Adore Cyber by Adore LLC
ScopeProcessReport

Agreement version 1.0

Authorization and Rules of Engagement

Effective September 1 2026

This agreement is between Adore LLC and the customer identified in the signed intake record. The signer is the Customer Representative. The customer and Adore LLC are the parties.

1. Purpose and condition to testing

The customer requests a fixed-scope external security assessment of the approved target. Adore LLC will not begin testing until payment is confirmed. Adore LLC will not begin testing until the customer signs this agreement. Adore LLC will not begin testing until authority over the target is verified. Adore LLC must accept the target in writing. Payment alone does not authorize testing.

2. Customer authority

The customer represents and warrants that it owns the approved target or has current written permission from the owner that expressly permits this assessment. The signer represents and warrants that the signer has authority to bind the customer and authorize Adore LLC to perform the accepted testing.

A customer may submit an application it owns even when that application runs on third-party hosting infrastructure. The customer must not submit systems owned or operated by a hosting provider, platform vendor, software vendor, customer, or other third party unless the customer provides written authorization from that owner that expressly covers Adore LLC and the accepted testing. The customer is responsible for complying with its hosting provider policies.

3. Approved target

Only the exact hostname or API base URL recorded in the written scope acceptance is approved. Related domains, parent domains, subdomains, cloud resources, mobile applications, internal networks, and third-party services are excluded unless separately listed and accepted in writing. The target must be publicly reachable. Adore LLC may reject any target.

Adore LLC may require a DNS TXT record, a file at a designated path, confirmation through an organization-controlled address, third-party written permission, or another reasonable method to verify authority.

4. Testing window and notices

Testing may begin only after Adore LLC sends written scope acceptance. The delivery window is 48 consecutive hours beginning at written scope acceptance. Time paused for customer action, target unavailability, an emergency stop, or a safety review is excluded from that window.

Adore LLC will send a start notice and a completion notice to the authorized business email. The customer may request an emergency stop at any time by calling +1 646 820 3179 and emailing support@adorellc.pro with the subject EMERGENCY STOP. Adore LLC may pause or stop work whenever safety, legality, authority, scope, or availability is uncertain.

5. Permitted methods

The base package permits external unauthenticated testing only. Permitted methods are rate-limited automated discovery, passive review, manual validation, ordinary HTTP and HTTPS requests, non-destructive input testing, minimal proof required to confirm a finding, and other non-destructive techniques accepted in writing by Adore LLC.

6. Prohibited methods

Denial of service, load testing, flooding, social engineering, phishing, physical testing, malware, persistence, lateral movement, password spraying, credential stuffing, brute force, destructive modification, bulk data extraction, unrelated user access, production data changes, user contact, employee contact, vendor contact, customer contact, third-party testing, and bypassing an emergency stop are prohibited.

7. Sensitive data and stop conditions

Adore LLC will minimize access to personal data, secrets, regulated data, and customer content. Adore LLC will use the minimum evidence needed to establish a finding. Adore LLC will stop the affected technique and notify the emergency contact when testing exposes significant sensitive data, creates material instability, reaches a third-party system, or appears to exceed authorization.

8. Customer responsibilities

The customer will provide accurate target and contact information. The customer will maintain backups. The customer will identify fragile systems and restricted hours. The customer will monitor production after the start notice. The customer will provide a reachable emergency contact. The customer will not conceal third-party ownership. The customer remains responsible for remediation and business decisions.

9. Deliverable and retest

Adore LLC will deliver one PDF report through an authenticated or otherwise access-controlled delivery method linked to the authorized business email. The report will identify the accepted scope, methodology, confirmed findings, severity, evidence, remediation guidance, and limitations.

The customer may make one consolidated retest request within 14 calendar days after report delivery. The retest covers only findings originally rated Critical or High and only the identified remediation. Adore LLC will schedule the retest after the customer confirms that remediation is ready.

10. Service limitations

Security testing is a point-in-time assessment. Results depend on scope, time, access, target behavior, and available evidence. The service does not guarantee identification of every vulnerability. The service does not guarantee prevention of an incident. The service is not a full penetration test, compliance audit, certification, attestation, or legal opinion. No report should be represented as proof of complete security.

11. Fees and refunds

The fixed fee is $500. Payment reserves an authorization review slot. If Adore LLC cannot verify authorization or declines the target before testing begins then Adore LLC will initiate a full refund. Stripe and the customer bank control the time required for a refund to appear. If the customer withdraws after testing begins then fees are nonrefundable.

12. Confidentiality and data handling

Each party will protect the other party nonpublic information using reasonable care. Adore LLC may use service providers needed for payment, hosting, communications, AI-assisted analysis, testing, and report delivery. Adore LLC will limit provider access to the service purpose.

Authorization and transaction records may be retained for legal, fraud prevention, tax, accounting, and security purposes. Raw testing artifacts and active delivery copies are scheduled for deletion within 90 days after delivery unless law, an incident, a dispute, or written customer instruction requires longer retention.

13. Coordinated handling

The customer authorizes Adore LLC to report findings to the named signer and emergency contact. Adore LLC will not publicly disclose a finding without customer permission unless disclosure is required by law. If testing shows that an unrelated third party is at risk then the parties will pause and coordinate a lawful response.

14. Disclaimer

Except for express commitments in this agreement the service and report are provided as available. To the maximum extent permitted by law Adore LLC disclaims implied warranties of merchantability, fitness for a particular purpose, noninfringement, and uninterrupted or error-free operation. Jurisdictional limits apply.

15. Limitation of liability

To the maximum extent permitted by law neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages or lost profits arising from this agreement. Each party aggregate liability arising from this agreement will not exceed the fee paid for the assessment. The limit does not apply to fraud, willful misconduct, the customer misrepresentation of authority, or obligations that cannot be limited by law.

16. Indemnity for unauthorized targets

The customer will defend and indemnify Adore LLC against third-party claims, losses, and reasonable costs arising from the customer false statement of ownership or authority, submission of an unauthorized target, or instruction to act outside the accepted scope. This section does not cover loss caused by Adore LLC gross negligence or willful misconduct.

17. Governing law and disputes

New York law governs this agreement without regard to conflict-of-law rules. State and federal courts located in New York County New York have exclusive jurisdiction. Before filing a claim the parties will give written notice and attempt in good faith to resolve the dispute for 30 days. Either party may seek immediate relief for misuse of systems, confidential information, or intellectual property.

18. Electronic records and signature

The customer consents to receive this agreement and related records electronically. The customer may download or print this agreement before signing. The customer may request a paper copy at support@adorellc.pro. Typing the signer full legal name, checking the required attestations, and submitting the form with intent to sign constitutes the customer electronic signature. Adore LLC records the agreement version, timestamp, payment session, source address, browser identifier, and submitted authorization details.

19. Entire agreement and order of precedence

The written scope acceptance, this Authorization and Rules of Engagement, the accepted intake, the service description preserved with the transaction record, the Service Terms, and the Privacy Notice form the agreement for the assessment. If terms conflict then that order controls. A change to target, method, window, or restriction must be accepted in writing by both parties before it applies.

Required signer attestations

  • I have authority to bind the customer.
  • The customer owns the target or holds written permission for this assessment.
  • I authorize only the exact target and methods accepted by Adore LLC.
  • I understand that payment alone does not authorize testing.
  • I understand the prohibited methods and emergency stop process.
  • I intend my typed name to be my electronic signature.

Related records: Service Terms and Privacy Notice.

Adore Cyber by Adore LLC

155 W 71st St Apt 4F New York NY 10023

support@adorellc.pro · +1 646 820 3179

Authorization and Rules of EngagementService TermsPrivacy Notice

© 2026 Adore LLC. Authorized defensive security work only.