The terms under which ShadowMap is provided.
ShadowMap is a subscription platform, not an engagement. It runs continuously against a scope you authorise, it acts on your instruction when you file a takedown, and it produces evidence you will hand to auditors. These terms set out who is responsible for what.
1. Acceptance and precedence
These Terms of Service ("Terms") form a binding agreement between you — an individual or, far more usually, the organisation you are authorised to bind — and Security Brigade InfoSec Private Limited ("Security Brigade", "we", "us", "our"), a company incorporated in India with its registered office in Mumbai, Maharashtra. ShadowMap is a product of Security Brigade; there is no separate ShadowMap legal entity.
By accessing shadowmap.com, requesting an evaluation, or using the ShadowMap platform, you agree to these Terms. If you are accepting on behalf of an organisation, you represent that you have authority to bind it. If you do not agree, do not use the site or the platform.
These Terms govern website access, enquiries, evaluations and platform use. A paid subscription is additionally governed by an order form and a master services agreement or equivalent commercial agreement (together, the "Agreement"). Where the Agreement and these Terms conflict, the Agreement prevails. Data protection is governed by the Data Processing Agreement referenced in Section 11, which prevails over both in respect of the processing of personal data.
2. What the service is
ShadowMap is a continuously-operating external exposure platform. It discovers and monitors what your organisation exposes to the internet and correlates it into a single exposure model. Capability areas include:
- external attack-surface discovery, enumeration and change monitoring;
- data exposure and source-code leakage, including repositories your organisation does not own;
- dark-web and identity exposure, including infostealer-derived credential and device compromise;
- brand protection and coordinated takedown workflow;
- adversarial validation of discovered exposure, within an authorised scope;
- vendor and third-party exposure assessed with the same outside-in methodology;
- threat and regulatory intelligence as supporting context, together with the reporting, workflow, integration and audit-log layer that carries findings out of the platform.
Discovery is outside-in. It requires no agent, no credentials into your environment and no network access, which is why an evaluation can begin from an apex domain alone.
ShadowMap is not a replacement for endpoint, identity or internal vulnerability tooling, does not perform internal attack-path or breach emulation, and does not provide legal, regulatory or compliance opinions. Output is evidence that supports your decisions; the decisions remain yours.
3. Subscription and scope
The subscription term, the monitored scope, user and vendor coverage, takedown allowance, any managed-service option, fees and payment terms are set out in the applicable order form. Where a capability is described on this website as part of the platform, it is included in the licence unless your order form says otherwise.
Access is granted to your organisation for its own internal business purposes. You may not resell, sublicence, or provide platform access or its output as a service to a third party without our written agreement. Monitoring a third party as a vendor within your own vendor-risk scope is a permitted use and is not resale.
4. Authorisation to monitor and validate
This section is the operative one, and it is the section that differs most from a point-in-time assessment. Please read it.
You warrant that you are entitled to have the scope monitored. You represent that you own, control, or are otherwise lawfully entitled to authorise external monitoring of the domains, addresses, brands, identities and other identifiers you configure or approve as in scope, including assets hosted by third parties or cloud providers, and that doing so does not breach an agreement you have with anyone else.
Authorisation is established through the Agreement, the end-user licence terms, onboarding and the associated scope configuration and customer approvals. A separate standalone rules-of-engagement document is not normally required for standard operation. Scope is a living configuration: you may add, exclude or withdraw identifiers at any time, and we act on the scope as configured at the time of the activity.
Validation is enabled only within an authorised scope, and only progressively. Where you enable adversarial validation, it is not switched on at go-live. Discovery and enumeration run first to build and validate your external inventory; validation is then introduced gradually and under monitoring. Payloads are non-destructive, validation logic is purpose-built per capability rather than run from generic public exploit code, automated check layers govern the process, and targeting is bounded to discovered and attributed inventory. Exclusions, rate limits and a non-intrusive scan depth are available for fragile systems, and we will apply them where you ask.
Vendor and third-party monitoring is outside-in only. Vendor exposure is assessed from publicly observable information using the same methodology applied to your own estate. It does not require the vendor's cooperation and involves no access to vendor systems. You remain responsible for ensuring that commissioning that assessment is consistent with your arrangements with the vendor.
Subject to Section 12, we are not liable for disruption, degradation or data loss arising from monitoring or validation activity carried out within the authorised scope and in accordance with the agreed configuration.
5. Acceptable use
You agree not to:
- configure, or ask us to configure, a scope covering assets, brands or identities you are not entitled to authorise;
- use recovered credentials, session cookies, tokens or other compromise artefacts to attempt access to any account, device or system other than your own in-scope estate — such material is provided so that it can be revoked, rotated and contained, not used;
- attempt to re-identify individuals in exposure material, or use that material for any purpose other than defending the estate in scope;
- redistribute, publish or sell exposure intelligence, findings or reports outside your organisation, other than to your professional advisors, auditors and regulators under confidentiality;
- share user credentials, or provision access for anyone outside your organisation without our agreement;
- reverse engineer, decompile, scrape, or attempt to extract the platform's detection logic, models or underlying data, or use the platform to build a competing product;
- circumvent technical rate limits, or use API access in a way that degrades the service for others;
- use the platform in breach of applicable law, including computer-misuse, data-protection and export-control law.
Exposure material is sensitive by definition. Treat findings, credentials and stealer-log artefacts inside your organisation with at least the care you would apply to a live incident.
6. Customer obligations
- Provide accurate scope information and keep it current — the platform can only reason about the estate you tell it about, plus what it independently discovers and attributes.
- Keep security, escalation and billing contacts up to date so alerts and notifications reach a person.
- Notify your own operations, SOC and hosting providers that continuous external monitoring is running, to avoid unnecessary incident escalation.
- Review and disposition findings within your own workflow. Service-level policies inside the platform are yours to configure; they are not a commitment by us about your remediation.
- Tell us promptly if scope authorisation changes or is withdrawn.
- Pay the fees set out in the order form when they fall due.
7. Takedown requests
Where you instruct us to pursue a takedown of impersonating, abusive or infringing content, you authorise us to submit that request on your behalf to hosts, registrars, platforms, marketplaces, app stores and other abuse desks, and to disclose to them the material complained of and the identity of your organisation as the complainant. Every request passes a human approval gate before dispatch.
You represent that you hold the rights you assert in a takedown request and that the request is made in good faith. Outcomes are decided by third parties, not by us: a request may be completed, denied, met with a counter-notice, or left unresolved, and we report the outcome as it stands. We do not warrant that any particular takedown will succeed or succeed within a particular period.
8. Availability and support
Every subscription includes analyst-led onboarding for the first thirty days. Ongoing support thereafter depends on the tier on your order form: standard subscriptions receive email and ticketing support with business-hours response, and managed-service subscriptions receive 24/7 remote support with a 24-hour response and 48-hour resolution target for platform, dashboard or API unavailability. An ongoing shared analyst, dedicated remote analyst or dedicated on-site analyst is available as a separately priced add-on.
We may carry out maintenance, and we may change, improve or retire individual platform features. We will not materially reduce the capabilities you have subscribed to during a paid term without notice. Any availability commitment, credit regime or support response target that applies to you is the one recorded in your order form or service-level schedule.
9. Intellectual property
Your data and your findings. Data you supply remains yours. Findings, reports and exports generated for your organisation are licensed to you perpetually and non-exclusively for your internal business purposes, including sharing with your auditors, regulators and professional advisors, on full payment of the fees due.
Our platform. The ShadowMap platform, its user interface, detection and correlation logic, validation methodology, models, collection infrastructure, source corpora, documentation and all related know-how remain the exclusive property of Security Brigade. Nothing in these Terms transfers ownership of any of it, and no licence is granted except the right to use the platform during your subscription.
Aggregated insights. We may use anonymised, aggregated and de-identified information derived from platform operation to improve detection quality, tune models and produce research, provided that no customer, individual or estate is identifiable from it.
Website content. Content on shadowmap.com is the property of Security Brigade or its licensors and is protected under the Copyright Act, 1957 and applicable international law. Do not reproduce or create derivative works from it without written permission.
Feedback. If you send us suggestions, we may use them without restriction and without obligation to you.
10. Confidentiality
Each party may receive confidential information of the other. "Confidential Information" includes, without limitation: exposure findings, validation evidence, asset inventories, credential and compromise data, system architectures, security configurations, commercial terms, and anything marked or reasonably identifiable as confidential.
Each party agrees to hold the other's Confidential Information in strict confidence, not to disclose it without prior written consent except to personnel and contractors who need to know and are bound by no less protective obligations, and not to use it for any purpose other than performing or receiving the service.
Confidentiality survives termination for five years, or for as long as the information remains a trade secret, whichever is longer. Disclosure compelled by law, regulation or court order is not a breach, provided reasonable prior notice is given where legally permitted.
11. Data protection
Where we process personal data on your behalf, we do so as a processor under our Data Processing Agreement, which is incorporated into the Agreement by reference and includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where transfers require them. We also accept customer-provided DPAs — send redlines or your draft to [email protected].
Our own collection and use of personal data is described in our Privacy Policy, our GDPR position in the GDPR page and our DPDP Act position in the DPDP compliance page.
12. Limitation of liability
To the maximum extent permitted by applicable law:
- No guarantee of complete discovery. ShadowMap is designed to find what is externally observable and attributable. It cannot guarantee that every asset, exposure, credential or impersonation affecting your organisation will be discovered, or discovered within any particular period. Continuous monitoring reduces exposure risk; it does not eliminate it.
- No guarantee of security. Nothing in the platform or its output is a warranty that your systems are secure or will not be attacked.
- Third-party outcomes. We are not liable for the decisions of hosts, registrars, platforms or abuse desks in relation to takedown requests, nor for the availability or accuracy of third-party sources and integrations.
- Aggregate cap. Our total aggregate liability arising out of or in connection with the service shall not exceed the fees paid by you for the service in the twelve months preceding the event giving rise to the claim.
- Excluded loss. Neither party is liable for indirect, incidental, special, consequential or punitive damages, including loss of profits, loss of data, loss of business opportunity or reputational harm, even if advised of the possibility.
Nothing in these Terms limits liability that cannot lawfully be limited, including for fraud, or for death or personal injury caused by negligence.
13. Indemnification
You shall indemnify, defend and hold harmless Security Brigade, its directors, officers, employees and contractors against claims, damages, liabilities, costs and expenses (including reasonable legal fees) arising from: (a) your breach of these Terms or the Agreement; (b) a scope you authorised that you were not entitled to authorise; (c) a takedown request you instructed, including any counter-notice or claim by the party complained of; (d) your use or onward disclosure of exposure intelligence, findings or reports; or (e) a third-party claim relating to your systems, content or data.
We shall indemnify you against claims arising from our gross negligence or wilful misconduct in providing the service, or from our material breach of Section 10.
14. Term, suspension and termination
The subscription runs for the term stated in the order form. Either party may terminate for cause on thirty days' written notice if the other materially breaches and fails to cure within that period.
We may suspend monitoring, validation or access immediately, on notice, if: fees are overdue; we reasonably believe the scope is not properly authorised or authorisation has been withdrawn or disputed; continued activity poses a risk of harm; or the platform is being used in breach of Section 5.
On termination or expiry, platform access ends and fees for the period served fall due. Data handling follows Section 10 of the Data Processing Agreement: destruction within thirty days for live production systems and within ninety days for backup and archival systems, with an option, exercisable in writing before termination or within thirty days after, to have customer-supplied personal data returned in a machine-readable format first. Written certification of destruction is available on request. Sections 5, 9, 10, 12, 13, 15 and 16 survive termination.
15. Governing law and disputes
These Terms are governed by the laws of the Republic of India. Disputes are resolved as follows:
- Negotiation — senior representatives attempt resolution in good faith within thirty days of written notice.
- Mediation — failing that, the dispute goes to mediation administered under the rules of the Mumbai Centre for International Arbitration.
- Arbitration — failing mediation within sixty days, to binding arbitration under the Arbitration and Conciliation Act, 1996, before a sole arbitrator appointed by mutual consent, seated in Mumbai, Maharashtra, conducted in English.
Either party may nonetheless seek injunctive or other equitable relief from the competent courts of Mumbai, Maharashtra, to protect Confidential Information or intellectual property.
16. General
Force majeure. Neither party is liable for failure or delay caused by circumstances beyond its reasonable control, including natural disasters, acts of government, attacks on the performing party's own infrastructure, war or civil unrest. The affected party shall notify the other promptly and mitigate.
Severability and waiver. If a provision is held invalid or unenforceable, the remainder continues in force. Failure to enforce a right is not a waiver of it.
Assignment. Neither party may assign these Terms without the other's written consent, except to a successor in connection with a merger, acquisition or sale of substantially all assets.
Changes. We may modify these Terms and will post the revised version here with a new "last updated" date. Continued use after a change constitutes acceptance. Changes that materially affect an active subscription are notified directly to the customer contacts on record.
17. Contact
Security Brigade InfoSec Private Limited
Registered Office: Mumbai, Maharashtra, India
Contractual and legal enquiries: [email protected]
Privacy and data protection: [email protected]
Security reports: [email protected]
General enquiries: [email protected]
Send the paper to your legal team.
Terms, DPA and security documentation are all public — no gate, no form. If your review needs something that is not here, ask and we will answer it directly.