01 / Service scope
Service scope and limitations
What the initial review covers
The $159 initial security scan is a scoped black-box assessment of one publicly accessible website identified in the booking. Specialised security-testing platforms assist with discovery and targeted testing, after which relevant results are reviewed and prepared as a prioritised report.
Depending on the target, checks may include attack-surface and subdomain discovery, technology and service fingerprinting, website and API routes, HTTPS and security configuration, exposed resources, authentication and session behaviour, access-control weaknesses, common injection risks, browser-side vulnerabilities and other externally observable issues.
How testing is performed
The standard assessment is designed to be controlled and non-destructive. Our tools may crawl authorised pages, inspect requests and responses, send crafted test requests and perform limited validation of potential findings. We do not intentionally disrupt the website, alter business data, access private customer information or continue testing where validation could create unreasonable risk.
Testing is limited to the website and related assets explicitly authorised by the customer. Automated output is not treated as a confirmed finding without review and sufficient supporting evidence.
Authenticated and source-code options
Authenticated testing can be included in the $159 initial security scan when requested before testing begins. The client must provide dedicated test accounts, confirm the permitted user roles and authorise the relevant logged-in areas in writing. We do not use real customer accounts or request customer passwords for this testing.
Source-code testing can be added for $99 where the client owns the code or is authorised to provide it. The written scope will identify the agreed repository or codebase, permitted testing activities and any exclusions.
What is not included
- A full manual penetration test, source-code review or compliance audit.
- Denial-of-service, load, social-engineering or phishing tests.
- Credential stuffing, password attacks, destructive exploitation or intentional access to restricted data.
- Internal networks, third-party platforms or assets outside the agreed scope.
- Authenticated, source-aware or business-logic testing not expressly included in the written scope.
- Implementation of fixes unless separately agreed in writing.
Reports and rechecks
The report provides a point-in-time view based on information available during the review. Findings are prioritised for the business owner and include practical notes for a developer or website maintainer. The initial scan includes one complimentary recheck of reported items requested within 14 days of report delivery.
Limitations
No security review can identify every vulnerability or guarantee that a website is secure. Results may be affected by website changes, third-party services, access restrictions and information unavailable during testing. High-risk, regulated or complex systems should obtain a formal penetration test from a suitably qualified provider.
02 / Customer agreement
Terms of service
1. Agreement
These terms apply when you purchase or request a LetsSecure service. By proceeding, you confirm that you have read and accepted these terms and the applicable service scope.
2. Your authority
You confirm that you own, control or have written authority to request testing of every website or asset you submit. You authorise LetsSecure to perform the checks described in the agreed scope. You must not submit an asset belonging to another person without their permission.
3. Testing options
Authenticated testing is included in the initial security scan when you select it before testing begins, provide dedicated test accounts and approve the relevant roles and logged-in areas in writing. Source-code testing is a $99 add-on for the agreed codebase. For source-code testing, you confirm that you own the supplied code or are authorised to provide it for security testing.
4. Your responsibilities
You must provide accurate contact and scope information, disclose relevant restrictions, maintain current backups and notify us promptly if testing should stop. Test accounts must not contain real customer information and should be disabled or removed after testing. You remain responsible for deciding whether and how to implement report recommendations.
5. Fees and delivery
Prices are displayed in Australian dollars unless stated otherwise. The initial security scan is $159 and the source-code testing add-on is $99. Payment is due as presented during booking or invoicing. The usual report target is 24-72 hours after payment, scope confirmation and receipt of required information, but this is an estimate rather than a guaranteed deadline.
6. Monthly Watch
Monthly Watch is billed at $59 per month until cancelled. It provides a recurring external re-assessment of the agreed website, including attack-surface changes and updated findings within the standard scope. It is not continuous monitoring or an emergency incident-response service. Cancellation takes effect before the next billing period; fees already charged are not refunded except where required by law.
7. No-action credit
If the initial review finds no actionable security issues, the customer receives the completed baseline report and a $79.50 credit toward a Monthly Watch subscription. The credit is not redeemable for cash, cannot be transferred and is applied only to that customer's eligible subscription.
8. Reports
You may use and share your completed report with employees, developers, hosts and advisers for your business purposes. LetsSecure retains ownership of its underlying report format, methods and general materials. You must not misrepresent, resell or publish the report as a certification.
9. Confidentiality
We will handle non-public information supplied for the service with reasonable care and use it only to provide, administer or protect the service, except where disclosure is required by law.
10. Service limitations
LetsSecure provides a practical point-in-time review, not a guarantee, certification or complete penetration test. To the extent permitted by law, we are not responsible for vulnerabilities not identified, later website changes, third-party systems or losses caused by decisions made without appropriate professional assessment.
11. Australian Consumer Law
Nothing in these terms excludes rights or remedies that cannot lawfully be excluded, including applicable rights under the Australian Consumer Law.
12. Refusal or suspension
We may refuse, pause or stop work where authority cannot be verified, the requested activity falls outside our safety boundaries, payment is overdue or continuing could create unreasonable risk.
13. Governing law and contact
These terms are governed by the laws applicable in New South Wales, Australia. Questions or concerns should be sent to info@letssecureit.net.
03 / Personal information
Privacy policy
What we collect
We may collect your name, email address, business name, website address, billing information, messages, service instructions and records created while providing a review. For separately scoped services, we may also receive temporary test-account credentials or authorised source code. We may collect technical information that is publicly visible from the authorised website.
Why we collect it
We use this information to respond to enquiries, confirm authority and scope, provide and improve services, prepare reports, process payments, maintain business records, prevent misuse and meet legal obligations.
How we collect it
Information may be collected when you contact us, submit a booking, make a payment, provide service instructions or communicate with us. Basic technical logs may also be generated when our website or service systems are used.
Service providers
We may share only the information reasonably required with providers supporting email, hosting, payments, business administration and security-review tools. Some providers may process or store information outside Australia under their own privacy and security arrangements. We do not sell personal information.
Storage and retention
We take reasonable steps to protect information from misuse, interference, loss and unauthorised access. Information is retained only for as long as reasonably needed for the service, business records, dispute handling or legal requirements, then deleted or de-identified where appropriate.
Your choices
You may request access to or correction of personal information we hold about you. You may also ask a privacy question or make a complaint by emailing info@letssecureit.net. We may need to verify your identity before responding.
Policy changes
We may update this policy as our services or obligations change. The current version and update date will be published on this page.