These terms govern use of this website, and they describe how we agree and run work where no separate contract exists yet. A signed engagement letter or statement of work always takes precedence over this page.
1. Who we are
Dunime ("we", "us", "our") is a technology company operating from Delhi NCR, India. We build custom SaaS, web platforms, dashboards and business automation, and we do cybersecurity work: security architecture and implementation, cyber audits, and vulnerability assessment and penetration testing.
Dunime Technologies Private Limited, CIN U62020DC2026PTC473332, a private limited company operating from Delhi NCR, India. These terms apply to this website and to work carried out under an engagement letter or statement of work signed with us.
2. What these terms cover
Sections 3 and 17 apply to anyone who visits this website. The rest applies to clients, and only where a signed engagement letter or statement of work does not say something different. Where the two conflict, the signed document wins, every time.
Nothing on this website is an offer capable of acceptance. Prices, timelines and capabilities described anywhere on this site are indicative until they appear in a document we have both signed.
3. Using this website, and reporting a problem with it
This site is provided for information. Do not attempt to gain unauthorised access to it or to the systems behind it, and do not use it to distribute unlawful material. In India, unauthorised access to a computer resource is actionable under section 43 of the Information Technology Act 2000 and an offence under section 66. That is not a threat; it is the reason the paragraph below exists.
Responsible disclosure. If you find a vulnerability in this website, we want to hear about it. Email director@dunime.com with enough detail to reproduce it, and give us a reasonable chance to fix it before you publish. In return, provided you stay within the boundaries below, we will not treat your research as unauthorised and we will not pursue legal action over it.
The boundaries: no denial-of-service or load testing; no social engineering of our people or our suppliers; no accessing, copying, altering or deleting data that is not your own; stop as soon as you have proof a flaw exists rather than pressing further; no automated scanning heavy enough to degrade the service for others; and nothing that would break the law regardless of our permission. Testing against our clients' systems is never covered by this section.
We do not run a paid bug bounty.
4. How work is agreed
Work is performed under a written engagement letter or statement of work that sets out the scope, the deliverables, the milestones, the fees and what acceptance means. Anything outside that document is out of scope until it is added to it in writing.
Changes to scope are agreed in writing before the work is done, along with their effect on price and date. We would rather have an awkward conversation early than deliver something nobody agreed to.
6. What we need from you
By instructing us, you confirm that you own the systems in scope or are authorised to have them tested, that you have taken your own backups, and that you accept testing carries a real if small risk of disruption to a live system. Where you want that risk near zero, we test a staging environment instead, and we will say so plainly if that limits what the results are worth.
You also agree to give us accurate information about the environment. A test run against a description that is out of date produces findings that are out of date.
7. What a report from us is, and what it is not
A report describes what we found, in the scope we were given, in the window we were given, against the systems as they stood at that moment. Change the code, the configuration or the threat and the findings age immediately.
No test finds every vulnerability, and no honest provider claims otherwise. A clean report means we did not find a problem within that scope and window. It does not mean there is none.
Our reports are not certificates of compliance and are not accredited certifications. We are not a certification body. Where you need a certificate that carries accreditation, we prepare you for it and work alongside the body entitled to issue it. See the Regulatory status page for what we do and do not claim.
8. Fees and payment
Fees, the payment schedule and what triggers each payment are set in the engagement letter or statement of work, and agreed before any work begins. Scope, currency, tax treatment and payment terms differ by engagement, so they are stated in that document rather than published here. We do not invoice for anything that is not in it. Where an engagement is priced against a fixed scope, a change to the scope is agreed in writing, and priced, before the work is done.
9. Intellectual property
Ownership of what an engagement produces is set in the engagement letter or statement of work, and agreed before work begins. It differs by engagement, so it is settled in that document rather than assumed from this page. Where we use third-party or open-source components, they are listed in the handover with their licences, so nothing arrives carrying a claim you did not know about.
10. Confidentiality, and the one exception
Each party protects the other's confidential information and uses it only for the engagement. Findings, evidence and reports produced during an audit or a test are confidential to the client. We do not name clients publicly without written permission, and we do not use findings from one engagement as marketing material for the next.
The exception worth stating in advance, so it is never a surprise: some disclosures are compelled by law and confidentiality cannot override them. As a body corporate in India we are subject to CERT-In's directions of April 2022, which require certain cyber incidents to be reported to CERT-In within six hours of being noticed. Where the DPDP Act applies to a personal data breach, notification duties to the Data Protection Board of India and to affected individuals apply as well. We will tell you if we have to make such a report, unless we are lawfully prevented from telling you.
11. Personal data
Where an engagement involves personal data, you are the Data Fiduciary under India's Digital Personal Data Protection Act 2023 and we are a Data Processor acting on your documented instructions. Under the GDPR the equivalent terms are controller and processor. Section 8(2) of the DPDP Act requires that arrangement to sit on a valid contract, so a data processing agreement forms part of the engagement.
For clients in the European Union, that agreement needs to meet Article 28 of the GDPR, and transfers to us rely on Standard Contractual Clauses because India holds no adequacy decision. How we treat personal data of our own is set out in the Privacy Policy.
Where we can do the work without live personal data, we will ask for masked or synthetic data instead. It is usually enough, and it lowers the stakes for both of us.
12. Warranties and liability
We warrant that we will perform the work with reasonable skill and care, by people competent to do it. We do not warrant that any system will be free of vulnerabilities, or that a system we have tested cannot be compromised. Security work reduces risk. It does not remove it, and any provider who tells you otherwise is selling something.
We warrant that the work is carried out with the skill and care expected of a competent practitioner in this field, and that we hold the rights needed to deliver what we deliver. We do not warrant that any system is free of vulnerabilities: no assessment finds everything, and a report describes a system as it stood on the dates tested. Our total liability under an engagement is limited to the fees paid for it, and the engagement document may set a different limit where the parties agree one. Nothing here limits liability that cannot lawfully be limited.
13. Suspension and termination
We will suspend or stop work immediately, without waiting for notice periods, if we come to believe the authority to test does not exist, if continuing would be unlawful, or if continuing would put a third party at serious risk. We will explain why.
Either party may end an engagement in writing on the notice stated in the engagement document. Work completed up to that point is payable, and anything already produced and paid for is handed over. Where we hold credentials or access to your systems, they are surrendered or revoked at the point work stops.
14. Governing law and disputes
These terms, and any engagement made under them, are governed by the laws of India. The courts at Delhi have jurisdiction.
15. Changes to these terms
We may update this page. The date at the top is the date of the version you are reading. Changes do not alter a signed engagement, which can only be varied the way that document says it can.
16. Contact
Questions about these terms, and security reports under section 3, go to director@dunime.com. It is the only address we use.
Questions about these terms, or about an engagement made under them, should be raised in writing so that both parties have a record of what was asked and what was answered.
This page is written from the primary sources and states the position as at the date above. Where the law changes, this page changes with it.