Legal
Security Testing Terms
Last updated 20 September 2026
In short
- We never test anything without written authorisation from its owner.
- We test only what the agreed scope lists, in the agreed window, and nothing else.
- If we find something critical or see signs of a real attack, we tell you straight away.
- Findings are confidential and never appear in our portfolio.
- Data we see during testing is deleted 30 days after the final report or retest.
- A test shows the state of your systems at one point in time. It can't find every weakness.
1. What these terms cover
These terms apply to all our security work: penetration testing of web apps, APIs, mobile apps and networks, cloud and code reviews, monthly scans, phishing drills, malware cleanup, compliance readiness and security consultations. They add to the Terms & Conditions. Where the two differ on security work, these terms apply.
2. Written authorisation comes first
Accessing a computer system without the owner's permission is an offence under India's Information Technology Act, 2000. So before any testing starts, we need a written authorisation, signed or sent from an official account by someone entitled to give it, confirming that:
- you own the systems in scope, or have the right to authorise testing of them;
- you have any permission a third party requires, such as a hosting provider, cloud platform, app store or software vendor whose rules call for notice or approval;
- you accept the scope, testing window and methods described in the quote.
We may ask for proof of ownership or control. We refuse any request to test systems that aren't yours to authorise.
3. The agreed scope
Every engagement has a written scope that lists:
- the targets: domains, IP ranges, apps, APIs, accounts or staff groups;
- the testing window;
- the methods that are in and out of scope;
- anything we must not touch;
- who we report to, and an emergency contact on your side.
Anything not listed is out of scope and won't be tested. If we come across something out of scope that looks exposed, we'll tell you, but we won't test it without a new authorisation.
4. How we test
- We don't run denial-of-service or load attacks, and we don't deliberately delete or corrupt data, unless the scope expressly includes it.
- We use the least access needed to show that a weakness is real, and we don't take more data than that requires.
- If testing seems to be affecting a system's stability, we pause and contact you.
- Critical findings are reported to your named contact straight away, without waiting for the report.
- Phishing drills run only with written approval from your management. Drill pages record that a click or submission happened. They don't store real passwords.
- Test accounts and anything we install for testing are removed or listed for you to remove when testing ends.
5. What we need from you
- A current backup of anything in scope before testing starts.
- Letting your IT team, security monitoring and hosting provider know about the test, and adding our testing addresses to allow-lists if the scope requires it.
- Test accounts and access as agreed, and a stable environment during the window.
- A contact who can respond during the testing window.
6. Reports and retests
You receive a written report of what we found, how serious each issue is, how we confirmed it, and how to fix it. Where the scope includes a retest, we check your fixes once and update the report. Further retests are quoted separately.
7. Confidentiality
Everything about your security work is confidential: the scope, findings, reports, credentials and evidence. We share it only with the contacts you name. We never publish it or use it in our portfolio or ads, and we never mention you as a security client without your written permission. If we find a weakness in third-party software, we disclose it to the vendor only with your agreement, and without identifying you.
8. Data we see during testing
Testing can expose personal or business data. We access only what's needed to prove a finding, and we don't copy data beyond that. All test data and evidence are deleted 30 days after the final report or retest. We keep the report itself confidentially for our records.
9. Signs of a real attack
If we see evidence that your systems have already been compromised, we stop the related testing and tell you immediately. You remain responsible for your own legal reporting duties. These may include reporting cyber incidents to CERT-In and notifying data breaches under the Digital Personal Data Protection Act. We'll help you with the facts we found.
10. Limits of testing
A test checks your systems as they were during the testing window, using the methods in scope. It reduces risk but can't find every weakness, and new ones appear as systems change. Despite our care, testing can occasionally cause slowdowns or errors. By authorising testing within the agreed scope, you accept that risk. Our liability is limited as set out in section 17 of the Terms & Conditions.
11. Compliance readiness
Our compliance readiness work, such as a gap assessment and policies for ISO 27001, SOC 2 or the Digital Personal Data Protection Act, prepares you for an audit. It isn't a certification or a legal opinion. Certification comes from an accredited auditor, which is a separate engagement.
12. Contact
WhatsApp +91 91236 12207. For anything urgent during a test, use the emergency contacts agreed in your scope.