Terms of Service

Last updated: June 11, 2026

Acceptance of Terms

By accessing and using the Cybersecify Consulting (OPC) Private Limited ("Cybersecify", "we", "us", or "our") website (cybersecify.com) and our services, you agree to be bound by these Terms of Service. If you do not agree to these terms, please do not use our website or services.

Services

Cybersecify provides penetration testing and compliance readiness services. All services are provided under separate engagement agreements that define the scope, timeline, deliverables, and terms specific to each project.

Service Delivery Terms

The following terms apply to standard service engagements unless otherwise specified in a signed engagement agreement:

  • Penetration test engagements (testing and final report) complete within 5 business days per scope from kick-off. Business days are Monday to Friday; the weekend is a quality buffer and is not counted.
  • Retests are included at no additional cost if requested within one month of the initial (v1.0) report delivery date.
  • All prices displayed on the website are in Indian Rupees (INR) and exclude applicable taxes (GST or other duties). Tax will be added at the time of invoicing as required by law.

Payment Terms

Unless otherwise specified in a signed engagement agreement, the following payment terms apply:

  • Penetration Testing (Startup & Growth plans): 50% of the engagement fee is due before testing begins. The remaining 50% is due upon delivery of the final report. Payment is accepted via bank transfer (NEFT/RTGS).
  • Audit & Compliance (one-time engagements): 50% of the engagement fee is due before work begins. The remaining 50% is due upon delivery. Payment is accepted via bank transfer (NEFT/RTGS).

OpenEASD

OpenEASD is offered as two distinct products that share a brand: a self-hosted open source tool and a hosted scan service we run on your behalf. Terms differ for each and are listed separately below.

OpenEASD Self-Hosted (Open Source)

The self-hosted version of OpenEASD is distributed by Cybersecify under the MIT License at github.com/cybersecify/OpenEASD. Users clone the repository and run OpenEASD themselves on their own infrastructure. Cybersecify does not receive scan data, does not store findings, and does not provide commercial support for self-hosted use. By downloading, installing, or running OpenEASD yourself, you agree to the following:

  • Use against authorised targets only. You represent and warrant that you will use OpenEASD only against domains and infrastructure that you own or have explicit written authorisation to scan. Using OpenEASD against any other target is prohibited and may constitute unauthorised computer access under applicable laws.
  • No warranty. OpenEASD is provided "as is" without warranty of any kind. Cybersecify makes no guarantee that the tool will detect all vulnerabilities, will produce accurate findings, or will be free of defects. The MIT License terms in the repository govern all warranty and liability.
  • No liability for findings or actions. Cybersecify is not liable for any findings produced by OpenEASD, any actions you or any third party take (or fail to take) based on those findings, or any consequence arising from your use of the tool. All risk of use rests with you.
  • External, non-intrusive reconnaissance only. OpenEASD is designed to perform external, non-intrusive reconnaissance using publicly observable configuration. It is not a substitute for a penetration test or a full security assessment.
  • No substitute for professional advice. Findings reflect publicly observable configuration at the time of scanning and may not capture all risks. For a qualified review of findings or a full security assessment, engage a certified security professional.
  • Community support model. Support for self-hosted OpenEASD is provided on a best-effort basis through the public GitHub repository (issues and pull requests). Cybersecify does not provide direct commercial support for self-hosted use.

OpenEASD Hosted Scan Service

Cybersecify operates a free hosted version of OpenEASD at cybersecify.com/openeasd/. You submit a domain through the form on that page; we run an external attack surface scan against the submitted domain on our infrastructure and email the report to the address you provide. By submitting a domain for a hosted scan, you agree to the following:

  • What you can request is the monthly scan. The scan you sign up for on our website is the recurring monthly scan described below. It includes active testing and therefore requires your authorisation, verified by email from your domain.
  • Passive collection needs no authorisation, and we may perform it separately. Passive collection reads only information already publicly available about a domain: DNS records, certificate transparency logs, published registrations and similar. It does not connect to, probe, or otherwise touch your systems. Because it involves only public data, it requires no permission, and we may carry it out independently of any request from you, including to prepare information we share with you.
  • Authorisation required for active testing. You represent and warrant that you own the submitted domain, or hold explicit written authorisation from the domain owner to request a scan. We will not run scans where authorisation is unclear. Submitting a domain you are not authorised to scan is prohibited and may constitute unauthorised computer access under applicable laws.
  • Data handling. The information you submit (name, work email, domain, optional role and company) is used to deliver the scan report and follow up with you about your results. We do not sell submission data to third parties. We may retain submissions and the resulting reports for our internal records and to inform future product improvements. You can request deletion of your submission by emailing contact@cybersecify.com.
  • Scope. The recurring monthly scan you sign up for includes active testing, described in the monthly section below. Separately, passive collection uses only publicly observable configuration of the submitted domain. Neither authenticates to your systems, exploits a finding, nor performs any intrusive action against the target. It is not a substitute for a penetration test or a full security assessment.
  • Human-reviewed, best-effort delivery. Findings are reviewed by a member of the Cybersecify team before a report is delivered; where a finding appears material we validate it before raising it with you. We target 48 business hours from submission to report delivery but do not guarantee a specific turnaround. We reserve the right to decline, delay, or cancel a scan request without explanation.
  • No warranty on findings. Hosted scan findings are provided "as is." We make no guarantee that the scan will detect all vulnerabilities, will produce accurate findings, or will be free of defects. Cybersecify is not liable for any findings, for any action you or any third party take based on the report, or for any consequence arising from your use of the report.
  • No substitute for professional advice. Findings reflect publicly observable configuration at the time of scanning and may not capture all risks. For a qualified review of findings or a full security assessment, engage a certified security professional or one of our paid services.
  • Free of charge with no obligation. The hosted scan is free. Receiving a report does not create a contractual relationship and does not obligate you to purchase any paid service from Cybersecify.

OpenEASD Monthly Continuous Scan (Optional, Free)

The scan you request is recurring: your first report is delivered within 2 business days of sign-up, and thereafter we scan and report monthly, at no charge. The monthly cadence is a target, not a service level, and no specific delivery date is guaranteed for a free service. This is a separate permission from the single scan above and is never enabled by default.

  • Standing authorisation. By opting in you represent and warrant that your authorisation to have the domain scanned is ongoing, and that you will withdraw it if it ceases to be true. Authorisation for a single scan does not by itself authorise recurring scans.
  • Revocable at any time, and revocation stops the scanning. You may withdraw authorisation at any time, for any reason, with no notice period. Withdrawal ends the scheduled scans themselves, not merely the emails. Every monthly report carries a way to stop, and you may email openeasd@cybersecify.com at any time.
  • ๐Ÿ”ด Broader technical scope than the single scan. The monthly scan performs active and passive assessment. It is not limited to the external, non-intrusive reconnaissance that applies to the one-off hosted scan, and active testing can in principle affect the availability or behaviour of the systems tested. This is why the authorisation for it is verified separately and more strictly, below.
  • The request must come from the domain being scanned. The work email you submit must be at the domain you are asking us to scan. A request naming a domain you have no relationship with is rejected at submission. If you need a scan of a domain you manage on behalf of someone else, contact us and we will arrange it with the domain owner.
  • Authorisation is verified at the domain itself, not from a form, and nothing is scheduled by submitting one. Submitting the request form does not start a scan. The work email you submit must be at the domain being scanned; we email a single-use code to that address and you enter it to complete the request. This serves two purposes: it establishes authorisation to carry out active testing, and it ensures a report describing a domain's external exposure is only ever delivered to someone who controls that domain. A checkbox on a web form does not establish who ticked it; a code received at the domain establishes control of a mailbox there. A member of our team then reviews the request before any scan is set up. No monthly scan is scheduled until both have happened.
  • Findings may appear because our checks changed. Our tooling is developed continuously. A finding appearing for the first time may reflect a new check on our side rather than a change on yours. Reports distinguish the two.
  • Point-in-time, no monitoring guarantee. A monthly cadence is not continuous monitoring and is not an alerting service. Nothing here creates an obligation to detect, or to notify you of, any particular issue, and no service level applies to a free service.
  • No warranty and no liability, unchanged. The disclaimers applying to the hosted scan apply equally and in full to monthly scans and their reports.
  • We may end it. Cybersecify may change or discontinue the free monthly scan at any time, and may decline or stop scanning any domain at its discretion.

Website Content Disclaimer

The content on this website, including blog posts, articles, guides, pricing information, comparison tables, and technical descriptions, is provided for informational purposes only and does not constitute professional security advice, legal advice, or a guarantee of any outcome. While we make reasonable efforts to ensure accuracy, we do not warrant that all content is complete, current, or error-free.

Blog posts and articles may contain general security guidance that may not be applicable to your specific environment, technology stack, or regulatory requirements. You should not rely solely on website content to make security decisions. Always consult with a qualified professional for advice tailored to your situation.

Pricing information displayed on the website represents entry-level pricing and is subject to change. Final engagement pricing is determined based on scope, complexity, and requirements discussed during consultation.

If you spot an error, inaccuracy, or outdated reference on our website or in our content, please email errors@cybersecify.com. We aim to review and correct reported errors on a best-effort basis. We do not, however, guarantee continuous monitoring of all third-party references or that all corrections will be made.

Publishing a correction, an update, or a dated corrections note is a matter of editorial practice. It is not an admission of fault, negligence, or liability, and it is not a waiver of any term of these Terms. Where content on this website is found to be inaccurate or out of date, correcting or removing that content is the remedy we offer in respect of it. Nothing in this section extends the Limitation of Liability set out below.

Website Content Changes

Website content, including pricing, service descriptions, marketing claims, blog posts, and tool documentation, may change without notice as our offerings evolve. We do not maintain a public archive of prior versions. Final terms for any engagement are those captured in the signed engagement agreement or proposal between Cybersecify and the client. Where website content and a signed agreement conflict, the signed agreement governs. Screenshots, archived copies (including third-party archives such as the Internet Archive), or earlier versions of our website do not modify the terms of any engagement.

Use of Automated Tools

Cybersecify uses automated tools, proprietary scripts, and industry-standard scanning utilities as part of our security assessment methodology. These tools assist with reconnaissance, vulnerability discovery, and data analysis. All findings are manually verified, validated, and documented by our certified security professionals before inclusion in any client deliverable.

Website content, including blog articles and guides, may be assisted by automated tools and is reviewed and edited by our team before publication.

Sample Report Disclaimer

The sample penetration test report available on our website (at /sample-report) is provided for illustrative purposes only. It uses entirely fictional data, including fabricated company names, domains, IP addresses, and vulnerability findings. Any resemblance to real organizations or systems is coincidental.

Actual report content, structure, depth, and findings will vary based on the specific engagement scope, target environment, testing methodology, and vulnerabilities discovered during the assessment. The sample report should not be used as a benchmark for the volume or severity of findings in any real engagement.

No Guarantee of Security

Penetration testing and security assessments are best-effort, point-in-time evaluations based on the scope, access, and information available during the engagement period. A completed penetration test or security assessment does not guarantee that your systems are free from all vulnerabilities, nor does it guarantee that your systems will not be breached in the future.

Security is an ongoing process. New vulnerabilities, attack techniques, and threat actors emerge continuously. Our assessments reflect the state of your systems at the time of testing and cannot account for changes made after the engagement, zero-day vulnerabilities, or threats outside the defined scope.

Cybersecify shall not be held liable for any security incident, data breach, or loss that occurs after or outside the scope of our engagement.

Scope of Testing

All penetration testing activities are performed only on systems explicitly authorized by the client within a signed scope agreement. We do not test systems without proper written authorization. Clients are responsible for ensuring they have the legal right to authorize testing on the specified systems.

Penetration testing engagements include standard reconnaissance against the authorized scope, using only publicly accessible sources that do not access private systems or data outside the agreed scope.

Confidentiality

We treat all client information, including vulnerability findings and assessment reports, as strictly confidential. We will not disclose any information to third parties without your explicit written consent, except as required by law.

Limitation of Liability

While we exercise professional care in performing our services, penetration testing inherently involves testing security controls and may occasionally cause disruptions. To the maximum extent permitted by applicable law:

  • Cybersecify shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from our services, website content, or any information provided by us.
  • Our total liability for any claim arising from an engagement shall not exceed the fees paid by the client for that specific engagement.
  • We are not liable for damages resulting from the client's failure to implement recommended remediation measures.
  • We are not liable for any loss or damage caused by reliance on information published on our website, blog, or social media channels.

Indemnification

You agree to indemnify, defend, and hold harmless Cybersecify, its founders, employees, and contractors from any claims, damages, losses, or expenses (including legal fees) arising from: (a) your misuse of our reports, findings, or deliverables; (b) your failure to maintain adequate security controls after our engagement; (c) your provision of inaccurate information about systems in scope; or (d) any unauthorized use of our testing methodologies, tools, or techniques disclosed during an engagement.

Intellectual Property

All content on this website, including text, graphics, logos, and design elements, is the property of Cybersecify and protected by applicable intellectual property laws. You may not reproduce, distribute, or create derivative works without our express written permission.

Client Obligations

Clients engaging our services agree to provide accurate information about the systems to be tested, ensure proper authorization for all in-scope systems, notify us of any changes to the testing scope or schedule, and not use our reports or findings for any unlawful purpose.

Report Ownership and Usage

Upon completion of an engagement and receipt of full payment, clients receive an exclusive, non-transferable license to use the assessment report and its findings for internal security purposes, compliance audits, and remediation. Clients may share the report with their auditors, investors, or legal counsel on a need-to-know basis.

Clients may not publish, publicly distribute, or share the report with competitors or unauthorized third parties without our written consent. We retain the right to reference the engagement (without disclosing confidential details) for our portfolio, unless otherwise agreed in writing.

Letter of Attestation. Growth Pentest engagements include a one-page Letter of Attestation as a standard deliverable, issued for the engagement period and signed by our Lead Penetration Tester (OSCP certified). The Letter references the testing methodology used (OWASP, PTES, CVSS scoring), the engagement window, and the ISO 27001:2022 Annex A controls that penetration testing supports as evidence (A.8.8 and A.8.29). The Letter does not contain technical findings or vulnerability detail. It is a point-in-time engagement attestation referencing the testing performed; it is not a certification, accreditation, or guarantee of the client's overall security posture. Clients may share the Letter with auditors, customers, regulators, and procurement teams on a need-to-know basis. Startup Pentest engagements do not include a Letter of Attestation by default; one can be issued on request as a paid add-on.

Third-Party Tools and Services

Our website may contain links to third-party tools, resources, and services. We do not endorse, guarantee, or assume responsibility for the accuracy, reliability, or safety of any third-party content. Your use of third-party tools and services is at your own risk and subject to those parties' terms and conditions.

Engagement Cancellation

If a client cancels an engagement after the advance payment has been made but before testing begins, Cybersecify will refund the advance minus any costs already incurred for scoping, scheduling, or preparation. If testing has already begun, no refund is provided for work completed, but the client will not be billed for the remaining balance unless deliverables are provided.

If Cybersecify is unable to deliver due to circumstances beyond our reasonable control (including but not limited to natural disasters, internet outages, government actions, or client-side access issues), timelines will be extended accordingly. If delivery becomes impossible, we will refund any fees paid for undelivered work.

Price Lock

Once a client accepts a proposal and pays the required advance, the quoted price is locked for that engagement. Price changes on the website do not affect active or paid engagements.

Governing Law and Dispute Resolution

These terms shall be governed by and construed in accordance with the laws of India. Any disputes arising from these terms or our services shall be resolved through good-faith negotiation. If negotiation fails, disputes shall be subject to the exclusive jurisdiction of courts in Bengaluru, Karnataka, India.

Modifications

We reserve the right to modify these Terms of Service at any time. Changes become effective upon posting to this page. Continued use of our website or services after modifications constitutes acceptance of the updated terms.

Contact

For questions about these Terms of Service, please contact us at:

Email: contact@cybersecify.com
Address: Bengaluru, Karnataka, India