Skip to content

Business Refund Policy

Version 2026-07-31.1

Effective date: 31 July 2026 — Version 2026-07-31.1

This policy forms part of the Business Terms of Service. The service is offered to business customers only.

Full refund before authorization is signed

You may obtain a full refund while the purchased run has no signed Security Testing Authorization. After attaching the purchase to your account, use the refund action shown next to the unsigned run, or email melvyn@melvynx.com from the purchasing address.

Approved refunds are returned through Stripe to the original payment method. Bank processing times are controlled by Stripe and the receiving bank.

No refund after signature

Signing the authorization means that you approve the frozen scope, exclusions, testing rules and operational risk, and instruct us to schedule and begin performance. From that moment, the order is non-refundable.

The following do not create a refund right after signature:

  • no vulnerability is found;
  • fewer or lower-severity findings are found than expected;
  • Customer later changes priority, environment or target;
  • Customer revokes access after work is scheduled or begins; or
  • Customer fails to provide access or cooperation.

You pay for the professional audit effort and both reports, not for a guaranteed finding.

Exceptions

We will refund an amount required by non-waivable law. We will also provide an appropriate refund if we cancel an unsigned order, or if we permanently decline an authorized engagement without delivering the contracted reports and without a Customer-caused or legal blocker.

Chargebacks should not be used as a substitute for a refund request. Contact us first so the order and authorization record can be reviewed.

Contact: melvyn@melvynx.com.