LUMIFINE

Legal

Security Testing Terms

Last updated 20 September 2026

In short

1. What these terms cover

These terms apply to all our security work: penetration testing of web apps, APIs, mobile apps and networks, cloud and code reviews, monthly scans, phishing drills, malware cleanup, compliance readiness and security consultations. They add to the Terms & Conditions. Where the two differ on security work, these terms apply.

2. Written authorisation comes first

Accessing a computer system without the owner's permission is an offence under India's Information Technology Act, 2000. So before any testing starts, we need a written authorisation, signed or sent from an official account by someone entitled to give it, confirming that:

We may ask for proof of ownership or control. We refuse any request to test systems that aren't yours to authorise.

3. The agreed scope

Every engagement has a written scope that lists:

Anything not listed is out of scope and won't be tested. If we come across something out of scope that looks exposed, we'll tell you, but we won't test it without a new authorisation.

4. How we test

5. What we need from you

6. Reports and retests

You receive a written report of what we found, how serious each issue is, how we confirmed it, and how to fix it. Where the scope includes a retest, we check your fixes once and update the report. Further retests are quoted separately.

7. Confidentiality

Everything about your security work is confidential: the scope, findings, reports, credentials and evidence. We share it only with the contacts you name. We never publish it or use it in our portfolio or ads, and we never mention you as a security client without your written permission. If we find a weakness in third-party software, we disclose it to the vendor only with your agreement, and without identifying you.

8. Data we see during testing

Testing can expose personal or business data. We access only what's needed to prove a finding, and we don't copy data beyond that. All test data and evidence are deleted 30 days after the final report or retest. We keep the report itself confidentially for our records.

9. Signs of a real attack

If we see evidence that your systems have already been compromised, we stop the related testing and tell you immediately. You remain responsible for your own legal reporting duties. These may include reporting cyber incidents to CERT-In and notifying data breaches under the Digital Personal Data Protection Act. We'll help you with the facts we found.

10. Limits of testing

A test checks your systems as they were during the testing window, using the methods in scope. It reduces risk but can't find every weakness, and new ones appear as systems change. Despite our care, testing can occasionally cause slowdowns or errors. By authorising testing within the agreed scope, you accept that risk. Our liability is limited as set out in section 17 of the Terms & Conditions.

11. Compliance readiness

Our compliance readiness work, such as a gap assessment and policies for ISO 27001, SOC 2 or the Digital Personal Data Protection Act, prepares you for an audit. It isn't a certification or a legal opinion. Certification comes from an accredited auditor, which is a separate engagement.

12. Contact

WhatsApp +91 91236 12207. For anything urgent during a test, use the emergency contacts agreed in your scope.