Legal
Terms of Use
The terms that apply when you use this website. Paid work is governed by the engagement agreement we sign with you, not by this page.
- Last Updated
- 1 September 2026
- Published By
- SecureRoot Risk Advisory LLP, Kanpur, India
- Questions
- info@secureroot.co
- This site is general information, not advice scoped to your organisation
- Quote us with attribution, ask before republishing at length
- Indian law applies, with jurisdiction at Noida, Gautam Buddha Nagar, Uttar Pradesh
1.Who These Terms Are Between
This website, secureroot.co, is published by SecureRoot Risk Advisory LLP, a cybersecurity consultancy registered in India. Our registered office is at Plot No. 110-A Gandhi Gram, Kanpur Nagar, Uttar Pradesh 208007, India, and we also work from a branch office in Greater Noida West, Uttar Pradesh. These terms apply between us and anyone who uses the site.
By browsing the site you accept them. If you do not, please stop using the site. We update these terms from time to time, and the date at the top of the page shows the current version.
2.What This Website Is For
The site describes who we are, the services we deliver, the frameworks we work with and the way we run an engagement. It exists so that you can decide whether to talk to us.
Nothing on it is an offer capable of acceptance, a fixed price, or a commitment to take on a piece of work. Scope, fees, timelines, liability and confidentiality for any paid work are set out in the engagement agreement we sign with you. Where that agreement and this page differ, the agreement governs the work.
3.No Professional Advice, No Client Relationship
Security and compliance decisions depend on your systems, your obligations and your risk appetite. The material on this site is general information written for a broad audience, and it is not advice for your organisation.
Reading this site, downloading anything from it, or sending us an enquiry does not create a consultant and client relationship. That begins when a scope is agreed and an engagement agreement is signed. Do not act on anything here as though it were scoped advice, and do not treat it as a substitute for an assessment of your own environment.
4.Case Studies, Outcomes and Statements About Our Work
The case studies we publish are anonymised at our clients’ request. The scope, the approach and the figures describe what was delivered in that specific engagement, under that client’s conditions and constraints.
They are a record, not a forecast. Nothing on this site is a guarantee that your organisation will reach the same result, pass an audit, obtain a certification, or avoid a security incident. Certification and attestation outcomes are decided by independent auditors and certification bodies, not by us.
5.Acceptable Use
When you use this site, please do not:
- test, scan, probe or attempt to gain unauthorised access to this website or the infrastructure behind it, unless we have given you written permission for a specific test in a specific window
- attempt to disrupt or degrade the site, or to interfere with anyone else's use of it
- collect data from the site by automated means in a way that places an unreasonable load on it, or that ignores our robots directives
- use the site or anything on it to break the law, or to misrepresent your relationship with SecureRoot
If you believe you have found a security issue in this website, we would rather hear about it than not. Write to info@secureroot.co with enough detail to reproduce it, and give us a reasonable period to fix it before disclosing it publicly.
6.Intellectual Property
The text, structure, design, graphics and code of this site belong to SecureRoot Risk Advisory LLP or to our licensors. The SecureRoot name and logo, and the names of our platforms TrustGrid and DPDPA Compass, are ours.
You may read the site, print pages for your own reference, and share links to it freely. You may quote a short extract if you attribute it to SecureRoot and link to the page it came from. Republishing substantial parts of the site, reusing our material in a commercial product, or presenting it as your own, needs our written permission first. Ask us at info@secureroot.co.
Reports, control sets and other deliverables produced during an engagement are covered by the intellectual property terms of that engagement agreement, not by this page.
7.Third-Party Names, Tools and Links
Framework, standard and product names used on this site, including ISO 27001, SOC 2, PCI DSS, HIPAA and GDPR, together with the names of the testing and monitoring tools we reference, belong to their respective owners. We use them to describe the work we do.
Naming a standard does not imply that its owner endorses us, and naming a tool does not imply a partnership unless we say so explicitly. Where we hold a certification, accreditation or partner status, we state it plainly and can evidence it on request.
Some pages link to websites we do not control. We check a link when we add it, but we are not responsible for what those sites publish, or for what they do with your data once you are on them.
8.Availability and Changes
We maintain this site with care, but we do not promise that it will always be available, error free, or up to date at every moment. We may change, move or withdraw any part of it, including service descriptions and published material, without notice. Where content is out of date and it matters, tell us and we will correct it.
9.Liability
To the fullest extent permitted by Indian law, SecureRoot Risk Advisory LLP is not liable for any loss of profit, loss of business, loss of data, or any indirect or consequential loss arising from your use of this website or from reliance on its general content.
Nothing in these terms limits liability that cannot lawfully be limited, including liability for fraud. Our responsibility for paid work is defined in the engagement agreement covering that work, and this page neither extends nor reduces it.
10.Privacy
Our privacy notice explains what personal data we collect through this website, why we hold it, the basis we hold it on, exactly how long we keep it, and the rights you have over it under the DPDP Act and, where they apply, the EU and UK GDPR. It forms part of these terms.
11.Governing Law and Jurisdiction
These terms, and any dispute arising out of them or out of your use of this website, are governed by the laws of India. The courts at Noida, in the district of Gautam Buddha Nagar, Uttar Pradesh, have exclusive jurisdiction over any such dispute.
12.Contact
Questions about these terms, permission requests and corrections all go to info@secureroot.co.
SecureRoot Risk Advisory LLP
Plot No. 110-A Gandhi Gram,
Kanpur Nagar, Uttar Pradesh 208007,
India
If you would rather start a conversation about a piece of work, use the contact page.