Skip to content
Point-IT AS
PlatformHow it worksPricingSecurity & privacyContact
NOENNL
Order assessment

Terms of Service

These B2B terms govern Penny security assessment services ordered from Point-IT AS.

Effective: 5 September 2026

1. Business customers and authority

Penny is offered for professional/business use. The person ordering represents that they have authority to bind the customer and to authorise assessment of every submitted domain, host and IP address.

2. Scope and authorisation

Only targets confirmed in the accepted scope may be assessed. The customer must ensure that it owns, controls, uses with authority, or has explicit permission to test each target. Point-IT may request evidence, refuse a target or suspend work if authorisation is uncertain.

3. Service process

An online order does not automatically start scanning. Point-IT will normally contact the customer within 3 business days to validate scope and arrange execution. Reports are currently delivered manually as reviewed PDF files by email.

4. Nature of the assessment

Penny performs a point-in-time, best-effort external security assessment using automated and structured checks with human review. Results depend on the agreed scope, visibility, timing, tool coverage and available evidence. Findings may include false positives or false negatives.

5. No security guarantee

An assessment, score or report is not a certification, warranty of security, penetration-test guarantee or assurance that the environment is free from vulnerabilities or compromise. A later attack, breach or newly discovered vulnerability does not by itself establish a defect in the service.

6. Customer responsibilities

The customer remains responsible for its systems, backups, access controls, patching, monitoring, incident response, supplier management and decisions based on the report. The customer must notify Point-IT of fragile systems or restrictions relevant to the authorised checks.

7. Remediation and consultancy

Assessment prices include the report and recommendations stated in it. Implementation, configuration changes, remediation work, engineering and additional consultancy are excluded and billed separately at the published or agreed hourly rate.

8. Subscriptions

Penny Continuous Security has a minimum term of 12 months unless otherwise agreed in writing. The customer may choose annual prepayment or quarterly billing. Annual prepayment receives the price shown for annual billing. Additional on-demand or verification assessments are separate services and do not replace scheduled assessments.

9. Prices and payment

Prices shown on the website exclude VAT and other applicable taxes unless expressly stated otherwise. Norwegian-language prices are fixed NOK market prices and are not a live currency conversion of EUR prices. Payment terms stated on the invoice apply.

10. Changes and scheduling

Point-IT may reschedule assessment activity where needed for safety, authorisation, maintenance or technical reasons. Material scope changes may require a revised price or separate quote.

11. Liability

To the maximum extent permitted by applicable law, Point-IT is not liable for indirect or consequential loss, loss of profit, revenue, business, goodwill or anticipated savings. Point-IT's aggregate contractual liability arising from the relevant service is limited to the fees paid for that service during the preceding 12 months, or for a one-time assessment the fee paid for that assessment. This limitation does not apply where liability cannot lawfully be limited, including where mandatory law provides otherwise.

12. Third-party systems

Discovery may identify SaaS, hosting, mail or other third-party services. Point-IT will not intentionally perform intrusive testing against third-party infrastructure outside the authorised scope. The customer is responsible for obtaining any necessary third-party permission.

13. Confidentiality and reports

Point-IT treats non-public customer assessment information as confidential. Reports are intended for the customer and its authorised advisers. The customer should protect reports because they may contain sensitive security information.

14. Data protection

Personal-data processing is described in the Privacy Policy. Where a processor relationship exists under GDPR, the parties will enter into or apply an appropriate data-processing agreement where required.

15. Force majeure

Neither party is liable for delay or failure caused by events beyond reasonable control, including major internet outages, hosting failures, cyber incidents, power failures, governmental action or similar events, provided reasonable mitigation is taken.

16. Governing law and disputes

The agreement is governed by Norwegian law. The parties will first seek an amicable solution. Unless mandatory law requires otherwise, disputes shall be brought before the competent Norwegian courts.

17. Order of precedence and changes

A signed or expressly accepted written agreement takes precedence over these website terms where it conflicts. Point-IT may update these terms for future orders; the version accepted at the time of order applies unless the parties agree otherwise.

Point-IT AS

External security assessments with deterministic scoring, human review and clear remediation priorities.

Terms of ServicePrivacy policyData protectionLegal noticeResponsible disclosurePricing
© 2026 Point-IT ASOrganisation number 937 051 379 · Norway