Legal

Terms & Conditions

Version 2.0 · Effective 22 September 2026

These Terms govern your use of the ZeroRisk Labs website. They are not the terms of a service engagement — those are agreed separately, and section 16 sets out which document prevails where they differ.

For how we handle personal data, see our Privacy Notice and Data Processing Agreement, both of which take precedence over these Terms on data protection matters.

1. Acceptance of Terms

By accessing or using our website, you acknowledge that you have read, understood, and agree to be bound by these Terms. If you do not agree to these Terms, you must not use our website or services.

We reserve the right to update or modify these Terms at any time. Changes will be effective upon posting to this page with a revised effective date and version. Your continued use of the website after such changes constitutes acceptance of the updated Terms.

2. Description of Services

ZeroRisk Labs provides cybersecurity consulting and assessment services, including but not limited to security testing, adversarial simulation, incident readiness support, digital investigations support, governance and compliance advisory, and security training.

The specific scope, deliverables, timelines, and terms of any engagement are defined in a separate statement of work or engagement agreement between ZeroRisk Labs and the client.

3. Use of the Website

When using our website, you agree to:

  • Provide accurate and truthful information in any form submissions.
  • Use the website only for lawful purposes and in compliance with applicable laws.
  • Not attempt to disrupt, compromise, or interfere with the operation or security of the website.
  • Not submit automated, scripted, or bot-generated requests to our forms or API endpoints.
  • Not impersonate any person or entity, or falsely represent your affiliation with any party.

4. Security Testing and Prohibited Probing

Unauthorised security testing, scanning, probing, reverse engineering, vulnerability exploitation attempts, denial-of-service activity, or any similar activity against this website or related systems is strictly prohibited.

If you believe you have identified a security issue, you must report it through the responsible disclosure channel in section 5 and must not publicly disclose it until we have had a reasonable opportunity to investigate and remediate.

5. Responsible Disclosure

Report suspected vulnerabilities to security@zerorisklabs.com using the subject line "Security Incident". We acknowledge reports within 72 hours and will keep you informed of remediation progress.

Security researchers acting in good faith must avoid service disruption, data access beyond what is necessary to demonstrate the issue, and any action that compromises the confidentiality, integrity, or availability of data belonging to us or to our clients.

We will not pursue action against a reporter who acts within those limits. No bounty, compensation, or legal waiver is implied unless separately agreed in writing.

6. Intellectual Property

All content on this website — including text, graphics, logos, icons, images, code, and design elements — is the property of ZeroRisk Labs or its licensors and is protected by applicable intellectual property laws.

You may not reproduce, distribute, modify, create derivative works from, publicly display, or commercially exploit any content from this website without prior written consent from ZeroRisk Labs.

7. Confidentiality

All engagements are conducted under strict confidentiality. ZeroRisk Labs treats all client data, systems information, and findings as confidential, and does not disclose client identities or the existence of an engagement without written authorisation.

Specific confidentiality obligations, including non-disclosure terms, are defined in the engagement agreement or a separate non-disclosure agreement executed prior to the engagement.

8. Security Assessment Disclaimer

Security assessments reduce risk but cannot guarantee the absence of vulnerabilities, incidents, or unauthorised activity.

Threat landscapes and attack techniques evolve continuously; therefore, results and recommendations are point-in-time assessments unless otherwise stated in writing.

9. Authorisation and Scope for Engagements

Security services are performed only with explicit written authorisation from an authorised representative of the asset owner and strictly within the agreed scope and rules of engagement.

Clients are responsible for ensuring they have legal authority to request testing or analysis of target systems, applications, networks, and data. Where a third party controls the target infrastructure — a cloud provider, a hosting provider, or a SaaS vendor — that party's consent is also required, and obtaining it is part of scoping rather than an afterthought.

Authorisation is not a formality. Testing without it may constitute a criminal offence, including under the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and state computer crime statutes in the United States, the Computer Misuse Act 1990 in the United Kingdom, equivalent provisions implementing Directive 2013/40/EU in the European Union, the Cybercrimes Act 19 of 2020 in South Africa, and the Information Technology Act, 2000 in India. We will decline an engagement where authorisation cannot be established, and we will not proceed on a verbal assurance alone.

10. Limitation of Liability

To the maximum extent permitted by applicable law:

  • ZeroRisk Labs provides this website on an "as is" and "as available" basis without warranties of any kind, express or implied.
  • We do not warrant that the website will be uninterrupted, error-free, or free of harmful components.
  • ZeroRisk Labs shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the website.
  • Our total liability for any claim arising from or related to the website shall not exceed the amount you have paid to ZeroRisk Labs, if any, in the twelve months preceding the claim.

This clause limits liability for use of the website only. Liability for a service engagement is governed by the applicable engagement agreement and is negotiated there. Nothing in this clause limits liability that cannot be limited under the law applicable where you are located, or restricts any right or remedy available to a data subject under applicable data protection law.

11. Third-Party Links

Our website may contain links to third-party websites or services that are not owned or controlled by ZeroRisk Labs, including our recruitment platform. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party site.

We encourage you to review the terms and policies of any third-party website you visit through links on our site.

12. Form Submissions and Communications

When you submit an enquiry or service request, we use your details to respond to it and to scope the engagement you have asked about. We rely on the performance of a contract or steps taken at your request before entering one, and on our legitimate interest in responding to business correspondence — not on consent. The full basis is set out in our Privacy Notice, which governs if there is any difference between the two documents.

We do not send unsolicited marketing communications, and we do not add enquirers to a marketing list.

All form submissions are subject to abuse-prevention controls. Submissions that violate our acceptable use standards may be rejected.

We intentionally do not disclose our internal security architecture, monitoring logic, abuse-detection thresholds, tooling, or implementation specifics in these Terms or on any other public page. That information is available to clients and prospective clients under a non-disclosure agreement.

13. Export Controls and Sanctions Compliance

You agree not to use the website or services in violation of applicable export control, sanctions, anti-corruption, or trade compliance laws.

We may refuse, suspend, or terminate services where required to comply with legal or regulatory restrictions.

14. Indemnification

You agree to indemnify, defend, and hold harmless ZeroRisk Labs, its officers, employees, and affiliates from and against any claims, liabilities, damages, losses, or expenses (including reasonable legal fees) arising from your use of the website or violation of these Terms.

15. Force Majeure

ZeroRisk Labs is not liable for delay or failure to perform caused by events beyond reasonable control, including but not limited to natural disasters, utility outages, war, terrorism, labour disputes, governmental actions, or internet infrastructure failures.

16. Entire Agreement and Order of Precedence

These Terms, together with any applicable engagement agreement, statement of work, executed non-disclosure agreement, and our Data Processing Agreement, constitute the entire agreement between you and ZeroRisk Labs regarding the subject matter and supersede prior understandings related to it.

Where those documents conflict, the following order of precedence applies, from highest to lowest: any executed Standard Contractual Clauses or International Data Transfer Agreement; our Data Processing Agreement; the engagement agreement or statement of work; the executed non-disclosure agreement; our Privacy Notice; and these Terms.

On any question of how personal data is handled, the Data Processing Agreement and the Privacy Notice prevail over these Terms.

17. Termination

We reserve the right to restrict or terminate your access to the website at any time, without notice, for conduct that we believe violates these Terms, is harmful to other users, or is otherwise objectionable.

18. Governing Law and Jurisdiction

These Terms, which govern your use of this website, shall be governed by and construed in accordance with the laws of India, and disputes arising from your use of the website shall be subject to the exclusive jurisdiction of the courts in Guwahati, Assam, India.

This clause applies to website use only. The governing law and forum for a service engagement are agreed separately in the applicable engagement agreement, and we are willing to agree to the law and courts of the client's own jurisdiction where the engagement warrants it. Nothing in this clause requires a client to accept Indian jurisdiction as a condition of engaging us.

Nothing in these Terms removes or limits any right you have under mandatory provisions of the law applicable where you are located, including rights under applicable data protection law. Where the Standard Contractual Clauses, the International Data Transfer Agreement, or an equivalent transfer instrument has been entered into between us, the governing law and forum provisions of that instrument prevail over this clause in respect of matters falling within it.

19. Severability

If any provision of these Terms is found to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect.

20. Contact Us

If you have any questions about these Terms and Conditions, please contact us using the details below.

For anything concerning personal data — an access, correction, or erasure request, a Data Processing Agreement, or correspondence from a supervisory authority — write to privacy@zerorisklabs.com instead, so that it reaches the right team directly. To report a suspected vulnerability, use security@zerorisklabs.com as set out in section 5.

ZeroRisk Labs

Ambari, Guwahati, Assam 781001, India

Email: contact@zerorisklabs.com