Legal

Terms of Service

Effective date: 1 June 2025 ·  Crestline Defence (Pty) Ltd

1. Acceptance of Terms

By accessing or using GuardianScan (the "Service"), you agree to be bound by these Terms of Service. If you do not agree to these terms, do not use the Service.

These terms constitute a legally binding agreement between you and Crestline Defence (Pty) Ltd ("we", "us", or "our"). We may update these terms from time to time. Continued use of the Service after changes are posted constitutes acceptance of the revised terms.

2. Description of Service

GuardianScan is an automated cybersecurity assessment platform that performs security scans of internet-facing infrastructure on domains you own or are authorised to test. We offer three tiers of assessment:

Surface ScanR299

~5 minutes · Passive reconnaissance — security headers, DNS, SSL, open ports, technology fingerprinting.

Deep ScanR999

~25 minutes · Active testing — authentication, rate limiting, CORS, subdomain takeover, API enumeration.

Intelligence ScanR2,999

~90 minutes · Full OSINT, breach intelligence, Shodan CVE mapping, AI-generated threat narrative, POPIA liability assessment.

All prices are in South African Rand (ZAR) and include VAT where applicable. Scans are one-time purchases — there is no subscription.

3. Eligibility

  • You must be at least 18 years of age to use the Service.
  • You must own or have explicit written authorisation from the owner of any domain you submit for scanning.
  • You must have the legal capacity to enter into a binding agreement.
  • Use of the Service is restricted to lawful purposes only.

4. Authorisation Requirement

You represent and warrant that:

You are the registered owner of the domain submitted for scanning, OR you have explicit written authorisation from the domain owner to perform security testing on their infrastructure.

You acknowledge that scanning domains you do not own or are not authorised to test may constitute a criminal offence under:

  • The Cybercrimes Act 19 of 2020 (South Africa)
  • The Electronic Communications and Transactions Act 25 of 2002

Crestline Defence (Pty) Ltd accepts no liability for unauthorised scanning performed using our platform. We retain consent logs and DNS verification records which may be disclosed to law enforcement upon receipt of a valid court order.

Before each scan you will be required to accept our Rules of Engagement, confirming your authorisation. This acceptance is timestamped and stored as a legally admissible consent record.

5. DNS Verification

GuardianScan requires DNS TXT record verification before any scan may be commissioned. This process:

  • Is mandatory and cannot be bypassed under any circumstances.
  • Proves that you have administrative control over the domain's DNS zone.
  • Results in a verification record retained in our database for audit purposes.
  • Must be completed once per domain. Verified domains may be rescanned without re-verifying DNS, unless your domain record is removed.

6. Payment Terms

  • All prices are in South African Rand (ZAR).
  • Payments are processed securely by PayFast. We do not store your card details.
  • Payment must be completed in full before a scan commences.
  • Your scan will begin automatically upon confirmed payment from PayFast.
  • Prices are subject to change. The price displayed at time of purchase is the price you pay.

7. Refund Policy

  • Technical failure: A full refund will be issued if your scan fails to complete due to a fault on our side and we are unable to re-run the scan within a reasonable time.
  • Report delivered: No refund is available once your scan report has been generated and made accessible in your dashboard.
  • How to request: Email cd@thereggiesmith.com within 7 days of purchase, including your scan ID and a description of the issue.

8. Acceptable Use

You may not use GuardianScan to:

  • Scan domains you do not own or are not explicitly authorised to test.
  • Use findings from your report to plan, facilitate, or carry out attacks against any system.
  • Resell, redistribute, or publish scan reports without written permission from Crestline Defence (Pty) Ltd.
  • Reverse-engineer, scrape, or attempt to reproduce our scanning methodology.
  • Circumvent rate limits, authentication, or any technical access controls on our platform.
  • Use the platform for any purpose that violates South African law or international law.

We reserve the right to suspend or terminate accounts that violate these restrictions, without notice and without refund.

9. Disclaimer of Warranties

The Service is provided "as is" and "as available" without warranties of any kind, express or implied.

Security scanning is not exhaustive. GuardianScan checks a defined set of publicly accessible signals — it does not guarantee discovery of every vulnerability present on your systems. A clean or high-scoring report does not guarantee that your systems are completely secure, free from vulnerabilities, or immune to attack.

Findings should be reviewed by a qualified security professional before remediation action is taken. GuardianScan reports are intended as a starting point for investigation, not a substitute for a manual penetration test.

10. Limitation of Liability

To the maximum extent permitted by South African law, Crestline Defence (Pty) Ltd's total liability to you for any claim arising from your use of the Service shall not exceed the amount you paid for the specific scan giving rise to the claim.

We are not liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business opportunity, arising from your use of or reliance on the Service or any scan report.

11. Intellectual Property

All scan methodologies, report formats, platform code, UI designs, and associated documentation are the intellectual property of Promised Investment Group (Pty) Ltd.

GuardianScan is a product of Promised Investment Group (Pty) Ltd, operated under the Crestline Defence brand. All rights reserved.

Your scan report is licensed to you for internal business use only. You may share it with your employees, contractors, and professional advisors under a confidentiality obligation. Commercial redistribution or publication requires written consent.

12. Governing Law

These Terms of Service are governed by and construed in accordance with the laws of the Republic of South Africa.

Any dispute arising from or relating to these terms or your use of the Service shall be subject to the exclusive jurisdiction of the South African courts. You consent to the jurisdiction of the South Gauteng High Court, Johannesburg, for such disputes.

13. Contact

For questions about these terms, refund requests, or legal correspondence:

Crestline Defence (Pty) Ltd

Email: cd@thereggiesmith.com

Website: crestlinedefence.com

These terms were last updated on 1 June 2025. Registered users will be notified of material changes by email.