Draft pending legal review. This text is being finalised with counsel and the highlighted values are not yet filled in. It is published so you can read exactly what the product asks you to accept.
SecQon Terms of Service
Effective date: 27 August 2026 · Version: 2026-08-v1
These Terms of Service (the "Terms") are a binding agreement between Infiqon Private Limited, a company incorporated in India (CIN COMPANY_CIN) with its registered office at REGISTERED_ADDRESS ("Infiqon", "we", "us"), and the person or entity that creates a SecQon account ("Customer", "you").
SecQon performs live security testing against internet-facing systems. That is lawful only where it is authorised. By accepting these Terms you are making promises about your authority to permit that testing, and you are accepting responsibility if those promises turn out to be wrong. Please read Sections 5, 13, 14 and 15 carefully.
1. The agreement
1.1 The agreement between us consists of these Terms together with the Acceptable Use Policy ("AUP") and the Rules of Engagement ("RoE"), each of which is incorporated into these Terms by reference, plus any order, subscription or plan confirmation (collectively, the "Agreement").
1.2 Order of precedence. If there is a conflict, the RoE prevails over these Terms in respect of the conduct and scope of testing; the AUP prevails over these Terms in respect of permitted use; and these Terms prevail in all other respects.
1.3 You must accept all three documents before you may add an asset to SecQon. Acceptance is recorded electronically as described in Section 20.
2. Definitions
- "Asset" — a domain, subdomain, IP address, or API endpoint that you add to SecQon.
- "Verified Asset" — an Asset for which SecQon has successfully confirmed your control using one of its verification methods and whose verification has not lapsed.
- "Authorised Asset" — a Verified Asset that you are lawfully entitled to authorise us to test, as warranted in Section 5.
- "Scan" — any automated activity SecQon directs at an Authorised Asset, including reconnaissance, enumeration, vulnerability testing and validation.
- "Finding" — an issue reported by SecQon, with its evidence.
- "Report" — a document SecQon generates from Findings.
- "Customer Data" — data you submit to SecQon, plus Findings, evidence and Reports relating to your Assets.
- "Service" — the SecQon platform, including the web application, API, scanning engine and Reports.
3. Eligibility and your account
3.1 You must be at least 18 years old and capable of forming a binding contract.
3.2 If you accept the Agreement on behalf of a company or other entity, you represent that you have authority to bind that entity, and "you" means that entity. If you do not have that authority, you must not create an account.
3.3 You must provide accurate registration information, including a genuine business email address and, where requested, verifiable organisation details, and keep them current.
3.4 You are responsible for all activity under your account and for the security of your credentials. Notify us at SECURITY_EMAIL immediately if you suspect unauthorised access.
3.5 We may require additional verification of your identity, your organisation, or your authority over an Asset before enabling or continuing any part of the Service. We may suspend testing until that verification is complete.
4. The Service — what it is and what it is not
4.1 SecQon performs automated, AI-assisted external security assessment. It discovers internet-facing surface, tests it against known vulnerability classes, attempts bounded validation of exploitability, and reports what it finds with evidence.
4.2 SecQon is not a substitute for a manual penetration test, a code review, a threat model, or a professional security audit, and does not on its own constitute certification under SOC 2, ISO 27001, PCI DSS or any other framework. Compliance mappings in Reports are informational aids, not attestations.
4.3 We do not guarantee that SecQon will identify every vulnerability. Automated testing has inherent limits. The absence of a Finding is not evidence that a system is secure.
4.4 Findings are produced by security tooling and deterministic rules. Language models are used to explain, prioritise and write about Findings — never to decide whether a vulnerability exists, its severity, or its identifiers. Nonetheless, Findings may include false positives, and you should validate before acting on any Finding in a production change.
4.5 We may change, improve or discontinue features. We will not make a change that materially reduces the core functionality of a paid plan during a paid term without notice and, where the reduction is material, the option to cancel for a pro-rata refund.
4.6 Availability. We aim for high availability but do not offer a service level guarantee on free plans. Any service level commitment for paid plans will be stated in a separate written service level agreement.
5. Your authorisation warranty — the core promise
This Section is fundamental. We rely on it to operate lawfully.
5.1 You represent, warrant and undertake, on each occasion you add an Asset, verify an Asset, launch a Scan, or permit a scheduled Scan to run, that:
- you own the Asset, or you have express, current, written authorisation from the owner and operator of the Asset to authorise security testing of it by a third party on your behalf;
- you have authority to grant us the permissions in the RoE in respect of that Asset, and to bind any entity on whose behalf you act;
- you have obtained any consent additionally required from the hosting, cloud, CDN, WAF, managed service or other provider whose infrastructure serves the Asset, where their terms require it;
- testing of the Asset is lawful in every jurisdiction in which the Asset is hosted, operated or reachable, and does not breach any contract you are party to;
- the Asset does not fall within a prohibited category listed in the AUP; and
- you are not acting on behalf of an undisclosed third party, and not using the Service to test a system belonging to someone who has not authorised it.
5.2 We rely entirely on these warranties. Ownership verification proves technical control; it cannot and does not prove that you are legally entitled to authorise testing. That remains your responsibility in every case.
5.3 You will maintain records of your authority (for example, a written authorisation from an Asset owner) for as long as the Asset is in your account and for three years afterwards, and will produce them to us within five business days of a reasonable request, including where we receive an abuse complaint.
5.4 If your authority over an Asset is revoked, expires, or becomes contested, you must immediately remove the Asset from your account and notify us at ABUSE_EMAIL.
6. Your other obligations
6.1 You will comply with the AUP and the RoE at all times.
6.2 You are responsible for preparing your own systems for testing, including maintaining current backups, informing your hosting provider, security operations team or managed detection provider where appropriate, and choosing appropriate scan windows and profiles.
6.3 You will not attempt to circumvent, disable or interfere with the Service's scope controls, rate limits, verification requirements or safety limits, or use the Service to route or disguise traffic aimed at anything other than your Authorised Assets.
6.4 If you supply credentials, API keys or other secrets for authenticated testing, you are responsible for issuing dedicated, least-privilege, revocable test credentials, and for revoking them when testing ends. Do not supply production administrator credentials.
6.5 You will not resell, sublicense, or provide the Service to third parties as a service bureau without our prior written agreement, and will not use the Service to test assets belonging to your own customers unless we have agreed a written arrangement covering it.
7. Fees, billing and taxes
7.1 Paid plans are billed in advance through INFIQON Billing, our group billing service, which is the merchant of record for your purchase and issues your tax invoice. Prices are as displayed at the time of purchase and are inclusive of applicable taxes unless stated otherwise.
7.2 Applicable Indian Goods and Services Tax, or the appropriate treatment for an export of services, is determined and applied by INFIQON Billing based on the place of supply information you provide at checkout. You are responsible for the accuracy of that information, including any GSTIN.
7.3 Subscriptions renew automatically for successive terms until cancelled. You may cancel at any time, effective at the end of the current paid term.
7.4 Refunds. Except where required by law or expressly stated at the point of sale, fees are non-refundable. We do not refund fees for a period in which your account was suspended for breach of the AUP.
7.5 If a payment fails or is charged back, we may suspend the Service until the balance is settled.
7.6 We may change prices on renewal with at least 30 days' notice before the start of the renewal term.
8. Free plans and trials
Free plans and trials are provided as is, without any warranty, and may be modified, limited or discontinued at any time. Sections 5, 13, 14 and 15 apply in full to free plans.
9. Customer Data, Findings and confidentiality
9.1 You own your Customer Data. We claim no ownership of your Assets, your Findings or your Reports.
9.2 You grant us a non-exclusive, worldwide licence to host, process, transmit and display Customer Data solely to provide, secure and support the Service and to meet our legal obligations.
9.3 Findings are your Confidential Information. We will not disclose your Findings, evidence or Reports to any third party except: to subprocessors under confidentiality obligations, as you direct (including via a share link you create), or where compelled by law — in which case we will give you notice unless legally prohibited.
9.4 We may use aggregated, de-identified statistics derived from use of the Service — for example, the prevalence of a vulnerability class across our customer base — provided the result does not identify you, your Assets or your Findings.
9.5 Share links. If you generate a shareable Report link, anyone with that link can view that Report. You are responsible for who you give it to and for revoking it.
9.6 Retention. We retain Findings and evidence for the period stated in our Privacy Policy, and delete or anonymise them thereafter. On termination, you may export your Reports for 30 days, after which we may delete Customer Data.
9.7 Confidentiality (both ways). Each party will protect the other's confidential information with at least reasonable care and use it only for the Agreement. This does not apply to information that is public through no breach, independently developed, or lawfully received from a third party.
10. Data protection and privacy
10.1 Our processing of personal data is described in our Privacy Policy PRIVACY_POLICY_URL, which forms part of the Agreement.
10.2 Where we process personal data on your behalf, we do so as a data processor under your instructions, and we comply with applicable data protection law including India's Digital Personal Data Protection Act, 2023. A data processing addendum is available on request at LEGAL_EMAIL.
10.3 Minimisation to AI providers. Data sent to language-model providers is limited to normalised Finding fields and is scrubbed of credentials, secrets and personal data before it leaves our systems. Raw tool output, request/response evidence, screenshots and any credentials you supply are never sent to a language-model provider.
10.4 A current list of subprocessors is available at SUBPROCESSORS_URL. We will give notice before adding a subprocessor that processes Customer Data.
11. Our intellectual property
11.1 We and our licensors own the Service, including its software, scanning engine, rules, report templates, compliance mappings and brand. Nothing in the Agreement transfers those rights to you.
11.2 We grant you a non-exclusive, non-transferable right to use the Service and to use, copy and distribute Reports for your own internal business purposes, including sharing them with your customers, auditors, investors and regulators.
11.3 You may not copy, reverse engineer, decompile, scrape or create derivative works of the Service, or use it to build a competing product, except to the extent that restriction is prohibited by law.
11.4 Feedback you give us may be used without restriction or obligation.
12. Third-party services
The Service depends on third-party infrastructure and open-source security tools. We are not responsible for third-party services, and your use of any integration you configure (for example a webhook or chat notification) is governed by that third party's terms.
13. Disclaimers
13.1 Except as expressly stated in the Agreement, the Service is provided "as is" and "as available", and we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty arising from course of dealing or trade usage.
13.2 Without limiting the above, we do not warrant that: the Service will be uninterrupted or error-free; that it will detect all vulnerabilities or produce no false positives; that Findings will be complete or accurate; or that use of the Service will make any system secure or compliant.
13.3 Testing carries inherent risk. Even though SecQon is designed to be non-destructive, bounded and rate-limited, security testing can cause unintended effects on a target system, including degraded performance, errors, unexpected application behaviour, alert and log volume, account lockouts, blocking by a WAF or upstream provider, and data written by test inputs into forms or records. You acknowledge and accept this risk in respect of your Authorised Assets, and Section 15 applies to it.
13.4 Nothing in the Agreement excludes liability that cannot be excluded under applicable law, including liability for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.
14. Limitation of liability
14.1 Neither party is liable for indirect, incidental, special, consequential, punitive or exemplary damages, or for loss of profits, revenue, goodwill, business opportunity, anticipated savings, or loss or corruption of data, even if advised of the possibility.
14.2 Our aggregate liability arising out of or relating to the Agreement is limited to the greater of (a) the total fees you paid us in the twelve months immediately preceding the event giving rise to the claim, and (b) INR 10,000.
14.3 For clarity, on a free plan our aggregate liability is limited to INR 10,000.
14.4 The limitations in this Section do not apply to: your obligations under Section 15 (Indemnification); your breach of Section 5, the AUP or the RoE; your infringement of our intellectual property; amounts you owe us under Section 7; or either party's fraud, gross negligence or wilful misconduct.
14.5 These limitations apply regardless of the form of action, whether in contract, tort, statute or otherwise, and survive any failure of an exclusive remedy. Each party's liability is reduced to the extent the other party could reasonably have mitigated its loss.
14.6 Any claim must be brought within one year of the date the claim arose.
15. Indemnification by you
15.1 You will defend, indemnify and hold harmless Infiqon, its affiliates, and their respective directors, officers, employees, contractors and agents (the "Indemnified Parties") from and against any and all third-party claims, demands, actions, investigations, proceedings, and any resulting losses, liabilities, damages, fines, penalties, settlements, and reasonable legal and expert fees ("Losses"), to the extent arising out of or relating to:
- an Asset you were not entitled to authorise — any claim by the owner, operator, licensee or user of a system that testing was performed without their authorisation, or in excess of the authorisation given;
- your breach of Section 5, the AUP, the RoE, or any other term of the Agreement;
- a claim by a third party whose infrastructure or service was affected by testing you authorised, including a hosting, cloud, CDN, WAF, DNS, transit or shared-infrastructure provider, or another tenant of shared infrastructure;
- disruption, downtime, degradation, data alteration or data loss at or caused to any system as a result of testing you authorised, including losses claimed by your own customers or users;
- any regulatory, governmental or law-enforcement action or investigation arising from your use of the Service, including under India's Information Technology Act, 2000 or any equivalent computer-misuse, data-protection or cybercrime law of any jurisdiction;
- your violation of applicable law or of the rights of any third party, including privacy and intellectual property rights;
- credentials, payloads, targets or other content you supply to the Service; and
- your use or distribution of a Report, including any decision you or a third party takes in reliance on it.
15.2 Procedure. We will notify you promptly of a claim for which we seek indemnification (a delay only reduces your obligation to the extent it prejudices your defence). You will control the defence with counsel reasonably acceptable to us, and we will cooperate at your reasonable expense. You may not settle any claim in a way that imposes any obligation, payment or admission of fault on an Indemnified Party, or that does not fully release it, without our prior written consent. We may participate in the defence at our own cost, and may assume control of the defence if you fail to defend diligently, in which case your indemnity covers our reasonable costs of doing so.
15.3 This indemnity is not subject to the liability cap in Section 14.2 and survives termination of the Agreement.
15.4 This indemnity does not apply to Losses to the extent caused by our own gross negligence or wilful misconduct, or by our testing of a target we selected that was outside the scope you authorised.
16. Suspension, kill switch and termination
16.1 Immediate suspension. We may suspend Scans, your account, or both, immediately and without prior notice, where we reasonably believe that: a target is not authorised; the AUP or RoE has been breached; testing is causing harm to a third party or to shared infrastructure; we have received a credible abuse complaint or legal demand; or suspension is necessary to protect the Service, another customer, or any person. We will tell you why as soon as we reasonably can.
16.2 You may terminate at any time by cancelling your subscription and closing your account.
16.3 We may terminate the Agreement for material breach that is not cured within 15 days of notice, or immediately for a breach of Section 5 or the AUP, or if you become insolvent.
16.4 On termination: your right to use the Service ends, we stop all Scans and monitoring, and you may export your Reports for 30 days. Sections 5.3, 9, 11, 13, 14, 15, 17 and 18 survive.
16.5 We may report unlawful activity to law enforcement and to affected parties, and will preserve the relevant audit records where we do.
17. Changes to the Agreement
17.1 We may update these Terms, the AUP or the RoE. Each document carries a version identifier and a cryptographic hash of its text.
17.2 For a material change, we will give at least 30 days' notice by email and in the application, and you will be required to accept the new version before adding a new Asset or launching a new Scan. If you do not accept a material change, your remedy is to stop using the Service and cancel, with a pro-rata refund of any prepaid unused term.
17.3 Non-material changes (clarifications, corrections, contact details) take effect on publication.
18. Governing law and disputes
18.1 The Agreement is governed by the laws of India, without regard to conflict of laws rules.
18.2 The parties will first attempt to resolve any dispute in good faith within 30 days of written notice.
18.3 Any dispute not so resolved will be finally settled by arbitration under the Arbitration and Conciliation Act, 1996, by a sole arbitrator appointed by agreement between the parties, seated at JURISDICTION_CITY, India, conducted in English. The award is final and binding.
18.4 Subject to 18.3, the courts at JURISDICTION_CITY, India have exclusive jurisdiction, and either party may seek urgent injunctive relief from any court of competent jurisdiction.
19. General
19.1 Force majeure. Neither party is liable for a failure caused by an event beyond its reasonable control, excluding payment obligations.
19.2 Assignment. You may not assign the Agreement without our written consent, except to a successor of your business. We may assign to an affiliate or in connection with a merger or sale of assets.
19.3 Notices. Notices to you go to your account email address. Notices to us go to LEGAL_EMAIL and to our registered office.
19.4 Entire agreement. The Agreement is the entire agreement between us on its subject matter and supersedes prior discussions. Terms in your purchase order or vendor portal do not apply.
19.5 Severability and waiver. If a provision is unenforceable it is modified to the minimum extent necessary or severed, and the rest remains in effect. A failure to enforce is not a waiver.
19.6 No third-party beneficiaries, except the Indemnified Parties under Section 15.
19.7 Independent contractors. Nothing creates a partnership, agency or joint venture.
19.8 Publicity. We will not use your name or logo as a customer reference without your prior written consent.
20. Electronic acceptance and records
20.1 You accept the Agreement electronically. Each acceptance records the document, its version, a SHA-256 hash of its exact text, your user and tenant identifiers, the timestamp, your IP address and your browser user agent, in an append-only, cryptographically chained audit log.
20.2 You agree that this record constitutes a valid electronic record and signature under the Information Technology Act, 2000 and the Indian Contract Act, 1872, and that it is admissible evidence of your acceptance.
20.3 Adding an Asset and launching a Scan each create a further, separately recorded attestation under the RoE.
21. Contact
Infiqon Private Limited · REGISTERED_ADDRESS General and legal: LEGAL_EMAIL · Security: SECURITY_EMAIL · Abuse and emergency stop: ABUSE_EMAIL