This summary outlines how I engage with clients, scope projects, and deliver assessments. It ensures clear expectations before any work begins.
🛠️ Engagement Process
- 1
NDA & Scoping Call
Mutual NDA executed, followed by a call to define target environments and testing parameters. - 2
Proposal & Quote
I provide a written Scope of Work (SOW) and fixed quote within 2 business days. - 3
Contract & Deposit
SOW signed and a deposit paid to lock in calendar testing dates. - 4
Testing & Execution
Security testing executed strictly within the scheduled window. - 5
Payment Clearance & Final Deliverables
Remaining balance cleared. Upon full payment, the comprehensive Executive Summary and Technical Report are delivered. - 6
Retest & Closure
Remediation verification conducted within 30 days, followed by secure data destruction.
💳 Payment Terms & Deliverables
- Deposit: 25% to 50% based on complexity of working and to secure testing dates (determined during initial assessment).
- Final Balance: Due in full before the final report handover.
- Deliverable Leverage:
- Prior to full payment clearance, only a brief high-level summary is provided.
- The complete technical report and full executive summary are released only after final payment is cleared.
- Invoicing Currency:
- India-registered clients: INR + 18% GST.
- International clients: USD.
- Payment Delays: Late payments pause active testing immediately.
🗓️ Cancellations & Rescheduling
- Rescheduling: Flexible rescheduling is available—just let me know as early as possible so we can move your window.
- Cancellation Before Testing Starts: Full refund issued. No fees apply.
- Cancellation After Testing Begins: A processing fee is charged to cover the effort already spent. Only a brief summary of work completed to date will be shared.
🎯 Scope Discipline & Calendar Locks
- Fixed Scope: Testing is strictly limited to agreed targets. Scope additions require a formal requote.
- Client-Side Delays: Testing windows are firm. Environment downtime, missing access, or credential delays on your side consume the reserved calendar window.
🔒 Confidentiality & Data Security
- Strict Non-Disclosure: Standard mutual NDA applies. Your identity, security posture, and assessment findings are handled in strict secrecy.
- Data Destruction: Client access credentials and testing data are permanently wiped within 24 hours of project completion, with written confirmation provided.
⚖️ Liability & Assessment Limits
- Liability Cap: Total liability is capped at the fees paid for the specific engagement.
- Point-in-Time Assessment: Assessments represent a point-in-time security posture using best-effort manual testing. No security evaluation can guarantee 100% detection of all vulnerabilities.
🚫 What Is NOT Offered
To focus strictly on deep application security testing, I do not offer:
- 24/7 Monitoring, SOC, or MDR services
- Incident Response or Breach Forensics
- CERT-In Empanelled Audits
- Direct Code Patching / Bug Remediation
📧 Questions About Terms?
Need clarification on scoping or engagement requirements before booking?
Email Me