Terms of service.
The plain terms of a SmallShield subscription: what you pay, how you cancel, what we do, and what no scan can promise.
1. Who these terms are between
These terms are an agreement between SmallShield LLC, a South Carolina limited liability company in Mount Pleasant, South Carolina ("SmallShield," "we," "us"), and the business that subscribes to our service ("you"). By checking out on our website, signing the authorization form, or using the service, you agree to these terms. If you sign a separate written Client Services Agreement with us, that agreement controls where the two differ.
2. What the service is
SmallShield performs automated, external, non-intrusive security scanning of the website domains you authorize, and delivers written reports and alerts according to the plan you choose.
- External means we look at your website from the public internet only, the same view any visitor has.
- Non-intrusive means the scan reads and observes. It does not change anything on your website, does not log in, and does not attempt to break in.
- Reports are written summaries of what was observed at the time of the scan, with suggested fixes. They are information for you to act on. You decide whether and how to act.
- Alerts are emails about findings we classify as critical, sent as promptly as we reasonably can. We do not provide around the clock staffed monitoring and do not commit to a specific response time unless we agree to one in writing.
We may improve or change the scanning tools and methods we use at any time, as long as the service described in your plan continues to be delivered. We may use third party scanning platforms and infrastructure to deliver the service, and we remain responsible for the service.
3. What the service is not
To be clear about the limits of the service:
- Not internal access. We do not access, and do not ask for, your hosting control panel, servers, source code, databases, passwords, internal network, or employee devices.
- Not a penetration test. The service is automated vulnerability scanning. It is not a penetration test, a manual security audit, a source code review, or a social engineering assessment.
- Not repair. We identify findings and explain the fix. We do not fix, patch, or configure anything on your systems unless we both sign a separate written statement of work.
- Not a PCI ASV scan. We are not a PCI Security Standards Council Approved Scanning Vendor. If you are required to have ASV scans, you must engage a listed vendor separately.
- Not a HIPAA risk analysis or a compliance certification. Reports on the Compliance plan are formatted to help with your own documentation. They are not a HIPAA risk analysis, a SOC 2 audit, an ISO 27001 certification, or any other attestation, and they do not make you compliant with any standard.
- Not a home for protected health information. The service is not designed to receive, store, or transmit protected health information, and SmallShield does not act as a HIPAA business associate. Do not send us patient records. If you believe a business associate agreement is required, raise it in writing before the first scan.
- Not legal, regulatory, insurance, or accounting advice.
4. Authorization before any scan
We do not scan any domain until its owner has signed our authorization form. By signing it, you give SmallShield, and any scanning platform acting on our behalf, express permission to scan the listed domains for as long as your subscription lasts. That permission is your consent for the purposes of the Computer Fraud and Abuse Act, the South Carolina Computer Crime Act, and any other law about access to computer systems.
By signing, you confirm that: you own, operate, or have full authority to authorize scanning of each listed domain; the person signing can bind your business; your hosting provider's terms permit external scanning of your property, or you have obtained any required consent; and no listed domain belongs to someone else without their written consent.
Tell us in writing before you add, remove, or transfer a domain. You can withdraw authorization for any domain at any time by writing to us. Withdrawing authorization for every domain ends your subscription under Section 6. Scans performed before we receive your notice remain authorized.
5. Subscription and billing
- Monthly billing. Plans are billed monthly, in advance, through Stripe, our payment processor. Your subscription renews automatically each month until it is cancelled. You authorize recurring charges to the payment method on file and you are responsible for keeping a valid payment method on file.
- Failed payment. If a charge fails, we may pause the service after emailing your designated contact. Service resumes when payment succeeds. A pause does not extend your billing period or entitle you to a credit.
- No refunds for partial months. Fees are non-refundable except where the law requires otherwise. Cancelling mid-cycle does not produce a prorated refund; the service continues through the end of the period you have paid for.
- Price changes. We may change prices on thirty days' written notice. If you do not agree, cancel before the new price takes effect.
- Taxes. Prices exclude any applicable sales, use, or similar taxes, which are your responsibility.
6. Cancel by email
There is no contract term and no minimum commitment. Either of us may end the subscription at any time by written notice. For you, that means an email to william@smallshield.co, or a reply to any email we have sent you. Cancellation takes effect at the end of the billing period you have already paid for. When it ends, scanning stops, your authorization ends, and you keep every report already delivered.
We may end or pause the service immediately if we reasonably believe the confirmations you made in Section 4 are not accurate. Either of us may end the agreement immediately if the other materially breaches it and does not cure the breach within ten days of written notice.
7. Your responsibilities
- Keep the list of authorized domains accurate and current.
- Name at least one contact for reports and alerts and keep that contact current. We are not responsible for notices that do not arrive because of outdated contact details or spam filtering.
- You are solely responsible for evaluating, prioritizing, and fixing findings, and for your own backups, business continuity, incident response, and insurance.
- You may share reports with your own IT provider, auditors, insurer, or lawyer for your internal purposes. Do not resell, sublicense, or redistribute the service or the reports.
8. No guarantee of detection
SmallShield performs external, non-intrusive scanning and does not guarantee detection of every vulnerability. No security service can find every weakness or prevent every attack. We do not promise that your website is or will remain secure, that every vulnerability will be found, that findings will be free of false positives or false negatives, or that you will not experience a security incident, data breach, ransomware event, defacement, or downtime.
Each scan reflects what could be observed at the moment it ran. Conditions can change immediately afterward. A report with no critical findings is not a certification that your website is secure. Findings also depend in part on third party scanning engines and public vulnerability databases, and we do not warrant that those sources are complete or accurate.
The service and all reports are provided "as is" and "as available." To the fullest extent the law allows, we disclaim all warranties, express, implied, or statutory, including any implied warranty of merchantability, fitness for a particular purpose, title, and non-infringement.
9. Limitation of liability
These limits are a basic part of the bargain and are reflected in the prices.
- Cap. SmallShield's total liability arising out of or relating to the service or these terms, whether in contract, tort, negligence, strict liability, or otherwise, will not exceed the total fees you actually paid to SmallShield in the three months immediately before the event giving rise to the claim.
- Excluded damages. SmallShield will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost or corrupted data, business interruption, loss of goodwill, regulatory fines or penalties, breach notification costs, forensic investigation costs, credit monitoring costs, or ransom payments, even if advised of the possibility.
- Undetected vulnerabilities. Without limiting the above, SmallShield is not liable for any loss arising from a vulnerability the service did not detect, did not detect in time, or classified at a severity you disagree with, or from your decision not to act on a reported finding.
- Scanning impact. Scans are designed to be non-intrusive. In rare cases automated scanning may trigger firewall alerts, rate limiting, extra log volume, or a brief interruption. SmallShield is not liable for these effects when the scan was within the scope you authorized.
- Exceptions. Nothing in this section limits liability for fraud, willful misconduct, or gross negligence, or any liability that cannot be limited under applicable law.
10. Indemnification
You will defend, indemnify, and hold harmless SmallShield and its members, officers, and agents from any third party claim, demand, investigation, fine, loss, or expense, including reasonable attorneys' fees, arising from any inaccuracy in your confirmations under Section 4, including any claim that a scan was unauthorized; your violation of a hosting provider's terms; your use of or failure to act on any report; or your violation of law. SmallShield will defend and indemnify you from any third party claim that the service as delivered infringes a United States patent, copyright, or trade secret, subject to the cap in Section 9.
11. Confidentiality, data, and intellectual property
Scan results and reports are your confidential information. We protect them with at least reasonable care, use them only to deliver the service, and share them only with you and the people you direct us to. How we handle personal information is in our privacy policy. We keep scan data and reports for the term of your subscription and for twelve months after, then delete or anonymize them, unless the law requires longer retention or you ask for earlier deletion. We may use aggregated, anonymized data about vulnerability patterns to improve the service and describe general trends, never identifying you. We will not name you or use your logo in marketing without your written consent.
SmallShield keeps all rights in its methods, software, templates, report formats, and know-how. You receive a non-exclusive, non-transferable license to use the reports for your internal business purposes. You keep all rights in your websites, systems, and data.
12. General
- Independent contractor. SmallShield is an independent contractor. Nothing here creates a partnership, joint venture, agency, employment, or fiduciary relationship.
- Governing law and venue. These terms are governed by the laws of the State of South Carolina, without regard to its conflict of laws rules. Both of us consent to exclusive jurisdiction and venue in the state and federal courts in Charleston County, South Carolina.
- Talk first. Before filing suit, both of us will try in good faith to resolve any dispute by direct discussion for thirty days after written notice of the dispute.
- Jury trial waiver. Each of us knowingly and voluntarily waives any right to a jury trial in any action arising out of these terms.
- Time to bring a claim. Any claim arising out of these terms must be brought within one year after it accrues, to the extent the law allows.
- Events beyond control. Neither of us is liable for delay or failure caused by events beyond reasonable control, including internet or hosting outages, third party platform failures, natural disaster, or government action.
- Changes to these terms. If these terms change, this page changes and the date above moves. Material changes are emailed to your designated contact at least thirty days before they take effect. Continuing to use the service after that date means you accept the change.
- Survival. Sections 3, 4 (for scans already performed), 8, 9, 10, 11, and 12 survive the end of the subscription.
13. Contact
SmallShield LLC, Mount Pleasant, South Carolina. william@smallshield.co