CyRAACS SERVICE
Consulting services can provide the expertise and guidance needed to ensure your business is protected from malicious actors. Whether you’re looking to implement a comprehensive security strategy or simply need advice on compliance and data protection, a cybersecurity consultant can provide the support you need.

At CyRAACS, we perform an extensive Risk Assessment to identify the inherent and residual information security risks across the organization. Based on the assessment conducted, we recommend Risk Mitigation measures to ensure the appropriate security controls are in place in line with the organization risk appetite.

Business Continuity planning is essentially a form of insurance. It gives organizations the comfort of knowing that, even if disaster strikes, the damage won’t be overwhelming.
Having an effective Business Continuity Management ensures that organizations can continue to provide an acceptable service in the event of a disaster, helping them preserve their reputation and keep revenue coming in. In the event that its key management resources are compromised, it is critical for an organization to be proactive and create a viable plan of countermeasures.
CyRAACS’s business continuity professionals provide consultancy help in identifying risks arising from third party vendor networks, managing them effectively, and planning how you can operate, improving your organizational resilience.

An Information Security Maturity Model provides a path forward and enables the organization to periodically assess where it is along that path. Our unique qualitative and quantitative assessment model is adapted from the CMMI rating scale. CyRAACS’s Maturity Model Assessment framework helps to understand the organization’s risk exposure, and the maturity of the current information security program and identify areas for improvement, we also create benchmarks against other organizations and validate that security investments have improved security posture. We also provide a roadmap with opportunities in the areas of technology, process, and capabilities for information security.

For today’s way of the data treatment, it is an easy target to expose as organizations across the world are looking at the increasing amounts of data to deal with every day, this could be through e-mails, files, transactions, etc. Hence organizations urgently need to understand what their sensitive data is and where they are so that they can deploy appropriate controls to protect it. Data Flow Analysis (DFA) is the first step toward identifying sensitive data and implementing appropriate security controls for data protection.
CyRAACS’s DFA framework covers all the stages of the data lifecycle right from data acquisition to retirement. It helps to capture an accurate picture of the data flow at various stages within the organization. The output from DFA can act as key inputs to a Digital Rights Management (DRM) or Data Leakage Prevention (DLP) tool implementation, should an organization wish to implement those tools.

Build your future with us.
TERMS AND CONDITIONS
Effective Date: 1st April 2026 | Version: 1.1
“AI-Assisted Output” means any output, recommendation, assessment, mapping, evaluation, report or other content generated or materially assisted by artificial intelligence or automated analytical functionality within COMPASS.
“Authorised User” means an individual authorised by the Customer to access COMPASS under the Subscription.
“Certified Report” means an AI-Assisted Output that has undergone human review and certification in accordance with Clause 5.
“Confidential Information” means non-public information disclosed by one Party to the other in connection with this Agreement.
“COMPASS” means the CyRAACS governance, risk and compliance (“GRC”) platform, including its modules, features and related technology, as described in the Documentation.
“Customer Data” means information, records, evidence and other content submitted or generated by or on behalf of the Customer through COMPASS.
“Documentation” means the then-current user guides, product descriptions, and technical and security documentation made available by CyRAACS describing COMPASS’s functionality, modules and features in detail. The Documentation is incorporated into this Agreement by reference and may be updated by CyRAACS from time to time to reflect the evolution of COMPASS, provided that no such update shall materially reduce the core functionality purchased under an active Order Form without the Customer’s consent or a corresponding fee adjustment.
“Order Form” means a subscription order, proposal or other commercial document executed by the Parties specifying the Subscription, applicable modules and fees.
“Subscription” and “Subscription Term” mean the Customer’s subscription to COMPASS and the period specified in the applicable Order Form.
2.1 COMPASS is a cloud-based, AI-enabled GRC platform that helps organisations establish, manage, monitor and report on their governance, risk and compliance activities, including AI-assisted document mapping and evidence evaluation subject to human expert review. The specific modules and functionality available to the Customer are as set out in the applicable Order Form and described in the Documentation.
2.2 Subject to the Customer’s payment of applicable Fees and continued compliance with this Agreement, CyRAACS grants the Customer, during the Subscription Term, a limited, non-exclusive, non-transferable, non-sublicensable right to access and use COMPASS for its internal business, GRC, risk and compliance purposes. This is a right to access and use COMPASS, not a transfer of ownership of the platform or any underlying intellectual property.
2.3 The Customer may permit Authorised Users to access COMPASS within the scope of the Subscription and remains responsible for their compliance with this Agreement. CyRAACS may permit its own authorised personnel to access the Customer’s COMPASS environment to the extent necessary to provide the Subscription and any Professional Services.
3.1 The modules, number of Authorised Users, Subscription Term and Fees are set out in the applicable Order Form. No functionality is included merely because it exists within COMPASS generally; only functionality identified in the Order Form or Documentation as included in the Customer’s Subscription forms part of it.
3.2 Fees are payable in accordance with the applicable Order Form, are exclusive of applicable taxes, and are invoiced and payable within thirty (30) days of the invoice date unless otherwise stated. CyRAACS may charge interest on overdue amounts at 2% per month (or the maximum rate permitted by law, if lower) and may suspend access if payment remains overdue for more than 30 (Thirty) days’ written notice. Any good-faith invoice dispute must be raised within 15 (Fifteen) days of the invoice date; undisputed amounts remain payable pending resolution. Renewal-term Fees may be revised on not less than 30 (Thirty) days’ written notice.
The Customer is responsible for: the accuracy of information and evidence it submits through COMPASS; identifying appropriate internal stakeholders and ensuring their timely participation in assigned activities; reviewing AI-Assisted Outputs and compliance findings generated by COMPASS; determining and implementing any remediation or risk-acceptance decisions; and ensuring its own compliance with applicable laws and regulations. COMPASS is a tool that supports the Customer’s GRC programme; it does not replace the Customer’s own governance, risk-acceptance and compliance obligations.
5.1 COMPASS uses artificial intelligence to assist with functions such as document mapping, evidence analysis, compliance evaluation and report preparation, as further described in the Documentation. AI-Assisted Outputs may contain inaccuracies, omissions or errors and must be subject to appropriate human review before being relied upon for consequential GRC decisions; this acknowledgement directly informs the limitations of liability at Clause 12.
5.2 Where COMPASS requires human review, an appropriately authorised reviewer may approve, reject, request changes to, or override an AI-Assisted Output based on professional judgement and available evidence. Where a report is designated a Certified Report, certification confirms that: (a) the output was reviewed by the certifying individual; (b) the evidence relied upon was reviewed for apparent relevance, sufficiency and consistency with the applicable requirements as presented within COMPASS; and (c) the findings reflect the certifying individual’s professional judgement as at the date of certification, based on information available through COMPASS. Certification does NOT constitute a legal opinion, a warranty that the Customer is or will remain compliant with any law or standard, an audit or assurance opinion under any professional auditing standard (unless separately agreed in writing), or independent verification of facts beyond those available to CyRAACS through COMPASS.
5.3 Except where the Customer has separately opted in under an Order Form to a model-improvement programme, Customer Data shall not be used to train, fine-tune or improve general-purpose AI models made available to other customers or third parties. Any opt-in is withdrawable on [30] days’ written notice. CyRAACS may use aggregated, de-identified data that does not identify the Customer for analytics and product improvement.
5.4 Where the Customer’s use of COMPASS falls within scope of the EU Artificial Intelligence Act or equivalent AI-specific legislation, CyRAACS shall provide such transparency information as is reasonably required for the Customer to meet its own obligations as a deployer, on the Customer providing written notice that such legislation applies. Nothing in this Clause 5.4 constitutes CyRAACS accepting the role of “provider” of a high-risk AI system unless expressly agreed in writing.
6.1 The Customer retains ownership of Customer Data and grants CyRAACS a limited licence to process it solely to provide COMPASS, deliver support and contracted services, and comply with applicable law. The Parties shall comply with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (India), and shall execute a separate Data Processing Agreement (“DPA”) governing personal data processing, security measures, data transfers, breach notification, retention and deletion, and data-subject rights.
6.2 CyRAACS shall maintain, as a schedule to the DPA, a current named list of subprocessors engaged in processing Customer Data and shall give the Customer not less than thirty (30) days’ prior notice before engaging a new or replacement subprocessor. The Customer may object on reasonable data-protection grounds within that period; if unresolved within a further thirty (30) days, the Customer may terminate the affected Subscription without penalty as its sole remedy.
6.3 On termination or expiry, CyRAACS shall, on written request within thirty (30) days, make Customer Data available for export in a reasonably accessible format, and shall thereafter delete or anonymise or save, where retention is required by law within 30 (Thirty) days.
CyRAACS shall maintain administrative, technical and organisational safeguards appropriate to the nature of Customer Data processed through COMPASS, as further described in CyRAACS’s security documentation made available to the Customer on request, covering matters including hosting, encryption, access controls, logging, vulnerability management, backup and disaster recovery, and relevant security certifications. CyRAACS shall notify the Customer without undue delay following confirmation of a security incident affecting Customer Data.
Each Party shall protect the other’s Confidential Information, use it only for purposes connected with this Agreement, and disclose it only to persons who need to know it and are bound by confidentiality obligations. These obligations survive termination for two (2) years, save that obligations relating to trade secrets survive for as long as the information retains that character under applicable law.
CyRAACS retains all rights in COMPASS, including its software, algorithms, AI technology, workflows, templates and Documentation. The Customer retains rights in Customer Data and its own materials. The Customer may provide feedback on COMPASS, which CyRAACS may use to improve its products without transferring ownership of Customer Data.
The Customer shall not: (a) reverse engineer COMPASS; (b) attempt unauthorised access or interfere with Platform security; (c) use COMPASS to violate applicable law or upload malicious code; (d) circumvent usage restrictions or resell COMPASS without written authorisation; or (e) use COMPASS to build a competing product or permit unauthorised persons to access it.
Each Party warrants it has full authority to enter into this Agreement. CyRAACS warrants that COMPASS will materially conform to the Documentation. EXCEPT AS EXPRESSLY SET OUT IN THIS AGREEMENT, COMPASS AND ALL AI-ASSISTED OUTPUTS ARE PROVIDED “AS IS”, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT. CYRAACS DOES NOT WARRANT THAT COMPASS WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ANY AI-ASSISTED OUTPUT WILL BE ACCURATE OR COMPLETE. THE CUSTOMER’S SOLE REMEDIES FOR BREACH OF THIS CLAUSE 11 ARE AS SET OUT IN CLAUSE 12.
12.1 SUBJECT TO CLAUSE 12.4, EACH PARTY’S AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT SHALL NOT EXCEED THE FEES PAID OR PAYABLE BY THE CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, AND NEITHER PARTY SHALL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, REVENUE, DATA OR GOODWILL.
12.2 NOTWITHSTANDING CLAUSE 12.1, AND SUBJECT TO CLAUSE 12.4, CYRAACS’S AGGREGATE LIABILITY FOR CLAIMS RELATING TO THE ACCURACY, COMPLETENESS OR SUITABILITY OF ANY AI-ASSISTED OUTPUT SHALL NOT EXCEED THE FEES PAID IN THE THREE (3) MONTHS PRECEDING THE CLAIM, and the Customer’s sole remedy for such a claim shall be for CyRAACS to investigate and, where warranted, correct or regenerate the output; no monetary damages shall be payable except to the extent the deficiency resulted from CyRAACS’s failure to provide the human review required under Clause 5. CyRAACS shall have no liability whatsoever for reliance on an AI-Assisted Output that has not undergone certification under Clause 5, or that is relied upon beyond the scope of certification described in Clause 5.2.
12.3 CyRAACS shall indemnify the Customer against third-party claims that COMPASS or a Certified Report, used in accordance with this Agreement, infringes a third party’s intellectual property rights, and the Customer shall indemnify CyRAACS against third-party claims arising from Customer Data, the Customer’s breach of Clause 10, or the Customer’s unauthorised or unlawful use of COMPASS — in each case subject to the indemnified Party promptly notifying the indemnifying Party, granting it sole control of the defence and settlement, and providing reasonable cooperation, and subject to the cap in Clause 12.2 where the claim relates to an AI-Assisted Output.
12.4 Nothing in this Agreement excludes or limits either Party’s liability for death or personal injury caused by negligence, fraud, breach of confidentiality under Clause 8, infringement of the other Party’s intellectual property rights, or any liability which cannot lawfully be excluded or limited.
13.1 This Agreement commences on the Effective Date and continues for the Subscription Term, renewing automatically for successive equivalent periods unless either Party gives written notice of non-renewal at least 30 (Thirty) days before the end of the then-current term.
13.2 Either Party may terminate this Agreement with immediate effect on written notice if the other commits a material breach not remedied within thirty (30) days of notice, or becomes insolvent or ceases to carry on business. CyRAACS may suspend access on reasonable notice (or immediately in a security emergency) for overdue payment or breach of Clause 10.
13.3 On termination or expiry: licences granted to the Customer cease immediately; accrued Fees remain payable; Confidential Information is returned or destroyed on request; and Customer Data is handled in accordance with Clause 6.3. Clauses 6.1, 6.3, 8, 9, 11, 12 and 16 survive termination, together with any clause intended by its nature to survive.
Unless a separately executed SLA states otherwise, CyRAACS shall use commercially reasonable efforts to make COMPASS available with an uptime of not less than 99.5%, measured monthly, excluding scheduled maintenance (with at least 48 hours’ notice), Force Majeure Events, and third-party integration failures outside CyRAACS’s control. Support is provided in accordance with the applicable SLA or support policy; where a separately executed SLA provides service credits for missed availability, such credits are the Customer’s sole remedy for the relevant unavailability, save where it also constitutes a material breach under Clause 13.2.
CyRAACS may separately offer GRC consulting, implementation, configuration or training services (“Professional Services”) under a statement of work or Order Form specifying scope, deliverables and fees. Professional Services are optional, additional to the Subscription, and governed by the applicable statement of work; access to COMPASS is not conditional on purchasing them. CyRAACS will perform Professional Services with reasonable skill and care but does not warrant a specific outcome unless expressly stated in the statement of work.