Terms and Conditions
Last updated: 2 October 2026
These Terms and Conditions (“Terms”) apply to this website and to all cybersecurity services provided by CyberVigilens. We have written them in plain language on purpose. If anything here is unclear, please write to us before you engage us, because by signing an order, accepting a proposal or continuing to use our services you agree to these Terms.
1. Who we are
CyberVigilens (“we”, “us”, “our”) is a cybersecurity and managed security services company. Our office is at 2nd Floor, 7-1-67/12, Dharam Karan Road, Near Nature Cure Hospital, Ameerpet, Hyderabad, Telangana 500 016, India. You can reach us at sales@cybervigilens.com or on +91 9849004358.
“Customer”, “you” and “your” mean the organisation or person buying or using our services, and anyone who acts for them.
2. The services we provide
We offer managed and professional security services. These include 24×7 Security Operations Centre (SOC) and Network Operations Centre (NOC) monitoring, managed detection and response, SIEM as a service, incident management, managed endpoint protection, vulnerability assessment and penetration testing (VAPT), cloud security, OT and ICS security monitoring, offensive security (red teaming, breach and attack simulation, threat intelligence, honeypots), GRC and audit support, device management and L3 support, staff augmentation, product evaluation and implementation, and virtual CISO services.
The specific scope for any engagement, together with deliverables, timelines and fees, is defined in the proposal, statement of work or order we agree with you. That document controls if there is any difference between it and the general descriptions on this website or in our marketing material.
3. Services are delivered on a best-effort basis
We bring trained people, defined processes and good tooling to every engagement, and we work hard to keep your environment safe. That said, no security service anywhere can promise complete protection, and we do not. Our services are delivered on a commercially reasonable, best-effort basis.
This point matters, so we state it plainly:
- We do not guarantee that we will detect every threat, intrusion, malware sample or insider action, or that we will detect any of them in time to prevent loss.
- Detection and investigation depend on the quality, coverage and timeliness of the logs and telemetry available to us. If a source is missing, misconfigured or silent, we cannot see what it does not send.
- We do not guarantee that we will stop an attack in progress, recover lost data, or prevent every service interruption.
- We provide advice and recommendations. Acting on them is your decision and, unless we agreed otherwise in writing, your responsibility.
Response times, coverage windows and any service levels apply only as agreed in your order. Nothing on this website should be read as a guarantee of a particular outcome.
4. We are not an insurer
CyberVigilens is a security services provider. We are not an insurance company and our services are not insurance. Nothing we do transfers your cyber risk to us. We do not pay for losses, and nothing in these Terms or in any proposal should be read as an undertaking to cover the financial consequences of a security incident.
If you want financial protection against cyber losses, you should buy a dedicated cyber insurance policy from a licensed insurer. We are glad to share what we observe so your insurer and brokers can assess your risk, and that is the limit of our role.
5. Your responsibilities
Security is a shared effort. You remain responsible for your own environment at all times. In particular, you agree to:
- Keep at least one recent, offline, immutable backup of your critical data, disconnected from the network, and test your ability to restore it.
- Apply security patches and updates to your systems and keep them current.
- Configure and maintain your firewalls, endpoint controls, identity systems and access rules properly.
- Give us accurate and complete information about your environment, and keep it updated.
- Review and act on the alerts, findings and recommendations we send you, and tell us if you disagree or cannot act.
- Confirm that you have the legal right to give us the access and data you provide, including any employee or third-party data.
- Comply with the laws and regulations that apply to you and to the data you hold.
If you do not carry out these responsibilities, the protection we can provide is reduced, and we are not responsible for problems that result.
6. Access, credentials and account security
To monitor and protect your systems we may need access to them, at times with administrative or unattended rights. Please give us only the access needed for the agreed work.
You are responsible for the credentials and access rights you provide. Where you share passwords, keys or tokens with us, follow the principle of least privilege, share them only for as long as they are needed, and change or revoke them as soon as the work is done. We are not responsible for the security, retention or misuse of credentials you have shared, or for any loss that follows if you leave access in place after an engagement ends. We recommend you use a central password manager or secrets store and rotate credentials regularly.
7. Penetration testing, red teaming and offensive security
Some of our services actively test your systems. These can only be performed on systems you own or are lawfully authorised to test. Before any such work begins, you must give us written authorisation that clearly identifies the systems in scope, the permitted techniques and the testing window. You are responsible for obtaining any third-party consent needed, for example from a cloud provider or hosting vendor.
Testing results reflect the state of the environment at the time of the test. A clean result does not mean the environment is free of vulnerabilities, and a finding does not necessarily mean a system is exploitable in production. We report what we found using reasonable skill and care. We do not warrant that testing will find all vulnerabilities.
8. Third-party products and OEM support
Our services often involve or depend on third-party hardware, software and cloud services. Those products are covered by the terms and warranties of their own vendors. Where a product carries manufacturer or OEM support, you may need to raise serious issues directly with the vendor. We can help coordinate and communicate on your behalf, but we do not take over the vendor’s obligations and we are not liable for a vendor’s failure to respond, resolve, supply or meet its own service levels.
9. Compliance and audit support
We help you understand your security posture and prepare for audits, but we do not provide legal advice and we cannot certify your compliance. Unless we expressly agree otherwise in writing, any compliance or audit support is advisory. Responsibility for meeting a standard, regulation or contractual obligation remains yours, and you should take your own legal and audit advice where needed.
10. Fees and payment
Fees, billing cycles and payment terms are set out in your order or proposal. Unless stated otherwise, fees are exclusive of applicable taxes, which are added as required by law. Invoices are payable as agreed. If an invoice is overdue we may pause non-critical work or suspend services after giving you notice, and we will not be liable for consequences that follow from a suspension caused by non-payment.
11. Limitation of liability
This section is important, and we ask you to read it carefully.
To the maximum extent permitted by law, and except where the law does not allow exclusion or limitation:
- We are not liable for any indirect, incidental, special, punitive, exemplary or consequential loss or damage, or for any loss of profit, revenue, business, goodwill, opportunity, anticipated savings, data or use, however it arises, whether or not it was foreseeable, and whether the claim is in contract, tort (including negligence), statute or otherwise.
- We are not liable for extortion or ransomware payments, regulatory fines or penalties, third-party claims, or the cost of substitute services.
- Our total aggregate liability for all claims arising out of or in connection with an engagement, whether in contract, tort or otherwise, is limited to the total fees actually paid by you to us for the affected services in the twelve (12) months immediately before the event that gave rise to the claim.
- Where the engagement is a free trial, proof of concept, evaluation or pilot, or where no fees have been paid, our total aggregate liability is nil (zero).
These limits apply even if a remedy fails of its essential purpose, and they extend to our directors, officers, employees, agents and subcontractors. They do not apply to our fraud or wilful misconduct, or to any liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by our negligence where such limitation is not permitted.
Nothing in these Terms excludes or limits any right you may have that cannot be excluded or limited under the applicable law.
12. Confidentiality
Each of us may receive confidential information from the other. We use it only to deliver and improve the services and protect it with reasonable care. We do not disclose it to others except to our personnel and subcontractors who need it, or where we are required to by law. Please do not send us sensitive personal data unless it is needed for the engagement and you are entitled to share it.
13. Term, suspension and termination
Each engagement runs for the term in your order, and either party may terminate as allowed in that order. We may suspend or stop services immediately if we believe continuing would break a law, breach our terms with a third party, or put our staff or systems at risk, and we will tell you why. When an engagement ends, access you gave us should be revoked promptly, and we will return or delete your confidential information as agreed or as the law requires.
14. Changes to these Terms
We may update these Terms from time to time to reflect changes in our services, the law or business practice. When we do, we post the updated version here and change the date at the top. If the changes are significant, we will try to tell you directly. Continuing to use our services after a change takes effect means you accept the updated Terms. If you do not agree, please stop using the services and tell us in writing.
15. Force majeure
We are not liable for a failure or delay caused by events beyond our reasonable control. These include natural disasters, flood, fire, earthquake, pandemic, war, civil unrest, terrorism, government action, failure of the internet or telecoms, large-scale cloud or power outages, and widespread cyber attacks on infrastructure we do not control. If such an event delays us for more than 90 days, either of us may end the affected engagement on written notice.
16. Governing law and jurisdiction
These Terms and any dispute arising from them are governed by the laws of India. The courts at Hyderabad, Telangana have exclusive jurisdiction, unless applicable law requires otherwise.
17. Contact
If you have questions about these Terms, please write to sales@cybervigilens.com or use the address in section 1.