Skip to main content

// Compliance

Terms of Service.

Last updated: July 23, 2026. Legal framework and rules of engagement governing our assessments.

These Terms of Service ("Terms") govern access to and use of the website located at sdxshadowlabs.com (the "Site"), the free tools made available on the Site, and any security engagement entered into with SDX Shadow Labs ("SDX Shadow Labs," "the Firm," "we," "us," or "our"). By accessing the Site or engaging our services, you ("you," "the Client," or "User") agree to be bound by these Terms.

Note on legal entity: SDX Shadow Labs is currently operated under Shivam, and is in the process of formal incorporation. All references to "the Firm" in this document refer to this operating entity and its founders acting on its behalf. This section will be updated with full corporate registration details upon completion of incorporation.

1. Definitions

  • "Engagement" means any paid security assessment (penetration test, audit, architecture review, or SDLC consulting engagement) governed by a signed Statement of Work (SOW).
  • "Authorization Documents" means the Non-Disclosure Agreement (NDA), Master Services Agreement (MSA), Statement of Work/Rules of Engagement (SOW/RoE), and Letter of Authorization (LoA) executed prior to any Engagement.
  • "Free Tools" means any tool provided on the Site at no cost, including the security scanner, that does not require a signed Engagement.
  • "Target System" means any domain, application, host, or infrastructure submitted for testing, whether through an Engagement or a Free Tool.

2. Nature of Our Services

SDX Shadow Labs is a boutique offensive security consulting firm providing manual penetration testing, security auditing, secure architecture consulting, and Secure SDLC advisory services. We do not sell or resell automated scanning software; our commercial engagements are delivered as human-led professional services.

2.1 Scope of Deliverables: Deliverables for commercial engagements currently consist of technical security audit reports, vulnerability findings, Proof-of-Concept (PoC) evidence, and remediation verification reports. To validate the engagement, we issue our own Security Audit Completion Certificate to serve as technical proof of assessment and remediation. Current reports are delivered for internal risk management, engineering security posture improvement, and technical security evaluation.

Use of the Site, including reading our published research or requesting a scoping call, does not by itself create a client relationship, a contract for services, or any authorization to conduct testing.

3. Eligibility and Business Use

Our services are intended for business use by organizations (or individuals acting on behalf of an organization) that lawfully own, operate, or have documented authorization over the Target Systems in question. We do not knowingly provide services to individuals under the age of 18, and we do not knowingly collect information from minors (see our Privacy Policy).

4. Engagement Authorization and Scoping

4.1 No active security testing of any kind is performed under a commercial Engagement until all four Authorization Documents - NDA, MSA, SOW/RoE, and LoA - have been signed by an authorized representative of the Client.

4.2 By executing an SOW, the Client grants SDX Shadow Labs explicit, written authorization to perform the specific testing activities, against the specific Target Systems, described in that SOW - and no others.

4.3 For white-box engagements and architecture reviews, this authorization may include temporary, read-only access to source code repositories, cloud environments (AWS, GCP, Azure), and infrastructure configuration, strictly for the duration and purpose of the Engagement.

4.4 The Client represents and warrants that it owns, controls, or has obtained all necessary third-party permissions (including from hosting providers, cloud operators, or upstream vendors) for every Target System listed in the SOW, prior to the commencement of active testing. The Client agrees to indemnify SDX Shadow Labs against any claim arising from a breach of this warranty.

5. Rules of Engagement

All active testing under a signed SOW is conducted within a defined scoping window and subject to the following constraints unless the SOW explicitly states otherwise in writing:

  • No Denial of Service (DoS/DDoS) testing.
  • No social engineering (phishing, pretexting, physical intrusion) of Client personnel.
  • No testing of out-of-scope assets, including third-party services and production payment paths, unless specifically listed as in-scope in the SOW.
  • If accidental service disruption, data corruption, or system instability occurs, active testing is suspended immediately and the Client's designated emergency contact is notified without delay.

6. Free Security Scanner - Acceptable Use and Authorization

SDX Shadow Labs provides a free, self-service external exposure scanner on the Site (the "Scanner"). The Scanner is a passive, non-intrusive tool and is provided for general informational and educational purposes.

6.1 What the Scanner does. The Scanner performs read-only checks equivalent to a standard web browser request or public DNS lookup: HTTP response header inspection, TLS/SSL certificate analysis, DNS record resolution, and checks for the public accessibility of commonly known file paths. It does not attempt to exploit, bypass, brute-force, inject payloads into, or gain unauthorized access to any system.

6.2 What the Scanner does not do. The Scanner does not perform active exploitation, credential attacks, fuzzing, denial-of-service testing, or any technique intended to alter, damage, or gain elevated access to a Target System.

6.3 User representation. By submitting a domain to the Scanner, you represent and warrant that you own, operate, or otherwise have the right to request a passive exposure check of that domain. SDX Shadow Labs is not responsible for verifying ownership prior to a scan, and you assume sole responsibility for the domains you submit.

6.4 No guarantee of completeness. Results from the Scanner are illustrative and preliminary. They are not a substitute for a manual security assessment and should not be relied upon as a complete or authoritative statement of a system's security posture.

7. Intellectual Property

7.1 All content on the Site - including text, graphics, the SDX Shadow Labs name and logo, published research advisories, case studies, and blog content - is the property of SDX Shadow Labs and is protected under applicable copyright and trademark law, unless otherwise credited.

7.2 For paid Engagements: the final deliverable report is owned by the Client upon full payment. SDX Shadow Labs retains ownership of its underlying methodologies, proprietary tooling, testing frameworks, and any generic (non-client-specific) techniques used to produce that report.

7.3 You may not reproduce, redistribute, or create derivative works from Site content, including research advisories, without prior written permission, except for personal reference or with proper attribution for editorial/news purposes.

8. Confidentiality

SDX Shadow Labs treats all Client architecture, data, and findings arising from an Engagement as confidential, governed by the mutual NDA executed prior to scoping. We do not publicly disclose Client identities, findings, or engagement details without separate written consent, except as described in Section 9 (Responsible Disclosure).

9. Responsible Disclosure and Research Publications

Research advisories published on the Site (`/research`) describe vulnerabilities identified through the Firm's independent security research, disclosed and remediated under a coordinated responsible disclosure process:

  • The affected organization is notified privately upon discovery of the vulnerability.
  • A reasonable remediation window is provided before any public advisory is released.
  • Public advisories are published only after confirmed remediation, and are written to avoid enabling exploitation of any residual risk.
  • Organizations are not publicly named unless they have consented to be identified.

If you believe a published advisory contains an error, or you are a represented organization with a concern about a specific advisory, contact us using the details in Section 20.

10. Fees and Payment

10.1 Engagements are billed on a flat-fee basis as defined in the applicable SOW. Pricing tiers published on the Site are baseline indicators strictly limited to a standard scope of up to One Hundred Thousand (100,000) lines of custom-written source code (inclusive of API endpoints) per repository, and a maximum of five (5) server services. Environments exceeding this baseline will require a custom Enterprise scoping assessment and are not eligible for standard advertised tier pricing.

10.2 Any expansion of scope discovered or requested during an Engagement (additional endpoints, subdomains, environments, or credentials) will be handled through a formal Change Order specifying adjusted fees, agreed in writing before testing of the additional scope begins.

10.3 Payment terms, invoicing schedules, and late payment provisions are set out in the Master Services Agreement (MSA).

11. Warranties and Disclaimers

11.1 The Site and Free Tools are provided on an "as-is" and "as-available" basis, without warranties of any kind, express or implied, including fitness for a particular purpose or non-infringement.

11.2 Paid Engagements are delivered using industry-standard manual testing methodologies applied by qualified personnel. However, a security assessment represents a point-in-time evaluation. SDX Shadow Labs does not guarantee the identification of every vulnerability, nor does it guarantee that a Target System will not be subsequently compromised.

12. Limitation of Liability

12.1 To the maximum extent permitted by law, SDX Shadow Labs shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, business, or goodwill, arising out of or related to use of the Site, the Free Tools, or any Engagement.

12.2 SDX Shadow Labs' total cumulative liability arising out of any Engagement is strictly limited to the total fees actually paid by the Client for that specific Engagement.

12.3 Nothing in these Terms limits liability for gross negligence, willful misconduct, or fraud, where such limitation is not permitted under applicable law.

13. Indemnification

You agree to indemnify, defend, and hold harmless SDX Shadow Labs, its operators, and personnel from any third-party claim, loss, or liability arising from: (a) your breach of these Terms; (b) your submission of a Target System you did not have authorization to test or scan; or (c) your misuse of the Site or Free Tools.

14. Coordinated Retesting and Validation

Retesting of Critical and High-severity findings is included at no additional charge for Standard and Enterprise tier Engagements, provided the retest is requested within 30 days of final report delivery. Requests made after this window may be subject to additional scoping fees.

15. Termination

15.1 Either party may terminate an active Engagement in accordance with the termination provisions of the MSA, generally requiring written notice and settlement of fees for work completed to date.

15.2 SDX Shadow Labs reserves the right to suspend or terminate access to the Site or Free Tools for any user reasonably suspected of misusing them, including submitting domains without authorization or attempting to circumvent the passive-only limitations described in Section 6.

16. Force Majeure

Neither party shall be liable for delay or failure to perform obligations under these Terms due to causes beyond its reasonable control, including natural disaster, war, civil unrest, internet or infrastructure outage, or governmental action.

17. Changes to These Terms

We may update these Terms from time to time to reflect changes in our services, legal requirements, or operational practices. The "Last updated" date at the top of this page will reflect the most recent revision. Continued use of the Site after changes take effect constitutes acceptance of the revised Terms. Material changes affecting active Engagements will be communicated directly to affected Clients.

18. Governing Law and Dispute Resolution

18.1 These Terms, and any Engagement entered into under them, are governed by and construed in accordance with the laws of India.

18.2 The parties will first attempt to resolve any dispute through good-faith negotiation. If unresolved within 30 days, the dispute shall be subject to the exclusive jurisdiction of the competent courts located in New Delhi, India, unless the applicable MSA specifies binding arbitration.

19. Miscellaneous

  • Severability: If any provision of these Terms is found unenforceable, the remaining provisions remain in full effect.
  • Assignment: Client may not assign an Engagement without our written consent. SDX Shadow Labs may assign its rights in connection with a merger, acquisition, or sale of assets.
  • Entire Agreement: For paid Engagements, these Terms operate alongside the signed NDA, MSA, SOW/RoE, and LoA, which together constitute the entire agreement between the parties for that Engagement.
  • No Waiver: Failure to enforce any provision of these Terms does not constitute a waiver of that provision.

20. Contact

Questions about these Terms can be directed to:
SDX Shadow Labs
Email: contact@sdxshadowlabs.com