These Terms of Service ("Terms") govern your access to and use of the website operated by VCF Cyber Solutions Pvt. Ltd. ("VCF Cyber Solutions," "we," "us," or "our"), and, at a general level, your engagement of our cybersecurity assessment, VAPT, remediation, vCISO, managed security, and incident response services. By accessing our website or engaging our services, you agree to be bound by these Terms. If you do not agree, please do not use our website or engage our services.
We provide cybersecurity services including, but not limited to: Cyber Risk Health Checks, External Attack Surface Assessments, Web & API VAPT, Network VAPT, Cloud Security Assessments, SaaS Security Readiness, DPDP Security Readiness, AI Security Assessments, Security Remediation & Hardening, vCISO / Virtual Security Function, Managed Security, and Incident Response (collectively, the "Services"). The specific scope, deliverables, pricing, and timeline for any Service are set out in a separate proposal, statement of work, or service agreement ("SOW") agreed between you ("Client") and VCF Cyber Solutions. In the event of a conflict between these Terms and a signed SOW, the SOW governs for that engagement.
You agree to use our website only for lawful purposes and in a manner that does not infringe the rights of, restrict, or inhibit anyone else's use of the site. You must not attempt to probe, scan, or test the vulnerability of our website or infrastructure, or attempt to breach our security or authentication measures, without our prior written authorization — doing so may constitute unauthorized access under applicable law.
Pricing shown on our website (including "starting from" prices and typical timelines) is indicative only and subject to change based on the actual scope, complexity, and requirements confirmed during scoping. No engagement is binding until both parties have signed a proposal, SOW, or equivalent written agreement, and — where applicable — any required deposit or purchase order has been received.
To enable us to deliver Services safely and effectively, you agree to:
You represent and warrant that you are authorized to grant us permission to test and assess the systems identified in the SOW. You agree to indemnify us against claims arising from testing conducted on systems you did not have the right to authorize us to test.
All VAPT, assessment, and related testing activities are performed strictly within the scope and testing window agreed in the SOW, and constitute your written authorization for that testing under applicable law (including provisions relating to unauthorized computer access). Any testing outside the agreed scope requires a separate written authorization.
Incident Response engagements are time-sensitive and may commence on an expedited basis, with formal documentation (SOW, authorization) completed as soon as reasonably practicable, potentially in parallel with the start of work, given the urgency of containing an active incident. Verbal or email authorization from an authorized representative of the Client is sufficient to commence emergency work pending formal paperwork.
An advance payment is required before an engagement begins; the advance amount depends on the type and scope of Service and is specified in the applicable SOW or invoice. Fees, invoicing schedule, and any remaining payment terms for a given engagement are likewise set out in the applicable SOW or invoice. Unless otherwise agreed in writing, invoices are due within the period stated on the invoice. Late payment may result in suspension of ongoing Services (e.g. Managed Security, vCISO) until outstanding amounts are settled.
Both parties agree to keep confidential any non-public information disclosed in connection with an engagement, including assessment findings, reports, credentials, and details of the Client's systems and business. We will not disclose engagement findings to third parties without the Client's written consent, except: (a) to personnel and authorized subcontractors bound by equivalent confidentiality obligations and involved in delivering the engagement; (b) where required by law, regulation, or court order; or (c) to enforce our rights under the applicable agreement. This obligation survives the completion or termination of an engagement.
Reports, findings, and other deliverables we prepare for you become your property upon full payment for the relevant engagement, for your internal use and (where relevant) sharing with your auditors, regulators, or enterprise customers. We retain ownership of our pre-existing methodologies, tools, templates, and know-how, and may reuse general, non-client-identifying knowledge gained during an engagement to improve our Services. All content on our website (text, graphics, logos) remains the property of VCF Cyber Solutions or its licensors and may not be reproduced without permission.
Security assessments, VAPT, and related Services identify vulnerabilities and risks that are reasonably discoverable using industry-standard methodologies within the agreed scope and timeframe; they do not guarantee that all vulnerabilities will be found, or that your systems will be immune from compromise following the engagement. New vulnerabilities can emerge, and your environment may change, after an assessment is completed. Our Services are provided on an "as is" and "as available" basis, and — except as expressly stated in a signed SOW — we disclaim all warranties, express or implied, to the fullest extent permitted by law.
To the fullest extent permitted by applicable law, VCF Cyber Solutions' total liability arising out of or relating to an engagement shall not exceed the fees paid by the Client for that specific engagement in the twelve (12) months preceding the claim. Neither party shall be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, revenue, or data, except where such exclusion is not permitted by law or in cases of gross negligence, willful misconduct, or breach of confidentiality obligations.
Either party may terminate an ongoing engagement (e.g. Managed Security, vCISO) in accordance with the notice period specified in the applicable SOW. We may suspend or terminate Services immediately if: (a) the Client fails to pay undisputed fees when due; (b) continuing the engagement would require us to act unlawfully; or (c) we reasonably believe continuing testing poses an imminent risk to the Client's or a third party's systems.
These Terms are governed by the laws of India. Subject to the dispute resolution process (if any) specified in the applicable SOW, the courts at Nagpur, Maharashtra shall have exclusive jurisdiction over any disputes arising out of or relating to these Terms or an engagement.
We may update these Terms from time to time to reflect changes in our Services or legal requirements. The "Last updated" date at the top of this page indicates when it was last revised. Continued use of our website after changes take effect constitutes acceptance of the revised Terms; for active engagements, changes to commercial terms require mutual written agreement.
Questions about these Terms can be directed to:
VCF Cyber Solutions Pvt. Ltd.
3rd Floor, Vasant Villa, Bazaar Chowk, Jaitala Road, Nagpur, Maharashtra - 440010, India
Email: contact@vigilantecyberforces.com
Phone: +91 73853 69311 | +91 82088 22572