beaudited

Terms of sale

Supplier: Gianmaria Palumbo, VAT IT11703831005. Services are for businesses and professionals (B2B).

1. Initial check

A preliminary automated or sampled check, priced at 1 euro plus VAT. It is not a full inspection, a certification or legal advice.

2. Full inspection

Fixed price shown on the check's page, paid in advance. Delivery within 5 working days of receiving the required information. The report describes the state at the date of inspection on the pages or data named.

3. Formation of the contract

Who may buy. The services are intended for businesses, organisations and professionals. Whoever places an order declares that they are of legal age, act in the course of their business or profession, and have authority to bind the entity on whose behalf they order. Services are not sold to consumers: consumer protection rules, including the 14-day right of withdrawal, do not apply.

Acceptance. The contract is concluded in three steps on the order page: acceptance of these terms with a tick; specific approval of the clauses listed in the section “Specific approval of clauses”, given with a one-time code sent to the customer’s email; payment by card through Stripe, or an order by bank transfer against invoice. Alternatively the order may be sent by email: the provider replies with a written confirmation and the link to approve the clauses with the code, and work does not start before the approval. The version of these terms published on the date of the order applies.

Billing details. Every order requires: company name or full name, address, VAT number or tax code, and for Italian customers the SDI recipient code or a certified email (PEC) address for delivery of the electronic invoice. Without billing details the service does not start. Data are processed as described in the privacy notice.

4. Payment and invoicing

How to pay. Payment is taken through Stripe Payments Europe Ltd, by credit or debit card and by the other methods Stripe offers on the payment page. Card details are handled by Stripe directly: the provider never sees, receives or stores them. On request, payment by bank transfer against an invoice is possible.

Prices and VAT. Published prices are net of VAT. Tax is added at payment according to the customer’s status, which the customer declares by entering address and VAT number on the payment page:

Businesses and professionals in ItalyItalian VAT at 22%
Businesses in other EU member states, with a valid VAT numberReverse charge: VAT is accounted for by the customer and the invoice is issued without VAT
Businesses outside the EUOutside the scope of Italian VAT (place of supply rules)

Invoice. The electronic invoice is issued by the provider and transmitted through the Italian exchange system within the statutory deadline, currently twelve days from the supply, to the details given by the customer at payment. The Stripe receipt confirms the charge and does not replace the invoice.

Payment in advance. Inspections are paid before delivery. Repair work is 50% on order and 50% on delivery. The inspection fee is deducted from repair work on the same check.

5. How services are delivered

All services are delivered in writing, by email: reports, clarifications, quotes and answers to questions. No phone or video calls are provided. Questions about the report receive a written answer within 2 working days, at no extra cost, for 30 days from delivery.

6. Use of artificial intelligence

To draft reports, written replies and the code of the inspection tools, the provider uses an assistant based on artificial intelligence systems (Claude, by Anthropic), in a supporting role. The measurements in the reports are produced by deterministic tools (axe-core, DNS queries, header reading) and not by AI systems; every document delivered is checked and signed by the controller, who takes responsibility for it. What goes into the work with the assistant is the domain to be inspected and the site’s technical measurements, which are public data; the client’s names, email addresses, correspondence and credentials do not. Details are on the page How we use artificial intelligence. This information is given under Article 13 of Italian law 132/2025 and Article 50 of regulation (EU) 2024/1689.

7. Repair

Written quote with scope, exclusions, timing and price. 50% on order, 50% on delivery. The inspection fee already paid is deducted from a repair on the same check. Out-of-scope changes are quoted separately.

8. Periodic re-inspection and automatic renewal

Clause requiring specific approval: tacit renewal of the contract.

The periodic re-inspection runs monthly, with the fee charged in advance, and renews automatically from month to month on the same terms.

The customer may cancel at any time by writing to the provider, with no penalty and no need to give a reason: cancellation takes effect from the following monthly period, and the provider confirms it in writing within one working day.

9. Vulnerability analysis

Prior authorisation. This service involves an active security test of the customer’s systems. No active test is carried out without a written authorisation signed by the customer, defining the targets, exclusions, time window and rate limits. Without the signed authorisation the provider performs only the passive check. The authorisation of the system’s owner is what makes the test lawful under Article 615-ter of the Italian Criminal Code.

How it is carried out. The analysis is carried out through the BountyOS platform, which Gianmaria Palumbo heads and is responsible for. Active testing is delegated to licensed scanning tools and the results are reviewed by a qualified security professional before delivery; the provider does not hand over a raw list of scanner alerts.

Price and rewards. The analysis costs €500 + VAT and always gives the customer a summary report with the number, severity and category of the vulnerabilities found. The operational detail of each vulnerability and its remediation are governed by a separate reward agreement, with amounts tied to severity, agreed in writing before the full operational report is delivered. The customer is free not to sign the reward agreement, with no consequence: in that case they do not receive the detail, owe no reward, and keep the summary report already obtained.

Confidentiality. The provider does not disclose to third parties nor in any way exploit the vulnerabilities found, and keeps them confidential even if the reward agreement is not signed.

10. Liability

Clause requiring specific approval: limitations of the provider’s liability.

Except in cases of wilful misconduct or gross negligence and other cases where the law does not allow limitation, the provider’s total liability for any cause connected with the service does not exceed the amount paid for the service concerned.

Except in cases of wilful misconduct or gross negligence and other cases where the law does not allow limitation, the provider is not liable for indirect damage, loss of profit, or penalties imposed on the customer for breaches that existed before the inspection.

The provider guarantees the delivery described and the accuracy of the measurements reported as at the date of inspection. It does not guarantee rankings, outcomes of checks by authorities, or economic results.

11. Access and confidentiality

Access to client systems, where needed, is temporary, logged and revoked at the end of the work. Information received stays confidential.

12. Governing law and jurisdiction

Clause requiring specific approval: exclusive choice of court.

The contract is governed by Italian law. The courts of Rome have exclusive jurisdiction over any dispute about its interpretation, performance or termination, save for mandatory rules of jurisdiction. The Italian text of these terms prevails over this translation.

13. Specific approval of clauses

Under Articles 1341 and 1342 of the Italian Civil Code the customer specifically approves clauses n. 8 (Periodic re-inspection and automatic renewal: tacit renewal of the contract); n. 10 (Liability: limitations of the provider’s liability); n. 12 (Governing law and jurisdiction: exclusive choice of court). Approval is given by electronic signature with a one-time code sent to the customer’s email, separate from acceptance of these terms. The provider keeps the record of the signature: email, date and time, version, clauses approved, cryptographic hash of their text, IP address and user agent.

Last updated: 15 September 2026. Version 2026-09-15.