SpotDefence is operated by Eioneus Systems Private Limited, Pune, Maharashtra, India (“we”, “us”). This notice explains how we handle personal information from website visitors, business contacts and prospective clients. For privacy questions, requests or grievances, email support@spotdefence.com, addressed to the Privacy and Grievance Contact.
1. Scope and engagement data
We determine how website enquiries and business-contact information are used. Information processed during a client assessment is also subject to the signed engagement agreement and, where applicable, data-processing instructions. Where we act on a client's behalf, requests concerning that client's data may need to be directed to the client. No contract or notice removes rights or obligations imposed by applicable law.
2. Information collected
- Enquiries: your name, company, work email, optional phone number, selected service, message and the acknowledgement submitted with the form.
- Communications: information you provide by email or WhatsApp, and business-contact details supplied by colleagues who involve you in an enquiry or engagement.
- Technical information: hosting and external-resource requests can disclose IP address, request time, browser information and requested resources. Our enquiry endpoint uses limited technical information to control abuse and passes submitted enquiry details to SMTP2GO for email delivery.
Providing information is voluntary. Required fields help us respond and understand your enquiry; without suitable contact details we may be unable to respond. Do not submit passwords, access tokens, production credentials, personal records or confidential vulnerability evidence through the public form. Arrange an appropriate secure channel before sharing sensitive assessment material.
3. Purposes and grounds for use
We use information to respond to requests, discuss scope, prepare requested proposals, manage agreed services and business relationships, operate and protect the website, address abuse, meet legal obligations and handle disputes. Information voluntarily provided for an enquiry is used for that request and related follow-up. We obtain consent where applicable law requires it and rely on other permitted grounds only where they apply.
Where European or UK data-protection law applies, relevant grounds may include steps requested before a contract with you, performance of that contract, compliance with a legal obligation, or legitimate interests in business-contact communications and website security, subject to your rights. Where consent is required, it may be withdrawn by contacting us; withdrawal does not invalidate earlier lawful processing.
An enquiry does not subscribe you to a marketing list. The website does not offer an advisory subscription. We do not use website enquiries for decisions based solely on automated processing that have legal or similarly significant effects on you.
4. Service providers and disclosures
The website uses BigRock for hosting and server-side enquiry processing, SMTP2GO for enquiry email delivery, and externally hosted Google Fonts and cdnjs resources. These providers receive information needed for their respective services. Enquiries and subsequent correspondence may also be handled through our business email and communication providers. Information is shared with personnel and providers as needed for the purposes described here, subject to applicable confidentiality and data-protection requirements.
Choosing WhatsApp opens an external service subject to its own terms and privacy practices. Our website does not automatically place your completed form fields into the WhatsApp link. Information you choose to send there is handled through that service. You may use the enquiry form or email instead.
We do not sell personal information. We may disclose information where legally required or lawfully necessary to protect rights, investigate abuse, or establish, exercise or defend legal claims. A lawful business restructuring may involve relevant records, subject to applicable protections and notice requirements.
5. Cookies and international processing
The website's application code does not include advertising pixels or a marketing-analytics integration. External providers may process technical information or use technologies necessary for delivery, security and abuse prevention. Browser settings can restrict cookies, although some external functionality may be affected. If non-essential tracking is introduced, the notice and consent controls will be updated as required before its use.
Hosting, form processing and communications may involve processing outside India or your country of residence. Applicable transfer restrictions and safeguards govern such processing; we do not represent that all information remains in India. Contact us for information about the providers and transfer arrangements relevant to your enquiry or engagement.
6. Retention
- Enquiries: our retention schedule is three months from receipt. A new enquiry has its own retention period. If an enquiry becomes an engagement, information necessary to deliver or document that engagement is handled as an engagement record.
- Client reports: our retention schedule is six months from delivery of the final report. Clients should retain their own authorised copy. Retest reports have a six-month period from their delivery. A different period must be expressly agreed in writing and permitted by law.
- Other assessment material: credentials, working evidence and other artefacts are governed by the agreed scope, handling instructions and documented need; the report-retention period is not permission to retain unnecessary credentials or personal data.
- Legal and operational records: agreements, invoices, security logs and records needed for legal obligations or disputes may require a different period, limited to that purpose.
These periods apply to copies under our control, including relevant provider-held submissions and correspondence. Provider default retention is not a substitute for this schedule. Deletion must account for mailbox copies and provider systems; restricted backup copies may remain until the applicable backup cycle expires. Where lawful retention is necessary, access and use are limited to that purpose. You may request earlier deletion, subject to applicable obligations and exceptions.
7. Security
Reasonable technical and organisational safeguards are used as appropriate to the information and processing involved. Engagement-specific controls and secure transfer arrangements should be agreed before access is provided. No transmission or storage method can be guaranteed completely secure. Notifications of personal-data breaches are handled in accordance with applicable legal and contractual requirements.
8. Your rights and grievances
You may contact us to request access to, correction of, or deletion of your personal information, withdraw consent, or raise a privacy grievance. Depending on applicable law and its commencement, additional rights may include completion or updating, restriction, portability, objection and nomination of another person to exercise specified rights in the event of death or incapacity. Where available, you may object to direct marketing at any time.
Email support@spotdefence.com with enough information to identify your request, without sending unnecessary sensitive documents. We may make proportionate identity or authority checks. Requests are handled within applicable statutory time limits; exceptions and permitted extensions may apply. Where lawful, we will explain material limitations or refusals. You may escalate to a competent authority or court as applicable, after following any legally required grievance process. This notice does not waive statutory remedies.
9. Children and changes
This is a business-services website and is not directed to persons under 18. If you believe a child has supplied personal information, contact us so we can assess and address it. We update this notice when our practices or legal requirements change and provide additional notice or obtain fresh consent where required. Changes do not retrospectively authorise unrelated processing.
This website is operated by Eioneus Systems Private Limited, Pune, Maharashtra, India, trading as SpotDefence. These terms govern use of the public website to the extent enforceable under applicable law. Contact support@spotdefence.com about these terms.
1. Website information and enquiries
Service descriptions, examples, sample reports and other materials are general information, not a binding quotation, certification or assessment of your systems. Submitting an enquiry, receiving an acknowledgement or holding a scoping discussion does not create a security-testing engagement, reserve capacity or execute an NDA.
Information may become outdated or contain errors. Confirm material scope, price, timing and deliverable details in writing before relying on them for procurement or security decisions.
2. Separate engagement agreement
Paid services require an agreed written engagement covering scope, authorised targets, techniques, access, testing windows, fees, applicable taxes, payment milestones, deliverables and relevant safeguards. Retest eligibility, cancellation, refunds, rescheduling, dependencies and service commitments must be specified there. A website statement does not replace those agreed terms.
The signed engagement agreement governs that engagement and takes precedence over conflicting website descriptions. Website updates do not amend an existing signed agreement. Statutory rights and obligations remain unaffected.
3. Authority and testing boundaries
You must own the proposed targets or have documented authority to authorise testing, including permissions required under applicable third-party terms or law. Possession of credentials, a domain name or an IP address is not sufficient evidence of authority. No testing is authorised merely by submitting target details.
Testing may begin only after written authorisation and agreement on scope and rules of engagement. Production safeguards, backups, permitted techniques, rate limits, stop-work triggers and escalation contacts must be agreed as appropriate. Additional systems or techniques require approval before testing. Testing may be paused where authority is unclear or agreed safety boundaries cannot be maintained.
4. Limitations of security assessments
Assessments are limited by scope, time, access, techniques and the condition of systems when tested. Manual validation improves the quality of findings but cannot guarantee that every finding is correct, every vulnerability is discovered, or a system remains secure after testing.
A report is not a guarantee of uninterrupted operation, absence of future incidents, regulatory compliance or successful certification. Remediation and retest conclusions apply only to the changes and evidence examined within the agreed scope. Customers remain responsible for their security decisions and ongoing system operation, subject to the signed agreement.
5. Confidentiality and personal information
Arrange a suitable confidentiality agreement and secure channel before disclosing sensitive assessment information. A public enquiry does not itself create a mutual NDA. Do not submit credentials, secrets or personal records in the public form.
The Privacy Policy describes website personal-information handling. Confidentiality, permitted disclosures, secure access, processing roles, evidence retention and incident notification for client work are governed by the engagement documents and applicable law. Do not provide another person's information without a lawful basis or appropriate authority.
6. Intellectual property and reports
Website branding and materials are owned by Eioneus Systems Private Limited or their respective rights holders. You may view them and make reasonable internal copies to evaluate our services, retaining relevant notices. No right is granted to resell materials, misrepresent affiliation or use another party's trademarks without permission or a legal entitlement.
Ownership or licensing of reports, authorised sharing, third-party reliance and rights to underlying methods or tools are determined by the signed engagement agreement. Sample materials do not create reliance rights. Client and third-party materials retain their existing ownership.
7. Acceptable use and external services
Do not impersonate others, submit unlawful content, send spam, introduce malicious code or disrupt website access. These terms do not authorise testing against SpotDefence or any third party. Any testing permission must arise from an applicable written authorisation or the express boundaries of the responsible-disclosure policy.
External links and services have their own terms and privacy practices. Their inclusion does not guarantee availability or security. Website access may be restricted when reasonably necessary for maintenance, security, abuse prevention or compliance with law.
8. Availability and liability
To the extent permitted by law, the public website is provided without warranties of uninterrupted availability, accuracy, error-free operation or suitability for a particular purpose. This does not disclaim express obligations for paid services.
Liability, exclusions, insurance requirements and any negotiated cap for an engagement must be addressed in its signed agreement. No engagement liability cap is imposed by these website terms. Nothing excludes or restricts liability, remedies or consumer protections that cannot lawfully be excluded, or excuses fraud or fraudulent misrepresentation.
9. Governing law and disputes
These website terms are governed by the laws of India, including applicable laws in Maharashtra. Subject to mandatory statutory rights and any forum whose jurisdiction cannot lawfully be excluded, courts of competent jurisdiction in Pune, Maharashtra, have exclusive jurisdiction over disputes concerning these website terms. Engagement disputes follow the applicable signed agreement, subject to mandatory law.
Please first raise concerns at support@spotdefence.com so we can seek a resolution. This does not prevent urgent relief, interrupt statutory time limits or restrict a legally available complaint or remedy.
10. Changes and interpretation
Updated terms will carry a revised date, with further notice where legally required. Changes do not apply retrospectively to signed engagements. If a provision is unenforceable, the remaining provisions continue to the extent permitted by law. A delay in enforcing a right does not by itself waive that right.
SpotDefence, operated by Eioneus Systems Private Limited, welcomes good-faith reports about security vulnerabilities in the SpotDefence systems listed below. This policy explains what you may test, how to report safely, and how we coordinate remediation and disclosure. It does not authorise testing of any client or third-party system.
1. Security contact
Email support@spotdefence.com with the subject [Security Disclosure]. If the report contains sensitive information, send only a short description initially and ask us to arrange a suitable secure transfer method. Do not use the public enquiry form for vulnerability details, credentials, personal data or exploit code.
2. What to include
- The affected hostname, URL, feature and, where relevant, account role or environment.
- Clear reproduction steps, prerequisites, timestamps and a minimal proof of concept.
- The observed and potential impact, including whether any personal or third-party data may be affected.
- Supporting requests, responses, screenshots or logs with secrets and unrelated personal data removed.
- Any actions you took, data you accessed, test records you created, or cleanup we should perform.
- Your preferred contact details and whether you want public recognition. Anonymous reports are accepted, although we may be unable to ask follow-up questions.
3. Systems covered
This policy covers the web applications and content served from spotdefence.com, www.spotdefence.com, and the official preview at spotdefence-zeta.vercel.app, but only to the extent that the affected component is controlled by Eioneus Systems Private Limited. Another asset is covered only when we confirm that in writing before testing.
Hosting providers, email providers, form processors, content-delivery networks, social networks and other third-party services are governed by their own disclosure programmes. A SpotDefence name, link, DNS record or embedded component does not by itself authorise testing of the provider's underlying infrastructure.
4. Rules for safe research
- Use accounts and data you own or have explicit permission to use. Do not access another person's account or records.
- Use the minimum interaction and data needed to confirm the issue, then stop. Do not pivot, establish persistence, evade monitoring, or continue after we ask you to stop.
- Do not alter, delete, download in bulk, retain or publicly expose data. If you unexpectedly encounter sensitive data, stop, tell us what was accessed, and follow our handling instructions.
- Avoid disruption. Do not degrade availability, exhaust resources, send spam, create excessive traffic, or interfere with other users.
- Keep evidence secure, share it only with us or as legally required, and delete it after remediation is confirmed unless retention is required by law.
- Comply with applicable law. If you are uncertain whether a planned test is permitted, contact us before proceeding.
5. Activities not authorised
- Testing any client system, client data, employee personal account, or asset not expressly listed above.
- Denial-of-service, resource-exhaustion, stress, load or volumetric testing.
- Social engineering, phishing, vishing, credential stuffing, password spraying, brute force, physical intrusion or attacks against personnel.
- Malware, ransomware, destructive payloads, persistence, command-and-control, data exfiltration or supply-chain compromise.
- High-volume automated scanning, testing that causes repeated alerts, or activity that incurs material cost.
- Extortion, threats, demands for payment, or disclosure intended to pressure us before remediation can be coordinated.
Scanner output, missing security headers, version banners, best-practice observations, clickjacking without a sensitive action, self-XSS, open redirects without demonstrated security impact, and reports about unsupported or obsolete browsers may be closed as informational unless they demonstrate a credible exploit and material impact.
6. Our response targets
- Acknowledgement: targeted within 2 business days.
- Initial triage: targeted within 10 business days, subject to reproducibility and available information.
- Updates: when the status materially changes or at an interval agreed with the reporter.
These are response targets, not contractual service levels. Remediation time depends on severity, complexity, third-party dependencies, active exploitation and operational risk. Duplicate, previously known, non-reproducible or out-of-scope reports may be closed with an explanation where practicable.
7. Coordinated disclosure
Please do not publish, sell or share vulnerability details until we confirm remediation or agree a disclosure date. We will work toward a reasonable disclosure plan, commonly within 90 days, but the period may change where a fix is complex, a supplier is involved, users require time to update, active exploitation changes the risk, or law requires earlier reporting. We may notify affected parties, service providers, regulators, CERT-In or law-enforcement authorities where required or reasonably necessary.
8. Good-faith research and legal position
Research that follows this policy, stays within the listed systems and is performed in good faith will be treated by us as authorised security research for our systems. We do not intend to initiate legal action solely because of an accidental, good-faith breach of this policy where the researcher promptly stops, reports it and cooperates to reduce harm. This statement cannot authorise activity against third parties, bind another organisation, excuse unlawful or reckless conduct, or prevent us from acting where there is harm, bad faith, extortion, privacy abuse or a legal obligation.
9. Bounty, recognition and privacy
This is a disclosure programme, not a paid bug bounty. Testing costs, rewards and compensation are not promised. With your consent, we may acknowledge a helpful report after remediation. Reporter contact details and report content are used to investigate, communicate, remediate, meet legal obligations and prevent recurrence, subject to our Privacy Policy and applicable law.
SpotDefence is the cybersecurity-services brand of Eioneus Systems Private Limited, Pune, Maharashtra, India. Our work can involve source code, test credentials, technical evidence and sensitive business context. This Trust Center summarises how engagements are governed. The signed NDA, proposal, statement of work and rules of engagement define the controls for a particular client and take precedence where they set stricter requirements.
1. Accountability and engagement ownership
- Each assessment has an identified engagement lead and agreed client contacts for scope, escalation and stop-work decisions.
- Access to client material is limited to personnel assigned to the engagement and any specifically approved support role.
- Confidentiality, conflicts, authorised techniques and handling requirements are addressed before sensitive material is exchanged.
- Material changes to targets, techniques, access or timing require documented agreement.
2. Written authorisation and rules of engagement
Testing begins only after the parties document the legal entity requesting the work, in-scope assets, ownership or authority to test, excluded systems, permitted techniques, testing window, rate limits, production safeguards, escalation contacts and stop conditions. The client remains responsible for obtaining authorisation from relevant asset owners, cloud providers and other third parties. An enquiry, quotation or NDA alone is not permission to test.
3. Testing safeguards
- Testing follows the agreed scope and uses manual validation to confirm material findings.
- Production constraints, backups, monitoring expectations, test data, prohibited actions and emergency communications are agreed for the actual environment.
- Potentially disruptive techniques, destructive actions, persistence and access beyond the agreed proof are excluded unless expressly authorised in writing.
- When unexpected impact or sensitive exposure occurs, testing is paused or limited, evidence is preserved proportionately, and the named contacts are informed through the agreed channel.
No assessment can eliminate all risk or guarantee that every vulnerability will be found. Deliverables describe the tested scope, timing, assumptions and limitations so results are interpreted appropriately.
4. Access control and credentials
Clients should provide dedicated, scoped test accounts with the minimum permissions needed and multi-factor authentication where appropriate. Credentials, tokens, private keys, production secrets and personal records must not be sent through the public enquiry form or ordinary chat. The parties agree a suitable transfer method before exchange. Temporary access should be rotated or revoked promptly after testing and retesting.
5. Client data and evidence handling
- We request only the information reasonably needed to scope, perform and report the engagement.
- Access, storage location, transfer method, authorised recipients, permitted copies, redaction and deletion instructions are agreed according to the sensitivity of the material.
- Reports and evidence are treated as confidential client material and shared only with authorised recipients or as required by law.
- Clients should avoid supplying live personal data where representative test data can meet the objective.
- Where an engagement involves personal data, the parties document applicable roles, processing instructions, purpose, access, breach contacts and assistance obligations in the engagement terms.
- Client code, confidential evidence or personal data is not placed into public or consumer AI services. Any use of a third-party or AI-assisted service involving client material requires prior written agreement on purpose, data exposure, retention and applicable contractual safeguards.
6. Retention and deletion
Public website enquiries are scheduled for deletion after 3 months. Final client reports are scheduled for deletion after 6 months from final delivery. Working evidence, credentials, source extracts and other artefacts follow the written engagement instructions and should be minimised throughout the work. A different period may apply where the client agrees it in writing, a dispute or legal hold requires preservation, or law requires retention. Deletion from active working locations may not immediately remove protected backup copies, which remain subject to access restrictions and ordinary backup expiry.
7. Service providers and data location
The public website uses BigRock for hosting and server-side enquiry processing, SMTP2GO for enquiry email delivery, and externally hosted font and interface resources as described in the Privacy Policy. An engagement may require other infrastructure or specialist providers. Material providers that may receive client confidential information, along with relevant location or transfer requirements, are identified and agreed before that information is shared. A client may state restrictions on subprocessors, jurisdictions and remote access during scoping.
8. Vulnerability and incident management
Security concerns affecting SpotDefence systems can be reported under the Responsible Disclosure policy. Suspected incidents involving client material are assessed, contained and escalated through the agreed engagement contacts. We preserve relevant information, coordinate remediation and notify affected clients or authorities where required by contract or law. Applicable Indian obligations may include reporting specified cyber incidents to CERT-In within the required period and maintaining records required by lawful directions.
9. Deliverables and remediation
Engagement deliverables may include an executive summary, scope and limitations, methodology, risk-ranked findings, reproducible evidence, business impact, practical remediation guidance and a retest status. The exact deliverables and acceptance process are stated in the proposal or statement of work. Reports are point-in-time assessments of the tested scope and are not certifications, guarantees of security, or permission for third-party reliance unless expressly agreed.
10. Assurance requests
Prospective clients may request a mutual NDA, methodology information, a sanitised sample report, data-handling details, provider disclosures and answers to a security questionnaire. Availability is subject to relevance, confidentiality and the signed engagement. SpotDefence does not claim a certification, audit opinion or compliance status unless it is expressly identified and supported by current written evidence.
11. Client responsibilities
- Confirm ownership and written authority for every target and third-party dependency.
- Maintain backups, monitoring and a reachable incident contact during the agreed testing window.
- Provide accurate scope, architecture and account-role information, and notify us of material changes.
- Restrict report distribution, remediate according to risk, revoke temporary access and retain the authoritative report copy.
- Tell us about regulatory, residency, contractual or safety requirements before work begins.
12. Contact
For RFPs, NDA coordination, security questionnaires, data-handling requirements or incident escalation, contact support@spotdefence.com. Do not include credentials, exploit evidence or sensitive client information in the first email; request an appropriate secure channel.