Terms of service.
Last updated: 29 July 2026 · RedForge · contact@redforge.in
These terms govern your use of this website and any assessment RedForge performs for you. A signed engagement agreement, where one exists, takes precedence over anything here.
The one rule that matters most. RedForge does not test any system without written authorisation from someone empowered to grant it. Not as a favour, not as a demo, not “just a quick look”. Unauthorised access to a computer resource is an offence under sections 43 and 66 of the Information Technology Act, 2000, and good intentions are not a defence.
1. What we provide
Engineering security assessments: examining systems you own or are authorised to have tested, and reporting what we find. We are not an accredited audit body and issue no certifications.
2. Authorisation
- Active testing begins only after a written authorisation document is signed, listing the systems, tests, dates and testing windows.
- You confirm you own or hold authority to authorise testing of every listed system, including any required permission from your hosting or cloud provider.
- You may withdraw authorisation at any time in writing, and testing stops on receipt.
- The free attack-surface report is limited to publicly accessible information — no credentials, no submitted data, no state-changing requests — and therefore needs no authorisation beyond your request for it.
3. Your responsibilities
- Confirm your backups are current before active testing begins.
- Provide test accounts rather than real user credentials.
- Tell us about fragile systems, blackout periods and anything that must not be touched.
- Give us a contact who can be reached during the testing window.
4. Risk
Security testing carries inherent risk, including temporary service disruption, elevated log volume and alerting load. We rate-limit testing, work inside the windows you set, and stop on request. You accept this residual risk for the authorised scope, provided we act within the agreed terms.
5. What a report is and is not
- A report describes the state of the tested systems on the dates tested. It is a snapshot, not a warranty.
- No assessment can find every vulnerability. An absence of findings is not proof of security.
- No report constitutes certification of compliance with the DPDP Act or any other law.
- References to legal provisions are provided to help you direct remediation and should be confirmed with qualified counsel.
6. Fees
- Prices are quoted in Indian Rupees and, unless stated otherwise, exclude applicable taxes.
- Standard terms are 50% on signature and 50% on delivery of the report.
- Fees for work already performed are non-refundable if you terminate early.
- Work outside the agreed scope is quoted separately before it begins.
7. Confidentiality
Your findings are confidential. We do not disclose them, publish them, or use them in marketing without your written permission. We may refer to the engagement in anonymised form only — for example “a mid-sized Indian e-commerce company” — and you may object to even that in writing.
You may share your report internally and with your auditors, insurers, investors and regulators without restriction.
8. Personal data
Handled as described in our privacy policy. Where we process personal data on your behalf we act as a Data Processor under the DPDP Act; you remain the Data Fiduciary for your own users’ data. Nothing here reduces either party’s statutory obligations.
9. Liability
To the extent permitted by law, RedForge’s total liability arising from an engagement is limited to the fees paid for that engagement. Neither party is liable for indirect or consequential loss. Nothing limits liability for fraud, wilful misconduct, or anything that cannot lawfully be limited.
10. Website content
Everything on this site — including guidance on the DPDP Act — is provided for information only and is not legal advice. Do not act on it without advice from qualified counsel about your own circumstances. Prices and service descriptions may change; a written quotation governs.
11. Governing law
These terms are governed by the laws of India, and the courts of India have exclusive jurisdiction. Disputes are first addressed through good-faith negotiation and, failing resolution within 30 days, referred to arbitration under the Arbitration and Conciliation Act, 1996, conducted in English.
