Skip to content

Business Terms of Service

Version 2026-07-31.1

Effective date: 31 July 2026 — Version 2026-07-31.1

These Business Terms of Service (the Terms) form a binding agreement between Codelynx, LLC, Delaware limited liability company, EIN 37-2114657, at 8 The Green STE B, Dover, Delaware 19901, United States (Codelynx, we, us), and the business purchasing a security audit (Customer, you).

1. Business customers only

The service is offered exclusively to businesses and professionals acting for purposes related to their trade, business or profession. By ordering, you confirm that you are at least 18, are not purchasing as a consumer, and have authority to bind the organization identified during onboarding.

2. Contract documents and acceptance

The contract consists of, in descending order of precedence: the signed Security Testing Authorization and its immutable Rules of Engagement; any written order form signed by both parties; the Data Processing Addendum; these Terms; the Refund Policy; and the Privacy Policy.

Before Stripe Checkout opens, you must expressly accept the versions recorded with the order. Stripe payment does not itself authorize testing. Testing is authorized only when the separate Security Testing Authorization is signed.

3. Service purchased

One payment purchases one time-boxed manual security audit for the primary target and additional assets expressly listed in the signed authorization. Delivery consists of an HTML report for human review and a Markdown report for remediation by a coding agent. The service is not a subscription, certification, compliance attestation or guarantee that every vulnerability will be found.

4. Price, payment and taxes

The price displayed immediately before checkout is charged once in USD. Stripe processes payment card information; we do not receive complete card numbers. You are responsible for taxes, bank charges and currency conversion unless Stripe collects them at checkout. A new target or new audit requires a new purchase.

5. Refund before signature; no refund after signature

You may request a full refund at any time before signing the Security Testing Authorization. The customer dashboard provides this option after the paid order is attached to your account, and you may also email melvyn@melvynx.com.

Once the authorization is signed, the audit is scheduled and performance begins. From that moment, payments are final and non-refundable, including where the audit finds few vulnerabilities or no vulnerability. You purchase professional testing time and the resulting reports, not a promised number or severity of findings.

This rule does not limit any remedy that cannot lawfully be waived, or a refund we owe because we cancel the service without delivering it. Full details are in the Refund Policy.

6. Authorization and Customer authority

No testing begins until the primary target is verified and the authorization is signed. The signer represents and warrants that they:

  • have legal authority to bind Customer;
  • own or lawfully operate every listed target and can authorize the permitted testing;
  • have obtained every consent required by cloud, hosting, platform and other third-party agreements;
  • will not include another tenant, provider-owned system or third-party asset without that party's express permission; and
  • provide complete and accurate scope information.

Domain or mailbox control is technical evidence only; it does not replace the signer's warranty of legal authority.

7. Immutable Rules of Engagement

The signed authorization freezes the primary target, additional included assets, environment, authorization window, permitted method, exclusions, special instructions and the Customer's original text. Melvyn will follow the exclusions and rules recorded in that signed document. The Customer's original wording is preserved verbatim and controls over any heading, formatting or summary.

No oral statement or later dashboard edit expands the signed scope. A material change requires a new signed authorization or a written addendum accepted by both parties.

8. Testing method and prohibited activity

Testing is manual, proportionate and non-destructive. Unless a separate addendum expressly says otherwise, the following are prohibited: denial of service, volumetric load testing, destructive payloads, malware, persistence, social engineering, physical intrusion, mass modification or deletion, access to another tenant, and collection of more data than needed to prove a finding.

Testing may create test records, trigger logs, alerts or transactional messages and may carry residual availability risk. Customer must maintain appropriate backups and emergency contacts. Either party may pause testing immediately for safety, legal or scope concerns.

9. Customer responsibilities

Customer must provide accurate contacts, use dedicated low-privilege test accounts, avoid reused passwords, notify relevant internal teams and providers, maintain backups, and promptly revoke test access after delivery. Customer must not use a report to attack or access systems it does not own or control.

10. Delivery and cooperation

Our target is delivery within 48 hours after signature, subject to timely access, a functioning target and Customer cooperation. If blocked by Customer, a provider restriction, an outage or an unsafe condition, the deadline is extended by the period of delay. We will communicate material blockers.

11. Confidentiality and data protection

Each party must protect the other's confidential information and use it only for the contract. Findings and reports are not published, sold or used as a named or anonymous case study without Customer's separate written permission.

Where we process personal data on Customer's documented instructions, the Data Processing Addendum applies. Current providers are listed on the Subprocessors page.

12. Reports and intellectual property

We retain ownership of pre-existing tools, methodologies and templates. Upon full payment, Customer receives a perpetual, worldwide, non-exclusive right to use, copy and share its reports internally and with professional advisers, insurers, customers and contractors for defensive purposes. Exploit details may not be published or used offensively without our written permission and all required third-party permissions.

13. No security guarantee

The audit is a time-boxed assessment of the accessible scope at a point in time. A clean or low-finding report does not prove that the target is secure, compliant or free from vulnerabilities. Customer remains responsible for remediation, secure operation and independent compliance decisions.

14. Liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, exemplary or consequential losses, including lost profit, revenue or goodwill. Our aggregate liability arising from one audit will not exceed the amount paid for that audit.

These limits do not apply to fraud, willful misconduct, breach of confidentiality, infringement, indemnity obligations, or liability that applicable law does not allow to be limited. Customer accepts the residual operational risk expressly described in the signed authorization.

15. Indemnity for unauthorized scope

Customer will defend and indemnify Codelynx against third-party claims arising from materially false authority or ownership representations, or from targets Customer included without the required permission. This does not excuse our own out-of-scope conduct, negligence or willful misconduct.

16. Termination and revocation

Customer may revoke testing authorization at any time using the emergency contact in the signed document or by emailing melvyn@melvynx.com. Testing stops when revocation is received. Revocation after signature does not create a refund right for work already scheduled or performed. Sections intended to survive, including confidentiality, payment, data protection, intellectual property and liability, remain effective.

17. Governing law and disputes

These Terms are governed by the laws of the State of Delaware, United States, without regard to conflict-of-law rules. The state and federal courts located in Delaware have exclusive jurisdiction, except that either party may seek urgent injunctive relief in any competent court. Mandatory data-protection law and non-waivable rights remain unaffected.

Before filing a claim, the parties will give written notice and attempt in good faith to resolve the dispute for 30 days.

18. General terms

Neither party may assign the contract without the other's consent, except in connection with a merger, reorganization or sale of substantially all relevant assets. Neither party is liable for delay caused by events beyond reasonable control. If a provision is unenforceable, it is modified only as much as necessary and the remainder survives. No waiver is implied by delay.

The version accepted at checkout governs that order. Later changes do not retroactively change an existing order or signed authorization.

19. Contact

Codelynx, LLC
8 The Green STE B, Dover, Delaware 19901, United States
melvyn@melvynx.com — +1 (740) 990-2298