Zanshic provides offensive security services: black-box penetration testing, vulnerability reporting, and remediation advisory. Testing is external and non-destructive — we do not access source code, admin panels, or databases, and we do not carry liability for issues beyond the scope of the engagement. Zanshic does not provide incident response, managed defense, or ongoing infrastructure monitoring services.
The free trial requires a corporate email address matching the domain being tested, and confirms Client's authorization to request testing of that domain (see Authorization Agreement). One free trial is permitted per domain and per originating IP address. Zanshic reserves the right to deny or revoke trial access where authorization cannot reasonably be verified. Trial results are limited to a summary of risk level and finding count; full findings and remediation detail unlock with a paid subscription.
Paid tiers are billed monthly in advance. Client pays for the testing service itself, not for the number of findings produced — a report with zero findings is still a complete, billable deliverable. Subscriptions may be cancelled at any time, effective at the next billing cycle; no refunds are issued for partial billing periods already in progress. Pricing for existing clients is locked at the rate in effect when they subscribed and does not increase as Zanshic's general pricing rises for new clients.
Each subscription covers all domains explicitly defined in Client's authorized scope at a flat rate — there are no per-domain fees within an agreed scope. Up to four retests per month are included at no additional charge, to confirm that reported findings have been successfully remediated. Additional retests beyond this may be billed separately.
Clients on a monthly plan receive a weekly executive summary and a full monthly report. All reports are reviewed and approved by a human before delivery — nothing is sent to a Client, and nothing is submitted to any third-party platform, without that review.
Zanshic's testing identifies vulnerabilities that were discoverable using the techniques, time, and scope applied during the engagement. A report confirming no findings is not a guarantee that Client's systems are free of all vulnerabilities — it reflects the result of the specific testing performed. Zanshic makes no warranty that its service will detect every possible vulnerability, and carries no liability for security incidents occurring after a report is delivered ("post-report breaches"), including where Client has not yet remediated a previously reported finding.
To the maximum extent permitted by law, Zanshic's total liability under these Terms is limited to the fees paid by Client in the three (3) months preceding the claim. Zanshic is not liable for indirect, incidental, special, or consequential damages arising from use of the service.
Information collected through the website (domain, corporate email, and any data submitted for testing purposes) is used solely to deliver the service and is not sold or shared with third parties. See Section 5 of the Authorization Agreement for data retention specifics related to testing evidence.
These Terms are governed by the laws of the Kingdom of Morocco. Disputes are resolved through arbitration seated in Casablanca. Clients requiring United States governing law may request this at a 50% premium on contract price, via separate addendum.
Zanshic may update these Terms from time to time. Material changes will be communicated to active subscription clients by email prior to taking effect. Continued use of the service after changes take effect constitutes acceptance.
Questions about these Terms: contact@zanshic.com