Terms of service
General terms and conditions (AGB) for mobile application security assessments. For businesses only.
Parties
Harith Al-Ani, trading as vybebat, Max-Schwarze-Weg 27a, 46236 Bottrop, Germany, hello@vybebat.dev (the "Assessor"), and the business named in the order (the "Client").
Version 1.0, valid from 5 October 2026.
§ 1 Who these terms apply to
1. These terms apply to every agreement for a security assessment of a mobile application, and to related advice, between the Assessor and the Client.
2. The Assessor works for businesses only: companies, self-employed professionals acting in their profession, and public bodies. The Assessor does not contract with consumers. By ordering, the Client confirms it acts as a business.
3. The Client's own terms do not apply, even if the Assessor does not object to them.
§ 2 What is provided
1. The Assessor performs a time-boxed, sample-based security assessment of the mobile application named in the order or authorisation, against OWASP MASVS v2.1 and the testing profile agreed in the order, and delivers a written report.
2. This is a service, not a guaranteed result (a Dienstvertrag under § 611 of the German Civil Code). The Assessor owes careful, professional work according to the state of the art. The Assessor does not owe any particular outcome, and in particular does not owe finding every vulnerability that exists. Should this agreement nevertheless be treated as a contract for a result, the result owed is the accurate documentation of the tests performed and their outcome, not the absence of further vulnerabilities.
3. An assessment is not a penetration test unless the order says so expressly and names the systems involved. The Client's servers and APIs are not tested unless a separate written authorisation covering them is signed.
4. Not included: fixing issues, writing code, legal advice, certification, and ongoing monitoring.
5. The report is delivered as a PDF in English, unless agreed otherwise.
§ 3 Free assessments
1. Where the order states a price of zero (for example beta, open-source or nonprofit assessments), these terms apply in full, except the payment terms in § 6.
2. A free automated report is machine output that no person has reviewed. It says so on its first page. It is a list of candidates, not confirmed findings.
§ 4 What the Client provides
1. The build to be assessed, test accounts where needed, a technical contact, and the signed authorisation.
2. No work starts before the signed authorisation is received. Delays for that reason do not count against the Assessor.
3. Test accounts contain no real personal data.
4. The Client confirms that it owns or controls the application and any systems named in the authorisation, and that it has any consent third parties require. If this is not true, the Client indemnifies the Assessor against third-party claims that result.
5. If the Client does not provide what it has to, deadlines move accordingly and extra work may be charged at the agreed rate.
§ 5 How the work is done
1. The Assessor chooses the methods, within the agreed scope.
2. The Client's build is kept on the Assessor's own encrypted machines. It is never uploaded to an online scanner or sample-sharing service.
3. Sub-processors and AI tools. The Assessor uses no subcontractors without the Client's consent in text form. The same applies to AI services: excerpts of findings or decompiled code are only processed by an AI service if the order or authorisation names the service and the Client has agreed. The build file itself is never uploaded to an AI service.
4. Client material is deleted within 30 days after the report is delivered, unless agreed otherwise, and the deletion is confirmed in writing. Signed contracts and a record of what was tested (containing no client data) are kept for the legal retention periods.
5. If the Assessor sees signs of an active attack or a personal data breach, the Assessor informs the Client without delay, at the latest within 24 hours, and pauses the work if the Client asks.
§ 6 Price and payment
1. The price in the order applies. The Assessor uses the German small business rule: no VAT is charged (§ 19 UStG).
2. Invoices are due within 14 days without deduction.
3. For orders above EUR 1,500, 50 % is due when the order is placed.
4. Late payment interest and the flat fee under § 288 of the German Civil Code apply.
5. The Client may only set off claims that are undisputed or confirmed by a court.
§ 7 The report reflects one build, at one time
1. The assessment and the report relate only to the build identified in the authorisation (version and SHA-256), on the dates tested.
2. The Assessor does not update the report. Later changes to the app, its libraries, the platform or the threat landscape can introduce issues the report does not cover.
3. The absence of a finding is not a statement that no vulnerability exists.
4. The report is not a certification and does not confirm compliance with any law, regulation or standard. Any regulatory references are technical context, not legal advice.
5. Vybebat is not affiliated with, endorsed or certified by the OWASP Foundation. "OWASP MASVS" identifies the standard assessed against.
§ 8 Liability
1. The Assessor is liable without limitation (a) for intent and gross negligence, (b) for injury to life, body or health, (c) under the German Product Liability Act, and (d) to the extent of any guarantee the Assessor has expressly given.
2. For slight negligence, the Assessor is liable only for breach of an essential contractual duty, meaning a duty whose fulfilment makes proper performance of the contract possible in the first place and on which the Client may regularly rely. In that case liability is limited to the damage that was foreseeable and typical for this kind of contract when it was concluded.
3. Any other liability for slight negligence is excluded, including for indirect damage, lost profit, data loss and business interruption.
4. The Assessor is not liable for damage caused by the Client not acting, acting late or acting wrongly on the report.
5. These limits also protect anyone the Assessor engages to help perform the contract.
6. Claims for slight negligence become time-barred one year after the report is delivered. Statutory limitation periods for the cases in paragraph 1 are not affected.
§ 9 Using the report
1. The Client may use, copy and share the report internally, without limits in time or place.
2. The Client may give the report to third parties (its customers, auditors, investors, regulators) only complete and unchanged. Extracts need the Assessor's consent in text form, so that findings are never shown without their context and limits.
3. Methods, templates, scripts, rules and tools remain the Assessor's property.
4. The Assessor may name the Client as a reference only with the Client's consent in text form.
§ 10 Improving the scanner
The Assessor may use general, anonymised detection knowledge gained from an assessment to improve its methods and tools, for example that a certain configuration pattern causes a false positive. No code, data, names, or details that identify the Client or the application are kept for this purpose or ever published.
§ 11 Vulnerabilities in third-party components
If the Assessor finds a vulnerability in a third-party component the Client uses (a library, SDK or service), the Assessor tells the Client first. The Assessor may report it to that component's maintainer only with the Client's consent, or after 90 days, and in either case without naming the Client or the application.
§ 12 Confidentiality and data protection
Any separately signed confidentiality agreement and, where personal data is processed, the data processing agreement (GDPR Art. 28) apply. If they conflict with these terms, they take precedence. Without a separate agreement, the Assessor keeps all non-public information from the Client confidential for five years after the engagement ends.
§ 13 Ending an engagement
1. Either party may terminate for good cause.
2. The Client may withdraw the authorisation at any time. The Assessor then stops at once. Work already done is paid for at the agreed rate.
3. The Assessor may stop if the work turns out to be impossible, or if the conditions of the authorisation are not met. Payment for work already done remains due.
§ 14 General
1. Changes and additions must be in text form (email is enough).
2. German law applies, excluding the UN Convention on Contracts for the International Sale of Goods.
3. Place of jurisdiction for merchants and legal entities under public law is Bottrop, Germany.
4. If these terms exist in German and English, the version in the language the engagement was negotiated in prevails.
5. If one clause is invalid, the others remain valid.