Terms
Terms of service
These terms apply when you request an external penetration test from EXTERNAL10, a service of SCORE10 SL, CIF B23860547, 29670 Marbella, Spain. They are deliberately short. If something is unclear, ask before you sign up.
Last updated 11 September 2026
- 01
The service
One external penetration test of your organisation's internet-facing estate. We start from the domain your work email is on, discover the related domains and systems you own, and set out the exact scope in the engagement letter before we begin. Then: reconnaissance, controlled exploitation attempts against what we find, a written report, and a 60-minute video call to walk your team through it. We work from the internet only, with no credentials from you and no information beyond what is publicly available.
- 03
Scope
In scope:
- Your organisation, reached from your work-email domain as the starting point
- Related domains and internet-facing assets we discover that belong to you
- Web applications, mail, DNS, VPN and remote-access services, exposed admin panels
- Controlled password checks: default and commonly used passwords against standard accounts and usernames found publicly, rate-limited so nobody gets locked out
- The exact domains and hosts in scope are agreed and listed in the engagement letter before testing
Out of scope:
- Denial-of-service or anything that degrades availability
- Phishing or social engineering of your staff
- Physical access and on-site testing
- Internal testing, and testing with credentials you give us. We never receive passwords from you
- Third-party SaaS you do not operate yourself
- 04
Timing
We agree a start date with you. Active testing takes about 5 business days and the report is delivered within 10 business days of the start. The debrief meeting is held within 5 business days of the report. The authorization covers 30 days from confirmation.
- 05
Price and payment
1 000 EUR per engagement, excl. VAT. Prices exclude VAT. Spanish IVA (21%) is added for customers in Spain. EU businesses with a valid VAT number are invoiced under reverse charge. Customers outside the EU pay no VAT.
Nothing to pay up front. We invoice 1 000 EUR once the report is delivered and the debrief meeting is done. Bank transfer or card, 14 days.
- 06
What a test is, and is not
A penetration test is a snapshot of what an outside attacker could find in a limited time window. We cannot guarantee that every weakness is found, and a clean report is not a certification or a promise that your systems are secure. Fixing what we report is your responsibility.
- 07
Confidentiality
Everything we learn about your systems, and everything you learn about our methods, stays between us. The report is delivered to you alone. We may say that you are a customer only with your permission.
- 08
Liability
We test carefully and never intentionally damage data or disrupt operations. Our total liability for an engagement is limited to the fee you paid for it. We are not liable for indirect losses such as lost revenue or lost data, except where Spanish law does not allow such a limitation.
- 09
Law and disputes
Spanish law applies. Disputes go to the courts of Málaga, Spain, unless the law gives you the right to another venue.
- 10
Contact