Security Review Service Terms

Last updated: 6 September 2026

Poodle Collective Ltd
Company number: 16818378
Trading as PoodleCollective

1. About these Terms

These Security Review Service Terms ("Terms") set out the basis on which Poodle Collective Ltd, trading as PoodleCollective ("PoodleCollective", "we", "us" or "our"), provides Security Review services to the business purchasing or commissioning the service ("Client", "you" or "your").

These services are provided for business customers only.

By purchasing a Security Review, accepting a quotation or proposal, or otherwise instructing us to proceed, you confirm that you are acting wholly or mainly for the purposes of your business, trade or profession and not as a consumer.

If you are accepting these Terms on behalf of a company, partnership, organisation or other business, you confirm that you have authority to bind that organisation.

The agreed Security Review package, any quotation or proposal we provide, and these Terms together form the agreement between us for the Security Review.

Where our Data Processing Terms apply, they also form part of that agreement in relation to the processing of personal data on your behalf.

2. About the Security Review

The Security Review is a one-off preventative security service intended to identify and reduce avoidable security risks affecting a WordPress website.

Depending on the package selected and the website being reviewed, the work may include review, scanning, configuration, hardening and recommendations relating to:

  • WordPress core, plugins and themes;
  • website and hosting configuration;
  • firewalls and security controls;
  • malware and indicators of compromise;
  • administrator and other user accounts;
  • login and access protection;
  • backups and recovery arrangements;
  • website permissions and configuration;
  • databases;
  • security headers;
  • integrations and APIs;
  • checkout and payment integrations; and
  • account, membership or other business-critical functionality.

The precise scope depends on the Security Review package purchased or agreed.

The Security Review is a point-in-time assessment. It is not an ongoing website maintenance, monitoring or incident response service.

3. Standard Security Review

The Standard Security Review is £395 fixed fee.

It is intended for smaller business websites, brochure websites, blogs, portfolios and relatively straightforward WordPress installations.

The Standard Security Review includes:

  • WordPress security audit;
  • firewall configuration;
  • malware and threat scan;
  • login protection review and configuration;
  • backup and recovery review;
  • plugin and theme audit;
  • security hardening; and
  • written security report.

The fixed fee assumes that the website falls reasonably within the normal scope and complexity of this package.

4. Advanced Security Review

The Advanced Security Review is £595 fixed fee.

It is intended for established business websites, lead-generation websites, multi-user installations and websites with a larger plugin ecosystem, custom functionality or several integrations.

The Advanced Security Review includes everything within the Standard Security Review, together with:

  • detailed user access audit;
  • security header implementation;
  • database security review;
  • additional configuration hardening;
  • enhanced monitoring recommendations; and
  • more detailed findings and recommendations.

The fixed fee assumes that the website falls reasonably within the normal scope and complexity of this package.

5. Business Critical Security Review

The Business Critical Security Review starts from £995.

It is intended for ecommerce, membership, high-traffic, technically complex and business-critical websites, including websites handling customer accounts, payments, operational data or complex integrations.

The Business Critical Security Review includes everything within the Advanced Security Review, together with:

  • checkout and payment integration review;
  • detailed user role and permissions audit;
  • advanced hosting and server recommendations;
  • review of key integrations and APIs;
  • additional security and data-handling considerations; and
  • a findings review with your developer.

Because Business Critical websites can vary significantly in size, functionality, hosting, integrations and technical complexity, we will review the information you provide before confirming the scope and total fixed fee.

No Business Critical Security Review will begin until the scope and price have been agreed.

6. Confirming the Correct Package

We rely on the information you provide about the website, hosting, functionality, users, integrations and known security concerns when determining whether a package is appropriate.

If we identify before work begins that another package is more suitable, we will explain this and confirm any change in scope or price before proceeding.

If, after work begins, we discover material technical complexity or circumstances that could not reasonably have been identified from the information provided, we will tell you before carrying out significant work outside the agreed scope.

We will not charge for additional work without your agreement.

7. Your Authority to Instruct Us

You confirm that:

  • you own the website and relevant systems, or have authority from the owner to instruct us;
  • you are authorised to provide us with access to the systems included within the agreed scope;
  • you have authority to permit the security review, scanning, configuration and hardening activities we have agreed to carry out; and
  • where a system belongs to or is controlled by a third party, you have obtained any permission required from that third party.

Where appropriate, this includes hosting accounts, servers, domains, firewalls, security services, APIs and integrations.

Our authority is limited to the systems and activities reasonably necessary to provide the agreed Security Review.

We will not deliberately attempt to gain unauthorised access to third-party systems or test infrastructure outside the agreed scope.

If we reasonably believe that the necessary authority has not been provided, we may suspend or decline the affected work.

8. Third-Party Authorisation and Acceptable Use

Some hosting providers, platforms and other third-party services place restrictions on vulnerability scanning, security testing or automated activity.

You are responsible for notifying us of any relevant restrictions you are aware of and, where necessary, obtaining permission from the relevant provider before testing takes place.

We may refuse to perform a particular test or activity where we reasonably believe it could breach a third party's terms, cause disruption or exceed the authority provided to us.

9. Access and Credentials

You must provide the access reasonably required for us to carry out the agreed Security Review.

This may include access to:

  • WordPress;
  • hosting or server controls;
  • security services;
  • DNS;
  • backups;
  • databases; and
  • relevant third-party integrations.

Passwords, API keys and other sensitive credentials must not be sent through the general enquiry form or Security Review request form.

Where credentials are required, we will arrange an appropriate method for obtaining access.

Where reasonably practical, temporary or dedicated accounts should be used and removed or revoked when they are no longer required.

You are responsible for ensuring that access provided to us is authorised and sufficient for the agreed work.

Delays in receiving suitable access may delay completion of the Security Review.

10. How the Review is Carried Out

We may use a combination of:

  • manual inspection;
  • configuration review;
  • security tools;
  • vulnerability or malware scanning;
  • automated analysis; and
  • technical assessment.

Security tools and scanners can produce false positives, false negatives or incomplete results.

We will apply professional judgement when reviewing findings, but neither automated nor manual security assessment can identify every possible vulnerability.

The Security Review is based on the website, software, configuration and systems available to us at the time of the review.

11. Changes to the Website

Where included within the selected package, the Security Review may involve changes to the website or its configuration.

This may include changes to:

  • WordPress configuration;
  • login protection;
  • permissions;
  • firewall rules;
  • security headers;
  • plugins or themes;
  • hosting configuration; or
  • other security settings.

We will use reasonable care to minimise disruption and will take account of the website's existing functionality.

Where we believe a proposed security change creates a material risk of disrupting the website or an important feature, we may recommend the change rather than implementing it immediately, or request your approval before proceeding.

Security measures can occasionally conflict with plugins, themes, integrations, hosting environments or custom functionality.

Where an issue results directly from a change we make as part of the Security Review, we will take reasonable steps within the agreed scope to investigate and, where appropriate, adjust or reverse that change.

12. Backups and Recovery

Where included in the selected package, we will review the website's existing backup and recovery arrangements.

The Security Review does not itself provide an ongoing backup service.

Before making material changes, we may require confirmation that a suitable current backup or recovery method is available.

If we reasonably consider the available backup arrangements inadequate for a proposed change, we may delay that change until an appropriate backup has been created or another approach has been agreed.

You remain responsible for ongoing backup and recovery arrangements unless you have separately purchased a service from us that expressly includes them.

13. Malware and Existing Compromise

The Security Review includes malware and threat scanning within the agreed package.

Malware removal, hacked-site recovery, forensic investigation and incident response are not included unless expressly stated in the agreed scope.

If we identify evidence that the website may already be compromised, we will tell you as soon as reasonably practicable.

We may recommend that the Security Review is paused so that the active security incident can be dealt with first.

This may require Emergency Website Support or separately scoped remediation work.

We will not carry out substantial malware removal, recovery or incident-response work without your agreement to the additional scope and charges.

14. Penetration Testing and Formal Security Assessments

Unless specifically agreed in writing, the Security Review is not:

  • a penetration test;
  • an adversarial security assessment;
  • a full source-code security audit;
  • a forensic investigation;
  • a PCI DSS assessment or certification;
  • a Cyber Essentials or Cyber Essentials Plus assessment;
  • an ISO 27001 audit or certification;
  • a formal UK GDPR compliance audit; or
  • certification against any particular regulatory, contractual or industry security standard.

Where the Business Critical Security Review considers payment integrations, data handling or compliance-related matters, this is from the perspective of the website's technical security and configuration.

It does not constitute legal, regulatory, accounting or formal compliance advice.

15. Third-Party Software and Services

WordPress websites commonly depend on third-party:

  • hosting providers;
  • plugins;
  • themes;
  • APIs;
  • payment gateways;
  • security services;
  • content delivery networks;
  • software platforms; and
  • integrations.

We are not responsible for vulnerabilities, outages, defects, security failures or changes within third-party products or services that are outside our reasonable control.

Where we identify a concern involving a third-party product or service, we may recommend an update, configuration change, replacement or that you contact the relevant provider.

We cannot guarantee that a third party will correct a vulnerability, continue supporting a product or act on our recommendations.

Third-party licence, hosting, subscription and service costs are not included in the Security Review fee unless expressly stated.

16. Integrations and APIs

Where a Business Critical Security Review includes key integrations or APIs, our review is limited to their relationship with the website and the security considerations reasonably assessable within the agreed scope.

The review does not give us authority to probe, attack or security-test infrastructure belonging to an external provider.

Any deeper security testing of third-party infrastructure would require appropriate authority and a separately agreed scope.

17. Security Report

At the end of the Security Review, you will receive a written report or findings summary appropriate to the package purchased.

Depending on the package, this may include:

  • areas reviewed;
  • significant findings;
  • changes made;
  • identified risks;
  • matters that could not be fully assessed;
  • remaining concerns;
  • recommended improvements; and
  • suggested next steps.

The report represents our professional assessment based on the systems, access and information available to us at the time.

Recommendations may include work outside the Security Review.

You are not required to instruct PoodleCollective to carry out any additional work recommended in the report.

18. No Guarantee of Complete Security

No security review can eliminate every risk or guarantee that a website will remain secure.

The purpose of the Security Review is to identify weaknesses and implement reasonable measures within the agreed scope to reduce avoidable security risk.

We do not warrant or guarantee that:

  • every vulnerability will be identified;
  • every attack will be prevented;
  • the website will never be hacked or compromised;
  • malware cannot subsequently be introduced;
  • third-party services will remain secure;
  • future software updates will not introduce vulnerabilities;
  • new vulnerabilities will not subsequently be discovered; or
  • the website will satisfy every security or compliance requirement applicable to your organisation.

This does not reduce our obligation to perform the Security Review with reasonable care and skill.

19. Your Responsibilities

You are responsible for:

  • providing accurate and complete information about the website and its functionality;
  • telling us about known security incidents, unusual behaviour or previous compromises;
  • providing authorised access when required;
  • maintaining appropriate software licences and third-party subscriptions;
  • ensuring that you are entitled to instruct us in relation to the website and systems concerned;
  • obtaining any third-party permissions required;
  • informing us of regulatory, contractual or security requirements specific to your organisation;
  • ensuring appropriate people are available where decisions or approvals are required;
  • maintaining appropriate ongoing security and backup arrangements after the Security Review; and
  • reviewing and acting on recommendations that remain outstanding.

We will not be responsible for delay, incomplete findings or additional risk caused by information or access that is inaccurate, incomplete, unavailable or withheld from us.

20. Fees and Payment

Standard and Advanced Security Reviews are charged at the fixed fee shown for the package, provided the website falls reasonably within the stated scope.

Business Critical Security Reviews start from the advertised price, with the total fixed fee confirmed before work begins.

Unless otherwise agreed in writing, payment is required before work begins.

Additional work outside the agreed scope will be quoted or otherwise agreed before it is carried out.

21. Cancellation

If you cancel the Security Review before work has begun, we will refund any amount already paid, less any reasonable non-recoverable costs that we have already incurred specifically for your engagement.

If you cancel after work has begun, you will be responsible for the proportion of the agreed fee relating to work already completed and any reasonable non-recoverable costs or commitments already incurred.

Where you have paid in advance, any amount properly due to you after those deductions will be refunded.

Where the Security Review cannot proceed because you fail to provide required information, access or authority after reasonable requests from us, we may treat the engagement as cancelled by you.

22. Timescales

Any completion date or timescale we provide is an estimate unless expressly agreed in writing as a fixed deadline.

Timescales may be affected by:

  • delays in obtaining access;
  • website complexity;
  • hosting or server restrictions;
  • third-party providers;
  • unexpected technical problems;
  • existing security incidents;
  • delays in approvals; or
  • information discovered during the review.

We will keep you reasonably informed if a material delay occurs.

23. Data Protection

Each party must comply with applicable data protection law in relation to its own obligations.

Our Privacy Policy explains how PoodleCollective processes personal data for its own business purposes.

Where, in providing the Security Review, we process personal data on your behalf and you act as controller of that personal data, our separate Data Processing Terms will apply.

Where applicable, those Data Processing Terms govern the processing of that personal data, including matters relating to:

  • documented instructions;
  • confidentiality;
  • security;
  • sub-processors;
  • assistance with data protection obligations;
  • personal data breaches; and
  • return or deletion of personal data.

The Security Review does not transfer responsibility for your organisation's own data protection compliance to PoodleCollective.

24. Confidentiality

Each party must keep confidential information received from the other confidential and must not disclose it except where reasonably necessary to perform the agreement or where disclosure is required by law.

Information obtained during a Security Review may include particularly sensitive technical information, such as:

  • identified vulnerabilities;
  • security weaknesses;
  • server or hosting information;
  • system architecture;
  • security configuration; and
  • access information.

We will use such information only as reasonably required to provide the Security Review, comply with legal obligations or protect our legitimate legal rights.

You should treat the Security Report appropriately.

Publishing detailed vulnerabilities or security configuration information before weaknesses have been addressed may increase security risk.

25. Intellectual Property and Use of the Report

Once the relevant fees have been paid, you may use the Security Report for your own internal business purposes.

You may also share it where reasonably necessary with your:

  • employees;
  • professional advisers;
  • insurers;
  • hosting providers;
  • developers; or
  • other relevant suppliers.

We retain ownership of our pre-existing and underlying:

  • methodologies;
  • templates;
  • checklists;
  • tools;
  • processes;
  • know-how; and
  • other intellectual property.

You may not resell, commercially reproduce or present our methodology, templates or Security Review materials as your own security service without our written permission.

26. Limitations of the Review

Our findings are necessarily limited by the systems, information, access and agreed scope available to us.

We will not be responsible for a vulnerability or other issue that could not reasonably have been identified because:

  • required access was unavailable;
  • material information was withheld or inaccurate;
  • the relevant system was outside the agreed scope;
  • a third-party system prevented investigation;
  • the issue was not reasonably detectable using the agreed review methods;
  • the vulnerability was not known or reasonably discoverable at the time; or
  • the issue arose after the Security Review was completed.

Nothing in this section excludes liability where it would be unlawful to do so.

27. Liability

Nothing in these Terms excludes or limits liability for:

  • death or personal injury caused by negligence;
  • fraud or fraudulent misrepresentation; or
  • any other liability which cannot lawfully be excluded or limited.

Subject to the above, we will not be liable for:

  • loss of profits;
  • loss of revenue;
  • loss of anticipated savings;
  • loss of business opportunity;
  • loss of goodwill or reputation;
  • business interruption; or
  • indirect or consequential loss,

arising out of or in connection with the Security Review.

We will not be responsible for losses resulting from:

  • vulnerabilities or compromises that existed before the Security Review;
  • vulnerabilities introduced after completion of the Security Review;
  • recommendations which you choose not to implement;
  • changes made by you or another supplier after the review;
  • third-party hosting, plugins, themes, APIs, payment providers, software or services;
  • security incidents outside our reasonable control;
  • inaccurate or incomplete information supplied by you;
  • access restrictions that prevent us from assessing an area; or
  • systems that fall outside the agreed scope.

Subject to any liability which cannot lawfully be limited, our total aggregate liability arising out of or in connection with a Security Review, whether in contract, tort (including negligence), breach of statutory duty or otherwise, will not exceed the total fees paid or payable to us for the Security Review giving rise to the claim.

The limitations and exclusions in this section apply only to the extent permitted by law.

28. Indemnity for Unauthorised Instructions

You will be responsible for losses, liabilities and reasonable costs we incur as a direct result of you knowingly or negligently instructing us to access or test a system where you did not have the necessary authority to provide that instruction.

This does not apply to the extent that the loss was caused by our own failure to follow the scope or authority actually provided to us.

29. Suspending or Refusing Work

We may suspend or refuse to carry out any part of the Security Review where we reasonably believe:

  • you do not have authority to instruct us;
  • the requested activity may be unlawful;
  • the activity could involve unauthorised access to a third-party system;
  • continuing would create an unreasonable security or operational risk;
  • the website is actively compromised and requires incident response rather than preventative review;
  • required access or information has not been provided;
  • payment is overdue; or
  • continuing would place us in breach of law or a third-party service requirement.

Where reasonably possible, we will explain the reason and discuss an appropriate next step.

30. Relationship With Emergency and Ongoing Support

The Security Review is a one-off service.

Unless expressly included in the agreed scope, it does not include:

  • ongoing website maintenance;
  • ongoing security monitoring;
  • guaranteed incident response;
  • emergency website support;
  • future WordPress, plugin or theme updates;
  • ongoing backups;
  • malware removal;
  • hacked-site recovery; or
  • remediation of unrelated issues identified after the Security Review.

These services may be available separately.

If a website appears to be actively compromised, our Emergency Website Support service may be more appropriate than a preventative Security Review.

31. Changes to Scope

Any material change to the agreed Security Review scope must be agreed between us.

Where additional work is recommended, we will explain the work and any additional cost before proceeding.

You are under no obligation to purchase additional services simply because they are recommended in the Security Report.

32. Events Outside Our Reasonable Control

We will not be responsible for delay or failure to perform the Security Review where that delay or failure results from circumstances outside our reasonable control.

This may include significant failures of hosting providers, internet infrastructure, third-party platforms or other external systems required to complete the work.

Where this happens, we will take reasonable steps to resume the affected work when reasonably possible.

33. Entire Agreement

These Terms, together with the agreed Security Review package and any quotation or proposal expressly forming part of the engagement, constitute the agreement between us for the Security Review.

If a quotation or proposal contains a specific term that expressly differs from these Terms, that specific agreed term will take priority for that engagement.

Each party acknowledges that it has not relied on any statement or representation that is not contained within the agreement, except that nothing in this section limits liability for fraud or fraudulent misrepresentation.

34. Severability

If any provision of these Terms is found to be invalid, unlawful or unenforceable, that provision will be treated as modified to the minimum extent necessary to make it valid and enforceable.

If that is not possible, it will be treated as deleted.

The remaining provisions will continue in effect.

35. No Waiver

If either party does not immediately enforce a right under these Terms, that does not mean that the right has been waived.

36. Third-Party Rights

Unless expressly stated otherwise, a person who is not a party to the agreement has no right to enforce any provision of it.

37. Governing Law and Jurisdiction

These Terms, the Security Review agreement and any non-contractual dispute or claim arising from them are governed by the laws of England and Wales.

The courts of England and Wales will have exclusive jurisdiction over any dispute or claim arising out of or in connection with the Security Review or these Terms.

38. Contact

Questions about these Security Review Service Terms or the Security Review can be sent using the contact details published on the PoodleCollective website.

Poodle Collective Ltd
Company number: 16818378
Trading as PoodleCollective