Legal
Terms of service
These terms govern your use of kalkishield.com. They are not the terms on which security testing is delivered — that work is governed by a separate engagement contract, statement of work, rules of engagement and authorisation letter agreed in writing before any testing begins. Where those documents conflict with this page, those documents prevail.
Using this website
You may read this site, download the materials we offer, and contact us. You may not attempt to gain unauthorised access to any part of it, interfere with its availability, or use it to send anything unlawful.
Security testing of this website is welcome within the bounds set out in our responsible disclosure policy. Testing outside those bounds is not authorised.
No testing without written authorisation
We do not conduct security testing of any system without a signed authorisation letter from a person with authority to grant it, naming the systems in scope, the permitted techniques and the testing window. This protects both parties: unauthorised access to a computer system is an offence under the Information Technology Act, 2000, and an authorisation letter is what separates a commissioned assessment from one.
The demonstration report
The demonstration report offered on this site describes testing against a deliberately vulnerable target that we control. It is provided to illustrate our reporting standard. It is not client work, it is not redacted client work, and nothing in it should be read as a finding about any real organisation.
Reports and intellectual property
On payment in full, the report produced for an engagement belongs to the client, who may share it with their auditors, regulators and customers. We retain ownership of our methodology, tooling, templates and general know-how. We retain a copy of each report solely to service retests and to meet our own record-keeping obligations.
Confidentiality
We do not name clients. Engagements described publicly on this site are described by sector only, and never in a way that identifies the organisation. This undertaking survives the end of the engagement and is reciprocal — findings we deliver are confidential to the client.
What testing does and does not tell you
A penetration test is a point-in-time assessment of a defined scope using the techniques available at that time. It does not and cannot prove the absence of vulnerabilities, and it does not guarantee that a tested system will not be compromised. Anyone offering you that guarantee is selling something other than security testing. Findings and recommendations are provided in good faith on the basis of professional judgement; acting on them remains the client’s decision.
Liability
To the fullest extent permitted by law, our total liability arising out of or in connection with an engagement is limited to the fees paid for that engagement. We are not liable for indirect or consequential loss, loss of profit, loss of data, or business interruption. Nothing in these terms excludes liability that cannot lawfully be excluded, including for fraud, wilful misconduct, or death or personal injury caused by negligence. [CONFIRM CAP WITH COUNSEL AND WITH YOUR PROFESSIONAL INDEMNITY INSURER — a cap your policy does not match is worth little.]
Governing law
These terms are governed by the laws of India, and the courts at [CITY] have exclusive jurisdiction over any dispute arising from them.
Changes
We may update these terms. The version in force is the one published here at the time you use the site. Engagement contracts are not changed by changes to this page.
Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email: hello@kalkishield.com.