependencies, third-party integrations, and business requirements. We may not know the full extent of what your systems depend on, and a recommendation that works on the provided copy may not be suitable for your production environment without adaptation.
Whether and how you apply any recommendation is your decision. Our involvement ends at delivery of the final report. We make no warranty that findings or recommendations will remain effective against future attacks, future code changes, dependency updates, or any modification to your systems after delivery.
13. Timeline
There is no fixed time limit on engagements. The assessment takes as long as it takes to complete thoroughly. We will provide reasonable progress updates and deliver the final report within a reasonable time, consistent with our obligations under section 62 of the ACL.
14. Termination
Either party may terminate the engagement by written notice. If you terminate before the assessment is complete, a refund will be calculated proportional to the work not yet performed. If we terminate, you receive a full refund of the engagement fee. Confidentiality obligations survive termination.
15. Dispute Resolution
Any dispute arising out of or in connection with this agreement will be resolved as follows:
- The parties will first attempt to resolve the dispute by direct negotiation in good faith.
- If the dispute is not resolved within 14 days, either party may refer the dispute to mediation administered by the Resolution Institute in Perth, Western Australia.
- The costs of mediation will be shared equally.
- Nothing in this clause prevents either party from seeking urgent injunctive relief.
16. Governing Law
This agreement is governed by the laws of Western Australia. The parties submit to the exclusive jurisdiction of the courts of Western Australia and any courts entitled to hear appeals from those courts.
17. Unfair Contract Terms
These terms are intended to be fair and reasonable. Any term that a court or tribunal determines to be unfair within the meaning of sections 23-28 of the Australian Consumer Law is void to the extent of the unfairness, and the remaining terms continue in full force.
18. Relationship of Documents
Where a signed engagement agreement exists between the parties, it supplements these Terms of Service. If any provision of the engagement agreement conflicts with these Terms, the engagement agreement prevails to the extent of the inconsistency.
19. Entire Agreement
These Terms of Service, together with any signed engagement agreement, constitute the entire agreement between the parties. They supersede all prior discussions, representations, and understandings, whether written or oral, relating to the subject matter of the engagement.
20. Amendments
We may update these terms from time to time. The effective date at the top of this page indicates when the current version took effect. Changes apply to new engagements entered into after the update. For active engagements, material changes require written consent from the client.
21. Contact
For any questions about these terms:
Preventionlabs
Email: contact@preventionlabs.com.au
Location: Western Australia