Disclaimer & Limitation of Liability
Effective date: 15 August 2026 ยท Governed by the laws of the Hong Kong Special Administrative Region

1. Snapshot Nature of Findings

All findings, assessments, evaluations and recommendations provided by LuDuan AI Group ("LuDuan", "we", "us") reflect the environment, systems, configurations and information available to us as at the date of the assessment. They constitute a point-in-time snapshot only.

Organisational environments change continuously. System updates, configuration changes, personnel changes, new deployments or changes in the threat landscape occurring after the assessment date may affect the accuracy, completeness or applicability of our findings. We recommend periodic re-assessment to account for changes in your environment. The findings and recommendations in our deliverables are valid as at the assessment date only and should not be relied upon for decisions made after that date.

2. No Guarantee of Completeness

While we apply professional care and industry-standard methodologies, no assessment, penetration test, vulnerability scan or evaluation can guarantee the discovery of every vulnerability, gap or loophole. Undiscovered issues may exist due to the nature of testing, tool limitations, time constraints or information provided.

To the maximum extent permitted by law, LuDuan and its nominated consultants shall not be liable for any vulnerabilities, gaps or loopholes that are not identified during the assessment, evaluation, testing or scanning or for any loss or damage arising from such unidentified issues, whether direct, indirect, consequential or incidental.

3. AI-Generated Content

Our services may involve the use of artificial intelligence (AI) systems to generate preliminary findings, draft reports or provide initial insights. AI-generated content is for informational purposes only and does not constitute professional advice. Clients are responsible for exercising their own judgment and verifying AI-generated outputs before relying on them.

4. Reliance on Client-Provided Information

Our assessment relies on the accuracy, completeness and currency of information provided by you. We are not responsible for findings that are affected by inaccurate, incomplete or outdated information supplied by you or your representatives.

5. Third-Party Systems

Systems, services or platforms operated by third parties (including cloud providers, SaaS vendors and hosting providers) are outside our control. We are not liable for issues arising in such third-party environments or for changes made by third parties after the assessment.

6. Limitation of Liability

To the maximum extent permitted by applicable law (including the Control of Exemption Clauses Ordinance, Cap. 71), nothing in this Agreement shall exclude or restrict our liability for fraud, gross negligence, willful misconduct or death or personal injury caused by negligence.

Subject to the foregoing, our aggregate liability arising out of or in connection with any engagement whether in contract, tort (including negligence) or otherwise, shall not exceed the total fees paid by you for the specific engagement giving rise to the claim. We shall not be liable for any indirect, incidental, special, consequential or punitive damages or any loss of profits, revenue, data or business opportunities.

For higher-risk services (such as penetration testing and security architecture review), you acknowledge that the limitation of liability above has been brought to your attention at order placement and you accept it as reasonable in the context of the fees payable for such services.

7. Report Use

Reports and deliverables are provided for your internal use only and may not be shared with third parties without our prior written consent, except as required by law or as necessary for regulatory or insurance purposes.

8. Validity of Findings

Findings and recommendations are valid as at the assessment date only and should be re-validated before any procurement, compliance or security investment decisions are made based on them.

9. Governing Law

These terms are governed by the laws of the Hong Kong Special Administrative Region. Any dispute shall be subject to the exclusive jurisdiction of the courts of Hong Kong.

Relationship with Other Documents

This document forms part of the LuDuan legal framework together with the Non-Disclosure Agreement, Data Sharing Consent, Disclaimer, Penetration Test Authorization, Service Terms and Refund Policy. Where there is any conflict, the order of precedence is: Penetration Test Authorization, NDA, Data Sharing Consent, Disclaimer, Service Terms, Refund Policy, unless expressly agreed otherwise in writing. All documents acknowledged at order placement together constitute the agreement governing your engagement with LuDuan.