Terms of service
These are the terms on which Northloop Security provides its free snapshot and its paid services. They are written in plain English on purpose. Paid engagements are also covered by a short written authorisation and scope, which takes precedence where the two differ.
Who we are
Northloop Security is a trading name of Northloop, a London-based UK sole trader. Contact: security@northloopsystems.com.
What we do, and what we do not do
- We assess the external, public-facing posture of domains and systems you own or are authorised to represent. We do not test internal systems, log in to anything, or attempt to exploit a weakness unless a separate written scope says so.
- Free snapshots use passive, non-intrusive checks only. Anything that could affect the availability of your systems is excluded from every engagement by default.
- We never contact your clients, staff or suppliers, and we never test anything you have not authorised in writing.
- Our reports are an independent assessment of what could be observed at the date shown. They are not a certification, a warranty, or a guarantee that your systems are secure, and they do not replace an accredited penetration test or a Cyber Essentials certification body.
Authorisation
By requesting a snapshot or an assessment you confirm that you own the domain, or are authorised by its owner, and that you authorise Northloop Security to carry out the checks described. If you are not, do not submit the request. We may ask for evidence of authorisation before running any paid work.
Prices and payment
Every paid service is a fixed price, agreed in writing before work starts. Prices shown on this site are for a firm of up to about 25 staff and 3 domains; anything larger is quoted before you commit. We never bill by the hour. Invoices are payable within 14 days. Continuous Monitoring is billed monthly and can be cancelled at any time with one month’s notice.
Confidentiality
Everything we find about your firm is confidential. We share it only with you and with anyone you ask us to brief (for example your IT provider). We never use your findings in marketing and never publish anything that identifies a client. Aggregate statistics we publish (such as the proportion of firms without DMARC) name no firm.
Your responsibilities
Fixing what we find is your decision and your responsibility, or that of your IT provider. We will explain each finding and, in the relevant packages, brief your provider and re-test, but we do not make changes to your systems ourselves.
Liability
We carry out our work with reasonable skill and care. Our total liability to you in connection with any engagement is limited to the fees you have paid for that engagement. We are not liable for loss arising from a weakness that could not be observed from the outside, that arose after the date of the report, or that you chose not to fix. Nothing in these terms limits liability that cannot be limited by law.
Data
How we handle the details you give us and the findings we generate is set out in our privacy & testing policy. You can ask us to delete your data at any time.
Law
These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Last updated 29 August 2026. Northloop Security is a service of Northloop.