Authorisation
No testing begins without written authorisation from someone entitled to grant it for the systems in scope. Where the target is hosted by a third party, you are responsible for confirming that their terms permit security testing, and for notifying them where required.
Scope
The proposal states exactly what is in scope, what is excluded and the test window. Anything not listed is out of scope and will not be touched. Scope changes are agreed in writing and repriced before work continues.
Method and safety
Testing is non-destructive by default: no denial-of-service testing, no bulk data extraction, and the smallest proof of concept sufficient to demonstrate impact. Destructive or high-risk techniques are performed only with explicit written approval, in an agreed window, with a rollback plan.
Confidentiality
Findings, evidence and reports are confidential to you. Anonymised patterns may be discussed publicly only where nothing identifies the client, the product or the finding, and never within twelve months of the engagement.
Limitations
A penetration test is a point-in-time assessment of the scope tested. It cannot prove the absence of vulnerabilities, and it does not cover code, environments or configurations outside the agreed scope or deployed after the test window.
Payment and liability
EDIT-ME before launch: state your payment schedule, currency, taxes, cancellation terms, liability cap and governing jurisdiction. Have a lawyer review this section — the rest of this page is descriptive, but these clauses are contractual.