~/legal/termsLegal

Terms

How an engagement is contracted, what the commercial terms are, what an assessment covers, and what we do not issue. Written in plain language. The binding version is the signed agreement.

Draft, not yet reviewed by a lawyer. This page is a plain-language summary of how we work. It is not legal advice and it is not the binding agreement. A qualified lawyer must review and finalise it, together with the master services agreement, statement of work, authorization letter, non-disclosure agreement and rules of engagement templates. Where this page and a signed agreement differ, the signed agreement governs.

Website

This website

Everything here is provided for information. The site does not publish prices, and nothing on it is an offer or a binding commitment. Scope and price are agreed in a signed statement of work.

Contracting

How an engagement is contracted

The paperwork differs by engagement type. Offensive testing needs written authorization before it starts; compliance work needs access and evidence instead.

Non-disclosure agreementBoth
Signed before any detailed scope discussion, if you want one. Ask and we send it first.
Master services agreementBoth
The overarching terms: confidentiality, liability, intellectual property, data handling and payment.
Statement of workBoth
One per engagement. Scope, exclusions, dates, deliverables, commercial terms and anything agreed on the scoping call.
Authorization letterOffensive
Confirms that testing of every asset in scope is authorized by someone able to authorize it. Testing does not begin until it is in place.
Rules of engagementOffensive
Testing window, escalation contacts, out-of-scope assets, and what happens if something behaves unexpectedly.
Evidence and accessCompliance
Named contacts, read access to the systems in scope, and the policies, records and evidence the framework calls for.
Commercial

Quotation and payment

Indicative. The statement of work is the source for the commercial terms that actually apply to your engagement.

Quotation validity
A quotation is valid for 30 days from the date of issue. After that, pricing and scope may be reviewed against the current requirements.
First engagement
50% at kickoff and 50% on delivery of the final report, unless the statement of work says otherwise.
Ongoing engagements
Invoicing and payment terms can be agreed to suit how you work, and are set out in the statement of work.
The statement of work governs
Where anything on this page differs from a signed statement of work, the statement of work applies.
Working terms

How we work with you

These apply to offensive and compliance engagements alike, and are set out properly in the master services agreement.

Authorization to test
We test only assets you own or are authorized to have tested. Written authorization covering everything in scope is in place before testing begins.
Unauthorized assets
If an asset turns out not to have been authorized by its owner, responsibility for any resulting claim is allocated as set out in the signed agreement, and as applicable law permits.
Non-destructive by default
Engagements are planned to minimise disruption and testing is non-destructive by default. Some activity on live systems still carries operational risk, so anything higher-risk is identified and agreed in writing before it runs.
Information and access
Coverage depends in part on the accuracy and completeness of the information, access and documentation provided. Where something material is unavailable or unreachable, we record the limitation in the report rather than leaving it implied.
Liability
The signed agreement sets the limits on liability, normally by reference to the fees paid for the relevant engagement, and addresses indirect and consequential loss. Those terms apply as written and as applicable law permits.
Confidentiality
Mutual. Your systems, findings, documents and information are confidential to you. Our methodologies, tooling, templates and internal materials are confidential to us.
Deliverables and intellectual property
You receive the agreed rights to the final deliverables and may share the report with your customers, auditors, regulators and insurers on the terms in the agreement. Our pre-existing intellectual property, including methodologies, tooling and templates, remains ours. Extracts should not be presented in a way that changes their meaning.
Use as a reference
We describe an engagement publicly, including anonymously, only where you have agreed to it in the statement of work or in writing separately. The default is that we say nothing.
Evidence handling
Findings, credentials and captured data are treated as confidential, encrypted where appropriate, and accessible only to the people working on your engagement. Retention and destruction follow the schedule in the agreement.
Subcontractors
Work is performed by our own team. Where a subcontractor is involved, they are disclosed and approved as the agreement requires and are bound by equivalent confidentiality and security obligations.
Scheduling
Testing windows are booked and staffed in advance. Rescheduling and cancellation are handled on the terms set out in the statement of work.
Independence
We do not present remediation work we carried out as independent assurance. Where we have built or fixed something, the report discloses that relationship.
Governing law
We operate from India and propose Indian law and jurisdiction in our agreements. The governing law and forum for your engagement are those stated in the signed agreement.
Scope of an assessment

What an assessment covers

Worth stating clearly, because it shapes what the report can and cannot tell you. This applies to offensive and compliance work alike.

Point in time
An assessment describes what we found, in the agreed scope, during the agreed window.
Not exhaustive
No assessment covers everything. Time, scope, access and available information bound what can be reached, and anything outside the agreed scope is untested.
Not a guarantee
A clean report is not a guarantee that a system is secure or cannot be compromised. No assessment can provide that, and we would be cautious of any firm offering one.
Changes after testing
Changes to code, configuration, infrastructure or dependencies after the window can introduce issues the report could not have covered. A retest re-checks the findings listed in it.
Remediation
We set out what to fix and how. Designing, implementing and deploying the fix sits with your team, and we are glad to review the approach.
Not legal or compliance advice
Our reports are technical. Whether you meet a legal, regulatory or contractual obligation is determined by you, your advisers and your assessor.
Third-party limits
Where a cloud provider, WAF, upstream host or other third party restricts testing, coverage is limited accordingly and we record it in the report.
Certification

What we issue, and what we do not

We are not a certification body, and we do not present ourselves as authorized to issue certifications, attestations or independent opinions that a framework reserves for a separately qualified or accredited organisation.

What we provide is technical security testing, gap assessment, readiness assessment and remediation guidance, documented so that the organisation carrying out your formal assessment can work from it.

We do issue our own letter of attestation at the end of an engagement, after the retest. It records what was tested, when, what was found and what has been remediated, and it is yours to share. It is a statement about the engagement we performed. It is not a certification against any framework and does not substitute for one.

Where a framework requires formal certification, attestation or an independent opinion, that comes from the organisation qualified or accredited to provide it under that framework. A readiness assessment from us is preparation for that process. It is not the certification or attestation itself, and we do not describe it as one.

Questions about any of this before you sign anything? Write to [email protected] and we will answer them directly.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.