As of: September 2026
These terms and conditions (the "Terms") apply to all contracts and service agreements for security testing and audit services between Rheono, owner Samir Abis, Daimlerstr. 5E, 76669 Bad Schönborn, Germany (hereinafter the "Provider") and its clients (hereinafter the "Client"). By placing an order, the Client confirms that it has read and accepts these Terms.
These Terms apply to all services of the Provider: the free read-only initial check, the one-off deep single audit, and the continuous, autonomous security subscription (annual, with a monthly option) covering the Client's external web and API surface.
These Terms apply exclusively to contracts with merchants, businesses, and legal entities under public law. To the extent the Client is not a business, these Terms apply only insofar as their content does not conflict with the mandatory consumer protection laws.
Each specific service — in particular scope, price, term, permitted techniques and exclusions — is additionally set out in a written offer, a written authorisation and the rules of engagement (hereinafter "RoE"). Conflicts between these individual agreements and these Terms are resolved as follows: the individual contract and its annexes (RoE, NDA, DPA) prevail over these Terms; these Terms prevail over any purchasing or sales terms of the Client unless the Client has expressly named them in writing as the basis of its order.
Where a separate NDA, a separate data processing agreement (DPA), or a separate RoE amendment is concluded for individual services, they prevail in respect of the subject matter they cover.
The Provider delivers security tests: a continuous, standing test of the external web and API surface of the Client named in the RoE at regular test intervals (the exact cadence — including a retest after relevant changes or releases — is agreed individually in the offer or the RoE), a one-off deep single audit (3–5 days, one retest included), and a free read-only initial check in accordance with clause 4.
All results are individually verified by a named, individually identified researcher of the Provider (proof of concept) and documented in a signed report, including CVSS rating and mapping to NIS2 and ISO 27001 evidence.
The service covers exclusively the scope set out in writing in the current authorisation and RoE. Internal networks, mobile applications, cloud infrastructure and other surfaces are part of the service only if and to the extent they have been agreed in writing as a module.
Offers from the Provider are non-binding and remain valid for 14 days. The contract is based on the Provider's written offer including scope, price and timeline; any change to scope, term or price requires written or text form.
The contract is concluded by the Client's order in text form (email, form in the customer portal, or equivalent) and the Provider's order confirmation in text form, or by the commencement of performance.
By placing an order, the Client confirms that it has taken notice of these Terms. The contract is concluded exclusively on the basis of the respective offer, these Terms, the written authorisation and the RoE; no other terms — including those of the Client — form part of the contract unless expressly agreed in writing.
Where the order is placed via the customer portal (including payment via Stripe), the Client is referred to these Terms by a clearly visible link before the binding order is placed; the Terms are fully accessible before the order is finalised. The version accessible at the time of the order applies.
These Terms only form part of the contract in the version accessible at the time of conclusion under rheono.dev/terms. Amendments to these Terms with respect to the Client are only valid for future contracts or in accordance with clause 23.2.
Written and text form: declarations under these Terms may be made in text form (in particular email), unless written form is expressly required.
The free initial check is a one-off, read-only offer: it comprises at most approximately 300 web requests to the domain in a window of approximately 10–20 minutes, no logins, no test payloads, no port scans. It is only performed after human confirmation on the side of the Provider.
The initial check is non-binding, free of charge and creates no further rights or obligations. The resulting short written report belongs to the Client; it may be kept, shared or ignored. Whether a further collaboration follows does not affect the rights in the report.
A domain is not re-checked unless the Client expressly requests it or a new, significant finding exists (in both cases, communicated in advance). A permanent, indefinite opt-out is available at any time via the function described on the /security page, or on a word. Clauses 5, 12, 13, 14 and 22 apply correspondingly to the initial check; a separate detailed authorisation is not required for the read-only check.
Every invasive test — including every run of the continuous test — is conditional on a prior, dated, written (text form) authorisation from the Client with a specific scope. The scope shall at minimum name: the hosts, domains and IP ranges concerned; the applications and API endpoints to be tested; permitted roles and credentials (including test accounts); permitted techniques and test depth; rate limits and test windows; express exclusions (no-gos); the Client's responsible contact person and their deputy; and the emergency channel for critical notifications.
Without a current, valid authorisation, no test is performed. A granted authorisation does not renew automatically; it must be re-confirmed upon expiry, upon a change of scope, or after a pause of more than 90 days before the next run. The Provider is obliged to ensure the presence of a valid authorisation before each test run and to archive it together with the report.
By granting each authorisation, the Client expressly consents to all measures necessary for the performance of the services insofar as they would, without such consent, fall under the provisions of the German Criminal Code — in particular §§ 202, 202a, 202b, 202c, 269, 274, 303, 303a, 303b — as well as under §§ 3, 4, 23 of the Act Against Unfair Competition (trade secrets) and §§ 69c, 106 of the Copyright Act. This includes in particular: circumvention of access controls, access to and retrieval of data, simulated overloading of systems, setting of test backups, test objects and test accounts, and the associated write access — in each case only within the agreed scope and at the agreed intensity.
The Client shall name a responsible contact person (and a deputy) who is available at short notice at all times during performance for coordination.
The Client may at any time, via the channel named in the RoE, suspend the test with immediate effect (emergency stop); the Provider shall suspend the test immediately. After four weeks without resumption by the Client, the authorisation is deemed dormant; resumption requires fresh confirmation.
The Client shall provide in a timely and usable form all information, accesses, test accounts and approvals required for the performance of the services, and shall inform the Provider of material changes to the system under test (new endpoints, architecture changes, planned maintenance windows). Delays caused by the Client's failure to cooperate in time entitle the Provider to an appropriate extension of deadlines; in such case the Provider is released from schedule and deadline obligations.
The Client warrants that (a) it is the owner or authorised holder of the systems to be tested, or has expressly commissioned the test; (b) it has effectively obtained all required consents and rights of third parties — in particular from hosting, cloud, CDN and SaaS providers, as well as from employees and their representative bodies — or that such are not required; (c) the systems to be tested are not systems of authorities, not systems of critical infrastructure within the meaning of the BSIG, and not other classified or specially legally protected systems, unless expressly agreed in writing otherwise; and (d) the scope has been stated completely and correctly.
If the Client fails to perform or delays its cooperation obligations, the Provider is entitled to suspend performance without such suspension constituting a breach.
The Client acknowledges that a security test is necessarily connected with the targeted exploitation of vulnerabilities and the loading of systems. For test actions carried out within the scope of a valid authorisation and the RoE — including brief, technically unavoidable impairments of the availability, integrity or performance of the Client's systems — the Provider is liable exclusively in accordance with clause 14.
The Client therefore accepts the risk of brief interruptions within the agreed test framework; no right to compensation or reimbursement of costs arises for such interruptions, unless they are based on the intent or gross negligence of the Provider, or go beyond the agreed rate limits and techniques.
The Client shall maintain current, complete data backups of the systems under test and have a suitable restoration process. The Provider recommends to the Client a current, complete backup before a first run on a new system; the decision on the extent and timing of the backup lies with the Client.
The Client is obliged, upon the occurrence of an incident, to take all reasonable measures to limit and mitigate the damage, in particular by prompt restoration from backups and remediation. The Client bears the burden of proof for the existence, extent and amount of the damage it claims.
The agreed prices are fixed lump-sum prices (not usage-based) and are exclusive of statutory sales tax. Billing details are set out in the respective offer.
For one-off orders (audit), a prepayment of 50% of the agreed fee is payable before the commencement of performance. For annual subscriptions, the subscription fee for the running contract year is payable upon commencement of performance, unless monthly billing has been agreed; in that case the fee is payable in advance on the 1st of each month.
Invoices are due within 14 days of the invoice date without deduction. If the Client is in default of payment, the Provider is entitled to statutory default consequences (in particular default damages under § 288 BGB) and a reminder fee of EUR 5 per reminder.
If the default of payment exceeds 14 days after the due date, the Provider is entitled, after a further reasonable grace period of 7 days, to suspend performance until the outstanding amounts are settled; this does not release the Client from its payment obligations. If the Client remains in default despite reminder, the Provider may terminate the contract for cause (clause 9.3).
An increase of the fee is only permissible at the earliest with the beginning of each extension of the contract term, and only to a maximum of 5% compared to the previous fee. The Provider shall notify the Client in writing at least three months before the increase takes effect. The Client may object to the increase in writing within 30 days of receipt and terminate the contract to take effect on the date of the increase; in the absence of an objection, the adjusted prices apply from that date. During a running contract term the price remains fixed.
Contracts for the continuous service have a minimum term of 12 months (annual). After the minimum term, the contract is extended by a further 12 months unless a party terminates in writing at least three months before the end of the term.
On the Client's request, the continuous service may be agreed monthly; in that case either party may terminate with a notice period of 30 days to the end of a calendar month.
Either party may terminate the contract for cause without notice, in particular in case of: a serious breach of the written authorisation or the RoE; a serious breach of confidentiality or data protection obligations; a payment default of more than 14 days despite reminder; the occurrence of material grounds for insolvency; or force majeure (clause 17) lasting more than 60 days.
Upon termination of the contract — for whatever reason — the services performed up to that point remain payable in full. The subscription fee agreed for the running contract term remains payable in full upon termination before its expiry, unless the termination is based on the fault or an important reason of the Provider. The reports already created are handed over without restriction; all accesses, test accounts and permissions granted to the Provider are revoked with effect from the time of termination. The data protection consequences are regulated by clause 13.5.
The signed report is a documented state of affairs at the time of its creation. It does not constitute a guarantee of the completeness of all identified vulnerabilities, nor a guarantee of the lasting security of the Client's systems or the fulfilment of regulatory requirements (in particular NIS2, ISO 27001, SOC 2). The Provider is obliged to perform the agreed test according to the agreed effort and methodological standard (best effort in accordance with the RoE), not to bring about a particular security state.
Critical and high-critical findings are communicated by the Provider to the Client immediately, and at the latest within 24 hours of their verification, via the channel named in the RoE, including a preliminary assessment and possible immediate measures.
For the subscription: every material change of the system under test (release) is retested within the agreed scope; this is part of the service, not an additional event.
The Client shall notify defects of the report without undue delay after becoming aware, at the latest within 30 days after delivery. The Provider shall provide a cure by correction or re-testing at its own cost; in relation to the single audit, one retest of the finding is part of the service. Warranty rights beyond the cure (in particular withdrawal, reduction, damages for defects) are excluded, to the extent that the liability regulated in clause 14 does not apply.
The availability of the testing infrastructure operates on a best-effort basis; there are no fixed availability commitments (SLA). Brief interruptions of the testing activity (for example for maintenance) do not give rise to a right to reduction or damages.
Upon full payment of the agreed fee, the Client receives a non-exclusive, non-transferable, worldwide right to use the reports, proofs of concept and recommendations created for it for its internal purposes, for remediation of the findings, for submission to auditors, supervisory and investigative authorities, and — in accordance with clause 12 — to legally entitled bodies. Any further distribution of the reports (in particular publication, further passing to third parties without necessity, use for the marketing purposes of third parties) is excluded without the prior written consent of the Provider.
The Client receives no rights whatsoever in the pipeline, the agents, tools, scripts, methods, approach and the associated know-how of the Provider (the "service infrastructure"). In particular, the Client is not entitled to analyse, reproduce or reverse engineer the service infrastructure, or to use it for competitive evaluations.
The Provider may derive from the tests anonymised, aggregated metrics and statistics that are not attributable to the Client or its systems, and use these for the improvement of its own services, for research purposes and in external communication (including case studies without naming the Client), unless the Client objects. An objection applies to future tests; already anonymised metrics remain unaffected.
Where a finding relates to a vulnerability in a product, service or component provided by a third party (for example a SaaS service, a library or a plugin), the Provider is entitled to report this vulnerability to the respective manufacturer or via its bug bounty programme in accordance with the principles of responsible disclosure, whereby the Client will be informed in text form in advance. Such reporting does not constitute a breach of clause 12.
If the Provider discovers during an order a vulnerability not publicly known up to that point (zero day), it remains strictly confidential until its disclosure. Disclosure is made in accordance with the principles of responsible disclosure; the Provider coordinates timing and extent with the Client, unless the Client or a legal obligation (in particular towards the manufacturer, the BSI or a supervisory authority) requires earlier disclosure.
Both parties undertake to keep confidential all information obtained in the course of the cooperation which is not obviously publicly known and is marked as confidential or is to be treated as confidential by its nature ("Confidential Information"), including all findings, vulnerabilities, PoCs, systems, architectures, credentials and personal data, and to use it exclusively for the performance of the contract.
The confidentiality obligation continues for 5 years after the end of the contract. For information protected under § 17 of the German Act Against Unfair Competition (trade secret), it continues for as long as the information meets the statutory conditions for secret protection.
The confidentiality obligation does not apply insofar as the information (a) was already known to the recipient before disclosure; (b) becomes publicly known without a breach of this clause; (c) is acquired from an admissible third source; (d) is used by the Provider anonymously and aggregated pursuant to clause 11.3; or (e) the recipient is obliged to disclose by a statutory, official or judicial obligation. In case (e), the recipient shall — insofar as legally permissible and reasonable — inform the other party before disclosure and limit the disclosure to the legally necessary extent.
The Client shall not publish findings (including to the public, media or bug-bounty platforms) while they are not remediated or released by the Provider as published; this does not apply insofar as the Client is legally obliged (in particular in the course of its own NIS2 reporting duties) — in that case it shall coordinate timing and extent with the Provider insofar as reasonable.
To the extent personal data are processed in the course of the Provider's services (e.g. by access to client data within the test or in reports), the Client is the controller and the Provider is the processor within the meaning of Regulation (EU) 2016/679 (GDPR). The parties shall in that case conclude a data processing agreement (DPA) under Art. 28 GDPR, which forms part of the contract; it prevails over these Terms for the area it covers.
The Provider shall avoid access to personal data insofar as this is technically reasonable, and limit their processing to the extent necessary for the performance of the services (data minimisation, Art. 5 GDPR). Reports and PoCs contain only the data required for the respective finding.
The Provider shall inform the Client immediately, and at the latest within 24 hours, of a known incident concerning personal data of the Client, and support the Client in the fulfilment of its obligations under Art. 33 GDPR as well as in the technical and organisational post-processing.
The Provider processes the data of the Client in a data centre in the European Union (further information in the privacy policy under rheono.dev/privacy) and engages only sub-processors that assume the equivalent obligations under Art. 28 GDPR. The Client may object to the engagement of a sub-processor if the Provider cannot offer a technical and organisational alternative without substantially worsening the service.
After the end of the contract or after completion of the individual service, the Provider shall, at the choice of the Client, return or delete all personal data (including all copies), unless a statutory retention obligation (in particular tax, commercial or procedural) applies; in that case the data are restricted to the statutory purpose of retention.
With regard to the free initial check (clause 4): no systematic access to personal data is made; any individual, unavoidably collected data (e.g. within a finding) are also subject to this clause.
The Provider is liable towards the Client without limitation (a) for intent or gross negligence, including the intentional or grossly negligent breach of obligation of its statutory representatives and vicarious agents; (b) for damage to life, body or health; (c) to the extent that mandatory statutory liability exists (in particular under the Product Liability Act); and (d) to the extent that a guarantee has been expressly assumed in writing, within the scope of that guarantee.
In case of slight negligence, the Provider is liable only for the breach of essential contractual obligations (cardinal duties), limited to the contractually typical, foreseeable damage at the time of conclusion. Essential contractual obligations are obligations whose performance is a prerequisite for the proper performance of this contract and on whose performance the Client can regularly rely. These are in particular: (a) the performance of the agreed test within the scope set out in the valid authorisation; (b) the compliance with the written authorisation and the RoE; (c) the confidentiality obligation under clause 12; (d) the compliance with the data protection obligations including the DPA; and (e) the handover of the agreed, verified and signed reports.
Otherwise, in case of slight negligence, the liability of the Provider is excluded.
Without prejudice to paragraph 2: if the Provider, in slight negligence, breaches an obligation with the consequence that the Client suffers a loss, alteration or unavailability of data, the liability is limited to the demonstrable costs of restoration which would arise if the Client — as presupposed in clause 7 — had operated a proper, timely and complete data backup.
These liability provisions also apply to the Client's claims arising from the breach of data protection obligations (in particular under Art. 82 GDPR), unless a different provision is expressly made in the DPA.
The liability owed under paragraph 2 (including the provision on data loss) is limited to the amount of the annual compensation agreed in the running contract term; in the case of a contract for the single audit, to twice the audit fee; in each case per contract and calendar year.
The Provider maintains a liability insurance with a coverage sum of EUR 50,000,000 per insured event, without deductible. The insurance does not create a direct claim of the Client and does not replace any of the liability provisions of this clause. The Client is entitled, in the event of a valid liability claim, to require proof of the existence and the sums of the insurance on first request. An assignment of claims of the Client to the insurer of the Provider is only permitted insofar as the insurer requires it for the settlement of the insurance case.
The limitation periods for warranty claims (clause 10) are 12 months in the case of contracts with merchants, counted from the delivery of the respective report; they also apply to defects which only become recognizable after delivery, to the extent that the knowledge of the defect cannot be attributed to the Client.
Otherwise, the claims under this contract are subject to the statutory limitation periods; for tort claims, the statutory period of 3 years applies.
A shortening or extension of the limitation periods for claims based on intent or gross negligence, or on the areas listed in clause 14.1, is excluded. A reversal of the burden of proof to the detriment of the Client does not take place.
The Provider performs the services in principle with its own, individually named personnel. If the Provider engages subcontractors, this requires the prior consent of the Client, unless the subcontractor assumes exclusively aspects already released in the RoE.
An engaged subcontractor is subject to the same confidentiality and data protection obligations as the Provider. The Provider is liable for the selection, instruction and supervision of its subcontractor and for its fault as for its own.
Each affected party is released from its obligations to the extent that it cannot perform them without fault, if caused by an event of force majeure. Force majeure includes all circumstances not to be borne by the affected company, arising from outside, and not reasonably capable of being eliminated within a reasonable time, in particular: a failure of networks, data centres or power; official orders; epidemics; wars, natural disasters; as well as the failure of an essential service provider of the Provider, if the Provider could not offer a reasonable alternative.
Upon the occurrence of force majeure, the affected party is obliged to notify the other party immediately of the event and its expected duration and to take all reasonable measures to limit the effects. The affected deadline is extended by the duration of the impairment.
If the force majeure lasts more than 60 days, either party may terminate the contract without notice in writing; the consequences of termination are regulated by clause 9.4.
Both parties undertake to comply with the applicable statutory and official provisions when performing the contract, in particular with regard to data protection, export control, sanctions and anti-corruption.
The Provider will not perform a test on systems for which it has demonstrable knowledge that they are located in a region for which a relevant sanctions restriction exists, unless the Client ensures that the test takes place in accordance with the sanctions rules.
The Client is itself responsible for the fulfilment of its own regulatory obligations (in particular under NIS2, BSIG, sector-specific rules); the reports of the Provider do not replace an own compliance strategy.
An assignment of claims under this contract to third parties requires the prior written consent of the Provider, unless it is an intra-group assignment to a credit institution.
The Provider may transfer its rights and obligations under this contract to a legal successor by way of universal succession or a business transfer agreement, provided that the successor unconditionally assumes the confidentiality and data protection obligations and is identified to the Client.
Amendments and additions to this contract (including these Terms, the RoE and the scope) require text form. Oral agreements are ineffective, unless they are subsequently confirmed in text form.
Exception: the scope, the authorisation and the RoE are always and exclusively set out in text form and can only be amended in text form.
These Terms are available in German and English. In case of a dispute or any discrepancy between the versions, the German version shall prevail.
The laws of the Federal Republic of Germany shall apply to the contract, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and any other conflict of laws rules.
Exclusive jurisdiction for all disputes arising out of or in connection with this contract (including the determination of the validity of the contract) shall be the court competent for the seat of the Provider, insofar as legally permissible. This also applies to disputes concerning the content, validity or termination of the contract and to claims in tort.
Except: the statutory jurisdiction for claims on the protection of intellectual property rights; the exclusive jurisdiction for disputes concerning the registration, deletion or injunction of acts concerning a right or property located in Germany; and the jurisdiction of the habitual residence of a consumer, insofar as mandatory statutory rules for consumers restrict the application of this clause.
The European Commission provides a platform for online dispute resolution (ODR); the platform is available under ec.europa.eu/consumers/odr. The Provider is not obliged to, and does not voluntarily, take part in dispute resolution proceedings before a consumer arbitration board.
If individual provisions of this contract (including these Terms) are or become invalid, this shall not affect the validity of the remaining provisions. In the place of the invalid provision, the valid provision which comes closest to the economic purpose of the invalid provision shall apply (supplementary interpretation); this does not apply to provisions on a limitation of liability or the exclusion of claims, in which case the statutory provision applies.
The version of these Terms accessible at the time of conclusion under rheono.dev/terms applies. An amendment of these Terms with respect to the Client is only permissible in the case of: (a) future contracts (new order, new service); (b) existing contracts, if the Provider informs the Client in writing at least three months before the amendment takes effect and grants the Client a timely, free right of termination to take effect on the date of the amendment; or (c) a materially equivalent benefit accrues to the Client.
The complete, at-conclusion version of these Terms is archived by the Provider for the duration of the contract term plus three years and handed over to the Client on request.
Note: These terms were drafted in accordance with §§ 305–310 BGB and the specifics of continuous security testing. They apply to contracts with businesses; the actual collaboration (authorisation, scope, RoE) is governed by the respective written agreement.