Scope

What we do, and what we do not

Written down before you order. We would rather you knew where our work stops than discover it mid-job.

Included in the fee

No surcharge, however long it takes us.

  • Identifying the entry point and reconstructing what happened
  • Removing everything the attacker left — infected files, backdoors, accounts created without your knowledge, scheduled tasks
  • Restoring the files of the CMS and modules, in their installed version
  • Resetting every credential — admin, database, FTP/SSH, API keys
  • Applying the security patches available for your current version
  • Hardening the configuration — file permissions, headers, admin protection
  • Blocklist removal — Google Safe Browsing, antivirus lists
  • A written intervention report — what was done, what remains, by when
  • A 90-day re-cleaning guarantee

Not included in the fee

Not to bill you more, but because these are projects of a different nature, duration and budget.

  • Upgrading your store's version — a migration takes weeks, not hours
  • Repurchasing, renewing or replacing your paid modules — those licences belong to their vendors
  • Rewriting your custom development made incompatible by an upgrade
  • Replacing your theme if no compatible version exists
  • Modules for which the vendor no longer ships any fixed version — we tell you and propose alternatives
  • Software obtained outside official channels — nulled or cracked versions: we flag and remove them
  • Recovering commercial data lost before our intervention

What triggers a separate quote

Free, itemised, no obligation. You are free not to proceed.

  • Your store runs on a version the vendor no longer maintains → migration quote
  • Paid modules have no compatible version or valid licence → replacement quote, module by module
  • Your hosting cannot run a supported version → hosting migration quote
  • Your store carries custom development to take over → takeover quote

Our commitment, and its limit

We commit to applying every means and all the craft of our trade to clean your store and protect it as it stands.

This is a best-efforts obligation. We cannot guarantee no new attack will succeed: a store's security also depends on its software, its hosting and the people who access it.

The 90-day guarantee applies in full — unless the new infection exploits a flaw we reported to you in writing and which you chose not to address. We say so now so there is no surprise later.

Unmaintained versions

When a vendor stops maintaining a version, it stops publishing fixes. Flaws found after that date are never corrected.

We can clean your store, close the entry point and apply every patch that exists for your version. It will be clean and operational.

But we cannot make it durably safe while it runs on that version. This is not about skill: no provider can fix a flaw for which the vendor never published a patch.

Frequently asked

Why not include everything in one price?

Because the price would be wrong. A recovery is a few days of work; a migration is several weeks. A single fee would either overcharge those whose store is up to date, or produce an add-on mid-job.

What if I do not want to migrate now?

That is legitimate. We clean your store, hand you the list of what remains exposed and put risk-reduction measures in place. The only consequence is on the guarantee.

Who accesses my data during the work?

A named engineer, identified in your file, working from the European Union. Processing is governed by an Article 28 GDPR data processing agreement annexed to the contract.

What if the analysis confirms no compromise?

You keep the diagnostic report and nothing else is billed. If you prefer, the amount paid becomes a credit towards preventive hardening.

Is your store compromised?

First response from an engineer within 5 hours, Monday to Friday, 8am to 8pm.

Contact us