Terms of Service
Last updated: 2026-08-19
These Terms of Service (the “Terms”) govern your access to and use of WPfoss, including wpfoss.com, the free domain security checker, and the security engagements we deliver. The service is operated by WP FOSS LLC (“WPfoss”, “we”, “us”, “our”), a company registered in Delaware, United States, and registered with the Office of the Data Protection Commissioner (ODPC) in Kenya.
By using this website or the free checker, requesting a quote, or engaging us for work, you agree to these Terms. If you are accepting on behalf of a business, you confirm you have authority to bind that business. If you do not agree, please do not use the services.
1. Definitions
- Services — this website, the free domain security checker, and any security assessment, remediation, configuration, deployment, training or documentation work we agree to carry out for you.
- Engagement — a scoped piece of work described in a proposal or order and quoted as a fixed fee.
- Checker — the free domain security checker published on this site.
- Licences — third-party software licences we resell, currently heylogin Enterprise.
- Customer Systems — the domains, DNS zones, registrar accounts, mail platforms, cloud tenants and other systems you ask us to review or change.
2. The services
We are a specialist security practice. We carry out two kinds of engagement: DNS and email security (SPF, DKIM, DMARC and CAA, together with Cloudflare configuration, DNSSEC and web firewall rules), and heylogin team password management. We do not provide services outside that scope, and we will tell you when something falls outside it.
We also publish the Checker free of charge. It is provided for general information, it is not a penetration test or a formal audit, and it is not a substitute for professional advice on your specific circumstances.
3. The free domain security checker
- The checks run in your browser, querying public DNS over DNS-over-HTTPS.
- We log the result — the domain checked, its grade, and which controls passed or failed — so we can improve the tool and understand demand. We do not log your name, email address or IP address, so a check is not linked to a person. See the Privacy Policy.
- It reads only public DNS records, the same information any mail server on the internet already sees. You may run it against any domain, including domains you do not own.
- Results are a point-in-time indication based on public records and on the checks we have chosen to run. A clean result is not a guarantee that a domain is secure, and DKIM in particular cannot be verified from outside a domain, which is why it is reported for information only and excluded from the grade.
- The Checker is provided “as is”, free of charge, with no warranty. We are not liable for decisions taken on the basis of its output.
3a. Marketing emails
If you submit an enquiry through our contact form, or the subscribe box in our site footer, we add your email address to our mailing list and send you occasional guidance on DNS, email and password security. Every one of those emails carries a one-click unsubscribe link that takes effect immediately, and unsubscribing has no effect on any enquiry, quotation or engagement. Full detail, including what we store and for how long, is in section 2b of our Privacy Policy.
4. Scoping, quotes and fees
- Fixed fee, never hourly. We scope each Engagement and quote a fixed fee before work begins. If the work takes longer than we expected, that is our risk, not your cost.
- A quote is based on the scope described in the proposal. Work outside that scope is quoted separately and agreed in writing before it starts.
- Engagement fees are stated and payable in USD unless we agree otherwise, and are exclusive of any applicable taxes.
- heylogin licences are sold at the published list price of EUR 59.88 per user per year, with no markup, billed annually in EUR. Licence fees are separate from Engagement fees. The licence relationship, including its own terms and any renewal, is between you and heylogin.
- Payment terms are set out in the proposal or invoice. We may suspend work on overdue amounts after giving you notice and a reasonable opportunity to pay.
5. Cancellation and refunds
You may cancel an Engagement before work begins for a full refund of anything paid. Once work has started, we will refund any portion of the fixed fee attributable to work not yet performed, less costs already incurred on your behalf. Licence fees, once purchased from the vendor, follow that vendor’s own refund terms. Nothing here limits any right you have under applicable law.
6. Access to your systems, and your responsibilities
Most of our work requires access to Customer Systems. You agree that:
- You own, or are authorised by the owner to instruct changes to, every system you ask us to work on. We may ask you to confirm this in writing.
- You will provide access that is appropriate and time-limited, and will revoke it when the Engagement ends. Where we need temporary access to a credential, it is agreed in advance and rotated afterwards.
- You are responsible for maintaining your own backups and for telling us about anything unusual in your environment that a change could affect.
- You will make available a person who can approve changes and answer questions within a reasonable time. Delays in approval may extend the schedule.
7. How we make changes
Changes are staged rather than applied all at once, because the order matters more than the speed. DMARC moves through reporting mode before enforcement; DNSSEC is enabled registry-side first; firewall rules run in log-only mode before they are enforced. We document a rollback for changes that warrant one, and we agree disruptive changes with you in advance.
Despite this, changes to DNS, mail authentication and cloud configuration carry inherent risk, and some effects depend on third-party systems and propagation times outside our control. We do not warrant that no interruption will occur.
8. What we do not promise
No security work makes a business immune to attack. We reduce specific, identified risks using the controls described in your proposal. We do not warrant that your systems will not be compromised, that all vulnerabilities have been identified, or that a third party will not find a route we did not assess. Our reports describe what we examined and what we changed, and are current as at their date.
Our work is not legal, regulatory, insurance or accounting advice. Where you need to satisfy a specific regulator, standard or insurer, you remain responsible for confirming that what we deliver meets that requirement.
9. Acceptable use
You agree not to use the Services to:
- Test, scan or attempt to change any system you do not own or are not authorised to act on.
- Break any law that applies to you, or violate the terms of any platform we connect to on your behalf.
- Impersonate WPfoss or any other person.
- Probe or breach the security of this website, or attempt to derive its source beyond what is publicly served.
- Redistribute or resell the Checker, or present its output as your own product, without our written agreement.
10. Deliverables and intellectual property
On payment in full, the deliverables produced specifically for you, including reports, configuration records and written runbooks, are yours to keep, use and share, including with auditors, insurers and future providers. There is no lock-in. We retain rights in our own methods, checklists, templates and tooling, including the Checker, and in anything not produced specifically for you.
11. Confidentiality and publicity
Each party will protect the other’s non-public information with reasonable care and use it only to perform under these Terms, except where disclosure is required by law. Findings about your environment are your confidential information.
We will not name you, use your logo, publish a case study, or quote you without your specific prior agreement in writing to the exact wording. We do not publish claims we cannot evidence.
12. Third-party services
To deliver the Services we and our clients rely on third parties including Cloudflare, Google, heylogin, Stripe, Zoho and public DNS resolvers. Your use of those platforms is subject to their own terms and policies, and we are not responsible for their availability, pricing or conduct. We earn nothing from your Cloudflare or Google spend, and we do not mark up heylogin licences.
13. Data protection
We act as the Data Controller for enquiry, billing and support data, and as your Data Processor for any personal data we encounter within Customer Systems during an Engagement, which we handle on your documented instructions. We process personal data in line with the Kenya Data Protection Act, 2019, apply appropriate safeguards to cross-border transfers, and will notify you of a personal-data breach affecting your data without undue delay. Full details are in our Privacy Policy.
14. Warranties and disclaimers
We will perform the Services with reasonable skill and care, using appropriately experienced people. Beyond that, and to the maximum extent permitted by law, the Services and the Checker are provided on an “as is” and “as available” basis without warranties of any kind.
15. Limitation of liability
To the maximum extent permitted by law, we will not be liable for any indirect, incidental, consequential or special losses, or for lost profits, revenue, goodwill or data, or for issues caused by third-party platforms outside our control. Our total liability arising out of or related to these Terms or the Services is capped at the fees you paid us for the Engagement giving rise to the claim. Our liability for the free Checker, for which no fee is paid, is excluded to the fullest extent permitted by law. Nothing here excludes liability that cannot be excluded under applicable law, including for fraud.
16. Indemnification
You will defend and indemnify WPfoss against claims, damages and reasonable costs arising from: your breach of these Terms, including the Acceptable Use section; your instruction to us to work on a system you were not authorised to change; and any claim that material you supplied to us infringes a third party’s rights.
17. Term and termination
An Engagement runs until the agreed work is complete and handed over. Either party may terminate for material breach that is not cured within a reasonable time after notice. On termination we will hand over the work completed to date and any documentation produced, and you will pay for work performed. Terms that by their nature should survive, including intellectual property, confidentiality, liability, indemnification and governing law, will survive.
18. Changes to these Terms
We may update these Terms from time to time. For material changes we will give reasonable notice before they take effect; for minor changes we will update the “Last updated” date above. The Terms that apply to an Engagement are those in force when it was agreed.
19. Governing law and disputes
These Terms are governed by the laws of Kenya. If a dispute arises, the parties will first try to resolve it through good-faith discussion for at least 30 days, then through mediation in Nairobi. If it remains unresolved, it will be subject to the courts of competent jurisdiction in Kenya. Either party may seek urgent injunctive relief to protect its intellectual property or confidential information.
20. General
- Entire agreement: these Terms, together with any proposal, order, or the Privacy Policy referenced here, are the whole agreement between us.
- No waiver: not enforcing a right is not a waiver of it.
- Severability: if a provision is unenforceable, the rest remains in force.
- Assignment: you may not assign these Terms without our consent; we may assign them in a merger, acquisition, or sale of assets.
- Force majeure: neither party is liable for delays caused by events beyond its reasonable control.
- Notices: we send notices to your stated email; send notices to us at hello@wpfoss.com.
21. Contact
Questions about these Terms? Email hello@wpfoss.com.
