Home Book scan

Clear boundaries

How LetsSecure works.

Our service scope, customer terms and approach to personal information, written in plain English.

Last updated 23 July 2026

On this page Service scope Terms of service Privacy policy

01 / Service scope

Service scope and limitations

What the initial review covers

The $159 initial security scan is a scoped black-box assessment of one publicly accessible website identified in the booking. Specialised security-testing platforms assist with discovery and targeted testing, after which relevant results are reviewed and prepared as a prioritised report.

Depending on the target, checks may include attack-surface and subdomain discovery, technology and service fingerprinting, website and API routes, HTTPS and security configuration, exposed resources, authentication and session behaviour, access-control weaknesses, common injection risks, browser-side vulnerabilities and other externally observable issues.

How testing is performed

The standard assessment is designed to be controlled and non-destructive. Our tools may crawl authorised pages, inspect requests and responses, send crafted test requests and perform limited validation of potential findings. We do not intentionally disrupt the website, alter business data, access private customer information or continue testing where validation could create unreasonable risk.

Testing is limited to the website and related assets explicitly authorised by the customer. Automated output is not treated as a confirmed finding without review and sufficient supporting evidence.

Authenticated and source-code options

Authenticated testing can be included in the $159 initial security scan when requested before testing begins. The client must provide dedicated test accounts, confirm the permitted user roles and authorise the relevant logged-in areas in writing. We do not use real customer accounts or request customer passwords for this testing.

Source-code testing can be added for $99 where the client owns the code or is authorised to provide it. The written scope will identify the agreed repository or codebase, permitted testing activities and any exclusions.

What is not included

  • A full manual penetration test, source-code review or compliance audit.
  • Denial-of-service, load, social-engineering or phishing tests.
  • Credential stuffing, password attacks, destructive exploitation or intentional access to restricted data.
  • Internal networks, third-party platforms or assets outside the agreed scope.
  • Authenticated, source-aware or business-logic testing not expressly included in the written scope.
  • Implementation of fixes unless separately agreed in writing.

Reports and rechecks

The report provides a point-in-time view based on information available during the review. Findings are prioritised for the business owner and include practical notes for a developer or website maintainer. The initial scan includes one complimentary recheck of reported items requested within 14 days of report delivery.

Limitations

No security review can identify every vulnerability or guarantee that a website is secure. Results may be affected by website changes, third-party services, access restrictions and information unavailable during testing. High-risk, regulated or complex systems should obtain a formal penetration test from a suitably qualified provider.

02 / Customer agreement

Terms of service

1. Agreement

These terms apply when you purchase or request a LetsSecure service. By proceeding, you confirm that you have read and accepted these terms and the applicable service scope.

2. Your authority

You confirm that you own, control or have written authority to request testing of every website or asset you submit. You authorise LetsSecure to perform the checks described in the agreed scope. You must not submit an asset belonging to another person without their permission.

3. Testing options

Authenticated testing is included in the initial security scan when you select it before testing begins, provide dedicated test accounts and approve the relevant roles and logged-in areas in writing. Source-code testing is a $99 add-on for the agreed codebase. For source-code testing, you confirm that you own the supplied code or are authorised to provide it for security testing.

4. Your responsibilities

You must provide accurate contact and scope information, disclose relevant restrictions, maintain current backups and notify us promptly if testing should stop. Test accounts must not contain real customer information and should be disabled or removed after testing. You remain responsible for deciding whether and how to implement report recommendations.

5. Fees and delivery

Prices are displayed in Australian dollars unless stated otherwise. The initial security scan is $159 and the source-code testing add-on is $99. Payment is due as presented during booking or invoicing. The usual report target is 24-72 hours after payment, scope confirmation and receipt of required information, but this is an estimate rather than a guaranteed deadline.

6. Monthly Watch

Monthly Watch is billed at $59 per month until cancelled. It provides a recurring external re-assessment of the agreed website, including attack-surface changes and updated findings within the standard scope. It is not continuous monitoring or an emergency incident-response service. Cancellation takes effect before the next billing period; fees already charged are not refunded except where required by law.

7. No-action credit

If the initial review finds no actionable security issues, the customer receives the completed baseline report and a $79.50 credit toward a Monthly Watch subscription. The credit is not redeemable for cash, cannot be transferred and is applied only to that customer's eligible subscription.

8. Reports

You may use and share your completed report with employees, developers, hosts and advisers for your business purposes. LetsSecure retains ownership of its underlying report format, methods and general materials. You must not misrepresent, resell or publish the report as a certification.

9. Confidentiality

We will handle non-public information supplied for the service with reasonable care and use it only to provide, administer or protect the service, except where disclosure is required by law.

10. Service limitations

LetsSecure provides a practical point-in-time review, not a guarantee, certification or complete penetration test. To the extent permitted by law, we are not responsible for vulnerabilities not identified, later website changes, third-party systems or losses caused by decisions made without appropriate professional assessment.

11. Australian Consumer Law

Nothing in these terms excludes rights or remedies that cannot lawfully be excluded, including applicable rights under the Australian Consumer Law.

12. Refusal or suspension

We may refuse, pause or stop work where authority cannot be verified, the requested activity falls outside our safety boundaries, payment is overdue or continuing could create unreasonable risk.

13. Governing law and contact

These terms are governed by the laws applicable in New South Wales, Australia. Questions or concerns should be sent to info@letssecureit.net.

03 / Personal information

Privacy policy

What we collect

We may collect your name, email address, business name, website address, billing information, messages, service instructions and records created while providing a review. For separately scoped services, we may also receive temporary test-account credentials or authorised source code. We may collect technical information that is publicly visible from the authorised website.

Why we collect it

We use this information to respond to enquiries, confirm authority and scope, provide and improve services, prepare reports, process payments, maintain business records, prevent misuse and meet legal obligations.

How we collect it

Information may be collected when you contact us, submit a booking, make a payment, provide service instructions or communicate with us. Basic technical logs may also be generated when our website or service systems are used.

Service providers

We may share only the information reasonably required with providers supporting email, hosting, payments, business administration and security-review tools. Cloudflare Turnstile processes technical signals to help prevent automated form abuse. Some providers may process or store information outside Australia under their own privacy and security arrangements. We do not sell personal information.

Storage and retention

We take reasonable steps to protect information from misuse, interference, loss and unauthorised access. Information is retained only for as long as reasonably needed for the service, business records, dispute handling or legal requirements, then deleted or de-identified where appropriate.

Your choices

You may request access to or correction of personal information we hold about you. You may also ask a privacy question or make a complaint by emailing info@letssecureit.net. We may need to verify your identity before responding.

Policy changes

We may update this policy as our services or obligations change. The current version and update date will be published on this page.

Practical website security reviews for small online businesses.

Service scope Terms Privacy

info@letssecureit.net ยท Copyright 2026