Please read these terms before you use our websites or our free tools.
They are a contract between you and us. If you do not accept them, please do not use the sites.
These terms replace the terms and conditions dated 12 September 2023.
Effective from 22 August 2026
1. Who these terms are between
1.1 Us
These terms are issued by Techowl Infosec Private Limited, a company
incorporated in India, with its registered and operational office at A-406 Monarch,
Gaurav Path Road, Adajan, Surat, Gujarat 395009. In these terms, “we”,
“us” and “our” mean that company.
1.2 A note on names
“TechOwl” means the company. “TechOwl
Shield” means one specific product, our attack surface, dark web and
brand monitoring service. Where we mean the company we say TechOwl, and where we mean
that product we say TechOwl Shield.
1.3 You
“You” means anyone who visits our websites, runs one of our
free tools, or signs in to our platform. You do not have to be a customer for these terms
to apply to you.
1.4 The sites these terms cover
These terms apply to techowl.com, techowlshield.com and
app.techowlshield.com, and to everything offered on them, including the
free tools, the sign in pages and the platform itself. The same version is published at
each site.
Not everything below is on every site. Where a section applies to one site only, it says
so at the start of that section.
2. What these terms cover, and what they do not
2.1 What they cover
These terms cover your use of the websites, the free tools, any trial or proof of concept
access we give you, and any part of the platform you reach without a separate signed
agreement.
2.2 If you are a customer, your signed agreement comes first
If you or your organisation has signed an agreement with us, such as a master services
agreement, an order form, a statement of work or a data processing agreement,
that agreement governs the services it covers and prevails over these
terms wherever the two differ. These terms fill the gaps. They do not reduce
anything we promised you in a signed contract, and they do not add charges, cancellation
rules or refund rules to it.
2.3 These terms are not our privacy notice, and using the site is not consent
We explain what we do with personal data in our
privacy policy, and in the
short notice shown at the point where we collect anything from you.
Accepting these terms does not give us consent to process your personal data, and
we do not ask you to treat it that way. Under section 6(1) of the
Digital Personal Data Protection Act, 2023, consent has to be free, specific,
informed, unconditional and unambiguous, given by a clear affirmative action, and limited
to the personal data that is necessary for the stated purpose. Agreeing to a set of
website terms is none of those things. Where we need your consent we will ask for it
separately, at the point it is needed, and we will tell you what it is for.
2.4 Nothing here takes away your rights under the Act
You keep every right the Digital Personal Data Protection Act, 2023 gives you, including
the right to complain to the Data Protection Board of India. Nothing in these terms asks
you to give up any of those rights, and if any part of these terms ever appeared to do so,
that part would not work. Section 6(2) of the Act says that any part of a
consent which infringes the Act is invalid to that extent, and the illustration to that
sub-section deals with exactly this situation: a person who agrees to waive her right to
complain to the Board has given an invalid consent as to that part.
3. Using the websites
The content of our websites is for general information. It may change without notice.
We do not warrant that the information on the sites is accurate, complete, current or fit
for any particular purpose. Security information dates quickly, and material that was
correct when written may not be correct when you read it.
Deciding whether anything on our sites suits your situation is your responsibility. If you
need advice about your own environment, ask us and we will scope it properly.
4. The free tools
4.1 What they are
The free tools are published on techowlshield.com. At the date of these
terms they are the DMARC Report Analyzer, the Leaked Credential
Checker, the DNS Record Checker, the Security
Headers Analyzer, the Subdomain Finder and the SSL
Checker. We may add tools, change them or withdraw them at any time.
4.2 You may only point them at things you are entitled to test
This is the most important rule on this page
You may use the free tools only against a domain, host, record or mailbox that:
you own; or
your organisation owns and you are authorised to act for; or
you have permission in writing from the owner to test.
You must not use the tools to examine anyone else’s systems out of
curiosity, to prepare an attack, or to build a profile of another organisation.
Running a scan against something you are not
entitled to test may be an offence under the Information Technology Act,
2000 and other laws, and it is your responsibility, not ours.
We may log the queries you run, including the address you send them from, so
that we can detect misuse of the tools.
4.3 Personal data you type into a tool
Some tools accept an email address. The Leaked Credential Checker is the
clearest example, because it accepts an email address and tells you whether it appears in
known breach data.
If the email address or other personal data you enter belongs to somebody else,
you are responsible for being entitled to submit it. By entering it you
confirm that it is your own, or that you are acting for the organisation the address
belongs to, or that you otherwise have a lawful reason to check it. Do not use the tool to
look up private individuals who have nothing to do with you.
We handle whatever you type in accordance with our
privacy policy.
4.4 What a result means, and what it does not
Results from the free tools are indicative and point in time. They tell
you what our systems could observe at the moment you ran them, from the outside, without
access to your network.
A clean result is not a certificate, an audit, an assurance, or a
statement that you are secure or compliant. A finding is not proof that you have been
compromised. False positives and false negatives both happen. Do not present a free tool
result to a regulator, a customer or an insurer as evidence of your security posture, and
do not rely on one as the basis of a decision that matters without having it checked
properly.
4.5 Fair use
The tools are for occasional manual use. You must not run them through scripts, scrape
them, run them in bulk, resell their output, or put them behind your own product. We may
rate limit, block or withdraw access if usage looks automated or abusive.
5. Accounts, sign in and proof of concept access
Sign in is provided at techowl.com and at app.techowlshield.com. If we
give you an account, a trial or a proof of concept environment:
give us accurate registration details and keep them up to date
keep your password and any second factor to yourself, and do not share a login
you are responsible for what happens under your login
tell us at once if you think your credentials or your account have been compromised
trial and proof of concept access is time limited, is for evaluation only, and is
provided as it stands with no service commitment
we may suspend or withdraw access to protect the platform, our other customers, or
ourselves
6. Acceptable use
You must not:
use the sites or tools to break any law
attack, probe, overload or attempt to gain unauthorised access to our systems, or test
their security without our written permission, except as described in section 10
reverse engineer, decompile or copy any part of the platform, except where the law
says you may despite an agreement to the contrary
upload anything designed to damage a system, including malicious code
copy, republish or resell our content or our tool output as though it were yours
misrepresent who you are, or who you are acting for
use anything you obtain from us to attack, harass or profile another person or
organisation
7. Your duties under the Data Protection Act
Most of India’s data protection law places duties on organisations like us.
Section 15 of the Digital Personal Data Protection Act, 2023 is the part that
places duties on you, and those duties apply when you deal with us about your
own personal data. We set them out here because a set of terms is the right place for the
obligations that fall on the person using the service.
Under section 15 you must:
obey the law when you exercise your rights under the Act
not impersonate anyone else when you provide personal data for a
stated purpose
not suppress material information when you give personal data for a
document, a unique identifier, a proof of identity or a proof of address issued by the
State
not raise a false or frivolous grievance or complaint with us or with
the Data Protection Board of India
give only information that is verifiably authentic when you ask us to
correct or erase your personal data
These are the Act’s duties, not ours, and we cannot waive them for you.
The Schedule to the Act sets the penalty for breaching a section 15 duty at an amount
which may extend to ten thousand rupees, and only the Data Protection
Board of India can impose it, after an inquiry. We do not levy it, and we will not
threaten it.
What this means in practice for you is short. Ask us about your own data,
not somebody else’s. Do not pretend to be another person to get at their records.
When you ask us to fix something, send us something we can actually check.
8. Intellectual property
The design, layout, look, appearance, graphics, text, software and reports on our sites are
owned by us or licensed to us. You may read them, and print or download a copy for your
own reference. You may not otherwise copy, republish, adapt or distribute them without our
written permission.
Trade marks on the sites which are not ours are acknowledged as belonging to their owners.
If we deliver a report to you under a signed agreement, that agreement says what you may do
with it. These terms do not narrow it.
9. Links
Our sites may link to other websites for convenience. We do not control them, we do not
endorse them, and we are not responsible for their content or their handling of your data.
You may link to our home page or to a public page as it is. Please do not frame our pages
inside your own site, present our content as yours, or link in a way that suggests we
endorse you when we do not.
10. Reporting a security problem in our own systems
We are a security company and we would rather hear about a weakness than not.
If you believe you have found a vulnerability in our websites or platform, report it to
[email protected] with
enough detail for us to reproduce it. Please give us a reasonable period to fix it before
you tell anyone else.
While you are investigating, stay within these limits: do not access, alter or download
anyone else’s data, do not degrade or interrupt the service, do not run denial of
service tests or bulk automated scanning, and do not use social engineering against our
staff.
If you report a problem to us and you have stayed within those limits, we will not
treat your report as a breach of section 6 and we will not pursue you for it.
11. No warranty
We provide the websites, the free tools and any trial access as they
stand. To the fullest extent the law allows, we exclude all warranties and
conditions that are not written down here, including any implied warranty of
merchantability, fitness for a particular purpose or non infringement.
We do not warrant that the sites or tools will be available without interruption, that they
will be free of errors, or that any result they give will be complete or accurate.
Services delivered under a signed agreement carry whatever warranties that agreement
states. This section does not cut them down.
12. Liability
Nothing in these terms limits our liability for death or personal injury caused by our
negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be
limited under Indian law. Nothing in these terms limits any liability we owe you under the
Digital Personal Data Protection Act, 2023, and no part of these terms transfers our
obligations as a Data Fiduciary onto you.
Subject to that, and to the fullest extent the law allows:
we are not liable for indirect or consequential loss, or for loss of profit, revenue,
business, goodwill, anticipated savings or data, however it arises
we are not liable for any decision you take on the basis of a free tool result
our total liability arising from your use of the websites, the free tools or any trial
access will not exceed the amount you have paid us for the item in question in
the twelve months before the claim, which for a free tool is nil
Where you have a signed agreement with us, the liability provisions of that
agreement apply to the services it covers, and this section does not.
13. Suspension and termination
We may suspend or withdraw all or part of the sites, the tools or your access at any time,
including where we reasonably believe you have breached these terms, where we need to
protect our systems or other users, or where we are required to by law.
Where you hold a signed agreement, suspension of the contracted services is governed by
that agreement and not by this section.
14. Changes to these terms
We may update these terms. The version published on the sites is the one that applies, and
it carries the date it took effect. Where a change materially affects people who hold
accounts with us, we will tell those account holders.
Continuing to use the sites after a change means the updated terms apply to you from then
on. A change does not apply backwards to something that already happened.
15. Governing law and jurisdiction
These terms and any dispute arising from them are governed by the laws of
India.
The courts at Surat, Gujarat have jurisdiction, and you and we submit to
them.
This does not affect your right to complain to the Data Protection Board of
India about how we have handled your personal data, and it does not require
you to go to court first.
Use the same address whether you are asking about these terms, asking about your personal
data, exercising a right under the Act, raising a grievance, or reporting a security
problem in our systems. If you are raising a grievance about your personal data, we
acknowledge within seven working days.
Techowl Infosec Private Limited. Published at techowl.com and techowlshield.com.