Legal
Terms of Service
These terms set out the nature of our services, how assessment and quoting work, an important statement on decryption outcomes, client obligations, confidentiality, liability limits and dispute resolution.
Scope of these terms
These terms are issued by Zhengzhou SheMo Information Technology Co., Ltd. ("we", "us") in respect of services provided under the SheMo Noransom brand, and apply to your browsing of this website, submission of enquiries, engagement of an assessment and receipt of services.
These terms are a framework. The scope, deliverables, fees, schedule and respective obligations for any specific engagement are governed by the service contract, quotation or statement of work signed separately; where those conflict with these terms, the signed document prevails.
By submitting an enquiry, sending samples or engaging our services, you are deemed to have read and accepted these terms and the Privacy Policy.
Nature of the services
We provide technical services: ransomware decryption, incident response, data recovery, attack forensics and security hardening.
We do provide
- ransomware family and version identification, and recoverability assessment;
- recovery execution, including decryption, database and file repair, and backup and remnant data extraction;
- incident containment, evidence preservation and eradication of persistence;
- forensic analysis and reporting;
- hardening design, implementation and verification.
We do not provide
- communication, negotiation or ransom payment with attackers, nor purchase or transfer of cryptocurrency;
- identification of individual attackers, which is the remit of law enforcement;
- legal advice, compliance certification or audit opinions;
- warranties for third-party hardware or software products;
- any unauthorized activity against systems belonging to others, including penetration, attack or data acquisition.
A forensic report is a technical analysis document. It can serve as technical material for a police filing and compliance records, but it does not constitute a judicial expert opinion unless separately agreed and legally qualified as such.
Assessment, quotation and payment
Assessment first. Other than emergency containment guidance, we do not begin recovery work before family identification and the recoverability assessment are complete. The assessment states the recoverable scope, available paths, expected outcome and risks.
Quotation. Fees are determined after assessment based on service type, data volume, environment complexity, recovery difficulty and time requirements, and are provided as a written quotation. Once confirmed by both parties the quotation is the basis for settlement; changes in scope are handled through a written change order.
Payment. Payment milestones, methods and invoicing are set out in the contract or quotation. We do not accept settlement in cryptocurrency and provide no form of ransom payment.
Out-of-scope work. Additional effort caused by deficiencies in the client's own environment — hardware faults, missing licences, unavailable third-party systems — is not covered by the original quotation; we explain the situation first and any adjustment is agreed by both parties.
Important statement on decryption and recovery outcomes
Please read this section carefully — it is the part of these terms that most needs to be understood in advance.
- We do not guarantee successful decryption. Whether decryption is possible is determined by the ransomware family, the variant and the state of the keys. For mainstream strong-encryption families there is no feasible path unless keys have leaked. No statement of "100% decryption" or "guaranteed recovery" forms part of our commitments.
- Recovery outcomes are expressed as a scope, not as an absolute result. The assessment report gives an expected recoverable scope and the paths to it; what was actually achieved is evidenced by the data manifest and verification results at handover.
- Some data may be permanently unrecoverable. Where files are fully encrypted with no backup, disk regions have been overwritten, media are physically damaged, or key evidence has been wiped, the probability drops sharply and may be zero.
- Where the assessment concludes data is unrecoverable, we say so and advise on rebuilding and re-entering data rather than continuing work with no substantive prospect of success.
- Effect of prior actions. Reboots, reinstallation, formatting, disk check and repair utilities, third-party recovery software scans and virus cleanup performed before engaging us may already have irreversibly reduced recoverability; consequences arising from those actions fall outside our responsibility.
- We advise against paying a ransom in all circumstances. If a client decides independently to transact with an attacker, the associated risks and consequences rest with the client.
Client obligations
So that the service can proceed lawfully and effectively, you undertake to:
- Hold valid authority. Confirm that you own or are authorized to deal with the systems and data entrusted to us, and that internal approvals and any necessary third-party consents (cloud provider, hosting party, software vendor) are in place. We work only within the authorization you confirm in writing or in a traceable form.
- Ensure data legality. Confirm the data entrusted to us contains nothing whose possession or dissemination is prohibited by law, and that where personal information is involved you have a lawful basis and have met your notification obligations.
- Provide truthful and complete information about the incident, actions already taken, the environment and the state of backups. Withholding material information can skew the assessment, and the resulting consequences rest with you.
- Cooperate as needed: provide access, downtime windows, target storage and operations staff, and nominate a point of contact and an acceptance signatory.
- Complete acceptance promptly, carrying out sampling verification and acceptance confirmation within the agreed period.
- Retain your own copies of important data before and after our work. Our read-only method reduces risk but does not replace your own responsibility for data custody.
- Use deliverables lawfully. Reports, checklists and technical material are for your internal response, compliance records, police filing and other uses we have agreed.
Confidentiality
Each party owes the other a duty of confidence in respect of commercial and technical information learned during the engagement.
Our commitments
- Client identity, environment information, samples, data and report contents are used solely for the engagement and are not disclosed to unrelated third parties.
- Access is limited to personnel on the engagement, who are bound by confidentiality obligations.
- We do not use your name or marks in marketing, and do not disclose identifiable case details, without your written consent. Case studies published on this website are anonymized, illustrative examples.
- Working copies are deleted within the agreed period after the engagement, with a deletion confirmation available on request.
Exceptions
Where disclosure is required by law or by a judicial or regulatory authority, we will, to the extent legally permitted, inform you in advance of the scope disclosed. Information already lawfully in the public domain, or independently obtained by a party free of any duty of confidence, is not confidential information.
Confidentiality obligations survive the engagement for the period set out in the contract; absent such a term, for three years from its conclusion.
Limitation of liability
- We provide services with due professional care to generally accepted industry standards, but give no guarantee as to recovery outcomes, data completeness or the time to restore operations.
- Where our fault causes you direct loss, we bear the corresponding liability under law. Except where mandatory law or the contract provides otherwise, our aggregate liability is limited to the service fees you have paid for that engagement.
- We are not liable for indirect loss, loss of profit, business interruption loss, loss of goodwill, loss of data value, or third-party claims.
- The following fall outside our responsibility:
- reduced recoverability caused by actions you took before engaging us or contrary to our instructions (reboot, reinstallation, formatting, disk repair, third-party software scans);
- consequences of information you provided being untrue or incomplete, or of insufficient authorization;
- a further security incident arising because our hardening recommendations were not implemented;
- force majeure, third-party infrastructure failure, defects in third-party hardware or software, and subsequent actions by attackers;
- any consequence of you transacting with an attacker, including paying a ransom.
- Nothing in these terms excludes or limits liability that may not be excluded or limited under applicable law.
Governing law and dispute resolution
The formation, validity, interpretation, performance and dispute resolution of these terms are governed by the laws of the People's Republic of China.
Any dispute arising from these terms or the services shall first be addressed through good-faith negotiation. Failing that, either party may bring proceedings before the competent people's court at our place of domicile, Zhengzhou, Henan Province, China.
Where a separately signed service contract provides a different dispute resolution mechanism, such as arbitration, that contract prevails.
If any provision of these terms is held invalid or unenforceable, the remaining provisions continue in effect.
These terms were last updated on 11 September 2026. We may update them in response to changes in law or in our services, with updates published on this page; for engagements already under a signed contract, the terms agreed at signing apply.
Updated