LEGAL / TERMS

Terms & Conditions

These terms apply to your use of this website and, unless a signed engagement letter says otherwise, to any consulting work we do for you.

Last updated: 5 September 2026

1. Acceptance

By using this website or engaging our services, you agree to these terms. If you do not agree, please do not use the site or our services.

2. Nature of our services

We provide security assessments, data privacy consulting, identity and access advice, compliance readiness support and incident assistance. Our work is advisory. We do not guarantee that any system can be made immune to attack, and no assessment can identify every possible vulnerability.

3. Authorisation for testing

You must own the systems we test or hold written authority to allow testing. You agree to provide that authorisation in writing before any technical work begins, and to inform relevant hosting or third-party providers where their terms require it. Unauthorised testing requests will be refused.

4. Scope and changes

Each engagement has a written scope, timeline and deliverable. Work outside that scope is quoted separately. Either party may request a change; changes take effect once agreed in writing.

5. Your responsibilities

  • Give accurate information about your systems, data and constraints.
  • Maintain working backups before any remediation work.
  • Provide timely access, credentials and points of contact.
  • Decide on and implement (or ask us to implement) recommended fixes.

6. Confidentiality

Both parties keep the other's confidential information secret and use it only for the engagement. Findings are shared only with the people you nominate. This obligation survives the end of the engagement.

7. Fees and payment

Fees, milestones and currency are set out in the engagement letter or quote. Invoices are payable within 14 days unless stated otherwise. Late payment may pause work.

8. Intellectual property

You own the reports and documentation we deliver for your engagement. We retain ownership of our methodologies, tooling, templates and general know-how, and may reuse anonymised, non-identifying learnings.

9. Limitation of liability

To the maximum extent permitted by law, our total liability arising from an engagement is limited to the fees paid for that engagement. We are not liable for indirect or consequential loss, including lost profits, lost data or business interruption, or for incidents arising from recommendations you chose not to implement.

10. No legal advice

Compliance guidance is technical and organisational advice, not legal advice. For binding interpretation of GDPR, the DPDP Act or any regulation, consult a qualified lawyer.

11. Website use

Do not attempt to disrupt, scan or gain unauthorised access to this website, scrape it at scale, or misrepresent an association with SYIT. Content on this site is provided for information only.

12. Termination

Either party may end an engagement with 14 days' written notice. You pay for work performed up to termination; we hand over completed deliverables and delete or return your data as agreed.

13. Governing law

These terms are governed by the laws of India, and the courts of India have exclusive jurisdiction, unless your engagement letter states otherwise.

14. Contact

Questions about these terms? Contact us or read our privacy policy.