Service and billing terms
Legal-review draft — updated 29 July 2026. These terms must be confirmed by Beekeeper’s legal advisers before general sale.
1. Operator and application
Beekeeper is operated by Taglab Limited, company number 14711186, registered office Synergy House, Lawson Street, North Shields, United Kingdom, NE29 6TG.
These terms apply to enquiries, accounts, subscriptions and one-off services supplied through Beekeeper. The service is intended for business customers acting in the course of trade. Nothing in these terms affects rights that cannot lawfully be excluded.
2. Subscriptions and pricing
Single Asset, Growth and Scale are monthly recurring subscriptions billed through Stripe in the currency shown at Checkout. Prices exclude applicable taxes. Your subscription renews automatically each month until cancelled. You can cancel through Stripe’s billing portal; access continues to the end of the paid period unless otherwise stated.
Each paid billing cycle includes one verified deep-scan request and one focused retest request for every asset covered by the active plan. Each allowance is bound to that exact hostname and cannot be transferred to another asset. A focused retest checks remediation of findings from an earlier Beekeeper deep scan on the same asset; it is not a second deep scan or a new scope. Requests must be submitted during the applicable billing cycle. An accepted request may be scheduled later where Beekeeper’s availability requires it, but unused allowances do not accumulate unless agreed in writing.
We may change subscription prices by giving at least 30 days’ notice before the change takes effect at a renewal. If you do not agree, you may cancel before that renewal. One-off work remains charged at the price accepted in the relevant Checkout, quote or order.
3. Assets
An asset is one exact public hostname. Paths beneath that hostname are included in the same asset—for example, example.com includes example.com/portal. A subdomain such as portal.example.com is a separate asset and consumes separate plan capacity. Beekeeper does not silently expand authority from one hostname to a parent, sibling or subdomain.
4. Lawful authority and scope
Beekeeper does not authorise or encourage the testing of systems without the express permission of their owner. Customers are solely responsible for ensuring they have lawful authority before requesting any assessment.
A subscription, payment, password, employment relationship or domain relationship does not itself authorise testing. Every exact application host must be verified, and active testing requires written authority from a person entitled to grant it, an approved immutable scope, exclusions, stop conditions, test window and applicable rules of engagement. Beekeeper may require further evidence and may refuse, pause or stop work where ownership, authority, safety or legality is uncertain.
5. Acceptable use
You must not use Beekeeper:
- to request or facilitate unauthorised, unlawful, fraudulent or harmful testing or activity;
- to target an asset, tenant, account or data set outside the expressly approved scope;
- to upload malware, stolen credentials, unlawful content or personal information that is unnecessary for the service;
- to interfere with, overload, bypass or probe Beekeeper itself except through an agreed vulnerability-disclosure process;
- to resell, sublicense or white-label the service or a report without written permission; or
- to copy, reverse engineer or attempt to derive Beekeeper’s source code except to the extent applicable law expressly permits and that permission cannot be excluded.
6. Authenticated testing and credentials
Where authenticated coverage is agreed, customers must provide dedicated temporary test accounts containing synthetic or isolated test data, not real customer credentials, production administrator passwords, MFA seeds or recovery codes. Credentials are accepted only after scope approval through Beekeeper’s encrypted, expiring, one-time handoff. No authenticated or intrusive testing begins automatically.
Unless expressly agreed in writing, prohibited testing actions include denial-of-service or load testing, aggressive brute force, real payments or refunds, destructive changes or deletion, bulk export, contacting customers, testing unrelated tenants, persistent access, password changes, account lockout and social engineering. The customer must revoke all temporary access promptly after testing or on request.
7. Service boundary and AI assistance
Testing is a point-in-time assessment and is not a guarantee that vulnerabilities do not exist, that every vulnerability will be identified, or that remediation is complete. Timing and coverage depend on the verified asset, supplied access, agreed scope, safety constraints and service availability. Source-code, database, cloud-configuration and unusually complex multi-application reviews require separate written scope unless expressly included.
Beekeeper may use AI models to assist with analysing technical evidence and drafting findings or remediation guidance. AI-generated output is reviewed where appropriate but may be incomplete or incorrect and does not replace professional judgement.
8. Customer responsibilities
You must provide accurate details, maintain secure account access, nominate only assets you are entitled to test, maintain a recoverable backup, use dedicated test accounts, avoid sharing confidential report links, and promptly tell us about ownership, authority, access or scope changes. You remain responsible for deciding whether and how to implement remediation, testing changes safely and obtaining specialist advice where needed.
9. Availability and changes
Beekeeper is provided on a reasonable-endeavours basis. Continuous or error-free availability is not guaranteed, and no service level applies unless agreed in writing. We may change the service to maintain security, comply with law, address misuse or improve operation, provided that we do not materially remove a paid service already accepted without an appropriate remedy.
10. Suspension and termination
We may suspend or terminate access where an account is used unlawfully, contrary to these terms or outside authorised scope; where payment is overdue; where continued access creates a security, legal or operational risk; or where required by law. Where reasonably possible, we will explain the reason and provide an opportunity to remedy a non-urgent breach. Urgent protective action may be taken without advance notice.
11. Intellectual property and reports
Beekeeper’s software, branding, designs, methods, templates, site content and report formats remain the intellectual property of Taglab Limited or its licensors. Customers retain ownership of materials they provide. Once the applicable fees are paid, the customer receives a non-exclusive, non-transferable licence to use and share its completed report internally and with its professional advisers, insurers and remediation providers for its own security and compliance purposes. Publication, resale, white-labelling or commercial redistribution requires written permission.
12. Confidentiality
Each party must protect the other’s confidential information using reasonable care and use it only to perform or receive the service, exercise rights or comply with law. This does not cover information that is public through no breach, already lawfully known, independently developed or lawfully received from another source. A confidential report link must be protected as sensitive access information.
13. Refunds and cancellation
If Beekeeper cannot provide a paid service because an asset cannot lawfully or safely be onboarded, contact support for review. Statutory rights are unaffected. Partial-month refunds are not automatic after service has begun, but genuine service failures will be considered fairly. Any agreed refund does not authorise continued use of work or reports where the relevant fee has not been paid.
14. Limitation of liability
Nothing in these terms excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited.
Subject to that paragraph and to the fullest extent permitted by law, Taglab Limited is not liable for indirect or consequential loss, loss of profit, revenue, anticipated savings, business, opportunity, goodwill or data, or business interruption arising from or connected with Beekeeper. We are not responsible for a customer acting outside the agreed scope, failing to maintain backups, sharing credentials or report links insecurely, or treating a point-in-time assessment as a guarantee.
15. Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, including widespread hosting, cloud, CDN, payment-provider, telecommunications or internet failure; cyberattack not caused by its breach; natural disaster; fire; flood; epidemic; industrial dispute; civil disorder; war; sanctions; or government action. This does not excuse payment already due.
16. Export controls and sanctions
You must not use or make Beekeeper available in breach of applicable export-control, trade-sanctions or other laws. We may refuse or suspend service where reasonably necessary to comply with those laws or a provider’s binding restrictions.
17. Vulnerability disclosure
If you believe you have found a vulnerability in Beekeeper, report it privately to help@in-flow.co.uk. Do not access other users’ information, retain or disclose data, disrupt the service, use automated high-volume testing or publish details before we have had a reasonable opportunity to investigate and address the issue.
18. Governing law
These terms and any non-contractual dispute arising from them are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, except where applicable law gives a customer a mandatory right to bring proceedings elsewhere.
19. Entire agreement and changes
These terms, the accepted plan or quote, the approved scope and any expressly incorporated rules of engagement form the entire agreement for the service and replace earlier statements about it. Nothing in this clause limits liability for fraud or fraudulent misrepresentation. If documents conflict, the accepted written scope and rules of engagement control the testing activities, while these terms control the general service and billing relationship unless expressly agreed otherwise.
We may update these terms for future renewals or orders. We will give reasonable notice of a material change that affects an active subscription. Continuing after the effective date constitutes acceptance only to the extent permitted by law; otherwise you may cancel before the change takes effect.
20. Contact
Taglab Limited
Synergy House, Lawson Street
North Shields, United Kingdom, NE29 6TG
help@in-flow.co.uk