EXTERNAL10 Back to the site

Terms

Terms of service

These terms apply when you request an external penetration test from EXTERNAL10, a service of SCORE10 SL, CIF B23860547, 29670 Marbella, Spain. They are deliberately short. If something is unclear, ask before you sign up.

Last updated 11 September 2026

  1. 01

    The service

    One external penetration test of your organisation's internet-facing estate. We start from the domain your work email is on, discover the related domains and systems you own, and set out the exact scope in the engagement letter before we begin. Then: reconnaissance, controlled exploitation attempts against what we find, a written report, and a 60-minute video call to walk your team through it. We work from the internet only, with no credentials from you and no information beyond what is publicly available.

  2. 02

    Authorization

    By signing up you confirm that you are entitled to authorize testing of that domain. Before we start, an authorized signatory confirms these authorization terms by email:

    • The customer authorizes SCORE10 SL (EXTERNAL10) to perform security testing of the domains, subdomains and internet-facing systems the customer owns or is entitled to approve — identified from the customer's domain and listed in the engagement letter — for 30 days from confirmation.
    • Testing may include vulnerability scanning, controlled attempts to exploit weaknesses, and limited attempts with default or commonly used passwords against publicly known accounts. It will not intentionally damage data, lock out users or disrupt operations.
    • Testing of third-party systems requires separate permission.
    • All results are treated as confidential and reported to the customer, who may request that testing stops at any time.
  3. 03

    Scope

    In scope:

    • Your organisation, reached from your work-email domain as the starting point
    • Related domains and internet-facing assets we discover that belong to you
    • Web applications, mail, DNS, VPN and remote-access services, exposed admin panels
    • Controlled password checks: default and commonly used passwords against standard accounts and usernames found publicly, rate-limited so nobody gets locked out
    • The exact domains and hosts in scope are agreed and listed in the engagement letter before testing

    Out of scope:

    • Denial-of-service or anything that degrades availability
    • Phishing or social engineering of your staff
    • Physical access and on-site testing
    • Internal testing, and testing with credentials you give us. We never receive passwords from you
    • Third-party SaaS you do not operate yourself
  4. 04

    Timing

    We agree a start date with you. Active testing takes about 5 business days and the report is delivered within 10 business days of the start. The debrief meeting is held within 5 business days of the report. The authorization covers 30 days from confirmation.

  5. 05

    Price and payment

    1 000 EUR per engagement, excl. VAT. Prices exclude VAT. Spanish IVA (21%) is added for customers in Spain. EU businesses with a valid VAT number are invoiced under reverse charge. Customers outside the EU pay no VAT.

    Nothing to pay up front. We invoice 1 000 EUR once the report is delivered and the debrief meeting is done. Bank transfer or card, 14 days.

  6. 06

    What a test is, and is not

    A penetration test is a snapshot of what an outside attacker could find in a limited time window. We cannot guarantee that every weakness is found, and a clean report is not a certification or a promise that your systems are secure. Fixing what we report is your responsibility.

  7. 07

    Confidentiality

    Everything we learn about your systems, and everything you learn about our methods, stays between us. The report is delivered to you alone. We may say that you are a customer only with your permission.

  8. 08

    Liability

    We test carefully and never intentionally damage data or disrupt operations. Our total liability for an engagement is limited to the fee you paid for it. We are not liable for indirect losses such as lost revenue or lost data, except where Spanish law does not allow such a limitation.

  9. 09

    Law and disputes

    Spanish law applies. Disputes go to the courts of Málaga, Spain, unless the law gives you the right to another venue.

  10. 10

    Contact