Central Cybersecurity terms of service establish clear legal boundaries, client obligations, and operational standards for technical consulting, breach response, and digital evidence investigations. By accessing this website or engaging our security engineering team, organizations accept these binding terms governing technical assessments, incident evidence handling, and service liability limits.
Scope of Technical Consulting and Assessment Engagements
Our engineering team delivers vulnerability assessments, penetration testing, network incident response, and forensic data collection under written work orders. Each engagement operates within a defined technical scope agreed upon prior to testing. Findings and evidence packages remain confidential between Central Cybersecurity and the client. Organizations requesting priority emergency incident response must verify that authorized corporate officers permit network isolation, memory dumps, and log collection across affected servers.
Technical evaluations provide an assessment of network security at the time of testing. Security controls do not guarantee permanent protection against unpatched zero-day vulnerabilities or external adversary tactics. Organizations must maintain independent offsite data backups, enforce multi-factor authentication, and apply vendor security patches promptly to preserve system integrity.
Authorized Network Access and Statutory Compliance
Clients requesting security audits or penetration testing must hold documented legal ownership of target IP addresses and cloud infrastructure. Performing automated scans or penetration attempts against third-party networks without authorization violates national computer security laws. Legal provisions governing cognizable cyber offences under Section 77B of the Information Technology Act illustrate the severe legal consequences of unauthorized data interception and system interference.
Website visitors agree not to execute automated scraping scripts, inject malicious payloads, or attempt administrative credential bypasses against this platform. Central Cybersecurity logs security anomalies and reserves the right to block offending IP blocks and report suspicious activities to law enforcement authorities.
Evidence Custody and Data Protection Policies
Handling digital evidence during active breach investigations requires strict chain-of-custody protocols. Forensic images, memory captures, and network traffic dumps gathered during investigations follow recognized forensic standards. Our procedures align with our data protection privacy and cybersecurity framework to prevent unauthorized data exposure during legal discovery or regulatory audits.
Confidential client data is processed on isolated environments equipped with full-disk encryption and strict role-based access controls. We store investigation records only for the duration specified in service contracts or mandated by statutory retention rules. Upon project completion, client network diagrams and sensitive data dumps are purged per secure media sanitation standards.
Intellectual Property Rights and Written Work Products
All proprietary threat detection scripts, assessment frameworks, custom vulnerability tools, and methodology documents created by Central Cybersecurity remain our exclusive intellectual property. Clients receive a perpetual, non-exclusive internal license to use final security reports, audit documentation, and remediation plans generated for their specific organization.
Reproduction or distribution of our proprietary assessment tools or methodology to third parties without prior written consent is strictly prohibited. Final reports may be submitted to regulatory bodies or insurance underwriters to demonstrate compliance status.
Limitation of Liability and Governing Jurisdiction
Central Cybersecurity limits its financial liability for direct or indirect losses, business interruption, or data corruption to the total fee amount received for the specific service module giving rise to the claim. We are not liable for losses resulting from pre-existing system compromises, unapproved client configuration changes, or failure by client staff to implement recommended critical patches.
Statutory notifications issued by the Ministry of Electronics and Information Technology guidelines govern regulatory framework requirements for technical security providers across India. All legal disputes arising under these terms fall under the exclusive jurisdiction of the competent courts in Bangalore, Karnataka.
