// Compliance
Terms of Service.
Last updated: July 19, 2026. Legal framework and rules of engagement governing our assessments.
1. Authorization and Scoping
By executing a Statement of Work (SOW), the client grants SDX Shadow Labs explicit authorization to perform security testing on the target systems, hosts, networks, and environments specified in the SOW.
For white-box engagements and architecture reviews, this authorization explicitly includes granting temporary, read-only access to proprietary source code repositories, cloud platforms (e.g., AWS, GCP, Azure), and internal infrastructure configurations.
The client represents and warrants that they own, control, or have obtained all necessary third-party permissions (including from hosting providers or cloud operators) for the target systems before active testing begins.
2. Rules of Engagement
All active testing is performed within a defined legal scoping window under strict operational parameters:
- We do not perform Denial of Service (DoS/DDoS) attacks unless specifically requested and explicitly authorized in writing.
- We do not target client employees via social engineering (phishing) unless explicitly scoped in the SOW.
- In the event of accidental data corruption, system instability, or service disruption, active testing is suspended immediately, and the client point-of-contact is notified.
3. Limitation of Liability
Our services are provided on an "as-is" and "as-available" basis. While we apply standard methodologies and rigorous manual validation:
- Security assessments represent a point-in-time review of target environments. We do not guarantee that our assessments will identify every single vulnerability or prevent future breaches.
- In no event shall SDX Shadow Labs be liable for any consequential, indirect, special, or incidental damages (including loss of profits, data corruption, or business interruption).
- Our total cumulative liability under any SOW is strictly limited to the actual fees paid by the client to SDX Shadow Labs for the specific engagement.
4. Payment and Scoping Adjustments
Engagements are billed on a flat-fee basis as defined in the SOW. Any additions to the scope (such as extra endpoints, subdomains, or credentials discovered or requested during the engagement) will be handled via a formal Change Order detailing adjusted flat fees before testing of those targets begins.
5. Coordinated Retesting and Validation
Retesting of Critical and High-severity findings is provided free of charge for Standard and Enterprise tiers. This retest must be requested within 30 days of the delivery of the final report. Retests requested past the 30-day window are subject to additional scoping fees.
6. Governing Law
These Terms of Service and any associated Statement of Work (SOW) shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with these Terms shall be subject to the exclusive jurisdiction of the competent courts located in New Delhi, India, without regard to conflict of law principles.