Last updated 2026-07-27
Terms
These cover using this website and engaging me for the services described on it. Where something limits what you can expect from me, it says so plainly instead of hiding in a subclause.
Engaging me for paid work means these apply, unless we sign something separate that says otherwise — in which case that document wins.
What I provide
Exact scope, dates and price for your engagement are confirmed in writing before work starts. Prices on this site describe the standard shape of the work. A repository substantially larger or more complex than usual is quoted before you commit, never after.
What an audit is, and what it is not
Read this even if you skip the rest.
An audit is a point-in-time expert review of the code and configuration you give me access to, producing findings ranked by my assessment of real-world risk, with recommendations.
- It is not a security certification. Not SOC 2, ISO 27001, PCI DSS or HIPAA attestation, and it cannot be presented as one.
- It is not a penetration test. I read code. I do not attack running systems, and production is not touched unless separately agreed in writing.
- It is not a guarantee that your software is secure, correct or free of defects. No review of any depth can establish that. Something I did not find may still exist.
- It is not legal, regulatory, tax or financial advice. Where a finding touches compliance it is an engineering observation and a prompt to talk to a lawyer.
- It is not an insurance policy. An incident after an audit does not by itself mean the audit was deficient.
What you are responsible for
- Having the authority to grant access — you own the code, or have the right to have it reviewed.
- Providing read-only access, and not sending production credentials, admin accounts or live customer data.
- Backups and a rollback path, if I am implementing fixes. I work carefully; you keep the safety net.
- Accurate context. The review is only as good as what you tell me about how the system is used and what it is for.
- Revoking access when the engagement ends.
Confidentiality
Everything you show me — code, architecture, roadmap, metrics, the state of the business — is confidential. It will not be disclosed and will not be used for anything except your work. This continues after the engagement ends and does not expire.
I will sign your NDA if you have one, and the obligation applies whether or not you do. Equally, the report I write for you and my methodology are confidential to our engagement.
Fees and payment
- Fees are fixed and quoted in writing before work begins.
- Half to schedule the work, half on delivery.
- Invoices are due fourteen days from the invoice date.
- Quoted in US dollars. Taxes, where they apply, are additional.
- Fees do not vary with what I find. An audit surfacing three findings costs what one surfacing forty costs.
Scheduling and cancellation
- The introductory call is free and carries no obligation either way.
- Reschedule as often as you need, at any notice. There is no penalty.
- Cancel any time before I start reading the repository and you get a full refund, deposit included. Until then I have held a slot, not done the work.
- If I reschedule, you choose a new date or take a full refund of anything paid.
- If I conclude the work is not a good fit for you, I say so and refund anything paid. I would rather decline than deliver something you did not need.
What you own, and what I keep
You own the report on payment — findings, risk register, recommendations, architecture map. Use it internally, give it to your engineers, show it to investors or an acquirer. Any code I write for you during an implementation engagement is likewise yours on payment.
I keep my methodology: how I structure a review, my checklists and templates, and general expertise. None of that carries your confidential information into anyone else’s engagement.
I will not name you, quote you or describe your system publicly without written permission. If you are happy to be referenced I would be glad of it, but it is opt-in and asked separately.
Disclaimers
This website and its content, including the methodology and any notes, are general commentary rather than advice about your specific system.
Services are provided with reasonable professional skill and care. Beyond that, and to the fullest extent the law allows, no other warranties apply, express or implied.
Limitation of liability
To the fullest extent permitted by law:
- My total liability arising out of or relating to an engagement is capped at the total fees you paid for that engagement.
- I am not liable for lost profits, lost revenue, lost data, business interruption, reputational harm, or indirect or consequential loss.
- I am not liable for a defect, vulnerability, incident or outage an audit did not identify. That is the nature of a time-boxed expert review, and it is stated up front above.
Nothing here limits liability for fraud, wilful misconduct, or anything that cannot lawfully be limited.
Independent contractor
Rajiv Inc is an independent contractor — not an employee, partner, agent or joint venturer. I have no authority to bind you to anything and I work for other clients concurrently.
Ending an engagement
Either of us can end an engagement in writing. You pay for work completed to that point. Confidentiality, ownership and the liability cap survive.
Governing law
These terms are governed by the laws of India, and the courts of Chennai, Tamil Nadu have exclusive jurisdiction. If you are contracting from elsewhere and need a different jurisdiction, raise it before we start rather than after.
Changes
These terms may change. The version in force for your engagement is the one published when it was agreed; changes do not apply retroactively to work already scoped.
Questions about this page
Replies within two business days. Yes, no, or not the right fit.