Last updated: July 2026.
These terms of sale govern the sale of the automated security audit service offered on leak-sentinel.fr by Ludovic Cardinale (hereinafter "the Provider").
The service analyzes a website designated by the customer in order to detect exposed secrets, common misconfigurations and injection vulnerabilities (SQL injection, reflected XSS, open redirect), then delivers a report listing the issues found and the recommended fixes. The analysis is performed in a non-destructive way: GET requests only, no data modified or deleted. Injection tests consist of submitting harmless test values (markers) to the site's parameters to observe its behavior, without any destructive payload; they are only performed after verification of domain ownership by the customer.
This is an automated and non-exhaustive audit: it covers a defined set of checks and does not replace a manual penetration test. The Provider is bound by a best-efforts obligation.
The customer declares and warrants that they own or legitimately represent the submitted domain, and expressly authorizes its audit. No active audit is performed before verification of domain ownership (via DNS, file or meta tag). This verification and this consent constitute the legal basis of the service. Any submission of a domain not owned by the customer is the sole responsibility of the latter.
The initial scan is free. The full report is sold for €19 incl. tax and includes the detailed audit plus 3 re-scans (4 audits in total). A continuous monitoring option is offered by monthly subscription at €9 incl. tax/month (automatic re-scan and email alert on any new vulnerability), with no commitment and cancellable at any time; the subscription remains active until the end of the current period. VAT not applicable, article 293 B of the French CGI. Payments are made online via our provider Stripe; the Provider stores no bank card data.
Launch offer. On the occasion of the launch, the full report is offered at a reduced price of €5.70 incl. tax (i.e. −70%), limited to the first one hundred (100) reports sold. Beyond that number, the normal price of €19 incl. tax applies automatically. The applicable price is the one displayed at the time of payment.
"False positives refunded" guarantee. If the report flags a vulnerability that turns out to be an obvious false positive (an item that does not exist or is not exploitable on the audited domain), the customer may request a refund of the report concerned upon presentation of the disputed item.
The service is provided in digital form. After payment and verification of domain ownership, the audit is launched at the customer's request and the report is made available immediately in the interface (and, where applicable, sent by email).
In accordance with article L221-28 of the French Consumer Code, the customer, by requesting the immediate performance of the audit after verification, acknowledges waiving their right of withdrawal once the service has been fully performed. As long as the audit has not been launched, the order may be refunded on simple request.
The Provider cannot be held liable for the consequences of an undetected vulnerability, for the use made of the report, nor for any damage resulting from erroneous information provided by the customer (in particular regarding domain ownership). The report is provided for guidance; fixing the vulnerabilities is the customer's responsibility.
Data processing is described in our privacy policy.
These terms of sale are governed by French law. In the event of a dispute, an amicable solution will be sought before any legal action. The customer may use a consumer mediator free of charge. Failing agreement, the French courts have jurisdiction.