Terms

Terms of engagement

Short answer

Security testing is performed only against systems you own or are authorised to test, under a signed authorisation letter and a written scope. Testing is non-destructive by default, reports are confidential to you, and payment terms and liability limits are set out in the engagement letter that accompanies each proposal.

Authorisation

No testing begins without written authorisation from someone entitled to grant it for the systems in scope. Where the target is hosted by a third party, you are responsible for confirming that their terms permit security testing, and for notifying them where required.

Scope

The proposal states exactly what is in scope, what is excluded and the test window. Anything not listed is out of scope and will not be touched. Scope changes are agreed in writing and repriced before work continues.

Method and safety

Testing is non-destructive by default: no denial-of-service testing, no bulk data extraction, and the smallest proof of concept sufficient to demonstrate impact. Destructive or high-risk techniques are performed only with explicit written approval, in an agreed window, with a rollback plan.

Confidentiality

Findings, evidence and reports are confidential to you. Anonymised patterns may be discussed publicly only where nothing identifies the client, the product or the finding, and never within twelve months of the engagement.

Limitations

A penetration test is a point-in-time assessment of the scope tested. It cannot prove the absence of vulnerabilities, and it does not cover code, environments or configurations outside the agreed scope or deployed after the test window.

Payment and liability

EDIT-ME before launch: state your payment schedule, currency, taxes, cancellation terms, liability cap and governing jurisdiction. Have a lawyer review this section — the rest of this page is descriptive, but these clauses are contractual.