Skip to main content

Engagement Terms

Table of Contents

This summary outlines how I engage with clients, scope projects, and deliver assessments. It ensures clear expectations before any work begins.


🛠️ Engagement Process

  1. 1

    NDA & Scoping Call

    Mutual NDA executed, followed by a call to define target environments and testing parameters.
  2. 2

    Proposal & Quote

    I provide a written Scope of Work (SOW) and fixed quote within 2 business days.
  3. 3

    Contract & Deposit

    SOW signed and a deposit paid to lock in calendar testing dates.
  4. 4

    Testing & Execution

    Security testing executed strictly within the scheduled window.
  5. 5

    Payment Clearance & Final Deliverables

    Remaining balance cleared. Upon full payment, the comprehensive Executive Summary and Technical Report are delivered.
  6. 6

    Retest & Closure

    Remediation verification conducted within 30 days, followed by secure data destruction.

💳 Payment Terms & Deliverables

  • Deposit: 25% to 50% based on complexity of working and to secure testing dates (determined during initial assessment).
  • Final Balance: Due in full before the final report handover.
  • Deliverable Leverage:
    • Prior to full payment clearance, only a brief high-level summary is provided.
    • The complete technical report and full executive summary are released only after final payment is cleared.
  • Invoicing Currency:
    • India-registered clients: INR + 18% GST.
    • International clients: USD.
  • Payment Delays: Late payments pause active testing immediately.

🗓️ Cancellations & Rescheduling

  • Rescheduling: Flexible rescheduling is available—just let me know as early as possible so we can move your window.
  • Cancellation Before Testing Starts: Full refund issued. No fees apply.
  • Cancellation After Testing Begins: A processing fee is charged to cover the effort already spent. Only a brief summary of work completed to date will be shared.

🎯 Scope Discipline & Calendar Locks

  • Fixed Scope: Testing is strictly limited to agreed targets. Scope additions require a formal requote.
  • Client-Side Delays: Testing windows are firm. Environment downtime, missing access, or credential delays on your side consume the reserved calendar window.

🔒 Confidentiality & Data Security

  • Strict Non-Disclosure: Standard mutual NDA applies. Your identity, security posture, and assessment findings are handled in strict secrecy.
  • Data Destruction: Client access credentials and testing data are permanently wiped within 24 hours of project completion, with written confirmation provided.

⚖️ Liability & Assessment Limits

  • Liability Cap: Total liability is capped at the fees paid for the specific engagement.
  • Point-in-Time Assessment: Assessments represent a point-in-time security posture using best-effort manual testing. No security evaluation can guarantee 100% detection of all vulnerabilities.

🚫 What Is NOT Offered

To focus strictly on deep application security testing, I do not offer:

  • 24/7 Monitoring, SOC, or MDR services
  • Incident Response or Breach Forensics
  • CERT-In Empanelled Audits
  • Direct Code Patching / Bug Remediation

📧 Questions About Terms?

Need clarification on scoping or engagement requirements before booking?

Email Me