Rules of engagement / v1.0
Rules of engagement: we only test with written permission.
Rules of engagement are the written terms of a penetration test: what may be tested, when, how and by whom, and how to stop it. Ours start from one rule: we test only what the owner has authorized in writing1. The other seven say how we behave inside that permission.
§02 / Eight rules
The rules, as promises you can hold us to
Written authorization first.
From the system owner, before any testing starts. A system a vendor hosts for you needs the vendor’s permission too; we provide the letter and handle the paperwork with you.
§03 / The letter
What the authorization letter covers
The letter is short and specific. It is what turns a test into an authorized one, so every item below is filled in before we start.
- Systems
- The applications, APIs, hosts, accounts and AI assistants in scope, with their tools and the data sources they read.
- Exclusions
- What is out of scope, named as precisely as what is in it.
- Window
- The dates and hours of testing, with the time zone.
- Our traffic
- The addresses we test from, so your team can tell our traffic from anyone else’s.
- Test types
- What is allowed and what needs a separate yes: production, load, anything destructive.
- Contacts
- Named people on both sides, with phone numbers, for questions and for the stop rule.
- Third parties
- Written permission from every vendor that hosts a system in scope.
- Signature
- Someone with the authority to grant it, on your side.
§04 / Documents
Templates
- Authorization letterThe letter above, as a template.Not published yet
- Mutual NDAConfidentiality both ways, before the scoping call goes into detail.Not published yet
- Data processing agreementHow we handle personal data in your systems while we test them (verwerkersovereenkomst).Not published yet
These templates go up here once a lawyer has reviewed them.
Ready when you are
The method explains what happens inside these rules. The form starts with what you want tested.
Your side of the preparation, step by step: how to prepare for a penetration test.