Terms of service
Plain terms for a one-person business. If anything here reads as a trap, tell me and I'll change it.
Version 1.0, 18 September 2026
These terms apply to the security work I do for you and to this website. Together with the written scope we agree by email before any work starts, they are the whole agreement between us.
I'm not a lawyer and these aren't legal advice to you. They set out how I work.
1. Who you're dealing with
App Locksmith is the trading name of Nate Parker, a sole proprietor in Pennsylvania, United States. There is no company behind it and no staff. You work with me directly, and I don't subcontract your work to anyone else without asking you first.
You can reach me at nate@applocksmith.com.
2. How work gets agreed
Every engagement starts with a free call of about fifteen minutes. Nothing is charged for it, and I'll tell you honestly if I don't think I can help.
After that I send you an email setting out the service, the price, what's in scope and what I need from you. Nothing is charged before you agree to it. Once you have, the fee is payable up front and I start when it's paid.
If anything in that email conflicts with these terms, the email wins, because it describes your job specifically.
3. Services and prices
Prices are fixed for the scope described in your engagement email. They are flat fees, not estimates, and they don't change because the work took longer than I expected.
- Emergency lockdown
- $1,500
- App Store rejection fix
- $1,200
- Security questionnaire fix
- $1,200
- Pre-sale security review
- $2,000
- Security audit
- $950
- Mobile security audit
- $950
- Security on call (retainer)
- $350 per month
If your app is unusually large or the job turns out to be materially different from what we discussed, I'll tell you before I start and quote again. You're free to walk away at that point owing nothing.
4. Turnaround times
The turnarounds on the website are targets, and they are measured from when you have given me the access I need, not from when you book.
“I reply within 24 hours” means within 24 hours of your message reaching me, every day, not only business days. In practice it is usually a few hours; 24 is the promise, so that it holds while I am asleep. It is a promise about replying, not about resolving.
If I'm going to miss a target, you'll hear it from me before the date, not after. If I miss it by more than two business days for reasons that are mine rather than yours, you can cancel and I refund everything except the work already done.
5. The audit guarantee
The security audit and the mobile security audit are paid up front like everything else, and refunded in full if I find nothing worth fixing. Not part of it. All of it.
I decide what counts as worth fixing, acting reasonably and in good faith. In practice: if everything I find is informational, with no realistic path to your data, your money or your users, you get the fee back. You keep the report either way.
The refund is made within five business days of me telling you, to the card or account you paid from. I tell you; you don't have to ask.
This applies to the audit services only. It isn't a general satisfaction guarantee, and it doesn't apply once findings have been fixed.
6. The App Store rejection promise
If your next build is rejected again on a ground that was within the scope I was engaged to fix, I fix that too at no extra charge.
It doesn't cover new grounds of rejection, grounds outside the agreed scope, changes you or anyone else made after my work, or the review decision itself. Whether an app is approved is Apple's or Google's decision and nobody can promise you it.
Design, screenshot, metadata and content rejections aren't work I take on. If that's what yours turns out to be, I'll say so on the free call and you pay nothing.
7. The retainer
The retainer runs month to month at $350, payable in advance. You can cancel any time, effective at the end of the month you've paid for. I don't charge a cancellation fee and I don't ask for notice.
“Same-day response” on the retainer means I respond within one business day of you raising something. Emergency lockdown work is included in the retainer, subject to it being your app and a reasonable number of incidents; if something turns into weeks of work I'll tell you before it does.
I take a limited number of retainer clients so that the response time stays true. If I'm full, I'll tell you rather than take your money.
8. What I need from you, and what you're promising me
This is the most important section in these terms, and it's the one that protects both of us.
By engaging me you confirm that you own the systems you're giving me access to, or that you have authority from whoever does to let me examine and change them. You also confirm that letting me do so doesn't breach any agreement you have with anyone else, including your hosting provider, your app stores and your own customers.
If that turns out not to be true, you agree to cover any claim, loss or cost that comes to me as a result. I test what you tell me is yours. I have no way to verify ownership, and I don't test anything without permission.
- Access to what we agreed, promptly. Read-only where that's enough.
- A named person who can answer questions and make decisions.
- Backups of anything you'd mind losing, taken before I start.
- Telling me if any part of the system is shared with, or belongs to, someone else.
9. How I work on your systems
I don't run destructive tests. I don't run denial-of-service tests. I don't try to trick your staff or your customers, and I don't test anything outside the scope we agreed.
Security work on a live system carries some risk of interruption even when it's careful. Where I make changes, each one goes in separately so it can be reviewed and undone. Backups remain your responsibility.
Credentials you give me are kept in a password manager, used only for your work, and revoked or deleted when we're done.
10. Confidentiality
Anything I learn about your business, your code or your customers stays between us. I'll sign your NDA if you have one, and I'll provide one if you'd rather use mine.
This doesn't cover information that's already public, that you tell me I can share, or that I'm legally required to disclose. If I'm ever required to disclose something, I'll tell you first unless I'm forbidden from doing so.
11. Your report, and what I can say publicly
The report I write is yours. Use it however you like, including handing it to customers, buyers or investors, provided you share it in full rather than in pieces.
I keep the right to use my own methods, checklists and templates on other work. That's the trade: your findings are yours, my way of finding them is mine.
I won't name you, name your app, describe your systems or publish anything about your engagement without your written approval of the exact wording. That holds after the work ends and it holds indefinitely. If I want to write up something I learned, I'll ask, I'll anonymise it, and you'll approve it before it goes anywhere.
12. Payment
Flat-fee work is paid in full before I start. I invoice once you've agreed the scope, and I begin when it's paid. Retainers are paid monthly in advance.
This is how a one-person business avoids chasing money instead of doing the work, and it's why the prices are flat and the scope is written down before either of us commits.
Prices don't include any sales, use or similar taxes. If any apply, they're yours to pay.
If you change your mind before I start, you get all of it back. If you stop the work once it's under way, I refund the part I haven't done, judged honestly against where we got to, and you keep everything I've produced so far.
If a retainer month goes unpaid I may suspend the service. I'd always rather talk about it first.
13. What a security review is not
No security review can show that an app has no vulnerabilities, and anyone who tells you otherwise is selling something. A review examines a defined scope over defined dates, using the access given, and reports what was found.
My reports are not a certification, a warranty or an assurance that your app is secure. They describe what I checked, what I found and what I changed.
Nothing I give you is legal advice. Whether you must notify users or regulators after an incident, and what your privacy obligations are, are questions for a lawyer. I'll tell you what was exposed so you and your lawyer can decide.
14. Limit of liability
To the extent the law allows, my total liability to you for anything arising out of our work together is limited to the fees you have paid me for the service the claim relates to.
I'm not liable for lost profits, lost revenue, lost data, lost business opportunity or any indirect or consequential loss, even if I was told it was possible.
Nothing here limits liability for fraud, for gross negligence or wilful misconduct, or for anything else that can't lawfully be limited.
I'm one person. This limit is the reason a one-person business can afford to take on work like this at these prices, and it's why the prices are what they are.
15. Ending the agreement
Either of us can end an engagement in writing at any time. I refund the part I haven't done, I hand over what I've produced, and access gets revoked.
Sections 10, 11, 13 and 14 carry on after the work ends.
16. Law
These terms are governed by the laws of the Commonwealth of Pennsylvania, United States, without regard to its conflict of laws rules. Any dispute goes to the state or federal courts located in Pennsylvania, and we each agree those courts can hear it.
If any part of these terms turns out to be unenforceable, the rest still stands.
17. Changes
I may update these terms. The version in force when you engage me is the one that applies to your work, and I'll send it to you with your engagement email so there's no doubt about which one that was.
Questions about any of this: nate@applocksmith.com. I'd rather explain a clause now than argue about it later.