Security Assessment Authorization Agreement

DBAudit - Rules of Engagement

Last Updated: June 2026

This Security Assessment Authorization Agreement ("Agreement") is entered into between DBAudit ("DBAudit", "we", "us") and the individual or entity accepting these terms ("Client", "you") in connection with the security assessment services provided through the DBAudit platform.

By accepting this Agreement, you confirm that you have read, understood, and agree to be bound by the terms set out below.

1. Authorization and legal capacity

  • You represent that you control the submitted Supabase or Firebase project, or have explicit written authorization from its owner to commission DBAudit.
  • You represent that you have authority to bind the organization associated with the target domain to this Agreement.
  • You represent that the requested assessment complies with applicable law, regulation, and contractual obligations.
  • Any ownership verification DBAudit requests is evidence of control only. It does not replace your representation that testing is authorized under applicable law and provider terms.
  • Misrepresentation of ownership or authorization may result in immediate suspension or termination of service and may be reported to applicable authorities.

2. Scope of assessment

Authorized scope

  • The specific Supabase project or Firebase project submitted for the scan.
  • Its associated public backend APIs, Auth, Storage, and rules or policy surfaces.
  • Only the test accounts and schema-only exports supplied or created for the scan.

Out of scope

  • Other projects, tenants, accounts, domains, networks, or third-party services.
  • Generic web application, infrastructure, or endpoint security testing.

3. Assessment methodology

Permitted activities

  • Automated assessment of Supabase and Firebase access controls and configuration.
  • Read-only validation requests and authenticated checks using supplied test accounts.
  • Where a scan mode explicitly allows it, short-lived scanner-owned test accounts or test data that DBAudit attempts to remove after the check.

Prohibited activities

  • Denial-of-service or other availability-impacting attack traffic.
  • Modification, deletion, or corruption of existing production data.
  • Persistent backdoors, web shells, or malicious persistence mechanisms.
  • Social engineering, phishing, or physical security testing.
  • Testing outside the explicitly authorized target scope.
  • Retention, sharing, or monetization of non-public data found during testing.

4. Confidentiality and data handling

  • Findings and reports are provided only through authorized access paths in the DBAudit product.
  • If sensitive data is encountered during authorized testing, interaction with that data should stop immediately and exposure should be documented only as needed for the finding.
  • DBAudit may disclose information only when required by applicable law or with explicit written Client authorization.

5. Reporting and deliverables

  • Findings are delivered through the DBAudit product experience and may include severity, technical detail, exploitability evidence, and remediation guidance.
  • Available reporting depth and product capabilities may vary based on the active plan or purchase for the Client account.

6. Limitation of liability and disclaimer of damages

  • THE DBAUDIT PLATFORM AND ALL ASSOCIATED TOOLS, SCRIPTS, AUTOMATED CHECKS, AND GENERATED OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
  • Security assessment activities interact with live backend services. DBAudit is designed to avoid persistent changes by default, but optional scan modes can create test data or alter approved test data. You acknowledge and accept the risk of operational impact, data alteration, service disruption, or unintended side-effects arising from those activities.
  • TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, DBAUDIT AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AND AFFILIATES SHALL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES OF ANY KIND, INCLUDING WITHOUT LIMITATION LOSS OF DATA, LOSS OF REVENUE, LOSS OF PROFITS, BUSINESS INTERRUPTION, SYSTEM DOWNTIME, THIRD-PARTY CLAIMS, OR REPUTATIONAL HARM, ARISING OUT OF OR IN CONNECTION WITH YOUR USE OF THE PLATFORM OR ANY ACTION YOU CHOOSE TO TAKE WITH IT — REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF DBAUDIT HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
  • You expressly acknowledge that deep mutation probes can alter approved test data. These probes are disabled by default and are intended for staging or disposable environments. DBAudit bears no responsibility for the outcome of actions you choose to initiate through the platform.
  • Where limitation of consequential or incidental damages is prohibited by law, DBAudit's aggregate liability shall not exceed the total fees paid by you in the twelve (12) months preceding the claim.

7. Abuse enforcement and legal action

  • DBAudit actively monitors platform activity for signs of abuse, unauthorized use, or activity that exceeds the scope authorized under this Agreement.
  • In the event of actual or suspected abuse — including but not limited to unauthorized testing of third-party targets, deliberate data exfiltration, use of the platform to facilitate attacks, or circumvention of platform controls — DBAudit reserves the right to immediately suspend or permanently terminate account access without prior notice.
  • Where abuse is confirmed or credibly suspected, DBAudit will pursue all available legal remedies, including but not limited to civil claims for damages and reporting the activity to relevant law-enforcement authorities and regulatory bodies.
  • In connection with any abuse investigation, enforcement action, or lawful request from authorities, DBAudit will collect, retain, and disclose the minimum personally identifiable information ("PII") necessary, which may include: account registration details (name, email address), billing and payment records, IP addresses and session metadata, audit target history, and any communications with DBAudit support. This information may be provided to law-enforcement agencies, courts, affected third parties, or their legal representatives where required or permitted by applicable law.
  • You consent to the collection and disclosure of such PII for the purposes described above by accepting this Agreement. This consent is a condition of using the platform.

8. Term and revocation

  • This Agreement becomes effective upon acceptance by the Client.
  • The Client may revoke authorization by submitting written notice through official DBAudit support channels.
  • DBAudit may suspend or terminate assessment activity on expiration, cancellation, or material breach of this Agreement.

9. Indemnification

The Client agrees to indemnify, defend, and hold harmless DBAudit and its personnel from claims, liabilities, damages, costs, and expenses (including reasonable legal fees) resulting from misrepresentation of authorization, breach of this Agreement, violation of applicable law, or third-party claims alleging unauthorized testing based on Client-provided authorization.

10. Governing law and dispute resolution

This Agreement is governed by applicable law as determined by the controlling terms between DBAudit and the Client. This Agreement is the full understanding between the parties regarding authorization for security assessment activity and supersedes prior representations on this subject.

DBAudit is an independent product and is not affiliated with, endorsed by, or sponsored by Supabase or Firebase.