Security Testing Terms
Placeholder terms for a requested, limited security check. LEGAL REVIEW REQUIRED BEFORE PRODUCTION.
Parties
The requesting person or their organisation and JoshJess UG (Haftungsbeschränkt), which operates ReconSec.
Requested target
Only the website or domain named in the request and the public scope recorded with it.
Requester's authority
The requester confirms they own or operate the system or are expressly authorized. The request must use a business email on the same domain as the website.
Authorized scope
The Scan Scope published at the time of the request applies, in the version number stored with the request.
Prohibited actions
No DDoS, no intentional interruption, no destructive changes, no credential stuffing. In the public profile: no test accounts, no login to customer systems, and no authenticated authorization checks. No tests outside the named target.
Timing
The check runs after the request is reviewed. There is no instant or seconds-scale guarantee.
Handling of findings
First results or next steps go to the stated business email. Findings are not sold.
Confidentiality
The request and results are treated as confidential except where the law requires otherwise.
Personal data handling
Processed as described in the privacy notice. Personal data in findings is masked or redacted where technically possible. Data minimisation: document the exposure rather than copying personal details unnecessarily.
Limitation / escalation
The public flow authorizes only the low-impact profile. Deeper testing needs a separate agreement.
Contact
Product: team@reconsec.io. Provider: info@joshjess.de
Version / date
Version 2026-09-08.1. Development draft, not counsel-approved wording.
This text is a development draft and must be reviewed by qualified German legal counsel before production use. It is not legal advice.