General Terms and Conditions

As of: 3 October 2026 · Provider: Bocert GmbH, Berlin (Legal Notice)

§ 1 Scope of Application and Subject Matter of the Contract

These Terms and Conditions apply to all services offered by Bocert GmbH via itsecurity.today (hereinafter the "Provider"): the free basic website security scan, the paid detailed report with remediation instructions, the fix package, and retests. The services are directed exclusively to commercial customers (§ 14 BGB); the customer confirms this with the inquiry. The contract language is German.

§ 2 Conclusion of Contract and Place of Performance - exclusively Germany

The contract is concluded with Bocert GmbH, headquartered in Berlin, and is concluded in Germany. The service (scan, analysis, report, consultation) is performed in Germany. The technical retrieval of the website to be scanned is performed from the Federal Republic of Germany.

All contractual relationships (offer, acceptance, performance, invoicing, and payment) take place exclusively within Germany. This applies regardless of which server or in which country the scanned website is hosted and regardless of where the customer is located. Foreign hosting locations or foreign addresses of the customer do not change this; cross-border transactions are not conducted.

§ 3 Scanning Prerequisite: Operator Confirmation

A prerequisite for every scan is your explicit confirmation in the inquiry or portal form (checked box) that you are the operator of the website or have been effectively authorized by the operator, as well as confirmation of the order via the personal link in our confirmation email (double opt-in). We store these confirmations as proof of authorization (domain, time, text version, IP hash, browser identifier). Scans of third-party websites without proof of authorization are prohibited.

§ 4 Scope of Services and Scanning Care Rules

§ 5 Prices and Payment - Processing in Germany

All prices are gross prices including the statutory German value-added tax. The Payment is made exclusively in Germany in Euro via a payment method offered in Germany (e.g., bank transfer from a German/SEPA account or via a payment provider based in Germany). Invoicing is carried out by Bocert GmbH, Berlin.

§ 6 Informational Emails and Naming as a Reference

The provider uses the customer's e-mail address for the occasional transmission of information about their scans as well as similar products, offers, and services in the areas of security, IT, and website operation. The customer is expressly informed of this use in the scan form. The customer may object to this use at any time free of charge, including the underlying profiling (Art. 21(2) DSGVO), via the link in each e-mail or informally to info@itsecurity.today. Otherwise, § 7(2) No. 3 UWG applies.

By using the Service, the Customer agrees that the Provider may cite his name or the name of his company and the logo of his website as a reference. (e.g., "These companies have already been scanned"). The mention can be revoked at any time with effect for the future, informally by e-mail to info@itsecurity.today; the provider will remove the mention within 7 business days.

§ 7 Right of Withdrawal for Consumers

Consumers are entitled to a statutory 14-day right of withdrawal. The withdrawal must be made in text form (e-mail suffices) to info@itsecurity.today; upon request, we will promptly send a model withdrawal form. If, with the customer's express consent, work on the report was commenced before the end of the withdrawal period, the right of withdrawal shall be extinguished for that report (§ 356(5) BGB).

§ 8 Liability

The provider is liable without limitation in cases of intent and gross negligence, for injury to life, body, or health, under the Product Liability Act, and to the extent of warranties assumed. In cases of simple negligence, the provider is liable only for breach of essential contractual obligations (cardinal obligations), in which case liability is limited to the typical, foreseeable contractual damage. Liability for scanning incorrectly assigned domains as a result of incorrect information provided by the customer is excluded.

§ 9 Automated Security Checks and Scan Results

The security checks and analyses provided by ITSecurity.today / Bocert GmbH are carried out fully or partially in an automated manner. Despite careful development and regular updating of the testing procedures used, it cannot be guaranteed that the results are complete, error-free, or up to date at all times. In particular, security vulnerabilities or risks may remain undetected (False Negatives) or circumstances may be incorrectly classified as a security risk (False Positives).

The scan, analysis, and assessment results provided therefore serve as a technical basis for decision-making and information and do not replace an individual professional review of the respective system or matter.

Decisions and measures taken on the basis of the results provided are taken at the customer's own responsibility. Before carrying out safety-critical, production-relevant or otherwise material measures, the customer must appropriately review the underlying results or have them reviewed by appropriately qualified personnel.

ITSecurity.today / Bocert GmbH shall not be liable for damages arising solely from unverified or incorrectly interpreted scan, analysis or rating results, or from decisions or measures based thereon, to the extent legally permitted.

The statutory liability provisions, in particular liability for intent and gross negligence, for damages arising from injury to life, body or health, and other legally mandatory liability provisions, remain unaffected.

The security assessments and analyses provided by ITSecurity.today / Bocert GmbH are performed in whole or in part by automated means. Despite careful development and regular updating of the testing procedures used, it cannot be guaranteed that the results are complete, error-free or up to date at all times. In particular, vulnerabilities or risks may go undetected (false negatives), or facts may be incorrectly classified as security risks (false positives). The scan, analysis and rating results provided therefore serve as a technical basis for decisions and information and do not replace an individual expert review of the respective system or matter. Decisions and measures taken on the basis of the results provided are taken at the customer's own responsibility. Before carrying out safety-critical, production-relevant or otherwise material measures, the customer must appropriately review the underlying results or have them reviewed by appropriately qualified personnel. To the extent legally permitted, ITSecurity.today / Bocert GmbH shall not be liable for damages arising solely from unverified or incorrectly interpreted scan, analysis or rating results, or from decisions or measures based thereon. The statutory liability provisions, in particular liability for intent and gross negligence, for damages arising from injury to life, body or health, and other legally mandatory liability provisions, remain unaffected. The German version of these Terms and Conditions is the authoritative version.

§ 10 Applicable Law and Jurisdiction - Berlin

The security assessments and analyses provided by ITSecurity.today / Bocert GmbH are performed in whole or in part by automated means. Despite careful development and regular updating of the testing procedures used, it cannot be guaranteed that the results are complete, error-free or up to date at all times. In particular, vulnerabilities or risks may go undetected (false negatives), or facts may be incorrectly classified as security risks (false positives).

§ 11 Final Provisions

The scan, analysis and rating results provided therefore serve as a technical basis for decisions and information and do not replace an individual expert review of the respective system or matter.

Rechtstexte sind ausschließlich in deutscher Sprache maßgeblich. Übersetzungen der Landingpage (z. B. index-en.html) sind reine Leistungsbeschreibungen ohne Rechtsverbindlichkeit.

The German-language version of this document is legally binding.