Rules of engagement / v1.0

Rules of engagement: we only test with written permission.

Rules of engagement are the written terms of a penetration test: what may be tested, when, how and by whom, and how to stop it. Ours start from one rule: we test only what the owner has authorized in writing1. The other seven say how we behave inside that permission.

§02 / Eight rules

The rules, as promises you can hold us to

  1. Written authorization first.

    From the system owner, before any testing starts. A system a vendor hosts for you needs the vendor’s permission too; we provide the letter and handle the paperwork with you.

§03 / The letter

What the authorization letter covers

The letter is short and specific. It is what turns a test into an authorized one, so every item below is filled in before we start.

Systems
The applications, APIs, hosts, accounts and AI assistants in scope, with their tools and the data sources they read.
Exclusions
What is out of scope, named as precisely as what is in it.
Window
The dates and hours of testing, with the time zone.
Our traffic
The addresses we test from, so your team can tell our traffic from anyone else’s.
Test types
What is allowed and what needs a separate yes: production, load, anything destructive.
Contacts
Named people on both sides, with phone numbers, for questions and for the stop rule.
Third parties
Written permission from every vendor that hosts a system in scope.
Signature
Someone with the authority to grant it, on your side.

§04 / Documents

Templates

  • Authorization letterThe letter above, as a template.Not published yet
  • Mutual NDAConfidentiality both ways, before the scoping call goes into detail.Not published yet
  • Data processing agreementHow we handle personal data in your systems while we test them (verwerkersovereenkomst).Not published yet

These templates go up here once a lawyer has reviewed them.

Ready when you are

The method explains what happens inside these rules. The form starts with what you want tested.

Your side of the preparation, step by step: how to prepare for a penetration test.