Terms of Service

These terms cover two things: your use of this website, and the default terms on which I take on consulting, advisory, workshop and training work. Where a signed engagement letter, statement of work or framework agreement exists, that document wins over anything on this page.

Who you are dealing with

Relations Security ApS (registered as Agnoletti Security ApS)
CVR 42576786
Copenhagen, Denmark
Contact: relationsec.net/contact/

Part 1: Using this website

What the site is for

This site describes my services, publishes articles, and hosts material such as slide decks and games. It is provided as information, not as advice for your specific situation. Reading a page here is not the same as engaging me, and nothing on the site creates a client relationship or a duty of care.

No warranty on the content

I write about security accurately and to the best of my knowledge, and I correct things when they turn out to be wrong. Even so, the content is provided as is. Security guidance goes stale, regulations change, and your environment is not the one I had in mind while writing. Do not treat an article here as a substitute for advice on your own systems, your own risk appetite or your own regulatory obligations.

Acceptable use

Please do not attempt to disrupt the site, gain unauthorised access to it, scrape it at a volume that degrades it for other people, or use it to distribute malware or unlawful material. Automated crawling for search indexing is fine. If you want to test the site’s security, contact me first and we will agree scope, as described in the responsible disclosure note in my privacy policy.

Intellectual property and licensed material

Unless stated otherwise, the text, layout, graphics and code on this site are owned by Relations Security ApS. You may quote and link to it with attribution. You may not republish substantial parts of it as your own, or use it to train a commercial model, without written permission.

Some material here is deliberately free to use and carries its own licence, including the Malware & Monsters game and the other tabletop games published on this site. Where a download, repository or game states a licence, that licence governs, and it takes precedence over this section. If you are unsure what you are allowed to do with something, ask and I will tell you plainly.

Links to other sites

Where I link out, including to Google Calendar for booking and to code repositories, that service’s own terms and privacy policy apply. I do not control those sites and I am not responsible for their content.

Part 2: Terms of engagement

How an engagement starts

An enquiry is not a booking. Work is agreed in writing, by an engagement letter, a statement of work, a purchase order I have accepted, or a written confirmation of scope, dates and price by email. A quote is valid for 30 days unless it says otherwise. An engagement begins when I confirm it in writing, not when a form is submitted.

Scope, and changes to it

Each engagement records what is in scope, what is out of scope, what you will provide, and what the deliverable is. Security work has a habit of revealing more work, so if something material turns up that changes the effort involved, I will tell you as soon as I see it and we agree the change before I do it. I will not silently expand the bill.

Fees, invoicing and payment

Fees are agreed in advance, either as a rate per hour or per day, or as a fixed price for a defined deliverable. Unless agreed otherwise:

  • Prices are quoted excluding VAT. Danish VAT is added at the applicable rate. For business customers elsewhere in the EU holding a valid VAT number, the reverse charge applies.
  • Travel, accommodation and materials outside the Copenhagen area are billed at cost, agreed in advance.
  • Payment terms are stated on the invoice.
  • Late payment accrues interest and a collection fee at the rates set by the Danish Interest Act (renteloven).
  • For longer engagements I may invoice monthly in arrears, or partly on account, as agreed at the start.

Workshops, training and tabletop exercises

Booked sessions hold a date in my calendar that I then decline other work for, so cancellation terms exist for a reason rather than out of formality. Unless agreed otherwise:

  • Cancellation or postponement more than 14 days before the session: no charge.
  • Between 14 and 7 days before: 50 per cent of the agreed fee.
  • Less than 7 days before, or a no-show: the full agreed fee.
  • Non-recoverable costs already incurred, such as travel and printing, are billed in all cases.

If I have to cancel, you get the choice of a new date or a full refund of anything already paid.

What I need from you

To do the work properly I need timely access to the right people, systems and documents, a named contact who can make decisions, and accurate information about your environment. Where I am delayed by things outside my control, the timeline moves accordingly.

Authorisation for security testing

This one is not negotiable. Where an engagement involves testing, probing, assessing or otherwise touching systems, you confirm that you own those systems or are authorised by their owner to permit the work, and you provide that authorisation in writing before it starts. If a third party hosts or operates part of the target, you are responsible for obtaining their permission too. I will not proceed on a verbal assurance, and I will stop if the authorisation turns out not to cover what I have been asked to do.

Confidentiality

Anything you tell me about your environment, your incidents, your weaknesses or your business is confidential, and stays confidential after the engagement ends. I will not name you as a client, use your logo, or describe your situation publicly without your written agreement. Where I write or speak about patterns I have seen, it is anonymised and unattributable, and a specific client story only ever goes out with that client’s approval. The same duty runs the other way for my own methods, materials and pricing.

Data protection

Where an engagement involves me processing personal data on your behalf, we sign a data processing agreement under GDPR Article 28 before the work starts, and I act only on your documented instructions. My own processing as a controller is described in the privacy policy.

Deliverables and intellectual property

Reports, findings and recommendations produced specifically for you are yours to use inside your organisation once paid for. My underlying methods, templates, frameworks, game material and general know-how remain mine, and I keep the right to reuse them. Deliverables are prepared for you and for the situation described in the scope, and are not intended for a third party to rely on.

What I do not promise

I will apply proper professional skill and care, and I will tell you what I actually think rather than what is comfortable. What I cannot promise is a security outcome. No assessment finds every weakness, no exercise prevents every incident, and no advice makes an organisation breach-proof. Compliance with a standard or regulation depends on decisions and operations that are yours, not mine, so I can help you get there but I cannot warrant the result.

Liability

My total liability under an engagement is limited to the fees paid for that engagement, and I am not liable for indirect or consequential loss, lost profit, lost data or business interruption. Nothing here limits liability for gross negligence, wilful misconduct, or anything that cannot lawfully be limited under Danish law.

Ending an engagement

Either of us may end an ongoing engagement on 30 days’ written notice, and either of us may end it immediately for a material breach that is not fixed within 14 days of being pointed out. Work already done, and non-recoverable costs already committed, are payable.

Subcontracting

Most work I do myself. Where an engagement benefits from another specialist, I will tell you before bringing anyone in, and I remain responsible to you for their work and bound by the same confidentiality terms.

Governing law and disputes

These terms and any engagement under them are governed by Danish law. Disputes go to the courts of Copenhagen, Denmark. Before that, I would much rather pick up the phone.

Changes to these terms

These terms may be updated, and the current version is always the one published here. The version that applies to an engagement is the one in force when the engagement was confirmed. Last updated 24-08-2026.

No cookies here

Notice there’s no cookie banner here.
That’s intentional and the site is still GDPR-compliant. I chose to avoid cookies and stick to basic, privacy-friendly stats.
My analytics are cookieless: self-hosted Plausible (EU) and PostHog in cookieless mode, with your IP anonymized. No cross-site tracking, nothing that identifies you.
The one cookie I can set does the opposite of every other cookie: it tells my stats to ignore you completely, and you only get it if you ask.

Everybody wins.