1. Informational and point-in-time report
Website Security Snapshot, Website Health, and related reports are informational, point-in-time assessments. They may rely on publicly observable information, customer-provided information, questionnaires, automated rules, and third-party tools. Conditions can change immediately after a report is generated.
2. Not a penetration test or certification
- The report is not exhaustive.
- The report is not a penetration test unless a separate written agreement expressly says otherwise.
- No exploitation, social engineering, credential testing, destructive testing, or denial-of-service activity is performed.
- No authenticated application testing, physical inspection, source-code review, or continuous monitoring is performed unless separately contracted.
- The report does not certify security, safety, legal compliance, regulatory compliance, insurance eligibility, or suitability for any purpose.
3. Possible inaccuracies
Automated observations, third-party data, scoring, and recommendations may be incomplete, unavailable, delayed, outdated, or incorrect. Reports may contain false positives, false negatives, inconclusive findings, or observations affected by hosting, caching, DNS, bot protection, firewalls, temporary outages, geographic routing, provider limits, or later configuration changes.
Absence of a finding is not proof that a vulnerability, hazard, or issue does not exist. A favorable score does not mean secure or safe. A low score does not prove compromise, negligence, or noncompliance.
4. Customer authorization
Customers may submit a website, property, system, or other subject only when they own it, manage it, have permission to assess it, or are otherwise legally authorized to request the report. Everitt Ventures may reject or stop work that appears unauthorized, abusive, unlawful, unsafe, or technically unsuitable.
5. Professional verification required
Important findings should be independently confirmed before production, security, financial, legal, structural, operational, or safety-related changes are made. Customers should maintain backups, test changes, and consult qualified professionals where appropriate.
Reports are not legal, accounting, tax, insurance, engineering, inspection, appraisal, medical, emergency, or regulatory advice.
6. Remediation
Any remediation, implementation, or follow-up work is optional and separately scoped unless expressly included in writing. Recommendations may not be appropriate for every environment. Remediation cannot guarantee prevention of cyber incidents, data loss, outages, property loss, or other harm.
7. Continuing responsibility
The customer remains responsible for ongoing security, maintenance, monitoring, access control, backups, updates, incident response, physical verification, legal compliance, and decisions about whether and how to act on a report.
8. No guarantee
Everitt Ventures does not guarantee that a report will identify every vulnerability, hazard, weakness, maintenance issue, configuration problem, or future event. Providing a report or remediation does not make Everitt Ventures responsible for an attack, outage, loss, or incident that later occurs.
9. Contact
Questions about a report may be sent to team@everittventures.com.