Terms of engagement

These terms summarise how we work. They are not a substitute for the signed statement of work and authorisation letter that govern each engagement.

1. Authorisation

No testing of any kind begins until a written scope and authorisation letter has been signed by a person entitled to authorise testing of the systems concerned. Where systems are hosted by a third party, the client is responsible for obtaining that provider's permission where their terms require it.

2. Scope

Testing is strictly limited to the targets listed in the scope document. Anything not listed is out of scope. Scope changes require written agreement from both parties.

3. Conduct of testing

We use non-destructive techniques by default. Denial-of-service testing, physical intrusion and social engineering are performed only when explicitly included in scope. Testing stops immediately on request from an authorised client contact.

4. Confidentiality

All information obtained during an engagement is treated as confidential. Findings, reports and client identities are never disclosed, published or used as marketing material without the client's prior written consent.

5. Handling of data and findings

Client data is collected only where necessary to demonstrate impact, is stored encrypted, and is securely destroyed after the retention period agreed in the statement of work. Critical findings are escalated to the client the same day they are confirmed.

6. Reporting and retest

Each engagement produces a written report and a live debrief. A retest of the reported findings is included at no additional cost within 30 days of report delivery.

7. Limitations

A penetration test is a point-in-time assessment limited by scope and duration. It cannot guarantee that no vulnerabilities remain, and it does not transfer responsibility for the security of the client's systems.

Loading...
Back to top