Terms of Service
These terms govern your use of our website, products, and security services. By accessing the site, using our products, or requesting our services, you agree to these terms.
Last updated: August 2026
Scope of Service
We provide cybersecurity products and services, including Rassed for web vulnerability discovery and Misbah for source code review. We may introduce additional products or services in the future.
For professional security engagements, the scope, objectives, target assets, deliverables, and applicable limitations are agreed in a written proposal before work begins. We do not knowingly perform testing outside the agreed scope.
Authorisation
You must own the assets being assessed or hold valid written authorisation from the relevant owner to have them tested.
You are responsible for obtaining any third-party permissions required for the assessment, including permissions from hosting providers, cloud providers, or other infrastructure owners where applicable.
We will not knowingly begin an assessment without appropriate authorisation.
Acceptable Use
You may use our products and services only for lawful and authorised security testing, assessment, development, and defensive purposes.
You must not use our products or services to test systems without permission, interfere with systems or services you do not control, or conduct activity that violates applicable laws or third-party rights.
You are responsible for ensuring that your use of our products and services is authorised and lawful.
Client Responsibilities
You agree to provide accurate and sufficient information about the environment being assessed, maintain appropriate backups before testing, and provide a technical contact who can be reached during an engagement when required.
You are responsible for ensuring that testing will not knowingly violate your agreements with third parties or applicable operational requirements.
Limits of Testing
A security assessment reflects the state of the assessed assets at the time the assessment is performed.
No assessment can guarantee that every vulnerability or security weakness will be identified. Findings may depend on the available access, scope, configuration, technology, and testing conditions.
A security report is not a certificate that an environment is free from vulnerabilities and is not a substitute for regulatory, legal, or compliance requirements.
Confidentiality
We treat information accessed or received during an engagement as confidential and use it only as reasonably necessary to provide the agreed services.
We will not identify you as a client or use engagement-specific information in marketing materials without your written consent, unless disclosure is required by law.
Data Handling and Privacy
We handle information collected through our website, products, and security engagements in accordance with our Privacy Policy.
Where security testing involves access to client systems, data, source code, credentials, logs, or other confidential information, we take reasonable measures to protect that information and limit access to personnel who need it to provide the service.
Clients should avoid providing personal or confidential information that is not reasonably necessary for the agreed assessment.
Intellectual Property
Your source code, systems, data, and other materials provided by you remain your property.
Our products, software, tooling, methodologies, detection logic, documentation, and report templates remain our property unless otherwise agreed in writing.
You receive an unrestricted right to use the security reports delivered to you internally and for your legitimate business, security, compliance, and remediation purposes.
Fees and Payment
Fees for professional services are set out in the approved proposal or order.
Payment is due according to the payment schedule stated in the applicable proposal or order.
Value Added Tax and other applicable taxes or charges are added where required by law.
Service Availability
We aim to keep our website and products available and reliable, but we do not guarantee uninterrupted or error-free operation.
Maintenance, updates, technical issues, security events, and circumstances outside our reasonable control may temporarily affect availability.
Changes to These Terms
We may update these terms from time to time to reflect changes to our products, services, or legal requirements.
The latest version will be published on this website together with its effective or updated date.
Governing Law
These terms are governed by the laws of the Kingdom of Saudi Arabia.
Any dispute arising in connection with these terms will be subject to the jurisdiction of the competent courts or authorities in the Kingdom of Saudi Arabia, with the applicable jurisdiction determined in accordance with Saudi law.
A legal question?
Write to us and we will come back with the contractual detail you need.
legal@safina.sa
