Terms of service for CyVigilant.
These terms govern the delivery of security-assessment services by CyVigilant Technologies Private Limited under the CyVigilant brand. Please read them carefully before engaging our services.
Last updated · May 2026
Acceptance of Terms
By requesting, accepting, or using any security-assessment services provided by CyVigilant Technologies Private Limited ("CyVigilant", "CyVigilant") — including VAPT, penetration testing, CERT-In security audits, red team assessments, secure code review, and security architecture review — you ("Client") agree to be bound by these Terms of Service ("Terms"). If you are acting on behalf of a company or organization, you represent that you have authority to bind that entity. If you do not agree, do not engage our services.
Services
CyVigilant provides expert-led security-assessment services as defined in a mutually agreed Statement of Work ("SOW") or Proposal. Services are delivered within the scope, timeline, and rules of engagement documented in the SOW. Any work outside the agreed scope requires a written change order signed by both parties.
Authorization and Rules of Engagement
Before any assessment begins, the Client must provide written authorization confirming: (a) ownership or explicit permission to test all in-scope systems; (b) that testing is permitted under agreements with any hosting providers, cloud platforms, or third parties; (c) that relevant internal stakeholders have been notified. CyVigilant will not commence testing without a signed rules-of-engagement document. CyVigilant is not liable for consequences arising from an improperly authorized or over-scoped engagement.
Confidentiality
Both parties agree to treat the other party's confidential information — including engagement findings, vulnerability details, source code, architecture diagrams, and business information — with at least the same care used for their own confidential data. Confidentiality obligations survive termination of these Terms for five years. CyVigilant will not disclose findings to third parties without the Client's prior written consent, except as required by law or by the CERT-In audit process delivered through our empanelled partners.
Deliverables and Intellectual Property
Upon payment of all fees, the Client owns the engagement deliverables: the technical findings report, executive summary, proof-of-concept evidence, and (where applicable) the CERT-In Safe-to-Host certificate delivered through our empanelled partner. CyVigilant retains ownership of its methodologies, testing tools, templates, and proprietary processes used to produce deliverables. The Client is granted a perpetual, non-exclusive licence to use deliverables for internal security and compliance purposes.
Payment and Fees
Fees are specified in the SOW or Proposal and are payable as set out therein. Unless otherwise agreed, a 50% upfront deposit is required before engagement commencement, with the balance due on delivery of the final report. Overdue invoices accrue interest at 1.5% per month. Expenses incurred for on-site testing (travel, accommodation) are billed at cost with prior approval.
Warranties and Disclaimers
CyVigilant warrants that services will be performed in a professional manner consistent with industry standards. CyVigilant does not warrant that an assessment will identify every vulnerability in the tested systems, or that successful completion will guarantee regulatory compliance or prevent future security incidents. Security assessments are point-in-time evaluations; new vulnerabilities may emerge after an engagement closes.
Limitation of Liability
CyVigilant's total aggregate liability arising from or related to these Terms shall not exceed the fees paid by the Client for the specific engagement giving rise to the claim. In no event shall either party be liable for indirect, incidental, special, consequential, or punitive damages including lost data, lost revenue, or business interruption, regardless of the theory of liability, even if advised of the possibility of such damages. These limitations do not exclude liability for fraud, wilful misconduct, or death or personal injury caused by negligence.
Indemnification
The Client agrees to indemnify and hold harmless CyVigilant, its officers, employees, and contractors from claims, damages, fines, or expenses arising from: (a) unauthorized or improperly scoped testing due to Client misrepresentation of authorization; (b) Client's violation of applicable laws; (c) third-party claims related to data or systems the Client provided for testing without proper authority.
Term and Termination
These Terms remain in effect for the duration of the engagement SOW. Either party may terminate for material breach with 14 days written notice if the breach is not cured. Upon termination, the Client shall pay for all services delivered up to the termination date. Obligations of confidentiality, intellectual property, limitation of liability, and indemnification survive termination.
Governing Law
These Terms are governed by the laws of India. Disputes shall first be attempted to be resolved through good-faith negotiation. If unresolved within 30 days, disputes shall be referred to binding arbitration under the Indian Arbitration and Conciliation Act, 1996, with the seat of arbitration in New Delhi. Either party may seek injunctive relief from a court of competent jurisdiction.
General
These Terms, together with the applicable SOW or Proposal, constitute the entire agreement between the parties. In the event of a conflict, the SOW prevails. If any provision is found unenforceable, the remainder continues in full force. CyVigilant may update these Terms; continued use of services after notice of material changes constitutes acceptance.
Contact
For questions about these Terms, contact: CyVigilant Technologies Private Limited, Legal Team, legal@cyvigilant.com. For security concerns: security@cyvigilant.com.
