The deal, in plain words.
What you get when you buy a check, what it cannot promise you, when we give your money back, and what happens if something goes wrong.
Last updated
1. Who you are contracting with
VibeGuard is operated by Andrea Finotti, Corso Monte Cucco 121, 10141 Torino (Italy). You can reach us at support@vibeguard.tech, or through Contact us in your dashboard.
These terms apply when you buy a security check. By completing checkout you accept them. If you are buying on behalf of a company, you confirm you may bind it.
2. What you are buying
A one-time, independent security check of a web application you nominate, run against the deployed application from the outside. Each check produces a report of findings with evidence, a severity, and a suggested fix, plus one re-check to confirm what you fixed is really gone.
Checks come in depths (€59 to €199) that differ in how long the engine runs and how far it explores. The depth you buy, and what it includes, is shown at checkout and on the pricing page.
3. What a check is not
A check is evidence that we found something, never proof that nothing else exists. No security assessment, automated or human, can prove an application is free of vulnerabilities. A clean report means this check did not find a problem within the depth you bought — not that your application is secure.
It is not a penetration test carried out by a named human tester, not a code audit, and not a certification. It does not make you compliant with any standard, and we issue no attestation you can show a third party as proof of compliance.
You remain responsible for the security of your application. Nothing here transfers that to us.
4. You must be authorised
You may only order a check for an application you own or are explicitly authorised to test. You confirm this at checkout, and we record that confirmation with your order.
Testing a system without permission is a criminal offence in most countries. If you order a check without authorisation, you are responsible for the consequences, and you agree to cover any claim, loss or cost we incur because of it. We may cancel a check and close your account if we believe an application is not yours to test, and we will report unlawful use where we are required to.
5. What we do to your application, and what we do not
Checks are non-destructive. We do not:
- delete or alter your data, or submit real payments;
- run denial-of-service or load tests;
- attack third-party systems your application depends on;
- use any finding against you, or disclose it to anyone else.
A check does generate real traffic and will create test records where your application lets it — sign-ups, for instance. It may trigger your alerts, your rate limits and your error-reporting tools. Take a backup before you run one, and tell anyone who watches your monitoring that it is expected.
If you give us a test login, use a throwaway account with the least access that still reaches what you want checked, and revoke it after the check. Credentials are encrypted and deleted with the check, but an account you control is one we cannot leave behind.
6. Price and payment
The price you see is the price you pay. Prices are in euro, and nothing is added at checkout — no VAT, no fees, no surcharge for your country.
We do not charge VAT. VibeGuard is operated by an individual trading below the Italian threshold at which VAT registration is required, so no VAT is applied and your receipt will not show any. If that changes, it will change only for purchases made afterwards.
Payment is taken at checkout by Stripe. We never see or store your card details. Each check is a single purchase: there is no subscription and nothing renews.
7. Your right to change your mind, and why we ask you to waive it
As a consumer in the EU you normally have fourteen days to withdraw from a purchase made online, for any reason and without justification.
A security check begins soon after payment and consumes real computing time, so at checkout we ask you to request that it start immediately and to acknowledge that, once it has run, the right of withdrawal is spent. The exact words you accept are: “I ask VibeGuard to start this security check immediately. I understand that once the check has run I lose my 14-day right of withdrawal, and that until it starts I can still cancel for a full refund.”
In plain terms: before your check starts you can cancel and get all your money back. Once it has run and you have your report, you cannot withdraw — you have received what you bought. Clause 8 still applies if we got it wrong.
To cancel before a check starts, or to ask for a refund under clause 8, write to support@vibeguard.tech or use Contact us in your dashboard. You do not need a form.
8. When we refund you
We refund in full, without argument, when:
- your check never ran, or failed for a reason on our side;
- we could not reach your application and it was not because of something you changed;
- the report is empty or unusable because of a fault of ours;
- you cancel before the check starts.
We do not refund a check that ran and produced a report simply because the findings were fewer, or less severe, than you hoped. A check that finds nothing has still done the work you paid for, and telling you honestly that we found nothing is the service.
Refunds go back to the card you paid with, normally within five working days.
9. Your account and your data
Keep your password to yourself; you are responsible for what happens under your account. Tell us at once if you think someone else has got into it.
Reports and scan evidence are kept for 90 days so you can use the re-check and download what you need, then deleted. You do not have to wait: you can delete an app, a single check or a report from your dashboard whenever you like. What we collect and why is in the privacy policy, and how we handle your application is on the security page.
10. What we are liable for
We are liable to you for loss we cause by breaking this contract or by failing to use reasonable care and skill — up to the amount you paid for the check concerned.
We are not liable for a vulnerability a check did not find, for a breach of your application, or for business losses such as lost profit, lost data or lost opportunity. A check reduces your risk; it does not underwrite it.
Nothing here limits our liability for death or personal injury caused by negligence, for fraud, or for anything else the law does not allow us to limit. If you are a consumer, your statutory rights are unaffected by anything in these terms.
11. Suspension and closure
We may refuse or stop a check, and close an account, if it is used without authorisation, to attack someone, to break the law, or in a way that endangers our infrastructure or other customers. Where we stop a check you paid for and you were not at fault, we refund it.
You can close your account at any time; ask us through Contact us.
12. Changes to these terms
We may change these terms for future purchases, and the version in force when you buy is the one that governs that purchase. Substantive changes are dated at the top of this page. We do not change the terms of a check you have already paid for.
13. Law and disputes
These terms are governed by Italian law. If you are a consumer, you keep the protection of the mandatory rules of your own country and you may bring proceedings in the courts where you live.
Talk to us first — most things are a misunderstanding and we would rather fix it. If we cannot agree, consumers in the EU may use the European Commission's online dispute resolution platform.
Questions about any of this before you buy? Ask us at support@vibeguard.tech. See also the privacy policy and the security page.