Terms of Service
These terms explain how PoCForge (Cyber Security) provides remote offensive-security and vulnerability assessment / penetration testing (VAPT) services. They apply to use of https://pocforge.com and to commercial engagements unless a signed statement of work (SoW) or other written agreement says otherwise.
Last updated: 30 September 2026 · Contact: [email protected]
1. Who we are
References to PoCForge (Cyber Security), we, us or our mean the PoCForge (Cyber Security) practice operating this website and delivering security-testing services. References to you or client mean the organisation or individual requesting or receiving services, or using this website.
These pages describe general terms for a boutique remote offensive-security / VAPT practice serving clients in India and internationally. Specific commercial, technical and legal details for an engagement are set out in the applicable quote, SoW, rules of engagement (RoE) or other written agreement.
2. Website use
You may browse this website for lawful information about PoCForge (Cyber Security) services. You must not misuse the site (for example by attempting unauthorised access, disrupting availability, scraping in a way that harms the service, or using content to misrepresent an affiliation with PoCForge (Cyber Security)).
Website content is provided for general information. It is not a substitute for a scoped engagement, legal advice, or a guarantee of any particular security outcome.
3. Services and engagement model
PoCForge (Cyber Security) offers human-led security assessments which may include, depending on scope: web application testing, API security testing, mobile testing, cloud assessment, external infrastructure testing, internal / identity-focused testing, desktop / thick-client testing, AI / LLM-related testing, related advisory work, reporting and retest of agreed remediated findings.
Engagements are typically remote. Deliverables, timelines, environments, test accounts, inclusions, exclusions and commercial terms are defined in the SoW or equivalent written scope. Where marketing pages mention indicative pricing, those figures are guidance only; the final fee is as quoted for your scope.
4. Authorised testing only
PoCForge (Cyber Security) only tests systems you are authorised to have tested. By engaging us you represent that:
- you own the in-scope assets, or have written authority from the owner / controller to permit testing;
- you have identified production constraints, third-party hosted components, and any systems that must be excluded;
- you will not ask PoCForge (Cyber Security) to access, attack or exfiltrate data outside the agreed RoE.
Testing without proper authorisation may be unlawful. We may pause or decline work if authority, scope or RoE are unclear or appear insufficient.
5. Scope, rules of engagement and changes
Before active testing we agree (in writing, which may include email) the scope and RoE. That typically covers:
- in-scope hosts, applications, APIs, accounts, roles and environments;
- out-of-scope systems and prohibited techniques (for example denial-of-service, social engineering, or destructive actions, unless expressly authorised);
- testing windows, rate limits, emergency contacts and escalation paths;
- data handling expectations for evidence and findings.
Material scope changes may require an updated quote or change order. Findings outside the agreed scope are not automatically included unless we agree in writing to expand the engagement.
6. Client responsibilities
You agree to provide timely access, test credentials, architecture context and decision-makers needed for the engagement; to maintain appropriate backups and change control for in-scope systems; and to review draft findings and remediation guidance in good faith. Delays in access or feedback may affect timelines.
7. Confidentiality
Each party must keep the other party’s confidential information confidential and use it only for the engagement, except where disclosure is required by law or with prior written consent. Engagement artefacts (reports, evidence, credentials shared for testing) are confidential.
PoCForge (Cyber Security) may retain engagement records as needed for quality, dispute handling and legal compliance, under appropriate access controls. Public case studies or marketing references are used only with your prior written approval (or in anonymised form where we have agreed that approach).
8. Quotes, fees and payment
Quotes are based on the information you provide and remain valid for the period stated (or 30 days if none is stated), unless withdrawn earlier. Fees, currency, taxes (including GST where applicable), payment milestones and invoicing details are as set out in the quote or SoW.
Unless otherwise agreed in writing, invoices are payable within the stated payment terms. Late or non-payment may result in suspension of remaining work (including retest) after notice. Work already performed remains chargeable.
9. Intellectual property
Subject to payment of applicable fees and except for third-party materials, you receive a licence to use the engagement report and agreed deliverables for your internal security, compliance and remediation purposes. PoCForge (Cyber Security) retains ownership of its methodologies, templates, tools, know-how and pre-existing materials.
You retain ownership of your systems, data and materials. Credentials and access you provide remain yours; we use them only as needed for the engagement.
Website text, branding and design are owned by PoCForge (Cyber Security) or its licensors. You may not copy substantial site content for competing commercial use without permission.
10. No guarantee of complete security
Security testing is time-bound and scope-bound. A clean or limited findings list does not mean systems are free of vulnerabilities. Attack techniques, dependencies and configurations change. You remain responsible for operating security, patching, monitoring and residual risk acceptance.
11. Limitation of liability
To the fullest extent permitted by applicable law:
- PoCForge (Cyber Security) is not liable for indirect, incidental, special, consequential or punitive losses, or loss of profits, revenue, goodwill, data or business opportunity, arising from the website or services;
- PoCForge (Cyber Security)’s aggregate liability arising out of a particular engagement is limited to the fees paid for that engagement in the twelve (12) months before the claim, except where liability cannot be limited by law (for example fraud or wilful misconduct);
- nothing in these terms excludes liability that cannot lawfully be excluded.
Where a signed SoW or master agreement sets different liability terms, those written terms prevail for that engagement.
12. Indemnity (authorisation)
You agree to indemnify and hold PoCForge (Cyber Security) harmless against claims arising from testing carried out within the agreed scope and RoE where you lacked authority to authorise that testing, or from your misuse of report contents, except to the extent caused by PoCForge (Cyber Security)’s wilful misconduct.
13. Compliance and export / sanctions
Each party must comply with laws applicable to it in connection with the engagement. You are responsible for informing us of material regulatory constraints that affect testing (for example data residency or production change freezes). We do not claim any particular government empanelment or certification on these pages; verify any procurement requirement against official registers and the SoW.
14. Governing law and disputes
Unless a signed SoW or other written agreement specifies different governing law or dispute resolution terms, these Terms and any non-contractual obligations arising from them are intended to be interpreted under the laws of India, and the parties will first attempt in good faith to resolve disputes by discussion. Courts or arbitration venues, if not agreed in the SoW, should be confirmed in writing before engagement kickoff for cross-border work.
Where international clients require different governing law, that must be stated in the SoW.
15. Changes to these terms
We may update these Terms of Service by publishing a revised version on this page with an updated “Last updated” date. Material changes to an active engagement are handled through the SoW / change process for that engagement, not by website update alone.
16. Contact
Questions about these terms: [email protected]. Related: Privacy Policy, Contact.
Ready to scope an assessment?
Share a short brief — we will help define authorised scope and RoE.
