Terms of Service
Last updated 31 August 2026 · Cypliance, Ahmedabad, Gujarat, India
These terms govern your use of Cypliance ("we", "us"), a security testing service operated from India. By creating an account or running a scan you agree to them. If you are agreeing on behalf of an organisation, you confirm you are authorised to bind that organisation.
1. What the service does
Cypliance performs vulnerability assessment and penetration testing against systems you nominate, and reports what it finds with evidence. Depending on your plan this may include passive reconnaissance of public information, active testing that sends real attack traffic, internal network assessment, cloud configuration review, and testing of AI and LLM features.
2. Authorisation is your responsibility
You may only submit systems you own or are contractually authorised to test. Security testing sends real attack traffic. Directing it at a system you do not control is unlawful in most jurisdictions, including under the Information Technology Act, 2000 in India, and comparable computer-misuse legislation elsewhere.
Before any active testing runs, we require you to confirm on the record that you are authorised. We record who agreed, their stated role, the time, and the network address the agreement came from. You warrant that this confirmation is truthful and that you hold whatever permission is needed from system owners, hosting providers and any third parties involved.
You indemnify us against claims arising from testing you authorised without holding the right to do so.
3. What we will not do
Cypliance demonstrates that a weakness is real. It does not exploit one for gain or cause harm to prove a point. Specifically, we do not:
- delete, alter or exfiltrate your data;
- run denial-of-service or volumetric attacks;
- install persistence, backdoors or any lasting change on your systems;
- use one client's findings, credentials or data in another client's engagement;
- test anything outside the scope you submitted, or anything on your exclusion list.
Where a finding can only be proven by writing data, we create our own clearly-marked test record and act on that, never on yours, and only with your separate written approval.
4. Risk you accept
Active security testing carries inherent risk. Well-behaved systems tolerate it, but fragile or unusual configurations can slow down, log heavily, trigger alerts, lock accounts or, rarely, become temporarily unavailable. You agree to:
- tell us about fragile systems using the exclusions field before testing begins;
- hold a current, tested backup of anything in scope;
- give us a contact we can reach if something behaves unexpectedly.
We test at the intensity you select and stop when you ask us to.
5. No guarantee of completeness
No assessment finds every weakness. A clean report means the tests we ran did not find a problem within the scope and time agreed — it is not a certificate that your systems are secure, and it is not a warranty against future compromise. Systems change; a report describes a moment.
6. Your account
You are responsible for what happens under your account. Keep your password to yourself, turn on two-factor authentication, and tell us promptly if you believe someone else has access. Reports describe in detail how to attack your systems, which is precisely why we ask you to secure the account holding them.
One account is for one organisation. Do not share credentials with people outside it.
7. Plans, credits and payment
Plans are prepaid and grant a stated number of scans valid for a stated period. Unused scans expire at the end of that period. Prices are shown in your local currency where we support it; taxes may be added at checkout. Payment is handled by our payment providers — we never see or store your card details.
Refunds and cancellation are covered in our Refunds & Cancellation Policy.
8. Your data and your reports
Findings about your systems belong to you. We hold them to deliver the service and to let you read them later. What we collect and how long we keep it is set out in the Privacy Policy. We do not sell your data, and we do not publish anything about your systems without your written permission.
9. Acceptable use
You may not use Cypliance to test systems you are not authorised to test, to attack anyone, to build or refine offensive tooling for use against third parties, or to circumvent another party's security controls. We may suspend an account immediately where we reasonably believe testing is unauthorised, and we may be legally required to respond to lawful requests about it.
10. Availability
We aim to keep the service available but do not promise uninterrupted operation. Scanning capacity is shared, so a scan may be queued. Scheduled maintenance is announced where practical.
11. Liability
To the extent permitted by law, our total liability for any claim arising out of the service is limited to the amount you paid us in the twelve months before the claim arose. We are not liable for indirect or consequential loss, loss of profit, loss of data, or business interruption.
Nothing here limits liability that cannot be limited by law, including for fraud or for death or personal injury caused by negligence.
12. Ending the agreement
You may close your account at any time by writing to support@cypliance.com. We may suspend or end an account for breach of these terms, particularly clause 2 or clause 9. Unused credits are handled under the refunds policy.
13. Changes
We may update these terms. Material changes will be notified by email to account holders at least fourteen days before they take effect. Continuing to use the service after that means you accept the change.
14. Governing law
These terms are governed by the laws of India, and the courts of Ahmedabad, Gujarat have exclusive jurisdiction, save that we may seek injunctive relief in any competent court.
15. Contact
Questions about these terms: support@cypliance.com. Full details on the contact page.