TECHOWL

Terms of Use

Please read these terms before you use our websites or our free tools. They are a contract between you and us. If you do not accept them, please do not use the sites.

These terms replace the terms and conditions dated 12 September 2023.

Effective from 22 August 2026

1. Who these terms are between

1.1 Us

These terms are issued by Techowl Infosec Private Limited, a company incorporated in India, with its registered and operational office at A-406 Monarch, Gaurav Path Road, Adajan, Surat, Gujarat 395009. In these terms, “we”, “us” and “our” mean that company.

1.2 A note on names

“TechOwl” means the company. “TechOwl Shield” means one specific product, our attack surface, dark web and brand monitoring service. Where we mean the company we say TechOwl, and where we mean that product we say TechOwl Shield.

1.3 You

“You” means anyone who visits our websites, runs one of our free tools, or signs in to our platform. You do not have to be a customer for these terms to apply to you.

1.4 The sites these terms cover

These terms apply to techowl.com, techowlshield.com and app.techowlshield.com, and to everything offered on them, including the free tools, the sign in pages and the platform itself. The same version is published at each site.

Not everything below is on every site. Where a section applies to one site only, it says so at the start of that section.

2. What these terms cover, and what they do not

2.1 What they cover

These terms cover your use of the websites, the free tools, any trial or proof of concept access we give you, and any part of the platform you reach without a separate signed agreement.

2.2 If you are a customer, your signed agreement comes first

If you or your organisation has signed an agreement with us, such as a master services agreement, an order form, a statement of work or a data processing agreement, that agreement governs the services it covers and prevails over these terms wherever the two differ. These terms fill the gaps. They do not reduce anything we promised you in a signed contract, and they do not add charges, cancellation rules or refund rules to it.

2.3 These terms are not our privacy notice, and using the site is not consent

We explain what we do with personal data in our privacy policy, and in the short notice shown at the point where we collect anything from you.

Accepting these terms does not give us consent to process your personal data, and we do not ask you to treat it that way. Under section 6(1) of the Digital Personal Data Protection Act, 2023, consent has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data that is necessary for the stated purpose. Agreeing to a set of website terms is none of those things. Where we need your consent we will ask for it separately, at the point it is needed, and we will tell you what it is for.

2.4 Nothing here takes away your rights under the Act

You keep every right the Digital Personal Data Protection Act, 2023 gives you, including the right to complain to the Data Protection Board of India. Nothing in these terms asks you to give up any of those rights, and if any part of these terms ever appeared to do so, that part would not work. Section 6(2) of the Act says that any part of a consent which infringes the Act is invalid to that extent, and the illustration to that sub-section deals with exactly this situation: a person who agrees to waive her right to complain to the Board has given an invalid consent as to that part.

3. Using the websites

The content of our websites is for general information. It may change without notice.

We do not warrant that the information on the sites is accurate, complete, current or fit for any particular purpose. Security information dates quickly, and material that was correct when written may not be correct when you read it.

Deciding whether anything on our sites suits your situation is your responsibility. If you need advice about your own environment, ask us and we will scope it properly.

4. The free tools

4.1 What they are

The free tools are published on techowlshield.com. At the date of these terms they are the DMARC Report Analyzer, the Leaked Credential Checker, the DNS Record Checker, the Security Headers Analyzer, the Subdomain Finder and the SSL Checker. We may add tools, change them or withdraw them at any time.

4.2 You may only point them at things you are entitled to test

This is the most important rule on this page

You may use the free tools only against a domain, host, record or mailbox that:

  • you own; or
  • your organisation owns and you are authorised to act for; or
  • you have permission in writing from the owner to test.

You must not use the tools to examine anyone else’s systems out of curiosity, to prepare an attack, or to build a profile of another organisation. Running a scan against something you are not entitled to test may be an offence under the Information Technology Act, 2000 and other laws, and it is your responsibility, not ours.

We may log the queries you run, including the address you send them from, so that we can detect misuse of the tools.

4.3 Personal data you type into a tool

Some tools accept an email address. The Leaked Credential Checker is the clearest example, because it accepts an email address and tells you whether it appears in known breach data.

If the email address or other personal data you enter belongs to somebody else, you are responsible for being entitled to submit it. By entering it you confirm that it is your own, or that you are acting for the organisation the address belongs to, or that you otherwise have a lawful reason to check it. Do not use the tool to look up private individuals who have nothing to do with you.

We handle whatever you type in accordance with our privacy policy.

4.4 What a result means, and what it does not

Results from the free tools are indicative and point in time. They tell you what our systems could observe at the moment you ran them, from the outside, without access to your network.

A clean result is not a certificate, an audit, an assurance, or a statement that you are secure or compliant. A finding is not proof that you have been compromised. False positives and false negatives both happen. Do not present a free tool result to a regulator, a customer or an insurer as evidence of your security posture, and do not rely on one as the basis of a decision that matters without having it checked properly.

4.5 Fair use

The tools are for occasional manual use. You must not run them through scripts, scrape them, run them in bulk, resell their output, or put them behind your own product. We may rate limit, block or withdraw access if usage looks automated or abusive.

5. Accounts, sign in and proof of concept access

Sign in is provided at techowl.com and at app.techowlshield.com. If we give you an account, a trial or a proof of concept environment:

  • give us accurate registration details and keep them up to date
  • keep your password and any second factor to yourself, and do not share a login
  • you are responsible for what happens under your login
  • tell us at once if you think your credentials or your account have been compromised
  • trial and proof of concept access is time limited, is for evaluation only, and is provided as it stands with no service commitment
  • we may suspend or withdraw access to protect the platform, our other customers, or ourselves

6. Acceptable use

You must not:

  • use the sites or tools to break any law
  • attack, probe, overload or attempt to gain unauthorised access to our systems, or test their security without our written permission, except as described in section 10
  • reverse engineer, decompile or copy any part of the platform, except where the law says you may despite an agreement to the contrary
  • upload anything designed to damage a system, including malicious code
  • copy, republish or resell our content or our tool output as though it were yours
  • misrepresent who you are, or who you are acting for
  • use anything you obtain from us to attack, harass or profile another person or organisation

7. Your duties under the Data Protection Act

Most of India’s data protection law places duties on organisations like us. Section 15 of the Digital Personal Data Protection Act, 2023 is the part that places duties on you, and those duties apply when you deal with us about your own personal data. We set them out here because a set of terms is the right place for the obligations that fall on the person using the service.

Under section 15 you must:

  1. obey the law when you exercise your rights under the Act
  2. not impersonate anyone else when you provide personal data for a stated purpose
  3. not suppress material information when you give personal data for a document, a unique identifier, a proof of identity or a proof of address issued by the State
  4. not raise a false or frivolous grievance or complaint with us or with the Data Protection Board of India
  5. give only information that is verifiably authentic when you ask us to correct or erase your personal data

These are the Act’s duties, not ours, and we cannot waive them for you. The Schedule to the Act sets the penalty for breaching a section 15 duty at an amount which may extend to ten thousand rupees, and only the Data Protection Board of India can impose it, after an inquiry. We do not levy it, and we will not threaten it.

What this means in practice for you is short. Ask us about your own data, not somebody else’s. Do not pretend to be another person to get at their records. When you ask us to fix something, send us something we can actually check.

8. Intellectual property

The design, layout, look, appearance, graphics, text, software and reports on our sites are owned by us or licensed to us. You may read them, and print or download a copy for your own reference. You may not otherwise copy, republish, adapt or distribute them without our written permission.

Trade marks on the sites which are not ours are acknowledged as belonging to their owners.

If we deliver a report to you under a signed agreement, that agreement says what you may do with it. These terms do not narrow it.

9. Links

Our sites may link to other websites for convenience. We do not control them, we do not endorse them, and we are not responsible for their content or their handling of your data.

You may link to our home page or to a public page as it is. Please do not frame our pages inside your own site, present our content as yours, or link in a way that suggests we endorse you when we do not.

10. Reporting a security problem in our own systems

We are a security company and we would rather hear about a weakness than not.

If you believe you have found a vulnerability in our websites or platform, report it to [email protected] with enough detail for us to reproduce it. Please give us a reasonable period to fix it before you tell anyone else.

While you are investigating, stay within these limits: do not access, alter or download anyone else’s data, do not degrade or interrupt the service, do not run denial of service tests or bulk automated scanning, and do not use social engineering against our staff.

If you report a problem to us and you have stayed within those limits, we will not treat your report as a breach of section 6 and we will not pursue you for it.

11. No warranty

We provide the websites, the free tools and any trial access as they stand. To the fullest extent the law allows, we exclude all warranties and conditions that are not written down here, including any implied warranty of merchantability, fitness for a particular purpose or non infringement.

We do not warrant that the sites or tools will be available without interruption, that they will be free of errors, or that any result they give will be complete or accurate.

Services delivered under a signed agreement carry whatever warranties that agreement states. This section does not cut them down.

12. Liability

Nothing in these terms limits our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be limited under Indian law. Nothing in these terms limits any liability we owe you under the Digital Personal Data Protection Act, 2023, and no part of these terms transfers our obligations as a Data Fiduciary onto you.

Subject to that, and to the fullest extent the law allows:

  • we are not liable for indirect or consequential loss, or for loss of profit, revenue, business, goodwill, anticipated savings or data, however it arises
  • we are not liable for any decision you take on the basis of a free tool result
  • our total liability arising from your use of the websites, the free tools or any trial access will not exceed the amount you have paid us for the item in question in the twelve months before the claim, which for a free tool is nil

Where you have a signed agreement with us, the liability provisions of that agreement apply to the services it covers, and this section does not.

13. Suspension and termination

We may suspend or withdraw all or part of the sites, the tools or your access at any time, including where we reasonably believe you have breached these terms, where we need to protect our systems or other users, or where we are required to by law.

Where you hold a signed agreement, suspension of the contracted services is governed by that agreement and not by this section.

14. Changes to these terms

We may update these terms. The version published on the sites is the one that applies, and it carries the date it took effect. Where a change materially affects people who hold accounts with us, we will tell those account holders.

Continuing to use the sites after a change means the updated terms apply to you from then on. A change does not apply backwards to something that already happened.

15. Governing law and jurisdiction

These terms and any dispute arising from them are governed by the laws of India.

The courts at Surat, Gujarat have jurisdiction, and you and we submit to them.

This does not affect your right to complain to the Data Protection Board of India about how we have handled your personal data, and it does not require you to go to court first.

16. How to contact us

Email: [email protected]

Post: Techowl Infosec Private Limited, A-406 Monarch, Gaurav Path Road, Adajan, Surat, Gujarat 395009.

Use the same address whether you are asking about these terms, asking about your personal data, exercising a right under the Act, raising a grievance, or reporting a security problem in our systems. If you are raising a grievance about your personal data, we acknowledge within seven working days.

Techowl Infosec Private Limited. Published at techowl.com and techowlshield.com.