Parties and scope
These terms govern the agreement between CM Apps Software LLC ("SendTheCanary", "we") and the individual or entity signing up to our panel or using our services ("Customer", "you").
You accept these terms when you sign up to the panel, confirm a scope, or otherwise use the service.
If you act on behalf of an organisation, you represent that you are authorised to bind it. If you are not, do not use the service.
Definitions
"Test": the examination carried out within the scope we agreed. "Scope": the services, platforms, device matrix and scenario count you confirmed in the panel. "Finding": a single issue identified during testing that can be independently reproduced.
"Report": the document delivered with findings ranked by severity, alongside the coverage matrix and evidence. "Re-test round": the re-examination of affected findings after you ship fixes.
"Panel": the separate application where sign-up, scope selection, payment and live progress happen. "Tester network": the affiliated testers who can be assigned to a test.
How the agreement is formed
Signing up is free and does not by itself order a test. The agreement is formed the moment you confirm a scope in the panel and complete payment.
The scope screen you confirmed is the document that defines the subject of the agreement; it is recorded in the panel and emailed to you.
Enterprise requests may run through a separate quote and order form. Where one is signed, it prevails over this page.
What the service is
We provide independent software testing. We run the scenarios in the confirmed scope, report findings with reproduction steps and evidence, and carry out the re-test round after you ship fixes.
Testing is carried out by our core team together with our tester network. Every finding is independently reproduced by the core team before it enters the report.
Unless agreed otherwise in writing, testing is black box. Access to source code improves performance bottleneck analysis and security review but is not required.
What the service is not
We do not write code, build features or fix the defects we find. To keep our independence, the party that tests is never the party that fixes.
We do not provide consulting, architecture design, systems administration, penetration-test certification or legal compliance opinions. Our security review is based on the OWASP Top 10 and does not replace an accredited penetration test report.
Testing does not guarantee a product is defect free. The absence of a finding in an untested scenario does not mean there is nothing there; what was not tested is stated plainly in the report.
Account and panel
You are responsible for the security of your account. Do not share your password, keep multi-factor authentication on, and tell us immediately if you notice unauthorised access.
Actions taken under your account are yours. You may create users for your team and grant them permissions; you are responsible for the consequences of the permissions you grant.
You will not reverse engineer the panel, overload it with automated tooling, or attempt to circumvent its security controls. These are covered by the Acceptable Use Policy.
Your obligations
You represent that you are authorised to have the target system tested. Having an unauthorised system tested carries legal consequences for both of us; the accuracy of this representation is your responsibility.
You provide the access, accounts and environment detail the test needs, on time. Delay moves the delivery date by the same amount.
Where possible you provide a separate test environment. If we have to test in production, scenarios that create data are taken out of scope and we proceed with read-only checks; this narrows coverage noticeably.
You ensure the test environment holds no real personal data. Where it does, the Data Processing Agreement applies and you tell us in advance.
Third-party systems
Where your product relies on third-party services (payment provider, maps, identity, hosting), obtaining permission to test those services is your responsibility.
Where your hosting provider requires prior notice for load or security testing, you give that notice. We are not responsible for a test being halted because notice was not given.
Changes to scope
Scope is fixed at payment. If something outside it surfaces during testing, we ask you before continuing and obtain your approval, and any additional fee, in writing.
No work carried out without approval is ever invoiced. There are no surprise line items.
If you want to reduce scope, the Refund and Cancellation Policy applies to the part not yet carried out.
Fees, payment and tax
Prices appear in the panel as you select scope and are fixed at confirmation. We do not bill by the hour.
Amounts shown on the site are starting figures excluding VAT. The final amount follows the scope you choose, and taxes are shown separately on the invoice.
Where withholding or similar obligations fall on you, the net amount payable to us is unaffected by those deductions.
Subscriptions are charged at the start of each period. We give at least 30 days’ notice of a price change; if you do not accept it, you may end the subscription at the end of the period.
Late payment and suspension
If payment is late we remind you first. We may suspend the service 15 days after the due date and terminate 30 days after it.
Your data is not deleted during suspension; on termination the retention periods begin to run.
We may suspend without notice where the Acceptable Use Policy is breached or unauthorised testing is identified. In that case we state the reason in writing immediately.
Intellectual property
All rights in your product remain yours. This agreement transfers nothing to us.
The report and findings a test produces belong to you. You may use, reproduce and share them with third parties as you see fit.
Our methodology, checklists, tooling and templates remain ours. The report is yours; the right to use the method behind it is not transferred.
Automation tests we write under the Fleet package belong to you; they stay in your repository when the agreement ends.
Confidentiality and personal data
Our confidentiality obligations are set out in detail on the Confidentiality Undertaking page and apply even where no separate NDA is signed.
Processing of personal data is governed by the Privacy Policy and the Data Processing Agreement. Where a test touches personal data, the Data Processing Agreement forms an integral part of these terms.
Disclaimer of warranties
The service is provided with professional care and reasonable skill. Beyond that we give no warranty, express or implied.
We do not undertake that your product is defect free, that every defect has been found, or that nothing will go wrong after testing. Testing is a sampling activity; it produces no result for areas outside scope.
Rights granted to you by mandatory legislation are unaffected; this clause does not limit them.
Limitation of liability
Our total liability is limited to the amount you paid us for the engagement in question in the 12 months preceding the event giving rise to the claim.
We are not liable for indirect loss, loss of profit, loss of business, reputational harm or loss of data.
These limits do not apply to wilful misconduct, gross negligence, breach of confidentiality, or harm to life and physical integrity.
Indemnity
You agree to cover third-party claims arising from your requesting a test you were not authorised to request.
We in turn cover third-party claims arising from our own gross negligence or our breach of confidentiality.
Each party notifies the other of a claim within a reasonable time and cooperates in the defence.
Force majeure
We are not liable for delay caused by events outside our control, such as natural disaster, war, epidemic, wide-scale infrastructure failure or acts of public authority.
Where force majeure lasts more than 30 days, either party may terminate, with the fee for the part not carried out refunded.
Term and termination
For one-off tests the agreement ends on delivery of the report and completion of the re-test round.
Subscriptions run to the end of the period and can be ended at that point on at least 30 days’ notice. For committed subscriptions the Refund and Cancellation Policy applies.
Where one party materially breaches and does not cure within 15 days of written notice, the other may terminate immediately.
The following survive termination: confidentiality, intellectual property, limitation of liability, indemnity and governing law.
Changes
We may update these terms. We give at least 30 days’ notice of material changes by email and in the panel.
A test already under way is governed by the terms in force when it began. Changes do not apply retroactively.
If you do not accept a change, you may end the agreement before it takes effect.
Assignment, waiver and severability
You may transfer your rights under this agreement to an acquirer on a sale of your business. We may not assign our rights or obligations without your written consent.
Failure to exercise a right is not a waiver of it. If one provision is invalid the others are unaffected.
These terms, together with the documents they refer to, are the entire agreement between the parties and replace prior discussions.
Governing law and disputes
This agreement is governed by the law of Türkiye Cumhuriyeti. İstanbul Merkez (Çağlayan) Mahkemeleri ve İcra Daireleri has jurisdiction over disputes.
Before commencing proceedings, we each agree to spend 30 days trying in good faith to resolve the dispute.
Mandatory consumer rights and the competent consumer authorities in a consumer’s own country are unaffected.
These documents are published in English and Turkish. In the event of conflict the Turkish text prevails.