CoreSentinel Phishing Takedown — Customer Terms
These terms are specific to the Phishing Takedown service and supplement — they do not replace — Core Sentinel’s site-wide Terms of Use and Privacy Policy. Where these service terms conflict with the site-wide terms in relation to the Phishing Takedown service, these service terms prevail.
Provider: Core Sentinel Pty Ltd, ABN 51 611 410 658 (“Core Sentinel”, “we”, “us”, “our”), Governor Phillip Tower, 1 Farrer Place, Sydney NSW 2000, Australia. Contact: via the contact us form or phishing@coresentinel.com. Effective date: 26 August 2026. Supersedes: the v0.3 Terms of 23 June 2026. The principal change is the SLA: 48 hours of ordinary clock time replaces 48 Business Hours, and the refund is now issued automatically rather than on request.
1. About this agreement
These Terms & Conditions (“Terms”) govern the supply of the Phishing Takedown service (“Service”) by Core Sentinel to you, the customer (“Client”, “you”). By submitting an intake request and/or paying for the Service, you agree to these Terms. If you are entering into these Terms on behalf of an organisation, you warrant that you are authorised to bind that organisation.
2. Definitions
- “Phishing Asset” — the specific URL, domain, or hosted page reported by you and approved by Core Sentinel for action.
- “Case Approval” — the point at which Core Sentinel approves the case, your card is charged, and remediation work begins. The SLA clock starts here, not at intake submission.
- “SLA Period” — 48 hours from Case Approval, measured in ordinary clock time. The clock runs continuously and does not stop: weekends, public holidays and overnight periods all count. A case approved at 6pm on the Friday of a long weekend is due at 6pm on the Sunday. There is no concept of “business hours” in these Terms.
- “Refund Trigger Time” — 24 hours after the end of the SLA Period (that is, 72 hours after Case Approval). This is the point at which a refund is issued automatically under clause 12.
- “First Detected Downtime” — the first moment at which our automated monitoring observes the Phishing Asset to have stopped serving the phishing page, as recorded at the time of observation.
- “Takedown Confirmation” — confirmation that the Phishing Asset is genuinely Neutralized rather than briefly unreachable. Confirmation is given either by our automated monitoring agent (which requires the Asset to be unreachable across consecutive checks spanning several hours) or by a Core Sentinel analyst.
- “Time to Takedown” — the elapsed time from Case Approval to First Detected Downtime. This — and not the time at which Takedown Confirmation is given — is the figure measured against the SLA Period. The interval we spend confirming a takedown is ours to bear, not yours.
- “Neutralized” — the Phishing Asset is no longer reachable as a live phishing page by an ordinary visitor, as confirmed by Core Sentinel’s automated monitoring and/or analyst verification. This may be achieved by any one or more of: removal or disabling of the content by the hosting provider; suspension of the domain by the registrar or registry (e.g. clientHold / serverHold); removal from a content-delivery network; revocation of the TLS certificate; or active blocking by at least one major safe-browsing / browser-protection provider (e.g. Google Safe Browsing or Microsoft SmartScreen). “Neutralized” does not mean the attacker’s files or phishing kit have been destroyed, that any server has been seized, or that the same content cannot be re-published on different infrastructure.
- “Excluded Infrastructure” — hosts, registrars, registries, or country-code TLDs that are known to be abuse-resistant or non-cooperative (“bulletproof”), as identified by Core Sentinel during pre-case reconnaissance.
3. The Service
The Service is a fixed-price, per-incident service in which Core Sentinel works to Neutralize a single reported Phishing Asset. This includes infrastructure reconnaissance, evidence collection, and the submission of abuse reports to the parties able to act on the Asset (see clause 9), followed by a period of monitoring (clause 7).
The Service is not a continuous brand-monitoring, managed-security, incident- response, or legal service, and does not include detection of new lookalike domains or future attacks (which is a separate product).
4. Eligibility and your authority
You may use the Service only in relation to a Phishing Asset that impersonates, or targets the customers, brand, or systems of, an organisation that you own or are authorised to represent. You warrant that:
- (a) you are the brand/domain owner or an authorised representative;
- (b) the information you provide is accurate and complete; and
- (c) your use of the Service is lawful and not intended to disrupt, suppress, or remove any legitimate website, competitor, or content.
Misuse of the Service to target legitimate content is a material breach and may result in immediate termination, refusal of refund (subject to clause 12 and your non-excludable rights), and referral to relevant authorities.
5. Pricing and tiers
The Service is offered as two flat, per-incident tiers, priced in US dollars:
- Single Takedown — US$499 — full takedown process, evidence report, live status, and 7 days of post-neutralization monitoring (clause 7).
- Takedown + Sentinel Watch — US$799 — as above, with monitoring extended to 30 days.
All prices are in US dollars and include any applicable taxes.
6. Order process and acceptance
- You submit an intake request and select a tier.
- Payment is authorised at checkout — a hold is placed on your card and you are not charged at this point (see clause 8).
- Core Sentinel reviews the request. We may decline or cancel any case at our discretion, including (without limitation) where the Asset involves Excluded Infrastructure, where it was already offline or Neutralized, where authority or information is insufficient, or where the request appears unlawful or abusive. If we decline your case, the hold on your card is released immediately — we do not wait for it to lapse, and no charge is made. In the rare event that your card had already been charged, you are refunded immediately instead.
- Case Approval occurs when we approve the case and begin work. Your card is charged at this point, the SLA clock starts, and a binding agreement for the Service forms.
- A case can only be declined before Case Approval. Once we have approved a case and taken payment, we do not subsequently reject it: from that point the only outcomes are a confirmed takedown or the SLA remedy in clause 12.
7. The SLA, success criterion, and monitoring
SLA. Core Sentinel will use commercially reasonable efforts to Neutralize the Phishing Asset within the SLA Period — 48 hours from Case Approval. Our reporting and monitoring run continuously, 24/7, and so does the SLA clock. It does not pause for weekends, public holidays, or nights. Forty-eight hours means forty-eight hours, whenever your case is approved.
Success criterion. The SLA is met if the Time to Takedown — the elapsed time from Case Approval to First Detected Downtime — is 48 hours or less, and that downtime is subsequently the subject of a Takedown Confirmation.
Two consequences of measuring it that way, both deliberate and both in your favour:
- Confirmation may arrive after the SLA Period without costing you the SLA. If the Asset goes dark at hour 47 and our monitoring confirms it at hour 53, the SLA is met: we measure to the moment it went down, not to the moment we became certain.
- A brief outage does not stop the clock. While the Asset is unreachable but not yet confirmed, the countdown shown in your dashboard holds still. If the Asset comes back, the countdown resumes as though it had never paused — no time is credited back.
A safe-browsing/browser block satisfies the SLA; we will nonetheless continue to pursue the more durable outcomes of content removal and/or domain suspension.
The SLA is assessed once. It is settled at the first Takedown Confirmation and is not reopened afterwards for any reason. See clause 10(d).
Included monitoring. Once Neutralized, we monitor that same Asset for 7 calendar days from the point of neutralization. If the same Asset becomes reachable again as a live phishing page within that window, we re-initiate reporting at no additional charge. This covers the same reported Asset only.
Extended monitoring (Sentinel Watch). The “Takedown + Sentinel Watch” tier extends same-Asset monitoring and free re-takedown to 30 calendar days from neutralization.
No guarantee of permanence. You acknowledge that a browser block or content removal may be reversed or bypassed, that domain suspension is the more durable outcome, and that any Asset may be re-published on new infrastructure.
8. Payment
- Payment is processed by Stripe. Core Sentinel does not store your full card details.
- Your card is authorised at checkout (a hold, not a charge) and is charged at Case Approval — the same moment the SLA clock starts.
- If we do not approve your case, the hold is released immediately. We do not leave an authorisation sitting on your card to lapse on its own.
- An authorisation may expire after a period set by your card issuer. If it expires before Case Approval, we charge the payment method you saved at checkout instead, at the same price.
- Refunds under clause 12 are issued automatically. You do not need to ask for one, and there is no claim form, deadline, or dispute process to go through first.
9. Reporting and disclosure (your authorisation)
To deliver the Service, you authorise Core Sentinel to act on your behalf in reporting the Phishing Asset, and to disclose the reported URL and associated evidence (such as screenshots and technical indicators) to the parties able to act on it. These may include: hosting providers; domain registrars and registries; content-delivery networks; regional internet registries; safe-browsing and browser-protection providers; anti-phishing and threat-intelligence services; and regional law-enforcement and cybercrime reporting bodies (the latter on an opt-in basis where you elect, or where we consider it appropriate). See the service Privacy Notice for detail on these disclosures and on international transfers.
You acknowledge that the effectiveness of the Service depends on third parties that are outside Core Sentinel’s control, and that we cannot guarantee any particular third party will act.
10. Exclusions from the SLA and refund guarantee
The SLA and refund guarantee in clause 12 do not apply where:
- (a) the case involves Excluded Infrastructure (notified to you before payment);
- (b) the Asset was already offline or Neutralized at the time of Case Approval;
- (c) delay or failure is caused by you (e.g. failure to provide requested verification, authorisation, or evidence, or where you are not the legitimate brand owner or authorised representative);
- (d) anything occurring after the first Takedown Confirmation for the case. Once we have confirmed the reported Asset was taken down, the SLA for that case is finished and cannot be re-opened. In particular, neither of the following is an SLA failure, and neither entitles you to a refund under clause 12:
- the same Asset being resurrected — coming back online at the same address (we re-report it at no charge under clause 7, but the SLA has already been assessed); or
- the attacker re-publishing the same or similar content on new infrastructure, including a new domain, host or URL. That is a new incident, and a new case;
- (e) a controlling registrar, host, or authority refuses to act despite properly evidenced reporting, for reasons outside our control; or
- (f) performance is prevented by events outside our reasonable control (force majeure, upstream outages, etc.).
11. Your obligations
You will: provide accurate and lawful information; respond promptly to reasonable requests for verification or authorisation; not use the Service for any unlawful, abusive, or anti-competitive purpose; and comply with all applicable laws.
12. Refunds and the money-back guarantee
The guarantee. If the Time to Takedown exceeds the SLA Period of 48 hours (and no exclusion in clause 10 applies), you are entitled to a full refund of the fee paid for that case. There is no deduction for payment-processing fees.
It is automatic, and it is not conditional on you noticing. At the Refund Trigger Time — 24 hours after the SLA Period ends, so 72 hours after Case Approval — our systems refund the fee to the original payment method without any action by you. You do not have to claim it, ask for it, or meet a deadline. We email you when it happens. The 24-hour interval exists so that a takedown which is very nearly complete can still land, and so an analyst can review any clause-10 exclusion, before the refund becomes irreversible; it is not an extension of the 48-hour promise, which is already broken at hour 48.
Where a takedown is confirmed after the SLA Period has expired, the refund is issued as soon as that confirmation is recorded, rather than waiting for the Refund Trigger Time. Delivering late is still delivering late.
We keep working your case. A refund under this clause is not a cancellation of the Service. Reporting continues, and the monitoring window in clause 7 runs in full — at no charge to you. You keep everything you paid for and you keep your money.
Refunds are issued to the original payment method and typically appear on a statement within 5–10 business days, depending on your bank.
This money-back guarantee is offered in addition to any rights and remedies you have under applicable consumer law. Nothing in these Terms excludes, restricts, or modifies any consumer guarantee, right, or remedy that cannot lawfully be excluded under the Australian Consumer Law (ACL) or other applicable mandatory law. Where our liability for failing to comply with a non-excludable guarantee can be limited, it is limited to resupplying the Service or refunding the fee paid for the affected case.
13. Intellectual property
Any evidence report, recon output, or other materials we provide for your case are provided for your internal use in addressing the reported incident. Core Sentinel retains ownership of its methods, tooling, and templates.
14. Limitation of liability
Subject to clause 12 and any non-excludable rights: to the maximum extent permitted by law, Core Sentinel is not liable for any indirect, incidental, special, or consequential loss, or for loss of profit, revenue, data, or goodwill, arising from or in connection with the Service; and Core Sentinel’s total aggregate liability in connection with a case is limited to the fee paid for that case. The Service addresses a single reported Asset and does not protect against, and we are not liable for, other or future phishing, fraud, or security incidents.
15. Indemnity
You indemnify Core Sentinel against claims, losses, and costs arising from: your breach of clause 4 or 11; your provision of inaccurate information; or your use of the Service in relation to content you were not authorised to report.
16. Confidentiality
Each party will keep the other’s non-public information confidential and use it only to perform or receive the Service, except as required to deliver the Service (clause 9) or by law.
17. Term, suspension, and termination
These Terms apply from intake until the case is closed (including any monitoring window). We may suspend or terminate the Service for breach of these Terms, suspected unlawful or abusive use, or non-payment.
18. Governing law
These Terms are governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of its courts. If you are a consumer in another jurisdiction, you may have additional mandatory rights under your local law that these Terms do not override.
19. Changes to these Terms
We may update these Terms from time to time. The version in force at the time of your Case Approval governs that case.
20. Contact
Questions about these Terms or a case: contact us or phishing@coresentinel.com.