SHELL INFOSEC

Terms of Service

The legal agreement governing security assessments, penetration testing missions, cloud architecture consulting, sovereign AI implementations, and use of the SHELL INFOSEC website.

Safe Harbor
Authorized Testing
Mutual NDA
Strict Secrecy
IP Protection
Client Ownership
Arbitration
New Delhi Seat
Effective Date: September 14, 2026
Operating Seat: New Delhi, India
Legal Counsel: [email protected]

1. Acceptance of Terms & Contracting Entity

These Master Terms of Service (“Terms”) constitute a legally binding agreement entered into between the commercial entity, enterprise, or agency engaging our services (“Client”, “you”, or “your”) and SHELL INFOSEC (“Company”, “we”, “us”, or “our”), registered under the Ministry of Micro, Small and Medium Enterprises (MSME), Government of India, bearing registration number UDYAM-DL-09-0012062, with headquarters in New Delhi, Republic of India.

By commissioning our cybersecurity audits, signing a Statement of Work (SOW), executing an enterprise service contract, or accessing our platforms, you certify that you possess full legal and corporate authority to bind your organization to these Terms. If you do not have such authority, or if you do not agree to these Terms, you must not access our platforms or authorize any technical engagement.

2. Scope of Services & Statements of Work

SHELL INFOSEC provides specialized technical and advisory services spanning four primary domains:

  • Offensive Cybersecurity & Penetration Testing: Full-scope vulnerability assessments, web application penetration tests, mobile application security evaluations (iOS and Android), network infiltration simulations, cloud configuration audits (AWS, GCP, Azure), API security analysis, and manual source code audits.
  • Cloud Architecture & Infrastructure Engineering: Zero-trust network topologies, multi-region Kubernetes clusters, automated CI/CD security pipelines, infrastructure-as-code (Terraform, Ansible), and high-concurrency bare-metal server cluster management.
  • Sovereign AI & Autonomous Systems: Private on-premise Large Language Model (LLM) fine-tuning, Retrieval-Augmented Generation (RAG) vector pipelines, Model Context Protocol (MCP) agent integrations, and private neural inference clusters.
  • High-Assurance Software Engineering: Bespoke platform engineering, defensive software development, mission-critical API services, and real-time streaming architectures.

Each individual project engagement shall be documented in a written Statement of Work (“SOW”) executed by authorized representatives of both parties. Each SOW shall specify the exact scope, target IP addresses, application URLs, deliverables, timelines, access credentials, and compensation. If an explicit conflict arises between an executed SOW and these Terms, the SOW shall take precedence solely regarding the specific engagement it governs.

3. Rules of Engagement & Legal Safe Harbor

Because our offensive penetration testing and vulnerability research activities simulate real-world adversarial attacks, the following legal conditions and mutual covenants apply to all security testing operations:

A. Explicit Authorization to Test

Client warrants and represents that it possesses all requisite ownership, licenses, and rights to authorize SHELL INFOSEC to conduct offensive testing against the systems, networks, hostnames, and IP ranges designated in the applicable SOW. If the target assets are hosted on third-party cloud infrastructure (such as AWS, Google Cloud, Microsoft Azure, or a managed co-location facility), Client warrants that it has secured all necessary penetration testing permissions from said hosting providers.

B. Legal Safe Harbor Covenant

Client covenants that it will not initiate legal proceedings, file criminal complaints, or assert civil claims under Section 43 or Section 66 of the Indian Information Technology Act, 2000, the U.S. Computer Fraud and Abuse Act (18 U.S.C. 1030 - CFAA), or equivalent foreign cybercrime statutes against SHELL INFOSEC or its security personnel for actions conducted in good faith within the agreed Rules of Engagement.

C. Boundaries & Defensive Restraint

Unless explicitly agreed in writing under specialized Red Team Rules of Engagement, SHELL INFOSEC will not deliberately execute destructive denial-of-service attacks, physically breach corporate facilities, execute unauthorized extortion/ransomware simulations, or permanently alter or destroy client production databases. If an exploit reveals immediate risk of data corruption, our researchers immediately cease testing and notify Client within two (2) hours.

4. Client Cooperation & Security Responsibilities

Timely and successful execution of our engagements requires active client cooperation:

  • Designated Technical Liaison: Client shall designate a primary technical point of contact authorized to make operational decisions, adjust firewalls, and address urgent inquiries during testing hours.
  • Access Provisioning & Whitelisting: Client shall provide testing accounts, API tokens, staging environments, and firewall/WAF bypass configurations in a timely manner. Delays in access provisioning shall automatically extend project milestone deadlines.
  • Backup & Disaster Recovery: Client remains solely responsible for maintaining current, verifiable backups of all target systems and databases prior to commencement of active testing.
  • Immediate Credential Rotation: Client agrees to revoke and rotate all test credentials, temporary API keys, and testing access tokens immediately upon receipt of our final vulnerability assessment report.

5. Bilateral Confidentiality & Non-Disclosure

Given the highly sensitive nature of cybersecurity assessments and infrastructure blueprints, both parties agree to strict confidentiality obligations:

Scope of Confidential Information: Confidential Information includes all non-public technical data, source code, vulnerability findings, exploit payloads, penetration testing reports, architectural diagrams, business plans, and financial terms shared between the parties.

Standard of Care: Each party agrees to safeguard the other’s Confidential Information using at least the same degree of care it uses for its own most sensitive assets, but never less than reasonable commercial care. Access shall be limited strictly to personnel and cleared contractors with a genuine need to know who are bound by written confidentiality agreements at least as protective as these Terms.

Duration of Secrecy: Confidentiality obligations regarding vulnerability reports, security findings, and client source code shall endure perpetually, and for all other Confidential Information, for a period of five (5) years following termination of the applicable SOW.

6. Intellectual Property Ownership

Client Deliverables Ownership

Upon full payment of all invoiced fees, Client shall own all right, title, and interest in the customized final deliverables produced specifically for Client under an executed SOW, including written vulnerability assessment reports, architectural remediation guides, and custom client software builds.

Firm Background Technology & Methodologies

SHELL INFOSEC retains sole and exclusive ownership of all pre-existing tools, proprietary testing scripts, automated scanner harnesses, machine learning models, custom exploits, standard code libraries, and technical methodologies (“Background IP”). To the extent Background IP is embedded within deliverables, SHELL INFOSEC grants Client a perpetual, non-exclusive, royalty-free, worldwide license to use such Background IP solely for Client’s internal business operations.

7. Commercial Terms, Invoicing & Payment

Fees for our security missions and engineering deliverables shall be set forth in the applicable Statement of Work:

  • Payment Milestones: Standard engagements require an initial mobilization deposit (typically 40%–50%) upon SOW execution, with remainder due upon delivery of final reports and remediation debrief.
  • Payment Window: Invoices are payable within fifteen (15) calendar days from receipt, unless otherwise stated in the applicable SOW.
  • Applicable Taxes: All stated fees are exclusive of applicable taxes. For services delivered within India, Goods and Services Tax (GST) will be charged at the statutory rate. For international cross-border clients, services are zero-rated exports under Indian GST regulations against valid export documentation.
  • Late Payments: Undisputed overdue amounts accrue interest at the rate of 1.5% per month or the maximum statutory rate permitted under Indian commercial law, whichever is lower.

8. Warranties & Technical Disclaimers

SHELL INFOSEC warrants that all services will be executed in a professional, diligent manner in conformance with recognized cybersecurity industry standards (including OWASP, NIST SP 800-115, and PTES).

Critical Security Disclaimer

Client explicitly acknowledges that cybersecurity is an evolving domain. A vulnerability assessment or penetration test reflects the security posture of the target system solely at the specific time of testing. Successful completion of an assessment does not guarantee that the target system is completely impenetrable, immune from future vulnerabilities, or free from unknown zero-day exploits not present in public intelligence databases at the time of review.

EXCEPT AS EXPRESSLY STATED HEREIN, ALL SERVICES ARE PROVIDED “AS IS” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

9. Limitation of Liability

A. Exclusion of Consequential Damages

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, EXEMPLARY, OR CONSEQUENTIAL DAMAGES, INCLUDING LOSS OF PROFITS, LOSS OF DATA, SYSTEM DOWNTIME, BUSINESS INTERRUPTION, OR GOODWILL LOSS, REGARDLESS OF THE THEORY OF LIABILITY.

B. Aggregate Liability Cap

EXCEPT FOR WILLFUL MISCONDUCT, GROSS NEGLIGENCE, OR BREACH OF SECTION 5 (CONFIDENTIALITY), EACH PARTY’S MAXIMUM AGGREGATE LIABILITY UNDER THESE TERMS OR ANY SOW SHALL BE STRICTLY LIMITED TO THE TOTAL FEES ACTUALLY PAID BY CLIENT TO SHELL INFOSEC UNDER THE SPECIFIC STATEMENT OF WORK GIVING RISE TO THE CLAIM DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT.

10. Regulatory Compliance & Data Governance

Both parties agree to comply with all applicable data protection laws governing personal data handled in connection with services:

  • Indian DPDP Act, 2023: Both parties shall implement technical safeguards under Section 8(5) and adhere to notice, consent, and grievance redressal standards.
  • EU GDPR: Where personal data of EU residents is processed, the parties shall execute an Article 28 Data Processing Addendum incorporating Standard Contractual Clauses (SCCs).
  • U.S. HIPAA: Where systems handle electronic Protected Health Information (ePHI), the parties shall execute a formal Business Associate Agreement (BAA) prior to commencing active review.

11. Term, Termination & Data Sanitization

These Terms remain in effect until terminated in writing by either party:

Termination for Cause

Either party may terminate an SOW or these Terms immediately upon written notice if the other party materially breaches any provision and fails to cure such breach within fourteen (14) calendar days of receiving written notice thereof.

Mandatory Data Sanitization Post-Termination

Within fourteen (14) calendar days following completion of services or termination of an SOW, SHELL INFOSEC will securely purge and cryptographically wipe all temporary test environments, raw packet captures, test credentials, and staging database exports following NIST SP 800-88 Rev 1 guidelines.

12. Governing Law, Seat & Dispute Resolution

These Terms and any dispute or claim arising out of or in connection with them shall be governed by and construed in accordance with the substantive laws of the Republic of India, without regard to its conflict of law principles:

Good Faith Negotiation: In the event of any dispute, controversy, or claim, the parties shall first attempt in good faith to resolve the matter through executive negotiation between authorized corporate officers within thirty (30) days.

Binding Arbitration: If the dispute is not resolved through negotiation, it shall be referred to and finally resolved by binding arbitration under the Arbitration and Conciliation Act, 1996 of India. The arbitral tribunal shall consist of a sole arbitrator mutually appointed by both parties.

Seat, Venue & Language: The legal seat and venue of arbitration shall be New Delhi, India. The language of arbitration proceedings shall be English. The arbitral award shall be final, binding, and enforceable in any court of competent jurisdiction worldwide.

Exclusive Judicial Jurisdiction: Subject to the arbitration clause above, the courts located in New Delhi, India shall have exclusive jurisdiction over any legal proceedings arising hereunder.

13. Corporate Legal Contacts

All formal legal notices, breach escalations, and contractual inquiries should be delivered to our corporate headquarters:

Contracting Firm: SHELL INFOSEC
MSME Registration: UDYAM-DL-09-0012062
Corporate Office: New Delhi, Delhi 110001, Republic of India
Legal Counsel Email: [email protected]
Compliance Desk: [email protected]
Telephone Contact: +91 99119 48198
Engagement & Contracts

Execute a Custom SOW or Bilateral NDA

Our contracts and technical leadership team coordinates directly with enterprise procurement, external legal counsel, and chief information security officers to establish tailored Statements of Work and mutual non-disclosure agreements.

Legal Counsel[email protected]
General Desk[email protected]
Telephony+91 99119 48198