Terms and conditions
The terms our engagements run on
Governed by the law of the United Arab Emirates and the courts of Dubai. Written to be read before signing rather than after a dispute.
Last reviewed
1. Who these terms bind
These terms are between WebSec FZCO, trading as RedTeam Security, licence number 67814, registered in the IFZA, Dubai Silicon Oasis Authority free zone ("we", "us"), and the organisation purchasing services or using this website ("you").
Our services are sold business to business. They are not consumer services, and Federal Law No. 15 of 2020 on Consumer Protection is not intended to apply to them. If you are contracting as an individual for personal purposes, tell us before ordering.
2. Which document wins
Where documents conflict, the order of precedence is: a signed master services agreement; then the signed order document or proposal; then the signed testing authorisation and rules of engagement; then any data processing agreement; then these terms; then anything on this website. Marketing material never overrides a signed document.
3. Proposals and orders
A proposal is an invitation to treat, not a binding offer, and it lapses after sixty calendar days unless it says otherwise. A contract forms when both parties sign the order document, or when we begin work at your written request after receiving the authorisation described in clause 5.
Any change to scope that affects cost, duration, risk or the people assigned is recorded in writing before it takes effect. We may pause affected work until it is.
4. Fees, VAT and payment
Fees are stated in AED or USD as set out in the order document and exclude value added tax. UAE VAT is charged at the prevailing rate where the supply is taxable in the UAE. Where you are required to withhold tax under the law of your own jurisdiction, the amount payable to us is grossed up so that we receive the sum invoiced.
Invoices are payable within fourteen calendar days. Late payment carries interest at the rate permitted under Federal Decree-Law No. 50 of 2022 promulgating the Commercial Transactions Law. You may not withhold or set off any amount against sums owed to us.
Rescheduling requested fourteen or more days before a booked start date is free. Inside fourteen days we may charge for reserved time that cannot be reallocated, because testers are booked to a calendar and that time is genuinely lost.
5. Testing authorisation, and why we insist on it
We do not begin any offensive work without written authorisation. That authorisation must identify the in-scope targets, the testing window, anything excluded, an emergency contact reachable during the window, and the person approving it.
You warrant that you own the in-scope systems or hold the authority to authorise testing of them, including where they are hosted or operated by a third party. This is not a formality: unauthorised access to an information system is a criminal offence in the UAE under Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, and an authorisation that does not cover the target exposes both of us. We may suspend or stop testing immediately if authorisation appears incomplete, expired or insufficient, and we will not resume until it is corrected.
We do not warrant that testing will identify every vulnerability. A test is a time-boxed professional effort against a defined scope, not a proof of absence.
6. What you provide
Timely and accurate access, credentials, documentation and points of contact. You are responsible for your own backups, for notifying your hosting providers where their terms require it, and for telling us about business-critical windows we should avoid. Where missing access or approvals cause delay, we may revise the schedule and charge for standby time.
7. Confidentiality
Each party protects the other's confidential information with at least the care it applies to its own, and discloses it only to people who need it and are under equivalent obligations. Findings, reports, credentials and the existence of an engagement are confidential.
Obligations survive for five years after the engagement ends. Non-public vulnerability information about your systems is protected for as long as it remains non-public, without a fixed end date, because a five-year clock on an unpatched flaw would be worse than useless.
Personal data is handled as described in our privacy policy and, where required, under a separate processing agreement.
8. Intellectual property and your report
You keep all rights in your data and your systems. We keep all rights in our methodology, tooling, templates, scripts and general know-how, including anything we develop while working for you that is not specific to you.
On full payment you receive a perpetual, worldwide licence to use the report and deliverables inside your organisation for any lawful purpose, including showing them to your regulator, your auditors, your insurers and your customers under confidentiality. You may not publish them publicly or resell them without our written consent, and you may not remove attribution.
9. Clean closure
Every change we make to your environment during an engagement is recorded and handed to you as an artefact register with the report. Infrastructure we stand up for your engagement is dedicated to you and destroyed at closure rather than reused. Retention of captured material is stated in the order document with an end date.
10. Warranties and what we do not promise
We perform services with the reasonable care and skill of a competent provider of comparable services. Beyond that, services and deliverables are provided as they are. We do not guarantee a particular finding, a clean result, or that a system is secure. Risk ratings are professional opinion based on what was observable during the testing window.
11. Liability
Neither party is liable for indirect or consequential loss, or for loss of profit, revenue, goodwill, anticipated savings or data. Our total liability arising out of or in connection with an engagement is capped at the fees paid by you under the order document giving rise to the claim in the twelve months before the event.
Nothing in these terms limits liability for fraud, for wilful misconduct, or for anything else that cannot be limited under UAE law.
12. Indemnity
You indemnify us against third-party claims arising from your lack of authority to authorise testing, from inaccurate scope information, or from your failure to notify a third party whose systems or services were in scope, except to the extent the claim results from our own gross negligence or wilful misconduct.
13. Suspension and termination
Either party may terminate for material breach not remedied within ten calendar days of written notice. We may suspend or terminate immediately where continuing would be unlawful, where authorisation is insufficient, or where we are asked to do something that we reasonably consider unsafe or unethical. Fees accrued to the date of termination remain payable.
14. General
Neither party is liable for delay caused by events outside its reasonable control. Neither party may assign without the other's written consent, except to a successor in a genuine merger or sale of assets. Nothing here creates a partnership, agency or employment relationship. Notices are given in writing, and email is sufficient where the address is stated in the order document. Electronic signature and acceptance are valid under Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services. If a provision is unenforceable, the rest stands. These terms and the signed documents above them are the entire agreement.
15. Governing law and jurisdiction
These terms, and any non-contractual obligation arising from them, are governed by the federal law of the United Arab Emirates as applied in the Emirate of Dubai. The courts of Dubai have exclusive jurisdiction, and both parties submit to them.
Where an engagement is delivered outside the UAE, this clause still governs the contract between us unless the order document says otherwise in writing.
16. Using this website
The material published here, including our blog and reference pages, is provided for information. It is not advice for your specific circumstances and it does not create a client relationship. Do not use anything published here to test a system you are not authorised to test. Our responsible disclosure policy covers testing of our own systems and nothing else.
The entity behind this document
WebSec FZCO, trading as RedTeam Security, licence number 67814, registered in the IFZA, Dubai Silicon Oasis Authority free zone. IFZA Business Park, Building A2, Nadd Hessa, Dubai Silicon Oasis, Dubai, United Arab Emirates.
Questions about this document: [email protected]. Privacy requests: [email protected]. Security reports: [email protected].
Let's talk about your security
Tell us the objective you want tested. We will come back with a scope, a timeline and a quote, under NDA from the first conversation.
Email [email protected]Nadd Hessa, Dubai Silicon Oasis
Dubai, United Arab Emirates