Using this website
This website is provided for information. Its content describes how we work and what we have delivered; it is not a security recommendation for your specific environment, and it is not legal or regulatory advice.
Regulatory descriptions on this site, PCI DSS, ISO 27001, SOC 2, HIPAA, GDPR, NIS2, DORA, and regional frameworks, are summaries written to help you scope work. They are not a substitute for reading the standard or taking advice on how it applies to you.
Intellectual property
The content, design, code and marks on this site are owned by Dunicot Private Limited. You may read, print and share pages, and quote from them with attribution and a link. You may not republish substantial portions as your own, or use our name or marks to imply endorsement or a relationship that does not exist.
Reports delivered to a client are licensed to that client for internal use and for sharing with their auditors, regulators and customers under confidentiality. The underlying methodology remains ours.
Engagements
- Authorisation. We test only what we have been authorised in writing to test, by a party with authority to grant it. Where you are not the asset owner, as with a development agency, we require the owner’s written authorisation before active testing begins.
- Scope. Scope, rules of engagement, excluded techniques, testing windows and escalation contacts are agreed in writing before work starts, and price is fixed against that scope.
- Method. Testing is manual and adversarial. Findings are reproduced before they are reported and are subject to the verification criteria published on our methodology page.
- Deliverables. A technical report, an auditor-facing summary, and, once remediation is complete, a retest and attestation, as described in the engagement contract.
- No guarantee of completeness. A penetration test is a time-boxed assessment, not proof that no vulnerability exists. We say what was tested and what was not, and the absence of a finding is not a warranty of security.
Your responsibilities
- Provide accurate scope information, working test accounts, and timely access.
- Take backups before testing and ensure a rollback path exists for any environment in scope.
- Notify any third party whose authorisation is needed, such as a hosting provider, SaaS vendor or managed service provider.
- Act on critical findings promptly; we report them the same day rather than holding them for the report.
Confidentiality
Engagement information is confidential in both directions. We do not disclose that you are a client, name you publicly, or describe your systems without your written consent. Where engagements appear on this site without a client name, they are described by sector and scope for that reason.
Client names that do appear here are published with permission or were already public. Vendor “Hall of Fame” acknowledgements listed on this site are public credits for responsible vulnerability disclosure and are not client relationships. We state that wherever the list appears.
Liability
Nothing in these terms excludes liability that cannot lawfully be excluded, including for fraud, or for death or personal injury caused by negligence.
Subject to that, our liability arising out of an engagement is limited to the fees paid for that engagement, and we are not liable for indirect or consequential loss, loss of profit, or loss of data. Liability specific to an engagement is governed by that engagement’s contract, which prevails over this page.
Governing law
Which law applies depends on the entity you contract with. Where that entity is Dunicot Private Limited, these terms are governed by the laws of the Islamic Republic of Pakistan and the courts of Karachi have jurisdiction. Where it is Dunicot LLC, our United States entity, they are governed by the laws of the State of Wyoming and the courts of Sheridan County have jurisdiction. The governing law and dispute resolution mechanism for a specific engagement are set out in that engagement’s contract and prevail over this page.