Legal
Terms
Last updated August 1, 2026
These terms cover the Free Security Snapshot request form on this site — what requesting one does, and just as importantly, what it doesn’t.
The Free Security Snapshot
The Free Security Snapshot is a passive review of a company’s public attack surface, delivered as a short report. It’s built from information that’s already public: OSINT, DNS records, certificate transparency logs, breached-database checks, and a single load of your homepage — the same page, and the same JavaScript and CSS files, that any visitor’s browser already fetches.
I don’t log in, use credentials, submit payloads, or test for vulnerabilities, and I don’t go past that one page load — no crawling additional pages, no guessing at paths that aren’t linked. That’s a real constraint on what this service does, not a caveat — nothing here does anything your own browser wouldn’t already do by visiting your site.
Requesting one creates nothing
Submitting the form is a request for a free report — nothing more. It doesn’t create an engagement, a contract, or any obligation on either side. There’s no fee, no ongoing relationship, and no commitment to purchase anything, now or later.
Provided as-is
The Snapshot is provided free of charge, as-is, with no warranty of any kind, express or implied. I don’t guarantee it’s complete, accurate, or that it identifies every publicly exposed issue affecting the domain you submit. Treat it as one input, not a definitive assessment.
What it isn't
The Snapshot is not a penetration test, a security audit, or a compliance assessment. Requesting or receiving one doesn’t make you or your company compliant or certified under SOC 2, HIPAA, PCI DSS, or any other framework, and doesn’t certify anything. It’s a passive, informational report, nothing else.
What's recorded
Your first and last name, company name, work email, company domain, two flags computed from what you submitted (whether the email is a free or disposable-mail provider, and whether its domain matches the company domain you gave), the authorization confirmation, the IP address the request came from, your browser’s user agent, and a timestamp are recorded in the notification email your request generates. A copy — everything except the user agent — is also posted to a private Slack channel I use to review requests. There’s no separate database. Both are kept until you ask for them to be deleted — email jack@thompsonindustries.org and they’re removed. The privacy policy covers this in full.
Changes to these terms
These terms may be updated from time to time. The version in effect is whatever’s posted here at the time you submit a request.
Contact
Questions about these terms: jack@thompsonindustries.org. See also the Privacy policy for what the form collects and how long it's kept.