Skip to content
Cybercraft Labs

Terms andprivacy policy.

Cybercraft Labs Pvt Ltd · Last updated 1 September 2026

Terms
01

Acceptance and scope

These terms govern your use of this website and any engagement with Cybercraft Labs Pvt Ltd (“Cybercraft Labs”, “we”, “our”, “us”). By accessing the site, contacting us, or instructing us to carry out work, you confirm that you have read and accept them, together with the privacy policy below.

Where we sign a separate engagement letter, statement of work, master services agreement or non-disclosure agreement with you, that document governs the work it describes. These terms fill the gaps it leaves; they do not override it.

We may revise these terms to reflect changes in our services or in the law. The date at the top of this page records the last revision. Continued use of the site after a revision constitutes acceptance of it.

02

What our services are

We provide security testing, infrastructure and deployment work, software engineering, and technical advisory. Each engagement is scoped in writing before it begins: the systems in scope, the method, the deliverables, the schedule, and the fee.

Security testing is a point-in-time exercise against a defined scope. It is bounded by the time agreed, the access granted, and the state of the system at the time of testing. It is not a certification, a compliance approval, or a guarantee that a system contains no other defects.

Advice given in a consultation, including a free one, is informational. It does not by itself create an engagement, and no client relationship arises until both parties have agreed scope and fee in writing.

03

Authorisation for security testing

We will not test a system without written authorisation. Before an engagement begins, you must give us rules of engagement identifying the systems in scope, the systems explicitly out of scope, the permitted testing window, and a named contact reachable during it.

You confirm that you own the systems in scope or hold the authority to authorise testing against them. Where a system is hosted, operated or supplied by a third party, obtaining that party’s consent is your responsibility, and you must confirm it to us in writing before we begin.

We stop and notify you if we find evidence of a pre-existing compromise, if testing appears to affect a system outside the agreed scope, or if continuing would risk the availability of a production service. We will not act on a finding beyond what is needed to demonstrate it.

Where we find a critical issue, we report it to your named contact on the day we find it rather than holding it for the final report.

04

Your responsibilities

You agree to give us accurate and complete information, and to tell us promptly when something material changes — an architecture change mid-engagement, a system leaving your control, or a contact becoming unreachable.

You are responsible for maintaining current backups of any system we test or work on, and for having a route to restore service. Testing carries an inherent risk of disruption even when conducted carefully.

You agree not to use our services, our reports, or our communications for an unlawful purpose, including unauthorised access to systems you do not control. We may refuse or end an engagement where a request falls outside legal, ethical or professional boundaries, and we will say why.

05

Confidentiality

We treat your systems, your data, our findings, and the existence and detail of the engagement as confidential. We disclose them only to the people working on your engagement, and only as far as the work requires.

Credentials, access tokens and extracted data are held only for the duration of the engagement and the retest window, kept encrypted at rest, and destroyed afterwards. We do not retain client data to build a corpus, train a model, or seed future work.

These obligations survive the end of the engagement. They do not apply to information that is already public, that we hold independently, or that we are compelled to disclose by law — and where we are compelled, we will tell you unless we are prohibited from doing so.

We will not name you as a client, publish a case study, or describe your systems in our writing without your prior written consent. Our published research concerns software and techniques, not identifiable clients.

06

Fees and payment

Engagements are quoted at a fixed price against an agreed scope. The price is set before work begins and does not change because the work took longer than we estimated.

Where you change the scope mid-engagement, we will quote the change in writing before carrying it out. Work outside the agreed scope is not performed on assumption.

Invoices are payable within the period stated on them. Where an engagement is staged, we invoice at the stages set out in the engagement letter.

One retest of the findings we report is included in the engagement fee. It is not charged as an extra.

07

Warranties and limitation of liability

We perform our work with the reasonable skill and care expected of a competent security and engineering practice. Beyond that, and to the maximum extent permitted by law, our services and this website are provided “as is” and all implied warranties are disclaimed.

We do not warrant that testing will identify every vulnerability in a system, that a system will be secure after remediation, or that a deployment will be free of defects. Security is a property of a system over time, not a state a report confers on it.

To the fullest extent permitted by applicable law, we are not liable for indirect or consequential loss, including loss of data, revenue, profit or business opportunity. Our total liability arising out of an engagement is limited to the fees paid for that engagement. This limit applies however the claim is framed.

Nothing in these terms limits liability that cannot be limited by law, including liability for fraud.

08

Intellectual property

Reports, findings and remediation guidance produced for you are yours on payment of the engagement fee. You may share them freely inside your organisation and with your auditors, insurers and regulators.

Code we write specifically for you under an engagement is yours on payment, unless the engagement letter says otherwise.

We retain ownership of our methodology, our internal tooling, and anything we developed before or independently of your engagement. Where such a component is delivered as part of your system, you receive a perpetual, non-exclusive licence to use it for that system.

Our open-source projects, including Berserk Arch, are governed by their own licences and are unaffected by these terms.

09

Third-party services

Our work may reference or depend on third-party platforms, libraries and infrastructure providers. We do not control them and are not responsible for their content, availability, security or practices.

Where you choose to use such a service, reviewing and complying with its terms is your responsibility.

10

Governing law

These terms and any engagement with Cybercraft Labs Pvt Ltd are governed by the laws of India.

We would rather resolve a dispute by talking to you than by litigating it. If something goes wrong, raise it with us in writing first and we will try to settle it directly.

Privacy
01

What we collect

When you contact us — through the enquiry form, by email, or during a consultation — we collect what you send us: your name, your email address, your organisation, and whatever you choose to tell us about your systems and your problem.

If you subscribe to our writing, we collect the email address you give us and nothing else.

Our servers keep standard logs of requests to this site, which include IP address, browser and device type, and the pages requested. These exist for operations, security and performance, and for no other purpose.

During an engagement we necessarily handle material about your systems: configuration, credentials issued to us for testing, and data encountered while demonstrating a finding. That material is covered by the confidentiality clause in the terms above as well as by this policy.

02

How we use it

We use what you send us to answer your enquiry, to scope and deliver an engagement, to invoice for it, and to meet our legal and accounting obligations.

We do not sell, rent or trade personal information. We do not profile you, we do not run advertising, and we do not send unsolicited marketing. If you subscribe to our writing, we send you our writing; the unsubscribe link ends it immediately.

03

Cookies and analytics

This site sets no cookies, and carries no advertising or cross-site tracking.

We use Vercel Web Analytics to see which pages are read. It records the page visited, the referring site, an approximate location derived from your IP address, and your device, browser and operating system type. It uses no cookies and no cross-site identifiers: visitors are distinguished by a hash derived from the request, which is discarded after twenty-four hours. It cannot follow you to another site, and we cannot use it to identify you.

Web fonts are loaded from Google Fonts, which means your browser makes a request to Google to fetch them. That request is subject to Google’s own privacy policy.

04

Processors and hosting

This site is hosted by Vercel, which also provides the analytics described above. We rely on further third parties for email and, where you agree to it, source-code and infrastructure access during an engagement. These providers process data on our instructions and under their own contractual and security commitments.

Some of these providers operate outside India. Where information is transferred across a border, it is transferred under the safeguards those providers offer for such transfers.

We will tell you which providers are involved in your engagement if you ask, and we will agree in the engagement letter to any restriction you need on where your data may be processed.

05

Retention

Enquiries that do not become engagements are kept for twelve months and then deleted.

Engagement records — the report, the scope, and the correspondence — are kept for as long as we need them to support you, and afterwards for the period our legal and accounting obligations require.

Credentials, access tokens and any data extracted during testing are destroyed once the engagement and its retest window close. We do not keep them as reference material.

06

Security

We apply technical and organisational safeguards proportionate to the sensitivity of what we hold: encryption at rest and in transit, access limited to the people working on your engagement, and multi-factor authentication on the systems that hold client material.

No system can be guaranteed secure, and we will not claim otherwise. If a breach affects your information, we will tell you and the relevant authority as the law requires, and we will tell you what we know rather than waiting until we know everything.

07

Your rights

You may ask us what personal information we hold about you, ask us to correct it, and ask us to delete it. We will act on the request within a reasonable period, subject to any legal obligation that requires us to retain something.

Send requests to [email protected]. We may need to verify your identity before acting on one.

If you think we have handled your information wrongly, tell us first — we would rather fix it. You retain the right to complain to the relevant data protection authority regardless.

08

Changes and contact

We may update this policy to reflect operational, legal or regulatory change. The date at the top of this page records the last revision, and a material change will be described there rather than made quietly.

Questions about this policy go to [email protected]. Reports of a vulnerability in our own systems go to [email protected] — see the disclosure policy for how we handle them.