Terms
How an engagement is contracted, what the commercial terms are, what an assessment covers, and what we do not issue. Written in plain language. The binding version is the signed agreement.
Draft, not yet reviewed by a lawyer. This page is a plain-language summary of how we work. It is not legal advice and it is not the binding agreement. A qualified lawyer must review and finalise it, together with the master services agreement, statement of work, authorization letter, non-disclosure agreement and rules of engagement templates. Where this page and a signed agreement differ, the signed agreement governs.
This website
Everything here is provided for information. The site does not publish prices, and nothing on it is an offer or a binding commitment. Scope and price are agreed in a signed statement of work.
How an engagement is contracted
The paperwork differs by engagement type. Offensive testing needs written authorization before it starts; compliance work needs access and evidence instead.
- Non-disclosure agreementBoth
- Signed before any detailed scope discussion, if you want one. Ask and we send it first.
- Master services agreementBoth
- The overarching terms: confidentiality, liability, intellectual property, data handling and payment.
- Statement of workBoth
- One per engagement. Scope, exclusions, dates, deliverables, commercial terms and anything agreed on the scoping call.
- Authorization letterOffensive
- Confirms that testing of every asset in scope is authorized by someone able to authorize it. Testing does not begin until it is in place.
- Rules of engagementOffensive
- Testing window, escalation contacts, out-of-scope assets, and what happens if something behaves unexpectedly.
- Evidence and accessCompliance
- Named contacts, read access to the systems in scope, and the policies, records and evidence the framework calls for.
Quotation and payment
Indicative. The statement of work is the source for the commercial terms that actually apply to your engagement.
- Quotation validity
- A quotation is valid for 30 days from the date of issue. After that, pricing and scope may be reviewed against the current requirements.
- First engagement
- 50% at kickoff and 50% on delivery of the final report, unless the statement of work says otherwise.
- Ongoing engagements
- Invoicing and payment terms can be agreed to suit how you work, and are set out in the statement of work.
- The statement of work governs
- Where anything on this page differs from a signed statement of work, the statement of work applies.
How we work with you
These apply to offensive and compliance engagements alike, and are set out properly in the master services agreement.
- Authorization to test
- We test only assets you own or are authorized to have tested. Written authorization covering everything in scope is in place before testing begins.
- Unauthorized assets
- If an asset turns out not to have been authorized by its owner, responsibility for any resulting claim is allocated as set out in the signed agreement, and as applicable law permits.
- Non-destructive by default
- Engagements are planned to minimise disruption and testing is non-destructive by default. Some activity on live systems still carries operational risk, so anything higher-risk is identified and agreed in writing before it runs.
- Information and access
- Coverage depends in part on the accuracy and completeness of the information, access and documentation provided. Where something material is unavailable or unreachable, we record the limitation in the report rather than leaving it implied.
- Liability
- The signed agreement sets the limits on liability, normally by reference to the fees paid for the relevant engagement, and addresses indirect and consequential loss. Those terms apply as written and as applicable law permits.
- Confidentiality
- Mutual. Your systems, findings, documents and information are confidential to you. Our methodologies, tooling, templates and internal materials are confidential to us.
- Deliverables and intellectual property
- You receive the agreed rights to the final deliverables and may share the report with your customers, auditors, regulators and insurers on the terms in the agreement. Our pre-existing intellectual property, including methodologies, tooling and templates, remains ours. Extracts should not be presented in a way that changes their meaning.
- Use as a reference
- We describe an engagement publicly, including anonymously, only where you have agreed to it in the statement of work or in writing separately. The default is that we say nothing.
- Evidence handling
- Findings, credentials and captured data are treated as confidential, encrypted where appropriate, and accessible only to the people working on your engagement. Retention and destruction follow the schedule in the agreement.
- Subcontractors
- Work is performed by our own team. Where a subcontractor is involved, they are disclosed and approved as the agreement requires and are bound by equivalent confidentiality and security obligations.
- Scheduling
- Testing windows are booked and staffed in advance. Rescheduling and cancellation are handled on the terms set out in the statement of work.
- Independence
- We do not present remediation work we carried out as independent assurance. Where we have built or fixed something, the report discloses that relationship.
- Governing law
- We operate from India and propose Indian law and jurisdiction in our agreements. The governing law and forum for your engagement are those stated in the signed agreement.
What an assessment covers
Worth stating clearly, because it shapes what the report can and cannot tell you. This applies to offensive and compliance work alike.
- Point in time
- An assessment describes what we found, in the agreed scope, during the agreed window.
- Not exhaustive
- No assessment covers everything. Time, scope, access and available information bound what can be reached, and anything outside the agreed scope is untested.
- Not a guarantee
- A clean report is not a guarantee that a system is secure or cannot be compromised. No assessment can provide that, and we would be cautious of any firm offering one.
- Changes after testing
- Changes to code, configuration, infrastructure or dependencies after the window can introduce issues the report could not have covered. A retest re-checks the findings listed in it.
- Remediation
- We set out what to fix and how. Designing, implementing and deploying the fix sits with your team, and we are glad to review the approach.
- Not legal or compliance advice
- Our reports are technical. Whether you meet a legal, regulatory or contractual obligation is determined by you, your advisers and your assessor.
- Third-party limits
- Where a cloud provider, WAF, upstream host or other third party restricts testing, coverage is limited accordingly and we record it in the report.
What we issue, and what we do not
We are not a certification body, and we do not present ourselves as authorized to issue certifications, attestations or independent opinions that a framework reserves for a separately qualified or accredited organisation.
What we provide is technical security testing, gap assessment, readiness assessment and remediation guidance, documented so that the organisation carrying out your formal assessment can work from it.
We do issue our own letter of attestation at the end of an engagement, after the retest. It records what was tested, when, what was found and what has been remediated, and it is yours to share. It is a statement about the engagement we performed. It is not a certification against any framework and does not substitute for one.
Where a framework requires formal certification, attestation or an independent opinion, that comes from the organisation qualified or accredited to provide it under that framework. A readiness assessment from us is preparation for that process. It is not the certification or attestation itself, and we do not describe it as one.
Questions about any of this before you sign anything? Write to [email protected] and we will answer them directly.