Legal

Terms

Last updated August 1, 2026

These terms cover the Free Security Snapshot request form on this site — what requesting one does, and just as importantly, what it doesn’t.

01The offer

The Free Security Snapshot

The Free Security Snapshot is a passive review of a company’s public attack surface, delivered as a short report. It’s built from information that’s already public: OSINT, DNS records, certificate transparency logs, breached-database checks, and a single load of your homepage — the same page, and the same JavaScript and CSS files, that any visitor’s browser already fetches.

I don’t log in, use credentials, submit payloads, or test for vulnerabilities, and I don’t go past that one page load — no crawling additional pages, no guessing at paths that aren’t linked. That’s a real constraint on what this service does, not a caveat — nothing here does anything your own browser wouldn’t already do by visiting your site.

02No engagement

Requesting one creates nothing

Submitting the form is a request for a free report — nothing more. It doesn’t create an engagement, a contract, or any obligation on either side. There’s no fee, no ongoing relationship, and no commitment to purchase anything, now or later.

03Authorization

You confirm you're authorized

When you send a request, the “Free Security Snapshot — Authorization & Waiver” (v1.3) is shown and you agree to it before anything is submitted. I rely on that agreement and don’t independently verify it before preparing a report. In full, it reads:

  1. Authorization. You confirm that you are authorized to request a review of the domain you submitted on behalf of the organization that owns or operates it. Do not submit a domain you are not permitted to have reviewed.
  2. What the snapshot is. The Free Security Snapshot is built from information that is already public. That includes open-source intelligence, DNS records, certificate transparency logs, and breached-database checks, plus a single load of your homepage — the same page, and the same JavaScript and CSS files, that a browser visiting your site already fetches. It goes no further than that one page load: it does not crawl additional pages, follow links, or guess at paths that are not linked. It does not involve logging in, using credentials, submitting payloads, or testing for vulnerabilities, and no port scanning is performed.
  3. No warranty. The snapshot is provided "as is," without warranty of any kind. It is not a comprehensive assessment and may not identify every exposure or risk. It does not make your organization secure, and it does not establish compliance or certification under any standard, including SOC 2, HIPAA, or PCI.
  4. Limitation of liability. To the fullest extent permitted by applicable law, Thompson Industries and its owner will not be liable for any indirect, incidental, special, or consequential damages, or for any loss or damage arising out of the snapshot or your use of it, except to the extent such liability cannot be limited under applicable law.
  5. Release. You release Thompson Industries and its owner from any claim arising out of performing the review you authorize here — the public-data checks and the single homepage load described above, carried out within that scope.
  6. Electronic agreement. By clicking "I agree," you enter into this agreement electronically. We record your name, your company name, your email address, the submitted domain, and the date, time, and IP address of your agreement as evidence of it.

Waiver version 1.3

04No warranty

Provided as-is

The Snapshot is provided free of charge, as-is, with no warranty of any kind, express or implied. I don’t guarantee it’s complete, accurate, or that it identifies every publicly exposed issue affecting the domain you submit. Treat it as one input, not a definitive assessment.

05Scope limits

What it isn't

The Snapshot is not a penetration test, a security audit, or a compliance assessment. Requesting or receiving one doesn’t make you or your company compliant or certified under SOC 2, HIPAA, PCI DSS, or any other framework, and doesn’t certify anything. It’s a passive, informational report, nothing else.

06Your data

What's recorded

Your first and last name, company name, work email, company domain, two flags computed from what you submitted (whether the email is a free or disposable-mail provider, and whether its domain matches the company domain you gave), the authorization confirmation, the IP address the request came from, your browser’s user agent, and a timestamp are recorded in the notification email your request generates. A copy — everything except the user agent — is also posted to a private Slack channel I use to review requests. There’s no separate database. Both are kept until you ask for them to be deleted — email jack@thompsonindustries.org and they’re removed. The privacy policy covers this in full.

07Changes

Changes to these terms

These terms may be updated from time to time. The version in effect is whatever’s posted here at the time you submit a request.

08Contact

Contact

Questions about these terms: jack@thompsonindustries.org. See also the Privacy policy for what the form collects and how long it's kept.